Cybersecurity News
-
Expired Domains Can Become Cybersecurity Risks After They’re Re-Registered
Expired domain names may look abandoned, but many are quickly registered again, and their history can make them surprisingly valuable. New research from Infoblox Threat Intelligence found that roughly 50,000 previously registered…
-
Security Researchers Show Why Protecting Browser Cookies May Not Be Enough
Modern browsers have introduced stronger protections designed to make stolen login cookies harder for attackers to use. But new research from SpecterOps demonstrates another potential problem: instead of stealing the cookie itself,…
-
Apple Explains Threat Notifications for Mercenary Spyware Attacks
Apple has updated its guidance on how it alerts users who may be targeted by highly sophisticated mercenary spyware. In a support document published August 13, 2026, Apple explained that its Threat…
-
Cisco Patches Actively Exploited Firewall Flaw
Cisco published an advisory on Aug. 11 warning that a vulnerability in its firewall software allows an unauthenticated, remote attacker to force affected devices to reload unexpectedly, producing a denial-of-service condition. The…
-
Zoom Patches Annotation Vulnerability Chain Developed With AI Assistance
Zoom released patches on Aug. 11 for four vulnerabilities, three of which form an exploit chain in the company’s annotation feature that allows one meeting participant to execute code on another participant’s…
-
Over 700 Malicious Chrome VPN Extensions Routing Traffic
Socket’s Threat Research Team has identified 737 free VPN and proxy extensions in the Chrome Web Store that route users’ entire browser sessions through proxy infrastructure controlled by a single operator. The…
-
Fake Resume Malware Campaign Targets HR Departments
Cybersecurity researchers are warning about a new attack campaign targeting human resources departments with malicious job applications disguised as legitimate resumes. According to security research from Aryaka and reporting by Cybernews, attackers…
-
SQL Injection Flaw in Popular WordPress Plugin Exposes Over 400k Sites
A critical SQL injection vulnerability discovered in a widely used WordPress plugin has placed more than 400,000 websites at risk of database data exposure. Security researchers at Wordfence identified the flaw in…
-
Microsoft Releases April 2026 Windows Security Updates
Microsoft has released its March 2026 Patch Tuesday security updates, addressing 83 vulnerabilities across Windows, Office, SQL Server, Azure, and developer platforms. Among the fixes are eight critical vulnerabilities, along with two…
