Apple has issued new spyware threat notifications to users in 110 countries, warning that mercenary spyware attacks continue to target journalists, activists, politicians, diplomats and other high risk individuals.
Security researchers warn that a newly disclosed GeoServer zero day SQL injection vulnerability is being actively targeted and could lead to remote code execution on vulnerable systems.
Broadcom researchers reveal China linked Jewelbug using the XG Web platform to conduct cyber espionage against governments and militaries while operating cryptocurrency fraud campaigns.
Avanceon Middle East & South Asia and ACET Solutions have signed an exclusive partnership to strengthen OT cybersecurity and resilience across the Middle East and South Asia.
A security researcher has released a proof of concept for ShieldBreak, a new Microsoft Defender zero day that reportedly bypasses the RoguePlanet patch and enables SYSTEM level privilege escalation.
SAP has released security patches for multiple critical vulnerabilities, including a maximum severity flaw in Commerce Cloud that could allow unauthenticated attackers to execute arbitrary code.
OpenAI has expanded its Daybreak Cyber Partner Program, enabling leading cybersecurity firms to integrate advanced cyber AI models into security operations, vulnerability management, and incident response services.
Cybersecurity agencies from South Korea and the United States have warned that Gunra ransomware operators are exploiting Fortinet and Schneider Electric vulnerabilities to compromise critical infrastructure organizations worldwide.
Researchers have disclosed GhostSplice, a prompt injection technique that enables malicious MCP servers to manipulate AI coding agents into exposing sensitive data through fragmented instructions.
Cybersecurity researchers have identified malicious Solidity Pro Visual Studio Code extensions that steal crypto wallets, API keys, developer credentials, and sensitive tokens through delayed activation techniques.
Metabase has released security updates after confirming active exploitation of a zero day vulnerability that allows attackers to gain administrator access without authentication.
Atlassian has fixed a one click Rovo data exposure flaw, while a separate PromptArmor report says an AI prompt injection technique affecting Jira and Confluence data remained unresolved at publication.