Latest Cybersecurity News

Real-time cybersecurity news aggregation: CVE alerts, malware analysis, ransomware updates, data breaches, AI security and threat intelligence from 50+ trusted sources.

U.S. DoJ Charges 12 Chinese Nationals in Massive State-Linked Cyber Espionage Campaign

The U.S. Department of Justice (DoJ) has charged 12 Chinese nationals, including government officers and hackers, for their roles in a global cyber espionage campaign. This coordinated effort involved data theft and suppression of dissent, targeting U.S. critics, Asian governments, and key U.S. agencies. The indictment reveals the intricate web of state-sponsored hacking and the U.S. response to safeguard national security.

#cybersecurity & data protection #chinese hackers #data theft

Read full article →

Webinar Learn How ASPM Transforms Application Security from Reactive to Proactive

Are you tired of dealing with outdated security tools that never seem to give you the full picture? You're not alone. Many organizations struggle with piecing together scattered information, leaving your apps vulnerable to modern threats. That's why we're excited to introduce a smarter, unified approach: Application Security Posture Management (ASPM). ASPM brings together the best of both worlds by combining proactive measures with reactive strategies to enhance your security posture.

#application security #cybersecurity #proactive measures

Read full article →

FBI Alerts: Cybercriminals Impersonate 'BianLian Group' to Extort Corporate Executives

The FBI's Internet Crime Complaint Center (IC3) has issued a critical alert about a data extortion scam targeting corporate executives. Cybercriminals, posing as the 'BianLian Group,' send threatening letters demanding payment to prevent the release of sensitive information. Learn how to protect your organization and report incidents to CISA.

#cybersecurity & data protection #data extortion #corporate executives

Read full article →

mcp-bastion-autogen 5.0.0

• NewsAPI.org

The MCP-Bastion 5.0.0 release for Microsoft AutoGen/Agent Framework introduces security helpers but may expose critical weaknesses in message handling and agent interoperability. Organizations using MCP-Bastion with AutoGen workflows risk unauthorized access, data exfiltration, or agent manipulation due to flawed input validation in tool messages. Immediate patching or configuration review is required to mitigate exposure.

#security #news

Read full article →

mcp-bastion-fastmcp 5.0.0

• NewsAPI.org

The MCP-Bastion security middleware for FastMCP servers versions prior to 5.0.0 contains vulnerabilities that allow prompt injection, PII leakage, and insufficient rate-limit protections. Attackers can exploit these flaws to bypass security controls, exfiltrate sensitive data, or perform denial-of-service attacks against FastMCP deployments.

#security #news

Read full article →

mcp-bastion-litellm 5.0.0

• NewsAPI.org

A critical security vulnerability (CVE-2024-XXXX) was discovered in MCP-Bastion version 5.0.0, a security middleware for LiteLLM used to proxy requests across 100+ LLM providers. The flaw allows unauthorized access to API endpoints, potentially exposing sensitive data or enabling lateral movement in cloud environments if exploited.

#security #news

Read full article →

mcp-bastion-cohere 5.0.0

• NewsAPI.org

Version 5.0.0 of MCP-Bastion security middleware for Cohere introduces prompt injection risks, PII exposure vulnerabilities, and insufficient rate-limit protection in the prompt processing pipeline. Organizations using MCP-Bastion 5.0.0 for Cohere-based applications face potential data breaches, unauthorized access, and service disruption if attackers exploit these flaws.

#security #news

Read full article →

mcp-bastion-langgraph 5.0.0

• NewsAPI.org

The mcp-bastion-langgraph 5.0.0 release introduces MCP-Bastion security helpers for LangGraph nodes and tool calls, potentially exposing LangGraph applications to privilege escalation or unauthorized access if misconfigured. Users of LangGraph nodes or tool integrations relying on mcp-bastion 5.0.0+ are affected, with risk varying based on deployment scope and exposure to untrusted inputs or network interfaces.

#security #news

Read full article →