general
20 articles
US Water Cyberattacks Extend Beyond Minnesota to at Least 6 Other States
Michigan, South Dakota, and Georgia are reportedly on the list of states whose water systems have been targeted by Iran-linked hackers. The post US Water Cyb...
OpenAI reveals how criminals used ChatGPT to run scams
OpenAI banned a coordinated network of ChatGPT accounts that likely originated in Cambodia’s Preah Sihanouk province, a region reports have linked to online ...
Coldcard Users Lose $89m After Bitcoin Wallet Is Hacked
A hacker has drained nearly $89m from Coldcard Bitcoin wallets after exploiting a legacy bug
Elastic Defend now covers 800+ vulnerable drivers, with automated troubleshooting and ARM support
Attackers reaching for kernel access on a Windows machine bring a driver Microsoft already trusts. It is signed, it loads, and it carries a known flaw.
Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable
Thermo Fisher Scientific has patched a flaw in select Applied Biosystems human identification software that could allow data files to be altered before analy...
CrowdStrike: AI is now both the weapon and the target in cyberattacks
AI generates 2.5 signals for every human-triggered signal CrowdStrike has to assess.
Critical N-able N-central Flaw Actively Exploited to Gain God-Mode Access to MSP Networks
N-able has issued an urgent hotfix to address a critical authentication-bypass vulnerability in its N-central remote monitoring and management (RMM) platform...
N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete
N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed through tho...
Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code
Three high-severity security flaws have been disclosed in Hugging Face's Diffusers library that could allow crafted model repositories to stealthily execute ...
Metasploit Exploit Targets Critical Ruby on Rails Active Storage RCE Flaw
A new Metasploit Framework module has been submitted for review, targeting the critical Ruby on Rails Active Storage vulnerability, tracked as CVE-2026-66066...
Ruby on Rails Patches Critical Active Storage Vulnerability Affecting Image Processing
Ruby on Rails fixed a critical vulnerability that could let unauthenticated attackers read files and achieve remote code execution. Ruby on Rails has patched...
Mapping the malware blast radius a single alert won’t show you
In this interview with Help Net Security, Mike Wiacek, founder and CTO of Stairwell, explains Backstory, an AI agent that takes a single alert and works outw...
CareCloud Data Breach Exposes Patients’ Health, Social Security and Credit Card Data
CareCloud has reported a data security incident involving unauthorized access to its Amazon Web Services (AWS) environment that supports the CareCloud Health...
SonicWall SMA Zero-Days Let Attackers Turn One WebSocket Request Into Root Control
SonicWall SMA Secure Mobile Access appliances are again at the center of a zero-day storm, with chained flaws that let attackers turn a single crafted WebSoc...
Hackers Exploit Critical Arista VeloCloud Flaw to Execute OS Commands
Arista Networks has issued a warning about attackers actively exploiting CVE-2026-16812, a critical unauthenticated OS command injection vulnerability in on-...
SkillSpector: NVIDIA’s open-source security scanner for AI agent skills
SkillSpector is an open-source scanner from NVIDIA that reads an agent skill and tells you whether to install it. Point it at a directory, a zip file, a sing...
Coldcard Firmware Flaw Lets Hackers Steal $70 Million in Bitcoin From 1,196 Addresses
Blockchain analysts have linked a rapid series of Bitcoin wallet drains to a reported vulnerability in Coldcard firmware. A total of 1,196 addresses lost a c...
XCSSET v40 Infects Xcode Projects to Hijack Chrome and Trojanize Telegram on Macs
XCSSET v40 marks a significant escalation in macOS-focused supply chain attacks, weaponizing poisoned Xcode projects to hijack Chrome and Trojanize Telegram ...
AI cut phishing from hours to seconds, which is where DMARC and BIMI come in
In this Help Net Security video, Mike Boyle, VP of Business Units at GMO GlobalSign, and Rahul Powar, CEO and founder of Red Sift, unpack the evolution of em...