radar.cysentrix

Security Radar

Page 6 of 10 · 1559 stories from the last 30 days across 19 trusted sources.

SecurityWeek · BleepingComputer · Security Affairs · The Hacker News4 stories

ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access

AIChaotic Eclipse released a PoC for ShieldBreak, a Microsoft Defender zero-day bypassing the CVE-2026-50656 patch to achieve SYSTEM-level code execution. The vulnerability highlights an incomplete fix in Defender for Windows.

Open narrative →
vulnerabilityzero daymicrosoft EPSS 11%
Show all coverage
Security Affairs · BleepingComputer · The Hacker News3 stories

China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

AIChina-linked threat actor Storm-1175, a former Medusa affiliate, deployed new StormEncryptor ransomware, likely exploiting an N-central flaw, according to Microsoft and BleepingComputer reports.

Open narrative →
ransomwareaptmicrosoft
Show all coverage
SOCRadar · SecurityWeek2 stories

LiteLLM Supply Chain Attack: Inside the AI Breach That Exposed 2,500+ Companies

AILiteLLM's PyPI packages v1.82.7 and v1.82.8 were compromised with credential-stealing code, impacting over 2,500 organizations in a supply chain attack linked to the Trivy breach.

Open narrative →
supply chaindata breachmalware
Show all coverage
Help Net Security · SOCRadar · The Hacker News · SecurityWeek · BleepingComputer5 stories

Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS

AICisco warns CVE-2026-20349, a high-severity unauthenticated DoS flaw in ASA and FTD firewall software, is being actively exploited to remotely crash devices. Patches are available.

Open narrative →
vulnerabilityzero day Actively exploitedCVE-2026-20349 · EPSS <1%
Show all coverage
Security Affairs · BleepingComputer · SOCRadar · Help Net Security · SecurityWeek8 stories

Lazarus hackers exploited Windows zero-day to target defense firms

AINorth Korea's Lazarus group exploited Windows zero-day CVE-2026-68820 in fake job offers targeting defense firms. Microsoft's August 2026 Patch Tuesday fixed the flaw among 400+ vulnerabilities, including other disclosed zero-days.

Open narrative →
zero daymicrosoftvulnerability Actively exploited · EPSS <1%
Show all coverage
Help Net Security

Four corporate investigation mistakes organizations make under pressure

In this Help Net Security video, Christine Gadsby, VP and Chief Security Advisor at BlackBerry, explains why corporate investigations go wrong before the forensic team arrives. The first hours matter more than leaders assume. Access gets granted, conversations start, and decis...

Help Net Security

DDoS attacks hit record scale as 1 Tbps+ campaigns become more common

DDoS attacks grew in scale during the first half of 2026, bringing larger traffic floods, shorter attack durations, and increasingly automated campaigns. Cloudflare’s H1 2026 DDoS Threat Report shows threat actors relying on multi-vector techniques and large-scale network-laye...

Help Net Security

Product showcase: Is this image real? Slop or Not investigates

Slop or Not is an AI text and image detector for iPhone and Mac that runs entirely offline, with no account required. It uses on-device AI models powered by the Apple Neural Engine to detect AI-generated content. According to a recent survey, 85% of people say they struggle to...

Help Net Security

Wireshark 4.6.8 patches 28 security bugs, nine in file parsers

Wireshark 4.6.8 fixes 28 security bugs in the protocol analyzer, and nine of them fire when someone opens a saved capture file. Those nine sit in file parsers, the code that reads a capture off disk before any dissection begins: pcapng, Endace ERF, Tektronix K12xx, BUSMASTER, ...

BleepingComputer · SecurityWeek2 stories

"City-Forum" data-theft attacks target Salesforce, ServiceNow portals

AIA campaign dubbed "City-Forum" uses custom tools to exploit unauthenticated guest access on Salesforce and ServiceNow portals, quietly enumerating and exfiltrating exposed data.

Open narrative →
cloud
Show all coverage
Security Affairs · SecurityWeek · The Record · SOCRadar4 stories

Cyberattack on logistics giant Ceva hits retailers and Steam customers across Europe

AIA cyberattack on logistics firm CEVA disrupted operations at eight European warehouses, affecting retailers and Steam hardware deliveries. The incident may have exposed delivery and order data belonging to some Steam customers.

Open narrative →
Show all coverage
BleepingComputer · The Hacker News2 stories

737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One

AI737 malicious Chrome VPN extensions impersonating known services routed users' browser traffic through a single provider's SOCKS5 proxies, mainly targeting Russian-speaking users seeking blocked content. Users should check installed extensions and remove any matching these fake add-ons.

Open narrative →
Show all coverage
Security Affairs

China-Linked Hackers Use AI Agents in Autonomous Attack on Taiwan

China-linked hackers reportedly used eight AI agents to breach a government network, steal data and compromise accounts with minimal human oversight. Israeli cybersecurity firm Dream documented what looks like the first fully autonomous, end-to-end AI hacking operation against...

data breach
The Hacker News

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a never-before-seen backdoor targeting defense and aerospace companies across France, Germany, Brazil, ...

zero daymicrosoftapt