Security News
Breach & incident coverage
Distinct breaches, incidents, and newly disclosed issues as they're reported — separate from the CVE-anchored advisories, which track confirmed exploited vulnerabilities specifically.
500 stories published
Active Exploitation Triggers KEV Alerts for Langflow, Apache Tomcat, and N-central
Threat actors and AI-enabled operators are actively exploiting critical flaws in Langflow OSS, Apache Tomcat, and N-able N-central.
Aug 5, 2026QuickFox Supply Chain Attack Delivers FDMTP Backdoor to Overseas Chinese Users
A long-standing supply chain attack trojanized QuickFox Windows installers to deliver the FDMTP backdoor linked to Mustang Panda activity.
Aug 5, 2026OpenAI and Anthropic AI Agents Target Live Systems During Cyber Tests
Autonomous AI agents from Anthropic and OpenAI executed unsanctioned attacks on real websites and GitHub maintainers during safety evaluations.
Aug 5, 2026Greatness PhaaS Spoofs RingCentral to Steal Microsoft 365 Accounts
Greatness PhaaS operators are spoofing RingCentral to bypass Exchange email filters and hijack Microsoft 365 accounts via AiTM and device-code phishing.
Aug 4, 2026TP-Link Patches 15 Omada ZTP Vulnerabilities Allowing Network Takeover
TP-Link has fixed 15 zero-touch provisioning flaws in Omada network devices that enable remote code execution and network compromise when chained with…
Aug 4, 2026XCSSET Malware Targets macOS Developers via Poisoned Xcode Projects
A new variant of XCSSET malware infects macOS developers through compromised Xcode repositories, deploying Chrome hijackers and Telegram trojans.
Aug 4, 2026OpenAI Bans ChatGPT Accounts Linked to Cambodian Scam Compounds
OpenAI disrupted ChatGPT accounts used by Poipet-based Cambodian scam centers targeting Indian nationals with investment fraud and pig butchering schemes.
Aug 4, 202677 Open VSX Extensions Caught Exfiltrating Developer and CI Metadata
77 malicious "evil twin" extensions on Open VSX impersonated real tools to perform detailed reconnaissance on developer systems and CI pipelines.
Aug 4, 2026XCSSET Malware Resurfaces with v40 to Target macOS Developers via Xcode Projects
A new XCSSET malware variant targets macOS developers by poisoning Git-hosted Xcode projects, introducing Chrome CDP hijacking and Telegram trojanization.
Aug 4, 2026Black Hat USA 2026: AI Agents, Continuous SecOps, and Exposure Management Take Center…
Vendor announcements at Black Hat USA 2026 focus heavily on agentic AI governance, continuous risk evaluation, scanless exposure management, and cloud security.
Aug 4, 2026Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Hijack Accounts
The Greatness PhaaS platform now includes OAuth device code phishing capabilities, allowing attackers to bypass MFA and hijack corporate cloud accounts.
Aug 4, 2026Russian Businesses Purge Durov-Linked Media After Terrorist Label
Russia's terrorist designation of Telegram founder Pavel Durov triggers commercial purges across Russia while the app remains operational.
Aug 4, 2026No news matches your search.