50 storiesin cybersecurity
Wiz Red Agent Breaches Snowflake’s Internal Jira Through a GitHub Actions Flaw Missed by Security ScanningNewTrending
cybersecurityvia Wiz Research

Wiz Red Agent Breaches Snowflake’s Internal Jira Through a GitHub Actions Flaw Missed by Security Scanning

Wiz says its autonomous Red Agent discovered and exploited a GitHub Actions injection in a Snowflake repository just five days after the flaw went live, reaching internal Jira data during controlled testing.

about 17 hours ago10 min read
Hackers Raid French Tax Systems, Exposing Data of Nearly 900,000 AccountsTrending
cybersecurityvia AFP, as published by The Star

Hackers Raid French Tax Systems, Exposing Data of Nearly 900,000 Accounts

Hackers breached French tax and land registry systems in separate attacks, exposing data linked to at least 678,000 individuals and professional accounts, plus 200,000 land registry accounts.

2 days ago4 min read
New DRAM Scrambling Attack Challenges CPU Memory Security BoundariesTrending
cybersecurityvia GitHub research project

New DRAM Scrambling Attack Challenges CPU Memory Security Boundaries

Security researcher Christopher Domas has demonstrated a DRAM scrambling technique on AMD Family 16h processors that can remap physical memory addresses and expose protected memory regions beneath conventional CPU security boundaries.

5 days ago9 min read
Apple Explains Its Threat Notifications for Mercenary Spyware TargetsTrending
cybersecurityvia Apple Support

Apple Explains Its Threat Notifications for Mercenary Spyware Targets

Apple says its threat notifications are high-confidence warnings for users individually targeted by mercenary spyware. The company explains how alerts are delivered, how to verify them, and what users should do next.

5 days ago7 min read
City-Forum Campaign Targets Salesforce and ServiceNow Guest AccessTrending
cybersecurityvia Reco.ai

City-Forum Campaign Targets Salesforce and ServiceNow Guest Access

A long-running campaign is targeting Salesforce Experience Cloud and ServiceNow portals by abusing overly permissive guest access. Reco says the activity uses custom tooling to enumerate exposed data across organisations worldwide.

6 days ago8 min read
WordPress 7.0.4 Fixes High-Risk Imagick RCE Vulnerability Through Malicious File UploadsTrending
cybersecurityvia WordPress News

WordPress 7.0.4 Fixes High-Risk Imagick RCE Vulnerability Through Malicious File Uploads

WordPress 7.0.4 addresses CVE-2026-65640, an authenticated remote code execution vulnerability involving Imagick and Ghostscript. Administrators are urged to update, particularly on sites with multiple users who can upload files.

6 days ago4 min read
WindRelay and SpyNote Combine in a New NFC Payment Fraud SchemeTrending
cybersecurityvia Group-IB

WindRelay and SpyNote Combine in a New NFC Payment Fraud Scheme

Group-IB has uncovered WindRelay, an NFC relay malware used with SpyNote RAT in a social-engineering campaign that combines Android remote access with fraudulent card transactions.

6 days ago7 min read
Cisco Firewall Zero-Day CVE-2026-20349 Exploited in the WildTrending
cybersecurityvia Cisco Security Advisory

Cisco Firewall Zero-Day CVE-2026-20349 Exploited in the Wild

Cisco has confirmed active exploitation of a high-severity vulnerability in its Secure Firewall ASA and FTD software that can let unauthenticated attackers remotely force affected devices to reload, causing denial of service.

6 days ago7 min read
Google Cloud Sets 2029 Target for Post-Quantum Cryptography ReadinessTrending
cybersecurityvia Google Cloud Blog

Google Cloud Sets 2029 Target for Post-Quantum Cryptography Readiness

Google Cloud has outlined a roadmap to achieve full post-quantum cryptography readiness by 2029, with major milestones across encryption, digital signatures, identity, key management, and cloud infrastructure.

7 days ago11 min read
North Korean Hackers Build AI Tools to Support Cyberattacks, Report SaysTrending
cybersecurityvia Reuters

North Korean Hackers Build AI Tools to Support Cyberattacks, Report Says

A Genians report says North Korea-linked Kimsuky has built local AI capabilities that could support cyberattack automation, stolen-data analysis, malware development and more convincing phishing campaigns.

9 days ago7 min read
MinterEllison Cyber Risk 2026: AI Is Changing How Organisations Face AttacksTrending
cybersecurityvia MinterEllison - Perspectives on Cyber Risk 2026: The AI Edition

MinterEllison Cyber Risk 2026: AI Is Changing How Organisations Face Attacks

MinterEllison's 2026 cyber risk report finds that AI is reshaping attacks, defence and governance, while supplier exposure and incident preparedness remain major concerns for organisations.

9 days ago5 min read
OpenAI Raises Security Controls as Astra Approaches Critical Cyber Capability ThresholdTrending
cybersecurityvia OpenAI

OpenAI Raises Security Controls as Astra Approaches Critical Cyber Capability Threshold

OpenAI says preliminary evaluations of its upcoming Astra model show major advances in agentic coding and cybersecurity, prompting stronger safeguards as the company assesses whether it may reach the Critical threshold.

11 days ago6 min read