Global Cyber Intelligence
Worldwide Cyber Security News
Curated cyber security intelligence from national cyber agencies, independent researchers, and leading industry media across North America, Europe, the United Kingdom, and the Asia-Pacific region. Updated every thirty minutes.
Showing 45 of 45 matching stories
Last refreshed 14:49 UTC
- Threat IntelligenceCriticalGlobalIndustry Media
Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension
The critical, unauthenticated bugs allow attackers to bypass authentication and proxy a user’s browser traffic. The post Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension appeared first on SecurityWeek .
SecurityWeek · Just nowRead at source → - Threat IntelligenceCriticalGlobalVendor-Neutral Intelligence
Ukraine prosecutor general steps down amid scam call center bribery probe
Ukraine’s prosecutor general, Ruslan Kravchenko, resigned this week over allegations that officials in his office took bribes to shield scam call centers from law enforcement.
The Record by Recorded Future · 2h agoRead at source → - Threat IntelligenceCriticalGlobalIndustry Media
DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval
A flaw in DeepSeek Harness, DeepSeek's open-source tool for running AI coding agents on a developer's machine, let a sandboxed agent turn off its own sandbox with a single command. The tool runs an agent's commands inside an operating-system sandbox, so that an agent working on untrusted files cannot write outside its workspace. The agent could remove that limit by calling the tool's own web
The Hacker News · 3h agoRead at source → - Critical InfrastructureCriticalGlobalIndustry Media
ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws
AVEVA and Rockwell Automation also released patches for vulnerabilities affecting industrial control system products. The post ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws appeared first on SecurityWeek .
SecurityWeek · 4h agoRead at source → - Threat IntelligenceCriticalGlobalIndustry Media
Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets
Bitcoin wallet company Alby has warned of a critical flaw in Alby Hub that could have let an attacker take over a wallet and send its funds, but only where the owner had made the Hub reachable from the internet. Alby Hub is a self-hosted Lightning wallet, meaning the owner runs it on their own computer or server, and it holds their bitcoin. The flaw affects versions v1.7.0 through
The Hacker News · 4h agoRead at source → - Vulnerability & ExploitCriticalGlobalIndustry Media
Ivanti Patches Critical Flaws Across Enterprise Security Products
Six critical vulnerabilities in Neurons for ITSM could enable remote code execution, while Sentry and EPMM received patches for authentication bypass flaws. The post Ivanti Patches Critical Flaws Across Enterprise Security Products appeared first on SecurityWeek .
SecurityWeek · 4h agoRead at source → - Vulnerability & ExploitCriticalGlobalIndustry Media
Chrome 153 Patches Seventh Zero-Day of 2026
The Chrome update includes 230 security fixes, and users are advised to update their browsers as soon as possible. The post Chrome 153 Patches Seventh Zero-Day of 2026 appeared first on SecurityWeek .
SecurityWeek · 5h agoRead at source → - Vulnerability & ExploitCriticalGlobalIndustry Media
Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox
Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's JavaScript and WebAssembly engine. "Out-of-bounds write in V8 in Google Chrome prior to
The Hacker News · 5h agoRead at source → - Vulnerability & ExploitCriticalGlobalIndustry Media
Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed
The security researcher known as Chaotic Eclipse has dropped a proof-of-concept (PoC) for yet another zero-day in Microsoft Defender. The vulnerability, codenamed ShieldCrash, is assessed to be a patch bypass for CVE-2026-69414 (CVSS score: 7.8), also called ShieldBreak, which the researcher reported last month. "Microsoft has failed to properly patch ShieldBreak CVE-2026-69414," Chaotic
The Hacker News · 8h agoRead at source → - Vulnerability & ExploitCriticalGlobalIndustry Media
SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution
SAP has released security updates to address multiple vulnerabilities, including a maximum-severity flaw in SAP Extended Passport (EPP) Processing that could have a severe impact on the confidentiality, integrity, and availability of the application The vulnerability, tracked as CVE-2026-44756 (CVSS score: 10.0), has been described as a case of memory corruption. Discovered and reported by SAP
The Hacker News · 8h agoRead at source → - Vulnerability & ExploitCriticalGlobalIndustry Media
Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days
Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild. These include 723 flaws in Windows, 111 in Office and Office 2016, 62 in SQL, and 22 in Developer Tools. Of these, over 110 shortcomings have been assigned a critical severity rating.
The Hacker News · 10h agoRead at source → - Vulnerability & ExploitCriticalGlobalIndustry Media
N-able N-central Pre-Auth RCE Flaw Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026. The vulnerability in question is CVE-2026-86218 (CVSS score: 10.0), which has been described as a
The Hacker News · 10h agoRead at source → - Threat IntelligenceCriticalGlobalIndustry Media
Patch Tuesday Sets Another Record With 974 CVEs
Attackers are actively exploiting two of the vulnerabilities and another 58 are more likely to be exploited, according to Microsoft.
Dark Reading · 17h ago - Threat IntelligenceCriticalGlobalVendor-Neutral Intelligence
Scammer behind $245 million crypto heist pleads guilty to RICO charges
Malone Lam was indicted on scamming charges in September 2024 after drawing law enforcement scrutiny for parlaying stolen crypto into lavish Hamptons vacations, cars and private jets.
The Record by Recorded Future · 17h agoRead at source → - Vulnerability & ExploitCriticalGlobalIndependent Research
September 2026 Microsoft Patch Tuesday, (Tue, Sep 8th)
This month, Microsoft released patches for a record-breaking 973 vulnerabilities, including 113 rated critical. It is by far the largest Patch Tuesday to date, well ahead of the previous high of 664 set in July 2026. Two vulnerabilities are listed as exploited in the wild, while none were publicly disclosed before Patch Tuesday. Notable fixes include Windows privilege escalation and critical RCEs in Skype for Business, MSMQ and RRAS.
SANS Internet Storm Center · 19h agoRead at source → - Threat IntelligenceCriticalGlobalIndustry Media
Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days
The record-breaking September security update fixes two exploited privilege-escalation zero-days and 20 potentially wormable vulnerabilities. The post Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days appeared first on SecurityWeek .
SecurityWeek · 19h agoRead at source → - Vulnerability & ExploitCriticalGlobalIndustry Media
Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day
Tracked as CVE-2026-75650, the exploited defect allows unauthenticated attackers to execute arbitrary code. The post Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day appeared first on SecurityWeek .
SecurityWeek · 20h agoRead at source → - Threat IntelligenceCriticalGlobalIndependent Research
Stealing AI Reasoning Traces
Interesting research: “ Stealing Reasoning Traces from Proprietary LLM APIs “: Abstract: Leading large language model providers now conceal their models’ step-by-step reasoning, or chain-of-thought, to protect intellectual property and limit information leakage. Rather than storing these traces server-side, providers return them to the client as blocks of encrypted text, which the client passes back with each subsequent request. Building on prior research, we identify an architectural vulnerability: these encrypted blocks are fully compatible and interchangeable across different sessions, users, and models within a provider’s ecosystem. We exploit this compatibility to develop a scalable decryption jailbreak. By injecting an encrypted reasoning trace from a given model into a weaker, and less safeguarded model from the same provider, we force it to decode and output the trace verbatim in plaintext, without ever jailbreaking the more capable model directly. This vulnerability enables four distinct attack vectors. First, it circumvents anti-distillation mechanisms, allowing adversaries to extract a proprietary model’s reasoning, as we demonstrate across Anthropic, OpenAI, and Google. Second, it allows for large-scale private data extraction. Developers frequently share session logs publicly, unaware of contents of the encrypted blocks. By decoding 315,320 reasoning blocks scraped from public repositories, we recovered 367 Personally Identifiable Information (PII) artifacts and 182 credentials. Third, it inadvertently reveals hazardous information hidden within the reasoning process, even in cases where the model’s final, visible output safely rejects a malicious request. Fourth, attackers can leverage this flaw to execute invisible prompt injections, embedding malicious payloads entirely within encrypted blocks to poison public agentic rollouts. Following responsible disclosure, we propose concrete cryptographic and system-level mit
Schneier on Security · 1d agoRead at source → - Vulnerability & ExploitCriticalGlobalIndustry Media
Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell
Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026. "This update resolves a critical
The Hacker News · 1d agoRead at source → - Supply ChainCriticalGlobalIndustry Media
⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on. Elsewhere, a trusted software source delivered code that stole credentials, and a protocol designed for secure network management
The Hacker News · 2d agoRead at source → - Vulnerability & ExploitCriticalGlobalIndustry Media
Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released
A TantoSec proof-of-concept turns an AES-CBC "padding oracle" in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against applications in a specific non-default configuration, and Progress patched the chain in July. There are no confirmed reports of exploitation in the wild. Security firm TantoSec has published a working exploit chain targeting vulnerabilities
The Hacker News · 2d agoRead at source → - Vulnerability & ExploitCriticalGlobalIndustry Media
N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw
Every on-premises N-central build below 2026.3.1.14 — including servers updated to Hotfix 3 a day earlier — needs Hotfix 4. N-able's incident notice says the flaw has been exploited in the wild; its release notes say that is unconfirmed. N-able has released its fourth hotfix in five weeks for the N-central remote monitoring and management (RMM) platform, this time for a
The Hacker News · 2d agoRead at source → - Identity & AccessCriticalGlobalIndustry Media
JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies
Cybersecurity researchers have unpacked JSCeal, a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities. "The payloads are protected with javascript-obfuscator, using multiple techniques including RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers," Check Point Research said in a
The Hacker News · 2d agoRead at source → - Threat IntelligenceCriticalGlobalIndependent Research
Critical MikroTik Vulnerability - Patch Now, (Sun, Sep 6th)
Mikrotik released a patch late last week for an already-exploited vulnerability. The vulnerability allows an SSH authentication bypass and is already being exploited. At this point, assume compromise. Attackers have been adding new accounts to affected devices to maintain access after a patch is installed.
SANS Internet Storm Center · 2d agoRead at source → - Vulnerability & ExploitCriticalGlobalIndustry Media
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is
The Hacker News · 3d agoRead at source → - Vulnerability & ExploitCriticalGlobalIndustry Media
Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.
The Hacker News · 3d agoRead at source → - Vulnerability & ExploitCriticalGlobalIndustry Media
Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A
The Hacker News · 3d agoRead at source → - Vulnerability & ExploitCriticalGlobalIndustry Media
Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities
Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as
The Hacker News · 4d agoRead at source → - Threat IntelligenceCriticalGlobalIndustry Media
New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic
A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors. The attackers named the implant ted in debug strings left in the binary. It is not a HAProxy vulnerability, and installing it requires code execution on the host and
The Hacker News · 4d agoRead at source → - Threat IntelligenceCriticalGlobalIndependent Research
Security Vulnerability in a Voting System
It’s a vulnerability that allows someone to recover the order of ballots cast, newly exploited with AI tools. Nearly four years since the original vulnerability was disclosed, I was still able to use it to analyze voter behavior in Georgia (one of the 21 states that uses affected scanners) in the recent May 2026 primary. Notably, I never touched a voting machine, exploited a network, examined source code, or accessed anything non-public. After pointing a coding agent to the original vulnerability paper, I supplied it with two data sources highlighted in the paper: the early-voting list for each county, and the “CVR” (cast-vote record) file, containing every ballot and its selections (but not the voters’ names or other identifying information). The CVR file is available upon request, precisely because a public, ballot-level record is what makes election results independently verifiable...
Schneier on Security · 5d agoRead at source → - Vulnerability & ExploitCriticalGlobalIndustry Media
Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms – Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type, including
The Hacker News · 5d agoRead at source → - Vulnerability & ExploitCriticalGlobalIndustry Media
Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day
Google on Thursday released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-85046 (CVSS score: 8.8), has been described as a type confusion bug in V8, Chrome's JavaScript and WebAssembly engine. "Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote
The Hacker News · 5d agoRead at source → - Threat IntelligenceCriticalGlobalIndustry Media
GPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit Requests
OpenAI on Thursday officially unveiled GPT‑6 Astra, which it described as the "world's most intelligent and aligned model." The development comes days after the artificial intelligence (AI) company said the model had reached the "Critical" cybersecurity capability threshold under its Preparedness Framework. "Astra is state-of-the-art on computer use, browsing, software engineering,
The Hacker News · 5d agoRead at source → - Threat IntelligenceCriticalGlobalIndustry Media
What the AI Warning Letter Completely Missed
The recent open letter is right about the "window," but it omits naming who is coming through it or, critically, who will close it.
Dark Reading · 5d ago - Vulnerability & ExploitCriticalGlobalIndustry Media
Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root
Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7 umbrella CVEs, 2 of which are rated 9.8, with no workaround for any IOS XR version. The Nexus vulnerability, tracked as CVE-2026-20212 (CVSS score: 9.8), is
The Hacker News · 5d agoRead at source → - Vulnerability & ExploitCriticalGlobalIndustry Media
SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE
The exploitation activity follows attacks earlier this summer on two other zero-day vulnerabilities in the vendor's edge devices.
Dark Reading · 6d ago - Threat IntelligenceCriticalGlobalIndependent Research
FBI Probes Service Selling 153M+ Drivers Licenses
A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity also has learned that the New Orleans field office of the Federal Bureau of Investigation (FBI) today launched an official inquiry into the source of the images.
Krebs on Security · 2026-09-01Read at source → - Vulnerability & ExploitCriticalGlobalIndustry Media
Attackers Pounce on Critical Artifactory Bug Following Disclosure
CVE-2026-82329 is an authentication bypass flaw in JFrog's repository manager that enables bad actors to gain admin-level access on affected systems.
Dark Reading · 2026-09-01 - Vulnerability & ExploitCriticalGlobalIndustry Media
Critical Langflow Vulnerability Exploited as Attacks on AI Platform Rise
The attacks targeting CVE-2026-0768 are the latest threat against the low-code AI development platform, which is receiving more attention from adversaries this year.
Dark Reading · 2026-09-01 - Threat IntelligenceCriticalGlobalIndustry Media
The Guardrails Debate: Security Researcher Changes His Mind
While guardrails are critical, as evidenced by recent high-profile incidents, defenders need help staying ahead of attackers who do not play by the rules.
Dark Reading · 2026-08-31 - Supply ChainCriticalGlobalIndependent Research
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement released today, the Australian Federal Police (AFP) said two unnamed suspects from Western Australia, aged 21 and 23, were arrested in connection with a "sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses." The AFP did not name the defendants, but KrebsOnSecurity learned the 21-year-old suspect's real identity in June, and has been communicating with him ever since. This story includes interviews with TeamPCP's self-described spokesperson, and examines clues left behind by the TeamPCP leader that likely led to his undoing.
Krebs on Security · 2026-08-27Read at source → - Threat IntelligenceCriticalGlobalIndustry Media
'HTTP Terminator' Hunts for Novel Desync Attacks
James Kettle of PortSwigger talks with the Dark Reading News Desk about his AI-powered open source tool, which found new HTTP request-smuggling techniques.
Dark Reading · 2026-08-26 - Threat IntelligenceCriticalGlobalIndustry Media
Interpol's Jackal IV Disrupts West African Crime Infrastructure
The international law enforcement operation focused on disrupting crime-as-a-service networks and infrastructure behind groups like Black Axe.
Dark Reading · 2026-08-26 - Vulnerability & ExploitCriticalGlobalIndependent Research
Microsoft Plugs Nearly 400 Security Holes
Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.
Krebs on Security · 2026-08-11Read at source → - Threat IntelligenceCriticalGlobalIndependent Research
LG to Ban Residential Proxies from Smart TV Apps
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG's webOS store allow unknown third-parties to route their Internet traffic through a user's TV.
Krebs on Security · 2026-07-22Read at source →
Indexed sources
Every item displayed here links back to the original publication. CyberZonic does not host or re-publish full article text.
- CISA — Cybersecurity and Infrastructure Security Agency
North America · Government CERT
- NCSC UK — National Cyber Security Centre
United Kingdom · Government CERT
- ENISA — European Union Agency for Cybersecurity
Europe · Government CERT
- ACSC — Australian Cyber Security Centre
Asia Pacific · Government CERT
- CERT-FR — French National Cyber Security Agency
Europe · Government CERT
- Krebs on Security
Global · Independent Research
- Schneier on Security
Global · Independent Research
- SANS Internet Storm Center
Global · Independent Research
- The Hacker News
Global · Industry Media
- BleepingComputer
Global · Industry Media
- Dark Reading
Global · Industry Media
- SecurityWeek
Global · Industry Media
- The Record by Recorded Future
Global · Vendor-Neutral Intelligence
- CyberScoop
North America · Industry Media


