nestdaddy
Web World Financial Country Tech
Showing 20 of 92 tech news articles in Cybersecurity
Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records Cybersecurity
Thehackernews 4 days ago

Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records

A security breach at Gyazo, Helpfeel's image-sharing service, exposed about 23.62 million user records, including email addresses and password hashes, the Kyoto-based company said in a notice published Wednesday. It also exposed about 490 million image metadata records, mostly for images from Janua

Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks Cybersecurity
Thehackernews 4 days ago

Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

Cisco has warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation. The vulnerability, tracked as CVE-2026-76460 (CVSS score: 10.0), could allow an unauthenticated, remote attacker to bypass authentication. "This vulnerabilit

U.S. Seizes NightmareStresser Domains Linked to Hundreds of Thousands of DDoS Attacks Cybersecurity
Thehackernews 4 days ago

U.S. Seizes NightmareStresser Domains Linked to Hundreds of Thousands of DDoS Attacks

The U.S. Department of Justice (DoJ) on Tuesday announced the court-authorized seizure of internet domains associated with a distributed denial-of-service (DDoS)-for-hire service known as NightmareStresser. The domains in question are: nightmare-stresser[.]com and nightmarestresser[.]org. Visitors

AI Security Spending Jumps as Fear Outpaces Proof of Value Cybersecurity
Darkreading 4 days ago

AI Security Spending Jumps as Fear Outpaces Proof of Value

CISOs are not waiting for AI to prove its cybersecurity value before investing in the technology. Is it the right move?

Cybersecurity
Krebsonsecurity 4 days ago

Data Broker Radaris Loses Domains in Privacy Fight

The consumer data broker Radaris.com has long had a reputation for ignoring requests to remove personal information from its vast empire of people-search services online. That reputation caught up with the company recently in a lawsuit alleging Radaris violated a New Jersey privacy law that provides

Fighting Your Dragons Through Tough Tech Times Cybersecurity
Darkreading 4 days ago

Fighting Your Dragons Through Tough Tech Times

Cybersecurity industry veteran Hal Pomeranz gives a pep talk on career anxiety and self-doubt and shares how to build meaningful connections during historical tech industry downturns.

BragJack Attack Can Turn a Browser's Agentic AI Against It Cybersecurity
Darkreading 4 days ago

BragJack Attack Can Turn a Browser's Agentic AI Against It

A new type of attack hijacks the AI assistant built directly into various browsers to access sensitive information, execute malicious actions, and exfiltrate data.

Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution Cybersecurity
Thehackernews 4 days ago

Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution

A critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under active exploitation. The vulnerability in question is CVE-2026-89026 (CVSS v3.1 score: 9.8/CVSS v4.0 score: 9.3), which can allow an unauthenticated remote at

Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers Cybersecurity
Thehackernews 4 days ago

Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers

Enterprises in Russia have emerged as the target of three threat activity clusters tracked as NightEagle, Hacking Cat, and Toy Ghouls, according to multiple reports from Kaspersky. The cybersecurity vendor said it has identified attacks mounted by NightEagle (aka APT-Q-95), a threat actor known to

One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude Cybersecurity
Thehackernews 4 days ago

One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude

Security researchers at Forever Security have shown that one ordinary browser extension could take control of the AI assistants built into five Chromium-based products: Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon and the Claude in Chrome extension. Once the extension was ins

Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories Cybersecurity
Thehackernews 4 days ago

Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories

Mandiant says an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider and later spread Shai-Hulud across about 100 internal code repositories. Before the repository spread, the assistant recommended software that the attacker had poisoned, and the rec

Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix Cybersecurity
Thehackernews 4 days ago

Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix

Parallels Desktop for Mac has a flaw that lets an ordinary local account run code as root, the highest level of access on a Mac, software company JFrog said this week. The attack needs code already running on the machine as a normal user, so it does not work over the network. JFrog says the fix is

N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security Cybersecurity
Thehackernews 4 days ago

N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security

N0va is targeting organizations across North America and Europe with phishing campaigns that impersonate trusted services and abuse legitimate authentication flows. Successful attacks can give threat actors access to valid accounts without relying on obvious malware activity. From there, a single c

Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation Cybersecurity
Thehackernews 4 days ago

Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation

Google has disclosed that a high-severity security flaw in its Pixel Cellular Modem has come under exploitation in the wild. The vulnerability, tracked as CVE-2026-58704 (CVSS score: 8.0), is a privilege escalation flaw. "In Cellular Modem, there is a possible permission bypass due to a logic erro

Threat Intelligence Alone Won't Close the Exploitation Gap Cybersecurity
Thehackernews 4 days ago

Threat Intelligence Alone Won't Close the Exploitation Gap

A leaked credential shows up in a criminal marketplace, or a vulnerability gets a disclosure advisory, and either one can be weaponized against a real target before most security teams have triaged the alert. Attackers are combining that kind of intelligence with AI-assisted exploitation to accelera

Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks Cybersecurity
Thehackernews 4 days ago

Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks

Acronis has warned that a high-severity security flaw in its Backup plugin for cPanel and Web Host Manager (WHM) deployments has been exploited in the wild. The vulnerability, tracked as CVE-2026-87886 (CVSS score: 7.8), is described as a case of local privilege escalation due to insecure file perm

Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells Cybersecurity
Thehackernews 5 days ago

Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more than 6,000 active installs. "This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote

Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens Cybersecurity
Thehackernews 5 days ago

Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens

A critical security flaw in WSO2 API Manager has come under active exploitation in the wild, according to findings from watchTowr. The vulnerability, tracked as CVE-2026-5430 (CVSS score: 9.8/10.0), is a case of improper verification of a cryptographic signature that could result in account takeove

Cyber Op Targets South Korean Media & Automotive Sectors Cybersecurity
Darkreading 5 days ago

Cyber Op Targets South Korean Media & Automotive Sectors

A likely North Korean advanced persistent threat (APT) group used a previously undocumented Linux espionage toolkit to compromise load balancers, gain access to communications, and further exploit networks.

Microsoft Issues Emergency Fixes After Massive Patch Tuesday Cybersecurity
Darkreading 5 days ago

Microsoft Issues Emergency Fixes After Massive Patch Tuesday

You can't make an omelet without breaking a few eggs, and you can't patch nearly 1,000 CVEs without a few glitches.

Link copied to clipboard!