Latest Cybersecurity News

Real-time cybersecurity news aggregation: CVE alerts, malware analysis, ransomware updates, data breaches, AI security and threat intelligence from 50+ trusted sources.

U.S. DoJ Charges 12 Chinese Nationals in Massive State-Linked Cyber Espionage Campaign

The U.S. Department of Justice (DoJ) has charged 12 Chinese nationals, including government officers and hackers, for their roles in a global cyber espionage campaign. This coordinated effort involved data theft and suppression of dissent, targeting U.S. critics, Asian governments, and key U.S. agencies. The indictment reveals the intricate web of state-sponsored hacking and the U.S. response to safeguard national security.

#cybersecurity & data protection #chinese hackers #data theft

Read full article →

Webinar Learn How ASPM Transforms Application Security from Reactive to Proactive

Are you tired of dealing with outdated security tools that never seem to give you the full picture? You're not alone. Many organizations struggle with piecing together scattered information, leaving your apps vulnerable to modern threats. That's why we're excited to introduce a smarter, unified approach: Application Security Posture Management (ASPM). ASPM brings together the best of both worlds by combining proactive measures with reactive strategies to enhance your security posture.

#application security #cybersecurity #proactive measures

Read full article →

FBI Alerts: Cybercriminals Impersonate 'BianLian Group' to Extort Corporate Executives

The FBI's Internet Crime Complaint Center (IC3) has issued a critical alert about a data extortion scam targeting corporate executives. Cybercriminals, posing as the 'BianLian Group,' send threatening letters demanding payment to prevent the release of sensitive information. Learn how to protect your organization and report incidents to CISA.

#cybersecurity & data protection #data extortion #corporate executives

Read full article →

ABB PCM600 Vulnerability Exposes Critical Systems to Arbitrary Code Execution

A path traversal vulnerability in ABB PCM600 versions 1.5 to 2.13 (tracked as CVE-2018-1002208) permits arbitrary code execution via specially crafted messages. This flaw threatens critical manufacturing and industrial control systems (ICS) relying on ABB's protection and control software. Users must apply the vendor-supplied patch or implement mitigations immediately to prevent potential operational disruptions.

CVEs: CVE-2018-1002208

#abb #pcm600 #cve-2018-1002208 #path-traversal #ics-security

Read full article →

ABB IEC 61850 Vulnerability Exposes Critical Infrastructure to DoS Attacks

ABB’s IEC 61850 communication stack contains a vulnerability (CVE-2025-3756) enabling denial-of-service (DoS) attacks via crafted packets. Critical infrastructure sectors using ABB’s System 800xA and Symphony Plus platforms are exposed to operational disruptions or device crashes. Immediate mitigation and patching are advised to prevent potential outages in energy, chemical, or water treatment systems.

CVEs: CVE-2025-3756

#abb #iec-61850 #dos #cve-2025-3756 #critical-infrastructure

Read full article →

Critical ABB OPTIMAX Flaw Lets Attackers Bypass Authentication

A critical authentication bypass vulnerability (CVE-2025-14510) in ABB Ability OPTIMAX allows attackers to bypass Azure AD SSO authentication, exposing energy and water infrastructure to unauthorized access. This flaw impacts global industrial control systems (ICS) running vulnerable OPTIMAX versions, necessitating urgent patching to prevent operational disruptions or cyber-physical attacks. Organizations must prioritize mitigation due to the high-severity impact on critical infrastructure.

CVEs: CVE-2025-14510

#abb optimax #cve-2025-14510 #authentication bypass #azure ad #ics security

Read full article →

CISA Warns of Actively Exploited cPanel & WHM Vulnerability

CISA added CVE-2026-41940, a critical missing authentication vulnerability in WebPros cPanel & WHM and WP2 (WordPress Squared), to its Known Exploited Vulnerabilities (KEV) Catalog after detecting active exploitation in the wild. The flaw enables unauthorized access to sensitive systems, posing severe risks to federal agencies and private organizations relying on these web hosting platforms.

CVEs: CVE-2026-41940

#cve-2026-41940 #cisa #cpanel #authentication-bypass #cybersecurity

Read full article →