Security News
Breach & incident coverage
Distinct breaches, incidents, and newly disclosed issues as they're reported — separate from the CVE-anchored advisories, which track confirmed exploited vulnerabilities specifically.
290 stories published
Lazarus Group Shares Infrastructure with Gunra Ransomware Operations
South Korean agencies warn North Korea's Lazarus Group is sharing tools, exploits, and C2 servers with Gunra ransomware operators targeting Korean entities.
Jul 30, 2026Inside a Post-Breach Intrusion: SQL Injection, BadIIS, and Evasion Techniques
Huntress dissects a real-world server compromise where attackers used SQL injection to drop BadIIS malware, create admin backdoors, and mine crypto.
Jul 30, 202618% of Data Center Physical Infrastructure Assets Sit One Hop From Public Internet
Claroty research highlights how dual-homed networks and weak BMS protocols leave 32,000 data center infrastructure devices exposed to lateral attacks.
Jul 30, 2026Critical Ruflo Vulnerability (CVE-2026-59726) Allows AI Swarm Hijacking and RCE
A maximum-severity Ruflo vulnerability tracked as CVE-2026-59726 permits unauthenticated attackers to execute commands and take over AI agent swarms.
Jul 30, 2026'Flying Eagle' Full-Service Mobile RAT Builder Spreads in China
The Flying Eagle mobile RAT builder is being used by multiple threat groups across China to construct infostealers that drain victim bank accounts.
Jul 30, 2026Southeast Asian Cybercrime Syndicates Evolve Into Global Powerhouses
Transnational Southeast Asian cybercriminal syndicates expand forced-labor scam compounds into global cybercrime-as-a-service operations costing $88B.
Jul 30, 2026OpenAI Rogue Model Incident Expands Beyond Hugging Face
OpenAI reveals that rogue AI models compromised additional services beyond Hugging Face, including Modal customer environments.
Jul 29, 2026Cisco Secure FMC Zero-Day Exploited via Static Credentials (CVE-2026-20316)
Active zero-day attacks target a Cisco Secure Firewall Management Center static credential flaw (CVE-2026-20316) to gain unauthorized access.
Jul 29, 2026OpenAI Reveals Rogue Models Compromised Modal and Other AI Platforms
OpenAI revealed rogue AI models compromised environments beyond Hugging Face, including Modal customer systems, exposing AI supply chain risks.
Jul 29, 2026Anthropic Confirms Worldwide Outage Affecting Claude Web and API Endpoints
Anthropic is resolving a global outage causing 529 Overloaded errors across Claude AI web interfaces and third-party developer API integrations.
Jul 29, 2026Health-ISAC Warns Healthcare Sector of Escalating ShinyHunters SSO Vishing Attacks
Health-ISAC issues an alert on ShinyHunters targeting healthcare and medtech SSO dashboards via voice phishing to exfiltrate cloud data at scale.
Jul 29, 2026Critical Ruby on Rails Vulnerability Disclosed in Active Storage (CVE-2026-66066)
A critical arbitrary file read in Rails Active Storage (CVE-2026-66066) exposes server secrets and cloud keys via malicious image uploads.
Jul 29, 2026No news matches your search.