uz
Feedback

Firibgarlarga uchmang! Telemetrio bunday kanallarni topadi va belgilaydi 👉 Belgini ko‘rmoqchi bo‘lsangiz, obuna bo‘ling 👈

Vulnerability News

Vulnerability News

Kanalga Telegram’da o‘tish

Every day new posts about vulnerabilities and cybersecurity news. Get the latest news about the cyberspace! Group: @VulnerabilityNewsGroup

Ko'proq ko'rsatish
5 451
Obunachilar
+324 soatlar
+277 kun
+16830 kun
Postlar arxiv
Fake Decryption Tools Masked $11M Markup in Ransomware Recovery Scheme Zohar Pinhasi was paying ransoms to obtain decryption keys and then charging victims substantially more for remediation. The post Fake Decryption Tools Masked $11M Markup in Ransomware Recovery Scheme appeared first on SecurityWeek. https://www.securityweek.com/fake-decryption-tools-masked-11m-markup-in-ransomware-recovery-scheme/

TP-Link Faces State Lawsuits and New Scrutiny Over ISP Router Flaws SEC Consult has published technical details on vulnerabilities mentioned in a complaint filed by several US states. The post TP-Link Faces State Lawsuits and New Scrutiny Over ISP Router Flaws appeared first on SecurityWeek. https://www.securityweek.com/tp-link-faces-state-lawsuits-and-new-scrutiny-over-isp-router-flaws/

Rein Security Raises $25 Million to Guard AI Agents at Runtime The cybersecurity startup will invest in product innovation, agentic research, and employee base expansion. The post Rein Security Raises $25 Million to Guard AI Agents at Runtime appeared first on SecurityWeek. https://www.securityweek.com/rein-security-raises-25-million-to-guard-ai-agents-at-runtime/

SonicWall and Splunk Patch Critical Vulnerabilities Critical and high-severity vulnerabilities could allow attackers to bypass authentication, execute arbitrary code, and elevate their privileges. The post SonicWall and Splunk Patch Critical Vulnerabilities appeared first on SecurityWeek. https://www.securityweek.com/sonicwall-and-splunk-patch-critical-vulnerabilities/

US Seeks Alleged Chinese Hafnium Hacker With $10 Million Reward Zhang Yu was charged alongside Xu Zewei, who was extradited from Italy to the US in April 2026. The post US Seeks Alleged Chinese Hafnium Hacker With $10 Million Reward appeared first on SecurityWeek. https://www.securityweek.com/us-seeks-alleged-chinese-hafnium-hacker-with-10-million-reward/

Attackers Target Critical Atlassian Vulnerability Within Hours of PoC Publication Threat actors have started targeting CVE-2026-21589, a critical vulnerability in Atlassian’s self-hosted Data Center products. The post Attackers Target Critical Atlassian Vulnerability Within Hours of PoC Publication appeared first on SecurityWeek. https://www.securityweek.com/attackers-target-critical-atlassian-vulnerability-within-hours-of-poc-publication/

Security Awareness Training Isn’t Dead, but It Needs a Rethink All enterprises conduct security awareness training for their employees. But whether this has tangible benefits is debatable. The post Security Awareness Training Isn’t Dead, but It Needs a Rethink appeared first on SecurityWeek. https://www.securityweek.com/security-awareness-training-isnt-dead-but-it-needs-a-rethink/

Cisco Patches a Dozen Critical Vulnerabilities The security defects could lead to unauthorized access, information leaks, privilege escalation, DoS attacks, and remote code execution. The post Cisco Patches a Dozen Critical Vulnerabilities appeared first on SecurityWeek. https://www.securityweek.com/cisco-patches-a-dozen-critical-vulnerabilities/

Ransomware recovery CEO charged over secret ransom payments The owner of ransomware remediation company MonsterCloud has been charged with allegedly defrauding ransomware victims by secretly paying their attackers for decryptors while claiming to use proprietary technology to recover encrypted data. [...] https://www.bleepingcomputer.com/news/security/ransomware-recovery-ceo-charged-over-secret-ransom-payments/

Samsung Galaxy S26 hacked three more times at Pwn2Own Ireland ​​​On the second day of Pwn2Own Ireland 2026, security researchers collected $232,500 in cash awards after exploiting 45 unique zero-day vulnerabilities. [...] https://www.bleepingcomputer.com/news/security/samsung-galaxy-s26-hacked-three-more-times-at-pwn2own-ireland/

Owner of Empire cybercrime market gets 40 years in prison The co-creator of Empire Market, one of the largest dark web marketplaces before its shutdown, has been sentenced to 40 years in prison for facilitating $430 million in illegal transactions from 2018 to 2020. [...] https://www.bleepingcomputer.com/news/security/owner-of-empire-cybercrime-market-gets-40-years-in-prison/

ASOS links data breach to social engineering attack, credential theft ASOS is sending updates to affected customers about the cybersecurity incident it suffered earlier this week, confirming that hackers accessed some personal data. [...] https://www.bleepingcomputer.com/news/security/asos-links-data-breach-to-social-engineering-attack-credential-theft/

Microsoft Teams to get support for third-party deepfake detection tools Microsoft will soon introduce support for third-party deepfake detection solutions and impersonation protection in Teams meetings. [...] https://www.bleepingcomputer.com/news/security/microsoft-teams-to-add-third-party-deepfake-detection-impersonation-protection/

Uranium crypto exchange hacker convicted for stealing $53 million A Maryland man was found guilty of stealing more than $53 million after hacking the decentralized crypto exchange Uranium Finance twice in April 2021. [...] https://www.bleepingcomputer.com/news/security/uranium-crypto-exchange-hacker-found-guilty-of-53-million-theft/

OAuth grants pile up faster than you can review them. Here's how to keep up. OAuth grants create data highways between SaaS apps, AI agents, and other tools. And, they are multiplying faster than any security team can review them. As the recent Klue breach showed, attackers are taking notice and exploiting forgotten OAuth grants to gain access to corporate data. This article covers why OAuth risks are so hard [...] https://www.bleepingcomputer.com/news/security/oauth-grants-pile-up-faster-than-you-can-review-them-heres-how-to-keep-up/

Cisco warns of critical flaws allowing Nexus switch takeover Cisco released security advisories for five critical vulnerabilities in its NX-OS data center network operating system that could be exploited to run arbitrary code with root privileges on Nexus switches. [...] https://www.bleepingcomputer.com/news/security/cisco-warns-of-critical-flaws-allowing-nexus-switch-takeover/

FakeGit malware campaign returns with 17,610 malicious GitHub repos More than 17,000 fake repositories on GitHub are distributing the SmartLoader malware after the FakeGit campaign reactivated earlier this month to push the StealC infostealer. [...] https://www.bleepingcomputer.com/news/security/fakegit-malware-campaign-returns-with-17-610-malicious-github-repos/

Low-cost Android phones ship with residential proxy malware A malware campaign dubbed 'Midnight Mimosa' has been discovered on low-cost Android smartphones that ship with malicious software embedded in their firmware, allowing attackers to silently install apps, perform ad fraud, and turn devices into residential proxies. [...] https://www.bleepingcomputer.com/news/security/low-cost-android-phones-ship-with-residential-proxy-malware/

Ransomware attack disrupts Japan's IDCF Cloud used by govt clients IDC Frontier, a major Japanese cloud and digital infrastructure company, disclosed that its IDCF Cloud service was targeted in a ransomware attack that caused an outage at a data center cluster serving the eastern part of the country. [...] https://www.bleepingcomputer.com/news/security/ransomware-attack-disrupts-japans-idcf-cloud-used-by-govt-clients/

FBI disrupts Chinese hacking tools used to breach critical infrastructure The FBI has seized seven domains used by Chinese state-sponsored hackers known as Flax Typhoon to operate two hacking tools, MicroScan and FishHub, used in attacks that breached critical infrastructure and other organizations worldwide. [...] https://www.bleepingcomputer.com/news/security/fbi-disrupts-chinese-hacking-tools-used-to-breach-critical-infrastructure/