Scammers are impersonating FBI personnel who supposedly handle Internet Crime Complaint Center (IC3) complaints, using that disguise to deceive and revictimize people who already lost money once. The IC3 published the update on July 20, 2026, building on an earlier alert from April 2025. Since then,...
A security researcher discovered a broken access control vulnerability in Meta’s support infrastructure.
The post Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data appeared first on SecurityWeek.
The Qilin ransomware gang is exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach victims' networks, according to cybersecurity company Arctic Wolf. [...]
Several security issues were fixed in the Linux kernel.
Un escroc usurpe Damien Bancal et ZATAZ pour cibler les services communication par ingénierie sociale.
Several security issues were fixed in the Linux kernel.
Maxim Suhanov discovered that the NTFS file system implementation in the
Linux kernel did not properly validate file name length in certain
situations, leading to an out-of-bounds read. An attacker could use this to
construct a malicious NTFS image that, when mounted and operated on, could
expose se...
Dealerships installed alarms in millions of vehicles—and left them in even if the buyer didn’t want them. Now researchers warn they can be hacked to unlock, track, and disable cars.
Future major events can’t rely on yesterday's playbook. Lessons from the World Cup show why true cyber resilience starts months before kickoff and extends far beyond stadium perimeters.
The post What the World Cup can teach us about cybersecurity resilience appeared first on CyberScoop.
It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)
It was discovered that some AMD Zen 2 processors did not properly isolate
shared...
Ukraine's computer emergency response team, CERT-UA, has warned that the Kremlin-backed Sandworm hacking group is leveraging fake CAPTCHA checks on compromised websites that persuade users to run malicious code.
Read more in my article on the Hot for Security blog.
Instead of fighting over what app stores host, the San Francisco City Attorney is targeting how they make money from AI nudify apps.
Craneware, a provider of financial software for US healthcare organizations, has disclosed a cyber incident involving unauthorized access and data theft
Using social engineering, hackers compromised employee accounts with access to personal and health information.
The post Clover Health Investments Discloses Data Breach appeared first on SecurityWeek.
In a new campaign, North Korean hacking group Famous Chollima targeted crypto professionals through ClickFix lures to deliver Windows and macOS trojans
Amazon GuardDuty investigation agent is now in public preview. The feature provides AI-powered investigations of GuardDuty findings, AWS accounts and AWS organizations, helping security teams reduce investigation time. During the public preview, the investigation agent is available at no additional...
Microsoft has shared manual mitigations to help IT administrators fix Windows Server Update Services (WSUS) servers affected by a known issue that causes Windows Update scans to fail or time out. [...]
Cosmetics company Estée Lauder disclosed a data breach tied to a vulnerability in Oracle E-Business Suite (EBS) used for the company’s human resources operations. Estée Lauder is one of the largest beauty companies in the world, known for its prestige skincare, makeup, fragrance, and haircare brands...
Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites.
The two security flaws, tracked as CVE-2026-63030 and CVE-2026-60137, have been codenamed wp2she...