Russian-Alligned TA488 Returns With Persistent Outlook Web Access Attack
TA488 returned with OWA half-click exploit deploying OWAReaper implant that survived re-imaging
20 articles
TA488 returned with OWA half-click exploit deploying OWAReaper implant that survived re-imaging
Ruflo fixed a CVSS 10.0 flaw that exposed its MCP bridge without any authentication, putting AI provider keys, stored chats and persistent agent memory at risk.
Stack Sports discovered suspicious activity on June 8, 2026, after its internal security monitoring systems detected unauthorized activity affecting the Spor...
The Minnesota IT Services (MNIT) agency activated its cybersecurity incident response capabilities across the entire state after hackers targeted more than 3...
A Kaspersky study of 7,200 respondents across 18 countries highlights that only 27% of Gen Z use mobile antivirus software, and a mere 28% regularly back up ...
As outlined in The Register, CAF Bank, which serves approximately 14,000 charities, temporarily suspended its online banking services to address a security v...
Researchers say the Russian state-linked hacking group tracked as Laundry Bear recently began exploiting a bug in Microsoft Outlook Web Access.
As detailed in Bleeping Computer, the University of Pennsylvania experienced a significant data breach in 2025 due to a compromised single sign-on (SSO) acco...
Based on information from Dark Reading, security researchers identified a new class of vulnerabilities, dubbed "PleaseFix," that significantly compromise the...
Following insights from The Cyber Express, the cybercrime economy is increasingly valuing stolen data as a significant commodity, with one threat actor, Tana...
As noted by The Hacker News, OpenWrt released version 24.10.
The latest release of MCP overhauls its request metadata processing, replacing a complex handshake workflow with a stateless protocol core.
JetBrains released security updates for TeamCity On-Premises to address a critical vulnerability, CVE-2026-63077, which carries a CVSS score of 9.8.
A critical vulnerability in the vBulletin forum software allows unauthenticated attackers to execute arbitrary PHP code through template rendering, posing a ...
Las Vegas, USA, July 29th, 2026, CyberNewswire Catches rogue AI agents – and stops them in live production before they cause damage Sweet Security, the proac...
AI agents are designed to improvise as they complete tasks, making broad permissions a growing security risk. Token Security explains why identity, intent-ba...
Microsoft has released the KB5101684 preview cumulative update for Windows 11 24H2 and 25H2, which 42 bug fixes and additional feature improvements for the...
A new Mirai-derived IoT botnet can force an infected Linux device to reboot once its main process is killed, giving its persistence mechanisms another opport...
A critical vulnerability in the open-source AI orchestration platform Ruflo has been disclosed, allowing unauthenticated attackers to achieve full remote cod...
A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27, triggering a statewide cyberse...