uk
Feedback
Vulnerability News

Vulnerability News

Відкрити в Telegram

Every day new posts about vulnerabilities and cybersecurity news. Get the latest news about the cyberspace! Group: @VulnerabilityNewsGroup

Показати більше
5 137
Підписники
+224 години
+327 днів
+13630 день

Триває завантаження даних...

Залучення підписників
серпень '26
серпень '26
+5
в 0 каналах
липень '26
+185
в 0 каналах
Get PRO
червень '26
+156
в 0 каналах
Get PRO
травень '26
+204
в 0 каналах
Get PRO
квітень '26
+187
в 0 каналах
Get PRO
березень '26
+254
в 0 каналах
Get PRO
лютий '26
+116
в 0 каналах
Get PRO
січень '26
+166
в 0 каналах
Get PRO
грудень '25
+134
в 0 каналах
Get PRO
листопад '25
+139
в 0 каналах
Get PRO
жовтень '25
+8
в 0 каналах
Get PRO
вересень '25
+12
в 0 каналах
Get PRO
серпень '25
+13
в 0 каналах
Get PRO
липень '25
+11
в 0 каналах
Get PRO
червень '25
+12
в 0 каналах
Get PRO
травень '25
+18
в 1 каналах
Get PRO
квітень '25
+14
в 0 каналах
Get PRO
березень '25
+21
в 0 каналах
Get PRO
лютий '25
+17
в 0 каналах
Get PRO
січень '25
+15
в 1 каналах
Get PRO
грудень '24
+262
в 1 каналах
Get PRO
листопад '24
+206
в 1 каналах
Get PRO
жовтень '24
+166
в 0 каналах
Get PRO
вересень '24
+146
в 0 каналах
Get PRO
серпень '24
+137
в 0 каналах
Get PRO
липень '24
+96
в 1 каналах
Get PRO
червень '24
+91
в 0 каналах
Get PRO
травень '24
+95
в 0 каналах
Get PRO
квітень '24
+104
в 0 каналах
Get PRO
березень '24
+149
в 0 каналах
Get PRO
лютий '24
+279
в 0 каналах
Get PRO
січень '24
+395
в 0 каналах
Get PRO
грудень '23
+327
в 0 каналах
Get PRO
листопад '23
+38
в 0 каналах
Get PRO
жовтень '23
+32
в 0 каналах
Get PRO
вересень '23
+47
в 0 каналах
Get PRO
серпень '23
+53
в 0 каналах
Get PRO
липень '23
+51
в 0 каналах
Get PRO
червень '23
+42
в 0 каналах
Get PRO
травень '23
+43
в 0 каналах
Get PRO
квітень '23
+67
в 0 каналах
Get PRO
березень '23
+65
в 0 каналах
Get PRO
лютий '23
+45
в 0 каналах
Get PRO
січень '23
+67
в 0 каналах
Get PRO
грудень '22
+62
в 0 каналах
Get PRO
листопад '22
+71
в 0 каналах
Get PRO
жовтень '22
+70
в 0 каналах
Get PRO
вересень '22
+55
в 0 каналах
Get PRO
серпень '22
+44
в 0 каналах
Get PRO
липень '22
+54
в 0 каналах
Get PRO
червень '22
+78
в 0 каналах
Get PRO
травень '22
+46
в 0 каналах
Get PRO
квітень '22
+77
в 0 каналах
Get PRO
березень '22
+105
в 0 каналах
Get PRO
лютий '22
+48
в 0 каналах
Get PRO
січень '22
+61
в 0 каналах
Get PRO
грудень '21
+99
в 0 каналах
Get PRO
листопад '21
+68
в 0 каналах
Get PRO
жовтень '21
+170
в 0 каналах
Get PRO
вересень '21
+72
в 0 каналах
Get PRO
серпень '21
+104
в 0 каналах
Get PRO
липень '21
+72
в 0 каналах
Get PRO
червень '21
+292
в 0 каналах
Get PRO
травень '21
+1 344
в 0 каналах
Дата
Залучення підписників
Згадування
Канали
01 серпня+5
Дописи каналу
Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies Bitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones, then click ads on websites run by the same operators. Researchers named the operation Fuyao and attributed it to Zhejiang Fengwo IoT Technology Co., Ltd., a mainland China company founded in 2019. The same apps have a second job. When a box https://thehackernews.com/2026/07/cheap-android-tv-boxes-pose-as-phones.html

2
HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as Matryoshka. According to Blackpoint Cyber, the intrusion sequence begins with a spear-phishing message containing a link to an encrypted archive, which holds a Windows Shortcut (LNK). Executing the file triggers a multi-stage chain that https://thehackernews.com/2026/07/hollowframe-loader-deploys-matryoshka.html
71
3
Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk A Chinese-speaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations mainly located in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic, since January 2025. These targeted organizations operate across several sectors, such as healthcare, research, government offices, https://thehackernews.com/2026/08/suspected-chinese-speaking-hackers.html
51
4
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to travelers and steal credentials in an operation we call CaptiveCrunch. The post CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft appeared first on Microsoft Security Blog. https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/
41
5
Critical Code Execution Vulnerability Patched in TeamCity  Tracked as CVE-2026-63077, the security defect can be exploited without authentication via the agent polling protocol. The post Critical Code Execution Vulnerability Patched in TeamCity  appeared first on SecurityWeek. https://www.securityweek.com/critical-code-execution-vulnerability-patched-in-teamcity/
22
6
CareCloud Data Breach Impacts Over 350,000 In March 2026, hackers stole personal, financial, and medical information from the company’s AWS environment. The post CareCloud Data Breach Impacts Over 350,000 appeared first on SecurityWeek. https://www.securityweek.com/carecloud-data-breach-impacts-over-350000/
16
7
Critical Flaw Allowed to Azure Cosmos DB Pwnage Named CosmosEscape, the vulnerability exposed the primary key for Cosmos DB accounts, granting full read and write access. The post Critical Flaw Allowed to Azure Cosmos DB Pwnage appeared first on SecurityWeek. https://www.securityweek.com/critical-flaw-led-to-azure-cosmos-db-pwnage/
14
8
Prompted by OpenAI Disclosure, Anthropic Finds Its Own Models Hacked 3 Organizations A security company’s systems were hacked after it installed a malicious Python package deployed by Claude.  The post Prompted by OpenAI Disclosure, Anthropic Finds Its Own Models Hacked 3 Organizations appeared first on SecurityWeek. https://www.securityweek.com/after-openai-disclosure-anthropic-finds-its-own-models-hacked-3-organizations/
16
9
EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels When the AI Act comes into force, AI companies will be required to make clear to consumers with labels or digital watermarks that chatbots or imagery are generated with AI. The post EU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in Brussels appeared first on SecurityWeek. https://www.securityweek.com/eu-to-crack-down-on-ai-deepfakes-illicit-imagery-and-hacking-with-new-team-in-brussels/
15
10
Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace The internet giant has built an agent harness to find vulnerabilities across Chrome’s codebase. The post Google AI Uncovers 13-Year-Old Chrome Flaw Amid Record Patching Pace appeared first on SecurityWeek. https://www.securityweek.com/googles-ai-agent-uncovers-13-year-old-chrome-flaw-amid-record-patching-pace/
12
11
Cyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian Hackers Iran has the “geopolitical motivations” and a recent history of targeting water systems, experts pointed out. The post Cyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian Hackers appeared first on SecurityWeek. https://www.securityweek.com/cyberattacks-on-minnesota-water-systems-investigated-as-officials-warn-about-iranian-hackers/
12
12
In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research Noteworthy stories that might have slipped under the radar: parcel delivery company OnTrac hacked, Adobe patches, UK Department for Education loses 607,000 records. The post In Other News: OpenAI Open Source Tool, AWS Links Hacks to North Korea, Mythos Crypto Research appeared first on SecurityWeek. https://www.securityweek.com/in-other-news-openai-open-source-tool-aws-links-hacks-to-north-korea-mythos-crypto-research/
12
13
Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests One of Anthropic's Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security vendor. It was one of three incidents affecting real companies. [...] https://www.bleepingcomputer.com/news/security/anthropics-claude-breached-3-orgs-uploaded-pypi-malware-during-tests/
12
14
ESET tracks rise in malicious AI skills and adaptable malware Attackers are adapting established techniques to AI platforms, emerging technologies, and changing user behavior. ESET's new threat report examines the rise of malicious AI skills, AI-assisted malware, ClickFix attacks, record quishing activity, and ransomware tools designed to disable security software. [...] https://www.bleepingcomputer.com/news/security/eset-tracks-rise-in-malicious-ai-skills-and-adaptable-malware/
12
15
CISA warns of cyberattacks disrupting U.S. water utilities The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a significant increase in attacks targeting internet-exposed programmable logic controllers (PLCs) in the water and wastewater systems sector. [...] https://www.bleepingcomputer.com/news/security/cisa-warns-of-cyberattacks-disrupting-us-water-utilities/
16
16
Hacker uses DeepSeek AI to autonomously attack vulnerable servers A Chinese-speaking threat actor is using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous cyberattacks on exposed servers with limited human involvement. [...] https://www.bleepingcomputer.com/news/security/hacker-uses-deepseek-ai-to-autonomously-attack-vulnerable-servers/
13
17
OpenAI says its new GPT 5.6 models are becoming more cost-efficient OpenAI says it has reduced the price of two GPT-5.6 models, cutting Luna's API price by 80% and Terra's by 20% as it works to make its models more efficient. [...] https://www.bleepingcomputer.com/news/artificial-intelligence/openai-says-its-new-gpt-56-models-are-becoming-more-cost-efficient/
14
18
Online ad firm Adform’s script compromised to steal cryptocurrency Online advertising firm Adform suffered a supply-chain attack that delivered cryptocurrency-stealing scripts to websites using its ad platform, replacing wallet addresses copied to visitors' clipboards with ones controlled by an attacker. [...] https://www.bleepingcomputer.com/news/security/online-ad-firm-adforms-script-compromised-to-steal-cryptocurrency/
17
19
Arch Linux disables AUR package adoption to stop malware flood The Arch Linux project has temporarily disabled adoption of Arch User Repository (AUR) packages after a surge in malicious takeovers of existing packages. [...] https://www.bleepingcomputer.com/news/security/arch-linux-disables-aur-package-adoption-to-stop-malware-flood/
23
20
Amgen says cloud data breach exposed patient health, proprietary info Pharmaceutical company Amgen says it suffered a data breach after threat actors stole corporate data and patient information stored in multiple cloud systems operated by third-party service providers. [...] https://www.bleepingcomputer.com/news/security/amgen-says-cloud-data-breach-exposed-patient-health-proprietary-info/
33