Latest Cybersecurity News

Real-time cybersecurity news aggregation: CVE alerts, malware analysis, ransomware updates, data breaches, AI security and threat intelligence from 50+ trusted sources.

U.S. DoJ Charges 12 Chinese Nationals in Massive State-Linked Cyber Espionage Campaign

The U.S. Department of Justice (DoJ) has charged 12 Chinese nationals, including government officers and hackers, for their roles in a global cyber espionage campaign. This coordinated effort involved data theft and suppression of dissent, targeting U.S. critics, Asian governments, and key U.S. agencies. The indictment reveals the intricate web of state-sponsored hacking and the U.S. response to safeguard national security.

#cybersecurity & data protection #chinese hackers #data theft

Read full article →

Webinar Learn How ASPM Transforms Application Security from Reactive to Proactive

Are you tired of dealing with outdated security tools that never seem to give you the full picture? You're not alone. Many organizations struggle with piecing together scattered information, leaving your apps vulnerable to modern threats. That's why we're excited to introduce a smarter, unified approach: Application Security Posture Management (ASPM). ASPM brings together the best of both worlds by combining proactive measures with reactive strategies to enhance your security posture.

#application security #cybersecurity #proactive measures

Read full article →

FBI Alerts: Cybercriminals Impersonate 'BianLian Group' to Extort Corporate Executives

The FBI's Internet Crime Complaint Center (IC3) has issued a critical alert about a data extortion scam targeting corporate executives. Cybercriminals, posing as the 'BianLian Group,' send threatening letters demanding payment to prevent the release of sensitive information. Learn how to protect your organization and report incidents to CISA.

#cybersecurity & data protection #data extortion #corporate executives

Read full article →

CISA Adds 8 Actively Exploited Vulnerabilities to KEV Catalog

CISA added 8 actively exploited vulnerabilities to its KEV Catalog, including flaws in PaperCut, JetBrains TeamCity, Kentico Xperience, Quest KACE, Synacor Zimbra, and Cisco Catalyst SD-WAN Manager. These vulnerabilities pose critical risks to federal and private networks, requiring immediate patching to prevent cyberattacks, data breaches, and unauthorized access.

CVEs: CVE-2023-27351, CVE-2024-27199, CVE-2025-2749, CVE-2025-32975, CVE-2025-48700

#cisa #kev catalog #cybersecurity #vulnerabilities #cve

Read full article →

Axios npm Supply Chain Attack: Malicious Package Drops Remote Access Trojan

A supply chain attack compromised versions 1.14.1 and 0.30.4 of the Axios npm package by injecting the malicious dependency '[email protected]', which deployed multi-stage payloads including a remote access trojan (RAT). This affects developers and organizations using the compromised Axios versions, potentially leading to unauthorized system access and data exfiltration. Immediate code audits and dependency reviews are critical to mitigate risks.

#axios #npm #supply-chain-attack #malware #remote-access-trojan

Read full article →

Cisco’s John Chambers lived through the dot-com crash. He says the AI bubble is harder to navigate

• NewsAPI.org

Cisco’s John Chambers lived through the dot-com crash. He says the AI bubble is harder to navigate

Cisco CEO John Chambers compares the AI investment bubble to the dot-com crash, warning of potential security risks as overhyped AI ventures prioritize speed over security. The impact is broad, affecting investors, enterprises adopting unvetted AI solutions, and cybersecurity teams struggling with rapid AI tool proliferation. This could lead to increased attack surfaces and vulnerabilities in critical infrastructure.

#security #news

Read full article →

Indonesian govt taps locals for village cooperative jobs

• NewsAPI.org

Indonesian govt taps locals for village cooperative jobs

The Indonesian government plans to recruit staff for its Red and White Village Cooperatives from local communities, potentially introducing insider threats due to limited background checks. This initiative affects rural cooperative systems and increases the risk of fraud, data breaches, or unauthorized access by unvetted personnel.

#security #news

Read full article →