Security News
Breach & incident coverage
Distinct breaches, incidents, and newly disclosed issues as they're reported — separate from the CVE-anchored advisories, which track confirmed exploited vulnerabilities specifically.
286 stories published
Fake Roblox Xeno Script Launcher Delivers Multi-Stage Java RAT and Infostealer
Threat actors are distributing a trojanized Roblox Xeno script executor that drops a Java-based RAT capable of webcam spying and credential theft.
Aug 3, 2026DOUBLECUP ClickFix Service Hides Malware in Browser Cache Steganography
The DOUBLECUP ClickFix service uses browser cache steganography to infect Windows and macOS systems with CountLoader and DeviceManager RAT.
Aug 3, 2026Google Password Manager Passkey Flaws Allow Silent Account Hijacking
Unit 42 research details three post-compromise attack paths against Chrome's Google Password Manager passkey authenticator on Windows TPM systems.
Aug 3, 2026Liechtenstein Beneficial Ownership Register Breach Exposes 31,000 Entities
A cyberattack on Liechtenstein's Register of Beneficial Owners compromised data tied to 31,000 entities, triggering a government crisis response.
Aug 3, 2026Inside the Splintered Underground Market of the BTMOB Android RAT
Research into the BTMOB Android RAT reveals how a centralized malware-as-a-service operation fragmented into competing source-code sales and resellers.
Aug 3, 2026ExfilSquad Extorts UK Police Database, Leaking 135,000 Officer Contact Records
A cyberattack on the UK Police National Legal Database exposed contact details for over 100,000 officers and staff, claimed by ExfilSquad.
Aug 3, 2026Leaked DarkSword Exploit Kit Used by Chinese Group to Deploy GHOSTBLADE Spyware
Threat actors are leveraging the leaked DarkSword exploit kit to target iOS 18.4 through 18.7 devices with GHOSTBLADE spyware via credential phishing decoys.
Aug 3, 2026Brinks Home Data Breach: ShinyHunters Leaks 4.9M Salesforce Records
ShinyHunters has leaked 41GB of data stolen from Brinks Home's Salesforce instance after the physical security provider declined to pay a ransom.
Aug 3, 2026Hugging Face Diffusers Flaws Bypass Remote Code Safeguards
Three high-severity vulnerabilities in Hugging Face Diffusers allow malicious model repositories to execute arbitrary code despite safety checks.
Aug 3, 2026N-able N-central Auth Bypass Exploited in Wild After Incomplete Patch
Attackers are exploiting CVE-2026-18577 in N-able N-central servers to hijack managed endpoints and install persistent Cloudflare tunnels.
Aug 3, 2026OpenAI Teases Astra AI Model Built for Complex Workloads and Cryptography
OpenAI revealed Astra, a new AI model designed for long-running agentic tasks that solved 10 long-standing math and cryptographic challenges.
Aug 3, 2026COLDCARD Hardware Wallet RNG Flaw Exploited to Steal $88 Million in Bitcoin
A firmware integration error in COLDCARD wallets caused fallback to a weak RNG, allowing attackers to precompute keys and drain $88.6 million in Bitcoin.
Aug 2, 2026No news matches your search.