Cybersecurity News
-
Cyberattacks Using Routine Actions to Exploit Trust
Security researchers are increasingly warning that cyberattacks no longer rely on obvious malware or suspicious downloads. Instead, many modern campaigns succeed by blending into routine, trusted workflows, the everyday actions people perform…
-
CarGurus Breach Impacts 12M+ Accounts
Have I Been Pwned, a security service website, has added CarGurus to its data breach database, confirming that the automotive marketplace was impacted by a data leak affecting over 12 million accounts.…
-
SolarWinds Serv-U 15.5.4 Fixes Four Critical RCE Vulnerabilities
SolarWinds has released Serv-U 15.5.4 with patches for multiple critical vulnerabilities as well as feature parity improvements in File Share amongst other updates. Serv-U is commonly deployed in managed file transfer contexts,…
-
Android Mental Health Apps With Millions of Installs Contain Hundreds of Security Gaps
Mental health apps are increasingly handling data that looks a lot like medical records mood logs, CBT notes, medication schedules, and in some cases indicators of self-harm. And new research by mobile…
-
Malicious OpenClaw Skills on Mac Turn AI Workflows Into a Delivery Channel
Security teams have spent the last two years adapting to prompt injection and LLM data leakage. Now there’s a more operational threat emerging with the weaponizing of AI agent ecosystems and using…
-
npm Software Supply Chain Attack Spreads via CI and AI Coding Tools
Security researchers at Socket‘s Threat Research have uncovered a new supply-chain attack that blends typosquatting, credential theft, and emerging attacks on AI-assisted developer tooling. The campaign, tracked as SANDWORM_MODE, is being described…
-
Social Ads Used to Promote Fake Windows 11 Updates That Deliver Malware
Hackers are abusing Facebook’s advertising platform to distribute fake Windows 11 download pages that deliver credential-stealing malware instead of legitimate updates. In a Malwarebytes security report, campaigns were found using paid Facebook…
-
Active Exploitation Observed in Critical BeyondTrust Vulnerability
Security research published by Palo Alto Networks’ Unit 42 has found active exploitation of a newly disclosed critical vulnerability affecting BeyondTrust’s Remote Support, a software used for privileged access and remote administration.…
-
PayPal Reports Extended Customer Data Exposure
According to customer notifications reviewed by BleepingComputer, PayPal disclosed a data exposure incident that led to the prolonged exposure of sensitive customer information for several months. The software misconfiguration affected the working…
