Cybersecurity News

The latest threats, breaches, and security insights from top industry sources — updated every 30 minutes.

70 articles across 3 sources
All Sources Cybersecurity News The Hacker News Cybersecurity Dive
Showing 1–18 of 70 articles Refreshes every 30 min
Cybersecurity News
BIND DNS Servers Hit by 14 Security Flaws Enabling Cache Poisoning and Remote Crashes
Internet Systems Consortium has released security updates for BIND 9 after identifying 14 vulnerabilities that could allow attackers to poison DNS caches, crash exposed servers …
Cybersecurity News
CISA Wants Defenders to Plant Fake Credentials and Systems to Catch Hackers
CISA has urged organizations to deploy fake credentials, systems, files, and data assets inside their environments to expose attackers after an initial compromise. The agency pu…
Cybersecurity Dive
Manufacturers make patching progress, but identity management still major weakness
Misconfigurations remain widespread in the manufacturing sector, including internet-accessible remote-access software, a new report found.
Cybersecurity News
Hacked Thai College Website Abused to Redirect Google Searchers to Illegal Online Casino
A compromised Thai college website was quietly turned into a springboard for an illegal online casino, according to new findings from anti-fraud platform ADEX, which says the ca…
Cybersecurity News
Hackers Turn Telegram Into a Command Center for HEAVYGRAM Surveillance Malware
HEAVYGRAM is a Windows surveillance backdoor that turns Telegram into an operational command center for attackers. Rather than relying on a dedicated server, it uses bots, accou…
The Hacker News
Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday. An attack…
Cybersecurity News
SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia
SilkParasite is a cyberespionage operation aimed at government, energy and telecommunications interests in Central Asia. New infrastructure analysis indicates that the activity …
Cybersecurity News
North Korean IT Workers Use AI and Remote Desktop Tools to Fake Technical Interviews
North Korean operators are using artificial intelligence, remote-control software, and hired stand-ins to make fraudulent job candidates look genuine during technical interviews…
The Hacker News
Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar
A new CVE drops. Your scanner finds it. The severity score looks ugly. But that still does not answer the question that matters: Can it actually be exploited in your environment…
Cybersecurity News
FamousSparrow Exploits Public-Facing Exchange Servers to Deploy SparroWocky Backdoor
FamousSparrow has introduced a new backdoor called SparroWocky after breaking into public-facing Microsoft Exchange servers. The campaign shows how a known espionage group can t…
Cybersecurity News
Critical Docker Sandbox Vulnerabilities Enable Malicious Guests to Escape Isolated microVM Workspaces
Docker patched two serious vulnerabilities in Docker Sandboxes that could let a malicious guest workload break out of its intended shared workspace and access sensitive host-sid…
Cybersecurity News
Cisco Warns of Critical ISE 0-Day Vulnerability Exploited in Attacks
Cisco has issued an urgent security advisory for a critical zero-day vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). Th…
Cybersecurity News
One Compromised Kubernetes Node Can Expose Every Workload Identity Running on It
A Kubernetes node becomes an identity breach point when an attacker gains root access. Research shows a hostile process can impersonate other workloads and obtain their credenti…
The Hacker News
CISO's Expert Guide to Agentic Pentesting for Websites
Attackers now weaponize new vulnerabilities in about five days (Mandiant, part of Google Cloud). The median organization takes 43 days to patch one (Verizon DBIR 2026). A new fr…
The Hacker News
China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America
The China-aligned state-sponsored threat actor known as FamousSparrow has been observed deploying a previously unreported backdoor called SparroWocky in attacks targeting multip…
The Hacker News
OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized Uploads
OpenAI on Wednesday disclosed six new instances of "unexpected or concerning model behavior" that took place over the past six months, while sharing a new framework for reportin…
The Hacker News
BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS
The Internet Systems Consortium (ISC) has released BIND 9.20.29 and 9.21.26 to fix fourteen security flaws it disclosed on 16 September in BIND 9, its open-source DNS server…
The Hacker News
Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records
A security breach at Gyazo, Helpfeel's image-sharing service, exposed about 23.62 million user records, including email addresses and password hashes, the Kyoto-based company sa…