Latest Cybersecurity News
View all →CSS Bomb Attacks Turn Malicious Emails Into Password-Stealing Keyloggers
A new class of email-based attacks that exploit ordinary CSS styling code to hijack webmail interfaces, spy on user activity, and even steal passwords in…
Storm-1175 Launches StormEncryptor Ransomware Attacks Using N-able Security Flaw
Microsoft Threat Intelligence has identified a new ransomware campaign attributed to the financially motivated threat actor Storm-1175 that began deploying a previously undocumented ransomware strain,…
18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers
Swati KhandelwalAug 07, 2026Linux / Vulnerability A use-after-free bug in Linux’s SCTP networking code can be turned into full root on a host, and Tencent…
Security Affairs newsletter Round 589 by Pierluigi Paganini – INTERNATIONAL EDITION
Security Affairs newsletter Round 589 by Pierluigi Paganini – INTERNATIONAL EDITION Pierluigi Paganini August 09, 2026 A new round of the weekly Security Affairs newsletter…
CTEM isn’t failing. It’s not being operationalized
Cybersecurity is full of frameworks, regulations, and directives that tell organizations what they should do. Zero Trust, NIST, CIS Controls, CMMC, DORA, NIS2, and now…
G2: Wiz Named #1 Cloud Detection and Response (CDR) Solution
We’re thrilled to announce that Wiz has been named the #1 Cloud Detection and Response (CDR) solution in G2’s Winter 2025 CDR Grid Report. Based…
Claude in Chrome Prompt Injection Steals Gmail Codes to Hijack Slack, X and Claude.ai Accounts
An indirect prompt injection vulnerability in Claude on Chrome can be exploited to steal email verification codes and hijack accounts on platforms like Slack, X, and Claude.ai.…
Russian Hackers Use AI Slopsquatting to Publish 700+ Malicious npm Packages
A large-scale supply chain attack has hit the npm registry, with a suspected Russian threat actor publishing more than 700 malicious packages in just 48…
UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
A recent wave of cyber attacks targeting financial services, private equity, and professional services has been attributed to a data extortion group known as UNC6671.…