Security

164 articles · page 4 of 4

Security

Iranian Cyberattacks on US Water Systems May Escalate, Opinion Piece Warns

In a stark opinion piece published on The Hill, cybersecurity expert Tal Kollender warns that Iran is not waiting for the end of its current conflicts to probe and attack US water systems, asserting that these assaults are just the beginning of a broader campaign against American critical infrastructure. The piece, which does not cite specific new incidents, urges US officials to treat the threat as an ongoing and escalating challenge.

26 Aug·3 min
Security

Massive DDoS Attack Cripples Norway’s Government Digital Services

A large-scale distributed denial-of-service (DDoS) attack has disrupted Norway’s shared government digital infrastructure since Monday, August 25, 2026, knocking out multiple services relied upon by the public sector and potentially affecting citizens' access to government portals. Norwegian authorities are scrambling to mitigate the ongoing assault, which experts describe as one of the most disruptive cyberattacks against the country’s administrative backbone in recent years.

26 Aug·2 min
Security

Oracle Patch Overload: 1,449 Fixes Missed Critical Flaw — Attack Exploited Legitimate Database Feature

A cyberattack exploiting an Oracle database's legitimate Java functionality has exposed a critical security gap that even all 1,449 patches released in late July would not have prevented. Security firm Huntress documented the credential theft incident, highlighting that attackers used a 'simple' SQL injection on a public-facing web application to upload a post-exploitation toolkit called khunt directly into the database engine via its embedded Java Virtual Machine. Experts say the breach, while not an Oracle vulnerability, underscores the dangers of misconfigured database features and an over-reliance on patching over basic security hygiene.

26 Aug·3 min
Security

Thousands of Enterprise Servers at Risk From Hardware-Level BMC Vulnerabilities

Security researchers have identified vulnerabilities in Baseboard Management Controllers (BMCs) — specialized processors embedded in server motherboards that enable remote, out-of-band management — potentially exposing thousands of enterprise servers to hardware-level compromise. The flaws could allow attackers to gain persistent control over affected systems, bypassing traditional operating system defenses.

26 Aug·2 min
Security

AliExpress accused of using audio fingerprinting to track users without sound

Alibaba's global marketplace AliExpress has been accused of deploying hidden audio fingerprinting scripts that silently generate waveforms using a user's browser to collect device characteristics, even when no sound is playing. The discovery, made by developer Matt Callaghan and detailed in a blog post, revealed that the practice interferes with multipoint Bluetooth audio and raises new privacy concerns about browser-based tracking.

25 Aug·2 min
Security

AliExpress Caught Using Inaudible Audio to Fingerprint Web Visitors

Chinese e-commerce giant AliExpress has been secretly fingerprinting visitors by sending inaudible sawtooth waves to their browsers, a researcher discovered after the technique interfered with his Bluetooth headphones. The practice, which uses the WebAudio API to measure unique device characteristics, was uncovered by security researcher Matthew Callaghan and raises fresh privacy concerns about covert tracking methods.

25 Aug·3 min
Security

Anthropic Deploys Claude Mythos 5 for Cyber Defense, Offers $35M in Open Source Credits

Anthropic has announced it is now running its most powerful AI model, Claude Mythos 5, through its Claude Security vulnerability scanner, offering $35 million in credits to open source projects. The move marks a significant deployment of a model the company previously held back from public release, now tasked with scanning codebases for flaws and integrating with partner products protecting critical infrastructure.

23 Aug·3 min·5 sources
Security

CISA Orders Patching of TrueConf Flaws as Malware Distribution Campaign Expands to Android Car Systems

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch two actively exploited vulnerabilities in TrueConf, a Russian-built video conferencing platform, after compromised servers were found distributing malware to meeting participants. The development comes alongside separate supply-chain attacks targeting Android car head units and a confirmed social engineering breach at cybersecurity firm ReliaQuest, highlighting a surge in multi-vector threats.

22 Aug·3 min·4 sources
Security

US agencies warn Iranian hackers using AI to target Siemens PLCs in critical infrastructure sectors

A joint advisory from U.S. federal agencies has warned that Iranian hackers are actively targeting Siemens S7-series programmable logic controllers (PLCs) used in critical infrastructure, employing AI tools to develop exploits and adapt to defensive measures. The warning, issued by CISA, NSA, FBI, DOE, and EPA, comes amid ongoing Russian cyber-espionage campaigns against academia, government, and defense organizations, as detailed by Google's Threat Intelligence Group.

22 Aug·3 min·2 sources
Security

Microsoft patches max-severity Entra ID flaw under active attack

Microsoft has fixed a maximum-severity vulnerability in its Entra ID identity and access management service that attackers were already exploiting in the wild. The flaw, tracked as CVE-2026-69836 and carrying a CVSS score of 10.0, stems from unsafe deserialization and allows unauthenticated remote code execution over the network. Microsoft disclosed the issue on Thursday, stating that it has been fully mitigated server-side without requiring any action from customers.

22 Aug·2 min·2 sources