Latest Cybersecurity News

Real-time cybersecurity news aggregation: CVE alerts, malware analysis, ransomware updates, data breaches, AI security and threat intelligence from 50+ trusted sources.

U.S. DoJ Charges 12 Chinese Nationals in Massive State-Linked Cyber Espionage Campaign

The U.S. Department of Justice (DoJ) has charged 12 Chinese nationals, including government officers and hackers, for their roles in a global cyber espionage campaign. This coordinated effort involved data theft and suppression of dissent, targeting U.S. critics, Asian governments, and key U.S. agencies. The indictment reveals the intricate web of state-sponsored hacking and the U.S. response to safeguard national security.

#cybersecurity & data protection #chinese hackers #data theft

Read full article →

Webinar Learn How ASPM Transforms Application Security from Reactive to Proactive

Are you tired of dealing with outdated security tools that never seem to give you the full picture? You're not alone. Many organizations struggle with piecing together scattered information, leaving your apps vulnerable to modern threats. That's why we're excited to introduce a smarter, unified approach: Application Security Posture Management (ASPM). ASPM brings together the best of both worlds by combining proactive measures with reactive strategies to enhance your security posture.

#application security #cybersecurity #proactive measures

Read full article →

FBI Alerts: Cybercriminals Impersonate 'BianLian Group' to Extort Corporate Executives

The FBI's Internet Crime Complaint Center (IC3) has issued a critical alert about a data extortion scam targeting corporate executives. Cybercriminals, posing as the 'BianLian Group,' send threatening letters demanding payment to prevent the release of sensitive information. Learn how to protect your organization and report incidents to CISA.

#cybersecurity & data protection #data extortion #corporate executives

Read full article →

Critical Flaw in Carlson VASCO-B GNSS Receiver Exposes Critical Systems

A critical authentication bypass vulnerability (CVE-2026-3893) in Carlson VASCO-B GNSS Receiver versions prior to 1.4.0 allows unauthenticated remote attackers to hijack critical system functions. This flaw impacts critical manufacturing infrastructure globally, where the device is widely deployed, posing severe operational and safety risks. Organizations must immediately update affected systems to mitigate potential exploitation.

CVEs: CVE-2026-3893

#gnss #cve-2026-3893 #critical-vulnerability #carlson-software #cybersecurity

Read full article →

SpiceJet Booking System Flaws Expose Passenger Data: Critical Vulnerabilities Unpatched

SpiceJet's online booking system contains two unpatched high-severity vulnerabilities (CVE-2026-6375 and CVE-2026-6376) that allow unauthenticated attackers to access sensitive passenger data, including PNRs and booking details. These flaws affect millions of SpiceJet travelers globally and expose personally identifiable information to exploitation. Immediate mitigation is required to prevent large-scale data breaches.

CVEs: CVE-2026-6375, CVE-2026-6376

#spicejet #cve-2026-6375 #cve-2026-6376 #data-breach #transportation-security

Read full article →

Critical Authentication Bypass Flaw in Xiongmai IP Cameras Exposes Live Feeds

A critical authentication bypass vulnerability (CVE-2025-65856) in Xiongmai XM530 IP cameras allows unauthenticated attackers to access live video feeds and sensitive device data. This flaw, rated 9.8 (CRITICAL), exposes 31 endpoints due to missing authentication in ONVIF implementation, putting users of these surveillance devices at significant risk of unauthorized surveillance and data exposure.

CVEs: CVE-2025-65856

#cve-2025-65856 #ip-cameras #authentication-bypass #iot-security #critical-vulnerability

Read full article →

CISA Warns of Actively Exploited Marimo RCE Vulnerability

CISA added CVE-2026-39987, a critical remote code execution (RCE) vulnerability in Marimo, to its Known Exploited Vulnerabilities (KEV) Catalog due to active exploitation in the wild. The flaw affects Marimo, a popular data visualization tool, and poses severe risks to federal agencies and enterprises, mandating immediate patching to prevent unauthorized code execution and potential network compromise.

CVEs: CVE-2026-39987

#cisa #cve-2026-39987 #remote-code-execution #kev-catalog #cybersecurity

Read full article →