radar.cysentrix

Archive

Page 3 of 26 — 1560 stories total

← Back to radar
The Hacker News

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

Threat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) code. The vulnerability in question is CVE-2026-55040 (CVSS score: 9.1), which refers to a critical security feature bypass that stems fro...

vulnerabilitymicrosoft EPSS 4%
Help Net Security

Four corporate investigation mistakes organizations make under pressure

In this Help Net Security video, Christine Gadsby, VP and Chief Security Advisor at BlackBerry, explains why corporate investigations go wrong before the forensic team arrives. The first hours matter more than leaders assume. Access gets granted, conversations start, and decis...

Help Net Security

DDoS attacks hit record scale as 1 Tbps+ campaigns become more common

DDoS attacks grew in scale during the first half of 2026, bringing larger traffic floods, shorter attack durations, and increasingly automated campaigns. Cloudflare’s H1 2026 DDoS Threat Report shows threat actors relying on multi-vector techniques and large-scale network-laye...

Help Net Security

Product showcase: Is this image real? Slop or Not investigates

Slop or Not is an AI text and image detector for iPhone and Mac that runs entirely offline, with no account required. It uses on-device AI models powered by the Apple Neural Engine to detect AI-generated content. According to a recent survey, 85% of people say they struggle to...

Help Net Security

Wireshark 4.6.8 patches 28 security bugs, nine in file parsers

Wireshark 4.6.8 fixes 28 security bugs in the protocol analyzer, and nine of them fire when someone opens a saved capture file. Those nine sit in file parsers, the code that reads a capture off disk before any dissection begins: pcapng, Endace ERF, Tektronix K12xx, BUSMASTER, ...

Security Affairs

CEVA Logistics Cyberattack Disrupts European Warehouses and Shipments

CEVA Logistics suffered a cyberattack disrupting European operations, with eight warehouses affected and shipments halted at impacted sites. CEVA Logistics suffered a cyberattack on July 29 that disrupted parts of its European operations. The incident impacted impacted eight w...

Security Affairs

China-Linked Hackers Use AI Agents in Autonomous Attack on Taiwan

China-linked hackers reportedly used eight AI agents to breach a government network, steal data and compromise accounts with minimal human oversight. Israeli cybersecurity firm Dream documented what looks like the first fully autonomous, end-to-end AI hacking operation against...

data breach
The Hacker News

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a never-before-seen backdoor targeting defense and aerospace companies across France, Germany, Brazil, ...

zero daymicrosoftapt
BleepingComputer

Lazarus hackers exploited Windows zero-day to target defense firms

North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation Dream Job campaign. [...]

vulnerabilityzero daymicrosoft Actively exploitedCVE-2026-68820 · EPSS <1%
SecurityWeek

SharePoint Vulnerability Exploited Shortly After PoC Release

The vulnerability was patched by Microsoft in July and CISA warned that it could end up being exploited in the wild. The post SharePoint Vulnerability Exploited Shortly After PoC Release appeared first on SecurityWeek.

vulnerabilityzero daymicrosoft
SANS Internet Storm Center

Linux Kernel Process Accounting, (Wed, Aug 12th)

A couple of days ago, Xavier posted about Atuin to gain more insight into the command history. Atuin does a great job of better organizing what is usually handled by "bash&#;x26;#;x5f;history"&#;x26;#;xc2;&#;x26;#;xa0;and collecting meaningful additional data. Our reader David...

BleepingComputer

The Threat Hiding in Your Hiring Process: How Fake Remote Workers Get In

Fake remote workers can exploit gaps between hiring checks, device delivery, and account access to enter organizations under false identities. Specops Software explains how document verification and biometric liveness checks can help organizations confirm that the person recei...

Help Net Security

Deloitte strengthens AI governance to support trusted enterprise adoption

Deloitte has expanded AI Controls and Assurance services and solutions designed to help organizations confidently adopt, scale and govern AI across the enterprise. From early exploration to enterprise deployment, Deloitte’s enhanced services provide end-to-end support across t...

SecurityWeek

Mindgard Raises $30 Million to Protect AI Systems

The cybersecurity startup will use the fresh investment to scale its product, engineering, sales, and marketing teams. The post Mindgard Raises $30 Million to Protect AI Systems appeared first on SecurityWeek.

SecurityWeek

WhatsApp Unveils New Scam Alert Feature

Signal has also made a security announcement: an automatic key verification feature to complement its safety number system. The post WhatsApp Unveils New Scam Alert Feature appeared first on SecurityWeek.

SOCRadar

August 2026 Patch Tuesday: 421 Flaws, 3 Zero-Days

August 2026 Patch Tuesday: 421 Flaws, 3 Zero-Days Microsoft’s August 2026 Patch Tuesday release addresses 421 vulnerabilities , including three zero-days . One zero-day was exploited in the wild, while two others were pu

vulnerabilityzero daymicrosoft
CISA Alerts

Siemens RUGGEDCOM APE1808

View CSAF Summary Fortinet has published information on vulnerabilities in FortiOS. This advisory lists the related Siemens Industrial products. Siemens recommends to contact customer support for additional information, and follow Fortinet advisory for workarounds and mitigati...

vulnerability
Help Net Security

Lazarus hackers pair fake job offers with Windows zero-day exploit

The North Korea-linked Lazarus group is using fake job offers, trojanized PDF software and a Windows zero-day in attacks aimed primarily at the defense sector, Check Point researchers have found. The activity is part of Operation Dream Job, a long-running campaign in which att...

zero daymicrosoft
SOCRadar

SAP Commerce Cloud CVE-2026-58231 Requires Urgent Patching

SAP Commerce Cloud CVE-2026-58231 Requires Urgent Patching SAP has addressed CVE-2026-58231, a maximum-severity improper authorization vulnerability in the Data Hub Adapter for SAP Commerce Cloud. The flaw carries a CVSS

vulnerabilitycloud
The Hacker News

Enterprise Defenses Recovered at the Edge and Collapsed Inside

Enterprise defenses are tuned to catch the attacks that make noise. This year's data shows attackers winning by making none. According to Picus Labs' new Blue Report 2026, which measured more than 338 million real attack simulations across actual client production environments...

SecurityWeek

Ceva Logistics Operations Disrupted by Cyberattack

Affecting European contract logistics operations at eight Ceva warehouses, the incident caused shipment delays for multiple customers. The post Ceva Logistics Operations Disrupted by Cyberattack appeared first on SecurityWeek.

The Hacker News

Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

Adobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully exploited, could result in arbitrary code execution and privilege escalation. The most severe of the flaws are listed belo...

vulnerability
SOCRadar

Cisco ASA and FTD CVE-2026-20349 Exploited

Cisco ASA and FTD CVE-2026-20349 Exploited Cisco has confirmed active exploitation of CVE-2026-20349 , a High-severity denial-of-service (DoS) vulnerability affecting the Remote Access SSL VPN service in Cisco Secure Fir

vulnerability Actively exploitedCVE-2026-20349 · EPSS <1%
Schneier on Security

Prompt Injections for Defense

This seems to work: Researchers from Tracebit on Monday said they found that placing prompt injections alongside passwords, cryptographic keys, and other secrets stored on Amazon Web Services was often all that was needed to shut down attacks from AI hacking agents. The prompt...

SecurityWeek

Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack

LiteLLM was compromised through the Trivy hack and abused to distribute information-stealing malware to its users. The post Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack appeared first on SecurityWeek.

malwaresupply chain
Help Net Security

Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820)

Microsoft’s August 2026 Patch Tuesday delivered security fixes for 400+ vulnerabilities, including one that has been exploited in zero-day attacks (CVE-2026-68820) and three that were publicly disclosed prior to the release of the patches. Vulnerabilities of note CVE-2026-6882...

vulnerabilityzero daymicrosoft Actively exploited · EPSS <1%
The Hacker News

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO. The vulnerability in question is CVE-2026-59310 (CVSS score: 9.8), a directory-traversal vulnerability in the VMware vCente...

vulnerability EPSS 1%
Help Net Security

ConnectSecure helps MSPs automate Microsoft 365 security remediation

ConnectSecure has announced that Microsoft 365 Auto Remediation and AI-powered Training Assessments are now live on the ConnectSecure platform. The capabilities help managed service providers (MSPs) address supported M365 security findings, create and measure assessments, supp...

microsoft
Help Net Security

CBTS brings continuous penetration testing to enterprise security

CBTS has launched Penetration Testing as a Service (PTaaS), combining autonomous penetration testing with security expertise to help organizations continuously identify exploitable risks, validate attack paths, and prioritize remediation as their environments evolve. Cloud env...

cloud
SecurityWeek

Fresh Windows Zero-Day Exploited in North Korean Cyberattacks

The bug allowed attackers to gain full control of the victims’ systems and deploy the ForestTiger backdoor. The post Fresh Windows Zero-Day Exploited in North Korean Cyberattacks appeared first on SecurityWeek.

zero daymicrosoft
Help Net Security

Crytica’s RDAi detects OT device tampering from within

Crytica Security has developed a patented solution that delivers rapid, deterministic threat detection for operational technology (OT), protecting the embedded systems and connected devices that underpin critical infrastructure, national security, and healthcare without disrup...