Cybersecurity

Security news and threats

50 articles

Cybersecurity

Microsoft's Patch for Russian-Exploited Windows Zero-Day Proved Incomplete, New Flaw Under Active Attack

Microsoft and the US Cybersecurity and Infrastructure Security Agency (CISA) have issued warnings that attackers are actively exploiting a zero-click Windows vulnerability capable of exposing sensitive information on unpatched systems — coming on the heels of revelations that Microsoft's earlier patch for a separate zero-day, previously exploited by Russian state-sponsored hackers, failed to fully address the underlying flaw.

30 Apr·3 min
Cybersecurity

Critical Security Flaws Target Linux Systems and Web Hosting Infrastructure

Security researchers disclosed multiple high-severity vulnerabilities this week, including a critical authentication bypass in cPanel & WHM (CVE-2026-41940) that could expose millions of hosted websites to full server compromise, and a Linux privilege escalation exploit (CVE-2026-31431) capable of granting root access across every major Linux distribution using just 732 bytes of code — while the broader cybersecurity community continues to grapple with escalating software supply chain attacks.

30 Apr·3 min·3 sources
Cybersecurity

Open Source Security Breach Exposes Credentials of Widely-Used ML Monitoring Tool

A widely-used open source machine-learning monitoring tool was compromised late last week when attackers exploited a vulnerability in the developers' account workflow, pushing a malicious version that harvested user credentials, API tokens, and SSH keys from affected systems — a breach that underscores the persistent security risks embedded in the modern open source software supply chain.

28 Apr·3 min·3 sources
Cybersecurity

US Defence Contractor Employee Sold Government Hacking Tools to Russia, Exposing Spyware to Criminal Networks

An employee of Trenchant, a US defence contractor and government malware vendor, secretly sold a suite of powerful hacking tools to a Russian company, according to reporting by TechCrunch journalist Lorenzo Franceschi-Bicchierai. The tools are believed to have subsequently reached Russian intelligence services and may also have been acquired by Chinese criminal actors, in what security researchers are describing as one of the most consequential leaks in the modern commercial spyware industry.

28 Apr·3 min
Cybersecurity

UK Biobank Health Data Repeatedly Appearing on GitHub, Raising Privacy Concerns

Health data from the UK Biobank, one of the world's most significant biomedical research databases containing genetic and health information on approximately 500,000 volunteers, has repeatedly been discovered in public repositories on GitHub, raising serious concerns about data governance, researcher compliance, and the privacy of participants who contributed their biological samples and personal health records.

24 Apr·3 min·5 sources