Latest Cybersecurity News

Real-time cybersecurity news aggregation: CVE alerts, malware analysis, ransomware updates, data breaches, AI security and threat intelligence from 50+ trusted sources.

U.S. DoJ Charges 12 Chinese Nationals in Massive State-Linked Cyber Espionage Campaign

The U.S. Department of Justice (DoJ) has charged 12 Chinese nationals, including government officers and hackers, for their roles in a global cyber espionage campaign. This coordinated effort involved data theft and suppression of dissent, targeting U.S. critics, Asian governments, and key U.S. agencies. The indictment reveals the intricate web of state-sponsored hacking and the U.S. response to safeguard national security.

#cybersecurity & data protection #chinese hackers #data theft

Read full article →

Webinar Learn How ASPM Transforms Application Security from Reactive to Proactive

Are you tired of dealing with outdated security tools that never seem to give you the full picture? You're not alone. Many organizations struggle with piecing together scattered information, leaving your apps vulnerable to modern threats. That's why we're excited to introduce a smarter, unified approach: Application Security Posture Management (ASPM). ASPM brings together the best of both worlds by combining proactive measures with reactive strategies to enhance your security posture.

#application security #cybersecurity #proactive measures

Read full article →

FBI Alerts: Cybercriminals Impersonate 'BianLian Group' to Extort Corporate Executives

The FBI's Internet Crime Complaint Center (IC3) has issued a critical alert about a data extortion scam targeting corporate executives. Cybercriminals, posing as the 'BianLian Group,' send threatening letters demanding payment to prevent the release of sensitive information. Learn how to protect your organization and report incidents to CISA.

#cybersecurity & data protection #data extortion #corporate executives

Read full article →

CISA Warns of Actively Exploited Microsoft Defender Vulnerability

CISA added CVE-2026-33825—an access control flaw in Microsoft Defender—to its KEV catalog after confirming active exploitation. The vulnerability allows attackers to bypass security restrictions, affecting all users of Microsoft Defender across enterprises, government agencies, and individuals. Immediate patching is critical to prevent potential cyberattacks.

CVEs: CVE-2026-33825

#cisa #microsoft-defender #cve-2026-33825 #vulnerability-management #threat-intelligence

Read full article →

American Airlines Will Add PS Private Terminal Access For ConciergeKey Members

• NewsAPI.org

American Airlines Will Add PS Private Terminal Access For ConciergeKey Members

American Airlines is expanding access to PS private terminals for ConciergeKey members, a premium customer loyalty program. The expansion increases the attack surface for potential credential theft, social engineering, or unauthorized physical access to restricted aviation infrastructure. Affected parties include elite frequent flyers and private terminal operators, with potential impact on airport security protocols.

#security #news

Read full article →

Tourists say Kashmir has regained normalcy and feels safe year after Pahalgam terror attack

• NewsAPI.org

Tourists say Kashmir has regained normalcy and feels safe year after Pahalgam terror attack

The article erroneously tags a Kashmir tourism news piece with 'RCE' (Remote Code Execution) and a blank CVE ID, misleadingly associating it with cybersecurity vulnerabilities. The actual content discusses a return to normalcy in Kashmir post-terror attack, with no cybersecurity relevance. The misattribution creates confusion about the legitimacy of the tagging system.

#RCE

Read full article →

pypi-lockdown added to PyPI

• NewsAPI.org

pypi-lockdown added to PyPI

The Python Package Index (PyPI) introduced 'pypi-lockdown' to restrict package installations to internal feeds, addressing supply chain risks. This affects Python environments configured to use PyPI directly, particularly enterprise and open-source projects vulnerable to dependency hijacking. The change mitigates risks of malicious or compromised packages being pulled from untrusted sources.

#security #news

Read full article →