Cybersecurity News
Live intel feed from the top cybersecurity sources. Stay ahead of the latest threats, breaches, and vulnerabilities.
◈ Feed refreshes every 30 minutes automatically.
Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL
ServiceNow has released patches for four security flaws impacting the ServiceNow AI Platform, three of them rated 10.0 on the CVSS scoring system and exploitable, in certain circumstances, by an unauthenticated attacker.…
READ FULL ARTICLE ▸China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access
VulnCheck has disclosed two previously undocumented factory implants in firmware for routers built by Shenzhen Zhibotong Electronics (ZBT), each of which gives an unauthenticated remote attacker the ability to run comman…
READ FULL ARTICLE ▸ServiceNow warns of three max severity security vulnerabilities
ServiceNow released security patches for three new maximum-severity AI Platform vulnerabilities that can be exploited in code injection, SQL injection, and privilege escalation attacks. [...]
READ FULL ARTICLE ▸Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server
cPanel has released patches for a security flaw affecting domain parking and addon domain functionality in cPanel and WebHost Manager (WHM), which could allow code execution as the root user. The vulnerability, assigned…
READ FULL ARTICLE ▸Windows 11 KB5120998 update released with 35 changes and fixes
Microsoft released the KB5120998 preview cumulative update for Windows 11 versions 25H2 and 24H2, which comes with 35 changes, including improvements to the Start menu, taskbar, and Windows search. [...]
READ FULL ARTICLE ▸PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions
PaperCut has alerted customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. The company has released an…
READ FULL ARTICLE ▸APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations
Cybersecurity researchers have flagged a fresh set of campaigns targeting government and diplomatic organizations in Romania, Spain, and Türkiye between late September 2025 and early April 2026. These campaigns, per Rec…
READ FULL ARTICLE ▸Some Malicious PE Stats, (Thu, Aug 27th)
During my last FOR610 session, a student asked me if I had some statistics in mind about the compilers used to generate malicious PE files? A couple of months ago, I shared some stats about the trend in 64bits VS. 3…
READ FULL ARTICLE ▸ISC Stormcast For Friday, August 28th, 2026 https://isc.sans.edu/podcastdetail/10072, (Fri, Aug 28th)
READ FULL ARTICLE ▸Nearly 700 rogue AI agents coordinated in the Hugging Face attack
New details about the July attack on Hugging Face reveal that hundreds of AI agents driven by OpenAI's internal IM1 model coordinated the compromise through an unauthorized message board. [...]
READ FULL ARTICLE ▸OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face
OpenAI on Wednesday revealed that reward hacking was a key driver behind the artificial intelligence (AI)-powered hack of Hugging Face last month, adding that it found evidence of misaligned behavior as early as late May…
READ FULL ARTICLE ▸PaperCut warns of NG, MF flaw exploited in zero-day attacks
PaperCut is warning that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. [...]
READ FULL ARTICLE ▸Manchester Airports Group says hackers stole travelers' data
The Manchester Airports Group (MAG) disclosed that hackers breached its systems and stole customer data, including Wi-Fi sign-ups from Manchester, Stansted, and East Midlands airports. [...]
READ FULL ARTICLE ▸How Threat Research and MDR Help SMBs Build a Defensive Edge
Threat research gives security teams insight into how attackers operate, while MDR turns that intelligence into faster detection and response. ESET explains how combining threat intelligence, continuous monitoring, and h…
READ FULL ARTICLE ▸Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. …
READ FULL ARTICLE ▸A polymorphic phishing page (that occasionally breaks itself), (Thu, Aug 27th)
As I've mentioned before in some of my diaries, from time to time, I like to go over phishing messages that get caught in my various spam traps or sent to us here at the Internet Storm Center.
READ FULL ARTICLE ▸ISC Stormcast For Thursday, August 27th, 2026 https://isc.sans.edu/podcastdetail/10070, (Thu, Aug 27th)
READ FULL ARTICLE ▸Who Has Admin Rights in your Entra ID Directory?, (Wed, Aug 26th)
A common thing that folks should "worry" about in Entra (or any platform really) is "who has rights to administer"&#;x26;#;x3f;&#;x26;#;xc2;&#;x26;&#x…
READ FULL ARTICLE ▸ISC Stormcast For Wednesday, August 26th, 2026 https://isc.sans.edu/podcastdetail/10068, (Wed, Aug 26th)
READ FULL ARTICLE ▸Who’s Tracking You? Use This New Service to Find Out
It can be daunting to determine who's responsible for showing ads on the websites we visit, or who's harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily pa…
READ FULL ARTICLE ▸Microsoft Plugs Nearly 400 Security Holes
Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others tha…
READ FULL ARTICLE ▸Canadian Man Pleads Guilty in Snowflake Extortions
A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the…
READ FULL ARTICLE ▸Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connectio…
READ FULL ARTICLE ▸LG to Ban Residential Proxies from Smart TV Apps
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after …
READ FULL ARTICLE ▸Articles sourced from third-party feeds. Tech Savior does not author this content. Feed refreshes every hour.