Latest Cybersecurity News

Real-time cybersecurity news aggregation: CVE alerts, malware analysis, ransomware updates, data breaches, AI security and threat intelligence from 50+ trusted sources.

U.S. DoJ Charges 12 Chinese Nationals in Massive State-Linked Cyber Espionage Campaign

The U.S. Department of Justice (DoJ) has charged 12 Chinese nationals, including government officers and hackers, for their roles in a global cyber espionage campaign. This coordinated effort involved data theft and suppression of dissent, targeting U.S. critics, Asian governments, and key U.S. agencies. The indictment reveals the intricate web of state-sponsored hacking and the U.S. response to safeguard national security.

#cybersecurity & data protection #chinese hackers #data theft

Read full article →

Webinar Learn How ASPM Transforms Application Security from Reactive to Proactive

Are you tired of dealing with outdated security tools that never seem to give you the full picture? You're not alone. Many organizations struggle with piecing together scattered information, leaving your apps vulnerable to modern threats. That's why we're excited to introduce a smarter, unified approach: Application Security Posture Management (ASPM). ASPM brings together the best of both worlds by combining proactive measures with reactive strategies to enhance your security posture.

#application security #cybersecurity #proactive measures

Read full article →

FBI Alerts: Cybercriminals Impersonate 'BianLian Group' to Extort Corporate Executives

The FBI's Internet Crime Complaint Center (IC3) has issued a critical alert about a data extortion scam targeting corporate executives. Cybercriminals, posing as the 'BianLian Group,' send threatening letters demanding payment to prevent the release of sensitive information. Learn how to protect your organization and report incidents to CISA.

#cybersecurity & data protection #data extortion #corporate executives

Read full article →

CISA Warns of Actively Exploited Microsoft Exchange Vulnerability

CISA added CVE-2026-42897, a critical cross-site scripting (XSS) vulnerability in Microsoft Exchange Server, to its Known Exploited Vulnerabilities (KEV) Catalog due to active exploitation. The flaw affects Microsoft Exchange Server deployments and enables unauthorized script execution, posing risks of data theft and system compromise for federal agencies and private organizations alike, which must prioritize immediate patching.

CVEs: CVE-2026-42897

#cisa #microsoft exchange #cve-2026-42897 #xss #threat intelligence

Read full article →

JUST IN: Senate Parliamentarian Rules Against Major Sections of Reconciliation Bill Funding ICE, Border Patrol

• NewsAPI.org

The U.S. Senate Parliamentarian struck down three key provisions in the reconciliation bill funding ICE and Border Patrol, disrupting budget allocations for immigration enforcement and homeland security initiatives. The decision forces Congress to renegotiate or remove funding for critical border security programs, potentially delaying operations for DHS agencies like ICE and CBP.

#security #news

Read full article →

Rural Police Seize Arsenal and Four Vehicles Following Clash in Cuauhtémoc

• NewsAPI.org

Rural Police Seize Arsenal and Four Vehicles Following Clash in Cuauhtémoc

Rural police in Cuauhtémoc, Mexico, seized an arsenal and four vehicles after a violent clash, highlighting ongoing security vulnerabilities in rural law enforcement operations. The incident underscores risks to regional safety and the potential for weaponized vehicles in organized crime, with no reported injuries but significant operational disruptions. Immediate threat assessment and countermeasures are critical to prevent escalation.

#security #news

Read full article →

JVNDB-2026-015710:Python Software FoundationのPythonにおけるパストラバーサルの脆弱性

• NewsAPI.org

The Python Software Foundation's Python is vulnerable to path traversal attacks when the `shutil.unpack_archive()` function processes malicious ZIP archives containing absolute Windows paths (e.g., `C:\...`). This vulnerability specifically affects Windows systems and allows attackers to extract files outside intended directories, potentially leading to arbitrary code execution or data tampering.

#security #news

Read full article →