CyberLabRSS

πŸ”’
❌ About FreshRSS
There are new available articles, click to refresh the page.
☐ β˜† βœ‡ SecurityWeek

Organizations Warned of Exploited Windows, Adobe Acrobat Vulnerabilities

By: Ionut Arghire β€” April 14th 2026 at 08:57

The security defects allow attackers to escalate privileges and execute arbitrary code remotely.

The post Organizations Warned of Exploited Windows, Adobe Acrobat Vulnerabilities appeared first on SecurityWeek.

☐ β˜† βœ‡ SecurityWeek

Booking.com Says Hackers Accessed User Information

By: Eduard Kovacs β€” April 13th 2026 at 14:25

The online travel platform has not said how many customers’ booking information was exposed, but said the issue has been contained.Β 

The post Booking.com Says Hackers Accessed User Information appeared first on SecurityWeek.

☐ β˜† βœ‡ SecurityWeek

BrowserGate: Claims of LinkedIn β€˜Spying’ Clash With Security Research Findings

By: Kevin Townsend β€” April 13th 2026 at 14:00

Claims that β€œMicrosoft is running one of the largest corporate espionage operations in modern history” face scrutiny as researchers analyze LinkedIn’s browser extension probing

The post BrowserGate: Claims of LinkedIn β€˜Spying’ Clash With Security Research Findings appeared first on SecurityWeek.

☐ β˜† βœ‡ SecurityWeek

OpenAI Impacted by North Korea-Linked Axios Supply Chain Hack

By: Eduard Kovacs β€” April 13th 2026 at 12:34

The AI giant is taking action after determining that a macOS code signing certificate may have been compromised.

The post OpenAI Impacted by North Korea-Linked Axios Supply Chain Hack appeared first on SecurityWeek.

☐ β˜† βœ‡ SecurityWeek

International Operation Targets Multimillion-Dollar Crypto Theft Schemes

By: Eduard Kovacs β€” April 13th 2026 at 11:34

Law enforcement in the US, UK and Canada identified more than $45 million in cryptocurrency and froze $12 million.

The post International Operation Targets Multimillion-Dollar Crypto Theft Schemes appeared first on SecurityWeek.

☐ β˜† βœ‡ SecurityWeek

CPUID Hacked to Serve Trojanized CPU-Z and HWMonitor Downloads

By: Eduard Kovacs β€” April 13th 2026 at 10:52

Download links were replaced by a Russian-speaking threat actor to distribute a recently emerged malware named STX RAT.

The post CPUID Hacked to Serve Trojanized CPU-Z and HWMonitor Downloads appeared first on SecurityWeek.

☐ β˜† βœ‡ SecurityWeek

Fake Claude Website Distributes PlugX RAT

By: Ionut Arghire β€” April 13th 2026 at 09:52

The malware mimics the legitimate Anthropic installation, relies on DLL sideloading, and cleans up after itself.

The post Fake Claude Website Distributes PlugX RAT appeared first on SecurityWeek.

☐ β˜† βœ‡ SecurityWeek

Gmail Brings End-to-End Encryption to Android and iOS for Enterprise Users

By: Ionut Arghire β€” April 13th 2026 at 08:31

The feature allows enterprise users to compose and read end-to-end encrypted messages natively on their mobile devices.

The post Gmail Brings End-to-End Encryption to Android and iOS for Enterprise Users appeared first on SecurityWeek.

☐ β˜† βœ‡ SecurityWeek

Adobe Patches Reader Zero-Day Exploited for Months

By: Eduard Kovacs β€” April 12th 2026 at 07:45

The vulnerability is tracked as CVE-2026-34621 and Adobe has confirmed that it can be exploited for arbitrary code execution.

The post Adobe Patches Reader Zero-Day Exploited for Months appeared first on SecurityWeek.

☐ β˜† βœ‡ SecurityWeek

In Other News: Cyberattack Stings Stryker, Windows Zero-Day, China Supercomputer Hack

By: SecurityWeek News β€” April 10th 2026 at 14:44

Other noteworthy stories that might have slipped under the radar: Jones Day hacked, Internet Bug Bounty program paused due to AI, new Mac stealer malware.

The post In Other News: Cyberattack Stings Stryker, Windows Zero-Day, China Supercomputer Hack appeared first on SecurityWeek.

☐ β˜† βœ‡ SecurityWeek

Juniper Networks Patches Dozens of Junos OS Vulnerabilities

By: Ionut Arghire β€” April 10th 2026 at 13:44

A critical-severity flaw could be exploited remotely, without authentication, to take over a vulnerable device.

The post Juniper Networks Patches Dozens of Junos OS Vulnerabilities appeared first on SecurityWeek.

☐ β˜† βœ‡ SecurityWeek

Industry Reactions to Iran Hacking ICS in Critical Infrastructure: Feedback Friday

By: SecurityWeek News β€” April 10th 2026 at 12:41

The US government has warned that Iran-linked hackers are manipulating PLCs and SCADA systems to cause disruption.

The post Industry Reactions to Iran Hacking ICS in Critical Infrastructure: Feedback Friday appeared first on SecurityWeek.

☐ β˜† βœ‡ SecurityWeek

Orthanc DICOM Vulnerabilities Lead to Crashes, RCE

By: Ionut Arghire β€” April 10th 2026 at 11:53

Attackers could exploit these vulnerabilities in denial-of-service, information disclosure, and arbitrary code execution attacks.

The post Orthanc DICOM Vulnerabilities Lead to Crashes, RCE appeared first on SecurityWeek.

☐ β˜† βœ‡ SecurityWeek

Chrome 147 Patches 60 Vulnerabilities, Including Two Critical Flaws Worth $86,000

By: Eduard Kovacs β€” April 10th 2026 at 10:44

The critical vulnerabilities affect Chrome’s WebML component and they have been reported by anonymous researchers.

The post Chrome 147 Patches 60 Vulnerabilities, Including Two Critical Flaws Worth $86,000 appeared first on SecurityWeek.

☐ β˜† βœ‡ SecurityWeek

MITRE Releases Fight Fraud Framework

By: Ionut Arghire β€” April 10th 2026 at 09:51

The document provides a behavior-based model of the tactics and techniques employed by fraudsters.

The post MITRE Releases Fight Fraud Framework appeared first on SecurityWeek.

☐ β˜† βœ‡ SecurityWeek

Critical Marimo Flaw Exploited Hours After Public Disclosure

By: Ionut Arghire β€” April 10th 2026 at 09:12

Within nine hours, a hacker built an exploit from the unauthenticated bug’s advisory and started using it in the wild.

The post Critical Marimo Flaw Exploited Hours After Public Disclosure appeared first on SecurityWeek.

☐ β˜† βœ‡ SecurityWeek

Google Rolls Out Cookie Theft Protections in Chrome

By: Ionut Arghire β€” April 10th 2026 at 07:50

New Device Bound Session Credentials render stolen session cookies unusable by cryptographically binding authentication.

The post Google Rolls Out Cookie Theft Protections in Chrome appeared first on SecurityWeek.

☐ β˜† βœ‡ SecurityWeek

Microsoft Finds Vulnerability Exposing Millions of Android Crypto Wallet Users

By: Eduard Kovacs β€” April 10th 2026 at 07:33

The security hole affected an EngageLab SDK and it was reported by Microsoft to the vendor one year ago.

The post Microsoft Finds Vulnerability Exposing Millions of Android Crypto Wallet Users appeared first on SecurityWeek.

☐ β˜† βœ‡ SecurityWeek

Apple Intelligence AI Guardrails Bypassed in New Attack

By: Eduard Kovacs β€” April 9th 2026 at 13:43

RSAC researchers hacked Apple Intelligence using the Neural Exect method and Unicode manipulation.

The post Apple Intelligence AI Guardrails Bypassed in New Attack appeared first on SecurityWeek.

☐ β˜† βœ‡ SecurityWeek

Can We Trust AI? No – But Eventually We Must

By: Kevin Townsend β€” April 9th 2026 at 13:30

From hallucinations and bias to model collapse and adversarial abuse, today’s AI is built on probability rather than truth, yet enterprises are deploying it at speed without fully understanding the risks.

The post Can We Trust AI? No – But Eventually We Must appeared first on SecurityWeek.

☐ β˜† βœ‡ SecurityWeek

Google API Keys in Android Apps Expose Gemini Endpoints to Unauthorized Access

By: Ionut Arghire β€” April 9th 2026 at 12:26

Dozens of such keys can be extracted from apps’ decompiled code to gain access to all Gemini endpoints.

The post Google API Keys in Android Apps Expose Gemini Endpoints to Unauthorized Access appeared first on SecurityWeek.

☐ β˜† βœ‡ SecurityWeek

Palo Alto Networks, SonicWall Patch High-Severity Vulnerabilities

By: Ionut Arghire β€” April 9th 2026 at 11:58

The bugs could allow attackers to modify protected resources and escalate their privileges to administrator.

The post Palo Alto Networks, SonicWall Patch High-Severity Vulnerabilities appeared first on SecurityWeek.

☐ β˜† βœ‡ SecurityWeek

The Hidden ROI of Visibility: Better Decisions, Better Behavior, Better Security

By: Joshua Goldfarb β€” April 9th 2026 at 11:00

Beyond monitoring and compliance, visibility acts as a powerful deterrent, shaping user behavior, improving collaboration, and enabling more accurate, data-driven security decisions.

The post The Hidden ROI of Visibility: Better Decisions, Better Behavior, Better Security appeared first on SecurityWeek.

☐ β˜† βœ‡ SecurityWeek

Google Warns of New Campaign Targeting BPOs to Steal Corporate Data

By: Ionut Arghire β€” April 9th 2026 at 09:44

Tracked as UNC6783, the threat actor is likely linked to Mr. Raccoon, the hacker behind the alleged theft of Adobe data from a BPO.

The post Google Warns of New Campaign Targeting BPOs to Steal Corporate Data appeared first on SecurityWeek.

☐ β˜† βœ‡ SecurityWeek

Adobe Reader Zero-Day Exploited for Months: Researcher

By: Eduard Kovacs β€” April 9th 2026 at 08:44

Reputable researcher Haifei Li has come across what appears to be a PDF designed to exploit an unpatched vulnerability.

The post Adobe Reader Zero-Day Exploited for Months: Researcher appeared first on SecurityWeek.

☐ β˜† βœ‡ SecurityWeek

300,000 People Impacted by Eurail Data Breach

By: Ionut Arghire β€” April 9th 2026 at 08:28

In December 2025, hackers stole names and passport numbers from the European travel company’s network.

The post 300,000 People Impacted by Eurail Data Breach appeared first on SecurityWeek.

☐ β˜† βœ‡ SecurityWeek

$3.6 Million Stolen in Bitcoin Depot Hack

By: Eduard Kovacs β€” April 9th 2026 at 06:41

A hacker transferred more than 50 bitcoin from the Bitcoin ATM operator’s wallets after stealing credentials.Β 

The post $3.6 Million Stolen in Bitcoin Depot Hack appeared first on SecurityWeek.

☐ β˜† βœ‡ SecurityWeek

Shaky Ceasefire Unlikely to Stop Cyberattacks From Iran-Linked Hackers for Long

By: Associated Press β€” April 9th 2026 at 01:22

Hackers vowed to revive its efforts against America when the time was right β€” demonstrating how digital warfare has become ingrained in military conflict.

The post Shaky Ceasefire Unlikely to Stop Cyberattacks From Iran-Linked Hackers for Long appeared first on SecurityWeek.

☐ β˜† βœ‡ SecurityWeek

Data Leakage Vulnerability Patched in OpenSSL

By: Eduard Kovacs β€” April 8th 2026 at 15:37

A total of seven vulnerabilities, most of which can be exploited for DoS attacks, have been patched in OpenSSL.

The post Data Leakage Vulnerability Patched in OpenSSL appeared first on SecurityWeek.

☐ β˜† βœ‡ SecurityWeek

RCE Bug Lurked in Apache ActiveMQ Classic for 13 Years

By: Ionut Arghire β€” April 8th 2026 at 14:30

The vulnerability requires authentication for successful exploitation, but another flaw exposes the Jolokia API without authentication.

The post RCE Bug Lurked in Apache ActiveMQ Classic for 13 Years appeared first on SecurityWeek.

☐ β˜† βœ‡ SecurityWeek

FBI: Cybercrime Losses Neared $21 Billion in 2025

By: Ionut Arghire β€” April 8th 2026 at 13:32

The FBI received over 1 million complaints of malicious activity in 2025, with investment, BEC, and tech support scams causing the highest losses.

The post FBI: Cybercrime Losses Neared $21 Billion in 2025 appeared first on SecurityWeek.

☐ β˜† βœ‡ SecurityWeek

Massachusetts Hospital Diverts Ambulances as Cyberattack Causes DisruptionΒ 

By: Eduard Kovacs β€” April 8th 2026 at 12:31

Signature Healthcare was forced to cancel some services, and pharmacies are unable to fill prescriptions due to the hacker attack.

The post Massachusetts Hospital Diverts Ambulances as Cyberattack Causes DisruptionΒ  appeared first on SecurityWeek.

☐ β˜† βœ‡ SecurityWeek

Evasive Masjesu DDoS Botnet Targets IoT Devices

By: Ionut Arghire β€” April 8th 2026 at 11:49

Focused on persistence, the botnet does not engage in widespread infection and avoids blacklisted IPs and critical infrastructure entities.

The post Evasive Masjesu DDoS Botnet Targets IoT Devices appeared first on SecurityWeek.

☐ β˜† βœ‡ SecurityWeek

Hackers Targeting Ninja Forms Vulnerability That Exposes WordPress Sites to Takeover

By: Ionut Arghire β€” April 8th 2026 at 11:20

The vulnerability allows hackers to upload arbitrary files to a site’s server and achieve remote code execution.

The post Hackers Targeting Ninja Forms Vulnerability That Exposes WordPress Sites to Takeover appeared first on SecurityWeek.

☐ β˜† βœ‡ SecurityWeek

US Disrupts Russian Espionage Operation Involving Hacked Routers and DNS Hijacking

By: Eduard Kovacs β€” April 8th 2026 at 10:54

The APT28 threat group exploited vulnerable TP-Link and MikroTik routers to conduct adversary-in-the-middle (AitM) attacks.

The post US Disrupts Russian Espionage Operation Involving Hacked Routers and DNS Hijacking appeared first on SecurityWeek.

☐ β˜† βœ‡ SecurityWeek

Iran-Linked Hackers Disrupt US Critical Infrastructure via PLC Attacks

By: Mike Lennon β€” April 8th 2026 at 02:57

Federal agencies warn attackers are manipulating PLC and SCADA systems across multiple sectors, triggering operational disruptions and raising concerns over broader OT targeting.

The post Iran-Linked Hackers Disrupt US Critical Infrastructure via PLC Attacks appeared first on SecurityWeek.

☐ β˜† βœ‡ SecurityWeek

AnthropicΒ Unveils β€˜Claude Mythos’ – A Cybersecurity Breakthrough That Could Also Supercharge Attacks

By: Kevin Townsend β€” April 7th 2026 at 18:39

New AI model drives Project Glasswing, a effort to secure critical software before advanced capabilities fall into the wrong hands.

The post AnthropicΒ Unveils β€˜Claude Mythos’ – A Cybersecurity Breakthrough That Could Also Supercharge Attacks appeared first on SecurityWeek.

☐ β˜† βœ‡ SecurityWeek

The New Rules of Engagement: Matching Agentic Attack Speed

By: Nadir Izrael β€” April 7th 2026 at 16:40

The cybersecurity response to AI-enabled nation-state threats cannot be incremental. It must be architectural.

The post The New Rules of Engagement: Matching Agentic Attack Speed appeared first on SecurityWeek.

☐ β˜† βœ‡ SecurityWeek

Trent AI Emerges From Stealth With $13 Million in Funding

By: Ionut Arghire β€” April 7th 2026 at 16:34

The startup has created a layered security solution aiming to secure AI agents throughout their entire lifecycle.

The post Trent AI Emerges From Stealth With $13 Million in Funding appeared first on SecurityWeek.

☐ β˜† βœ‡ SecurityWeek

Critical Flowise Vulnerability in Attacker Crosshairs

By: Ionut Arghire β€” April 7th 2026 at 15:34

The improper validation of user-supplied JavaScript code allows attackers to execute arbitrary code and access the file system.

The post Critical Flowise Vulnerability in Attacker Crosshairs appeared first on SecurityWeek.

☐ β˜† βœ‡ SecurityWeek

Severe StrongBox Vulnerability Patched in Android

By: Eduard Kovacs β€” April 7th 2026 at 14:23

A critical DoS vulnerability in the Framework component of Android has also been fixed with the latest update.

The post Severe StrongBox Vulnerability Patched in Android appeared first on SecurityWeek.

☐ β˜† βœ‡ SecurityWeek

GrafanaGhost: Attackers Can Abuse Grafana to Leak Enterprise Data

By: Ionut Arghire β€” April 7th 2026 at 13:58

By targeting Grafana’s AI components, attackers can point to external resources and inject indirect prompts to bypass safeguards.

The post GrafanaGhost: Attackers Can Abuse Grafana to Leak Enterprise Data appeared first on SecurityWeek.

☐ β˜† βœ‡ SecurityWeek

Webinar Today: Why Automated Pentesting Alone Is Not Enough

By: SecurityWeek News β€” April 7th 2026 at 13:19

Join the live diagnostic session to expose hidden coverage gaps and shift from flawed tool-level evaluations to a comprehensive, program-level validation discipline.

The post Webinar Today: Why Automated Pentesting Alone Is Not Enough appeared first on SecurityWeek.

☐ β˜† βœ‡ SecurityWeek

GPUBreach: Root Shell Access Achieved via GPU Rowhammer AttackΒ 

By: Eduard Kovacs β€” April 7th 2026 at 11:31

Researchers have demonstrated that GPU Rowhammer attacks can be used to escalate privileges.

The post GPUBreach: Root Shell Access Achieved via GPU Rowhammer AttackΒ  appeared first on SecurityWeek.

☐ β˜† βœ‡ SecurityWeek

Medusa Ransomware Fast to Exploit Vulnerabilities, Breached Systems

By: Ionut Arghire β€” April 7th 2026 at 10:52

The group is using zero-days, quickly weaponizes fresh bugs, and exfiltrates and encrypts data within days of initial access.

The post Medusa Ransomware Fast to Exploit Vulnerabilities, Breached Systems appeared first on SecurityWeek.

☐ β˜† βœ‡ SecurityWeek

German Police Unmask REvil Ransomware Leader

By: Ionut Arghire β€” April 7th 2026 at 09:24

Shchukin is accused of extorting more than $2 million as the head of the GandCrab and REvil ransomware operations.

The post German Police Unmask REvil Ransomware Leader appeared first on SecurityWeek.

☐ β˜† βœ‡ SecurityWeek

White House Seeks to Slash CISA Funding by $707 Million

By: Eduard Kovacs β€” April 7th 2026 at 08:29

The Trump administration says the FY2027 budget refocuses CISA on its core mission: protecting federal agencies and critical infrastructure.

The post White House Seeks to Slash CISA Funding by $707 Million appeared first on SecurityWeek.

☐ β˜† βœ‡ SecurityWeek

Wynn Resorts Says 21,000 Employees Affected by ShinyHunters Hack

By: Eduard Kovacs β€” April 7th 2026 at 06:05

The high-end casino and hotel operator has likely paid a ransom to avoid a data leak.

The post Wynn Resorts Says 21,000 Employees Affected by ShinyHunters Hack appeared first on SecurityWeek.

☐ β˜† βœ‡ SecurityWeek

Google DeepMind Researchers Map Web Attacks Against AI Agents

By: Ionut Arghire β€” April 6th 2026 at 15:32

A vulnerability named β€˜AI Agent Traps’ allows attackers to manipulate, deceive, and exploit visiting agents via malicious web content.

The post Google DeepMind Researchers Map Web Attacks Against AI Agents appeared first on SecurityWeek.

❌