Skip to content
AttackFeed by Joe Wagner | Cybersecurity News from Across the Internet

AttackFeed by Joe Wagner

Cybersecurity News from Across the Internet

  • Attack/News Feeds
  • Gov Alerts/ISAC Feeds
  • Vulnerability Alerts
  • Privacy/Governance Feeds
  • Fraud Feeds
  • iOS App
  • Android App
AttackFeed by Joe Wagner | Hack-for-hire spyware campaign targets journalists in Middle East, North Africa  - CyberScoop
Attack Feeds
Hack-for-hire spyware campaign targets journalists in Middle East, North Africa  – CyberScoop
April 8, 2026
AttackFeed by Joe Wagner | Suspected Dream Market kingpin arrested after gold bars sent to his home address  - GRAHAM CLULEY
Attack Feeds
Suspected Dream Market kingpin arrested after gold bars sent to his home address  – GRAHAM CLULEY
May 14, 2026
AttackFeed by Joe Wagner | ShinyHunters’ Instructure Canvas LMS and Vimeo Breaches Impact Millions of Users  - Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds
ShinyHunters’ Instructure Canvas LMS and Vimeo Breaches Impact Millions of Users  – Hackread – Cybersecurity News, Data Breaches, AI and More
May 6, 2026
AttackFeed by Joe Wagner | Zero lessons learned: Convicted scammer allegedly ran another athlete-focused phishing scam from federal prison  - CyberScoop
Attack Feeds
Zero lessons learned: Convicted scammer allegedly ran another athlete-focused phishing scam from federal prison  – CyberScoop
March 16, 2026
AttackFeed by Joe Wagner | FortiGate Devices Exploited to Breach Networks and Steal Service Account Credentials  - The Hacker News
Attack Feeds
FortiGate Devices Exploited to Breach Networks and Steal Service Account Credentials  – The Hacker News
March 10, 2026
AttackFeed by Joe Wagner | NIST Limits CVE Enrichment After 263% Surge in Vulnerability Submissions  - The Hacker News
Attack Feeds
NIST Limits CVE Enrichment After 263% Surge in Vulnerability Submissions  – The Hacker News
April 17, 2026

Hackers Exploit CVE-2025-32975 (CVSS 10.0) to Hijack Unpatched Quest KACE SMA Systems  – The Hacker News

Posted on March 23, 2026 By [email protected] (The Hacker News)
Hackers Exploit CVE-2025-32975 (CVSS 10.0) to Hijack Unpatched Quest KACE SMA Systems  – The Hacker News
Attack Feeds

Threat actors are suspected to be exploiting a maximum-severity security flaw impacting Quest KACE Systems Management Appliance (SMA), according to Arctic Wolf. The cybersecurity company said it observed malicious activity starting the week of March 9, 2026, in customer environments that’s consistent with the exploitation of CVE-2025-32975 on unpatched SMA systems exposed to the internet. … Read More “Hackers Exploit CVE-2025-32975 (CVSS 10.0) to Hijack Unpatched Quest KACE SMA Systems  – The Hacker News” »

Politics live: new standards for datacentres being built in Australia; report warns of drone threat  – Data and computer security | The Guardian

Posted on March 22, 2026 By Krishani Dhanji
Politics live: new standards for datacentres being built in Australia; report warns of drone threat  – Data and computer security | The Guardian
Attack Feeds

Labor under pressure over fuel crisis as federal parliament returns. Follow updates live Get our breaking news email, free app or daily news podcast Should Australians work from home to save fuel? James Glenday then asks Tim Ayres whether he thinks Australians should consider working from home to conserve fuel. Countries like Sri Lanka have … Read More “Politics live: new standards for datacentres being built in Australia; report warns of drone threat  – Data and computer security | The Guardian” »

FBI Warns Russian Hackers Target Signal, WhatsApp in Mass Phishing Attacks  – The Hacker News

Posted on March 21, 2026 By [email protected] (The Hacker News)
FBI Warns Russian Hackers Target Signal, WhatsApp in Mass Phishing Attacks  – The Hacker News
Attack Feeds

Threat actors affiliated with Russian Intelligence Services are conducting phishing campaigns to compromise commercial messaging applications (CMAs) like WhatsApp and Signal to seize control of accounts belonging to individuals with high intelligence value, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI) said Friday. “The campaign  – Read More  – … Read More “FBI Warns Russian Hackers Target Signal, WhatsApp in Mass Phishing Attacks  – The Hacker News” »

Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager  – The Hacker News

Posted on March 21, 2026 By [email protected] (The Hacker News)
Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager  – The Hacker News
Attack Feeds

Oracle has released security updates to address a critical security flaw impacting Identity Manager and Web Services Manager that could be exploited to achieve remote code execution. The vulnerability, tracked as CVE-2026-21992, carries a CVSS score of 9.8 out of a maximum of 10.0. “This vulnerability is remotely exploitable without authentication,” Oracle said in an … Read More “Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager  – The Hacker News” »

CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026  – The Hacker News

Posted on March 21, 2026 By [email protected] (The Hacker News)
CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026  – The Hacker News
Attack Feeds

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added five security flaws impacting Apple, Craft CMS, and Laravel Livewire to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch them by April 3, 2026. The vulnerabilities that have come under exploitation are listed below – CVE-2025-31277 (CVSS score: 8.8) – A … Read More “CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026  – The Hacker News” »

Trivy Supply Chain Attack Triggers Self-Spreading CanisterWorm Across 47 npm Packages  – The Hacker News

Posted on March 21, 2026 By [email protected] (The Hacker News)
Trivy Supply Chain Attack Triggers Self-Spreading CanisterWorm Across 47 npm Packages  – The Hacker News
Attack Feeds

The threat actors behind the supply chain attack targeting the popular Trivy scanner are suspected to be conducting follow-on attacks that have led to the compromise of a large number of npm packages with a previously undocumented self-propagating worm dubbed CanisterWorm. The name is a reference to the fact that the malware uses an ICP … Read More “Trivy Supply Chain Attack Triggers Self-Spreading CanisterWorm Across 47 npm Packages  – The Hacker News” »

Hacker Group LAPSUS$ Claims Alleged AstraZeneca Data Breach  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on March 20, 2026 By Waqas
Hacker Group LAPSUS$ Claims Alleged AstraZeneca Data Breach  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

LAPSUS$ claims it breached AstraZeneca, offering alleged source code, credentials, cloud configs, and employee data for sale in leaked samples.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

FBI, CISA issue PSA on Russian intelligence campaign to target messaging apps  – CyberScoop

Posted on March 20, 2026 By Tim Starks
FBI, CISA issue PSA on Russian intelligence campaign to target messaging apps  – CyberScoop
Attack Feeds

Russian intelligence-affiliated hackers have gained access to thousands of users’ messaging apps with a global phishing campaign, the FBI and the Cybersecurity and Infrastructure Security Agency warned in a public service announcement on Friday. The high-value targets they’re pursuing include current and former U.S. government officials, political figures, military personnel and journalists, the two agencies … Read More “FBI, CISA issue PSA on Russian intelligence campaign to target messaging apps  – CyberScoop” »

Trivy Security Scanner GitHub Actions Breached, 75 Tags Hijacked to Steal CI/CD Secrets  – The Hacker News

Posted on March 20, 2026 By [email protected] (The Hacker News)
Trivy Security Scanner GitHub Actions Breached, 75 Tags Hijacked to Steal CI/CD Secrets  – The Hacker News
Attack Feeds

Trivy, a popular open-source vulnerability scanner maintained by Aqua Security, was compromised a second time within the span of a month to deliver malware that stole sensitive CI/CD secrets. The latest incident impacted GitHub Actions “aquasecurity/trivy-action” and “aquasecurity/setup-trivy,” which are used to scan Docker container images for vulnerabilities and set up GitHub Actions workflow  – … Read More “Trivy Security Scanner GitHub Actions Breached, 75 Tags Hijacked to Steal CI/CD Secrets  – The Hacker News” »

Trio sentenced for facilitating North Korean IT worker scheme from their homes  – CyberScoop

Posted on March 20, 2026 By Matt Kapko
Trio sentenced for facilitating North Korean IT worker scheme from their homes  – CyberScoop
Attack Feeds

Three American men were sentenced Friday for crimes they committed in furtherance of North Korea’s vast scheme to get operatives hired at U.S. companies, the Justice Department said. The trio — Audricus Phagnasay, 25, Jason Salazar, 30, and Alexander Paul Travis, 35 — pleaded guilty in November to wire fraud conspiracy for providing U.S. identities … Read More “Trio sentenced for facilitating North Korean IT worker scheme from their homes  – CyberScoop” »

Russian Intelligence Services Target Commercial Messaging Application Accounts  – IC3.gov News

Posted on March 20, 2026 By Joe-W
Gov/ISAC Feeds

Post Content – Read More – IC3.gov News 

Ubiquiti defect poses account takeover risk for UniFi Networking Application users  – CyberScoop

Posted on March 20, 2026 By Matt Kapko
Ubiquiti defect poses account takeover risk for UniFi Networking Application users  – CyberScoop
Attack Feeds

Researchers and threat hunters are scrambling to contain a maximum-severity defect in Ubiquiti’s UniFi Network Application that attackers could exploit to take over user accounts by accessing and manipulating files. The path-traversal vulnerability — CVE-2026-22557 — affects software used to manage UniFi networking devices, including access points, gateways and switches. The vendor disclosed and released … Read More “Ubiquiti defect poses account takeover risk for UniFi Networking Application users  – CyberScoop” »

Critical Langflow Flaw CVE-2026-33017 Triggers Attacks within 20 Hours of Disclosure  – The Hacker News

Posted on March 20, 2026 By [email protected] (The Hacker News)
Critical Langflow Flaw CVE-2026-33017 Triggers Attacks within 20 Hours of Disclosure  – The Hacker News
Attack Feeds

A critical security flaw impacting Langflow has come under active exploitation within 20 hours of public disclosure, highlighting the speed at which threat actors weaponize newly published vulnerabilities. The security defect, tracked as CVE-2026-33017 (CVSS score: 9.3), is a case of missing authentication combined with code injection that could result in remote code execution. “The … Read More “Critical Langflow Flaw CVE-2026-33017 Triggers Attacks within 20 Hours of Disclosure  – The Hacker News” »

Denver’s crosswalks hacked to broadcast anti-Trump messages  – GRAHAM CLULEY

Posted on March 20, 2026 By Graham Cluley
Denver’s crosswalks hacked to broadcast anti-Trump messages  – GRAHAM CLULEY
Attack Feeds

Pedestrians crossing a street in Denver, Colorado, got rather more than they bargained for last weekend, when the audio signals at two crosswalks began broadcasting a political message alongside their usual walking instructions. Read more in my article on the Hot for Security blog.  – Read More  – GRAHAM CLULEY 

Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks  – The Hacker News

Posted on March 20, 2026 By [email protected] (The Hacker News)
Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks  – The Hacker News
Attack Feeds

Apple is urging users who are still running an outdated version of iOS to update their iPhones to secure against web-based attacks carried out via powerful exploit kits like Coruna and DarkSword. These attacks employ malicious web content to target out-of-date versions of iOS, triggering an infection chain that leads to the theft of sensitive … Read More “Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks  – The Hacker News” »

Why Image Format Conversion Is Becoming a Practical Issue in Web Security and Performance  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on March 20, 2026 By Owais Sultan
Why Image Format Conversion Is Becoming a Practical Issue in Web Security and Performance  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

WebP boosts performance raises compatibility issues, making image format conversion to PNG essential for secure, flexible, and efficient web workflows today.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

Justice Department disrupts botnet networks that hijacked 3 million devices  – CyberScoop

Posted on March 20, 2026 By Matt Kapko
Justice Department disrupts botnet networks that hijacked 3 million devices  – CyberScoop
Attack Feeds

Authorities seized infrastructure powering four botnets that hijacked a combined three million devices and launched more than 300,000 DDoS attacks collectively, the Justice Department said Thursday. The botnets — Aisuru, Kimwolf, JackSkid and Mossad — enabled operators to sell access to the infected devices for various cybercrimes. The aftermath spanned thousands of attacks, including some … Read More “Justice Department disrupts botnet networks that hijacked 3 million devices  – CyberScoop” »

New Fake Zoom Meeting Invite Scam Spreads Malware on Windows PCs  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on March 20, 2026 By Deeba Ahmed
New Fake Zoom Meeting Invite Scam Spreads Malware on Windows PCs  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

Cybersecurity researchers at Sublime Security have discovered a new scam that uses realistic, interactive JavaScript-based Zoom meeting invites to trick users into installing malware.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

Magento PolyShell Flaw Enables Unauthenticated Uploads, RCE and Account Takeover  – The Hacker News

Posted on March 20, 2026 By [email protected] (The Hacker News)
Magento PolyShell Flaw Enables Unauthenticated Uploads, RCE and Account Takeover  – The Hacker News
Attack Feeds

Sansec is warning of a critical security flaw in Magento’s REST API that could allow unauthenticated attackers to upload arbitrary executables and achieve code execution and account takeover. The vulnerability has been codenamed PolyShell by Sansec owing to the fact that the attack hinges on disguising malicious code as an image. There is no evidence … Read More “Magento PolyShell Flaw Enables Unauthenticated Uploads, RCE and Account Takeover  – The Hacker News” »

Google Adds 24-Hour Wait for Unverified App Sideloading to Reduce Malware and Scams  – The Hacker News

Posted on March 20, 2026 By [email protected] (The Hacker News)
Google Adds 24-Hour Wait for Unverified App Sideloading to Reduce Malware and Scams  – The Hacker News
Attack Feeds

Google on Thursday announced a new “advanced flow” for Android sideloading that requires a mandatory 24-hour wait period to install apps from unverified developers in an attempt to balance openness with safety. The new changes come against the backdrop of a developer verification mandate the tech giant announced last year that requires all Android apps … Read More “Google Adds 24-Hour Wait for Unverified App Sideloading to Reduce Malware and Scams  – The Hacker News” »

The Importance of Behavioral Analytics in AI-Enabled Cyber Attacks  – The Hacker News

Posted on March 20, 2026 By [email protected] (The Hacker News)
The Importance of Behavioral Analytics in AI-Enabled Cyber Attacks  – The Hacker News
Attack Feeds

Artificial Intelligence (AI) is changing how individuals and organizations conduct many activities, including how cybercriminals carry out phishing attacks and iterate on malware. Now, cybercriminals are using AI to generate personalized phishing emails, deepfakes and malware that evade traditional detection by impersonating normal user activity and bypassing legacy security models. As a result,  – Read … Read More “The Importance of Behavioral Analytics in AI-Enabled Cyber Attacks  – The Hacker News” »

LeakNet ransomware: what you need to know  – GRAHAM CLULEY

Posted on March 20, 2026 By Graham Cluley
Attack Feeds

A ransomware gang that claims to be a group of “investigative journalists”? Meet LeakNet – the group using fake CAPTCHA pages to trick employees into hacking themselves. Read more in my article on the Fortra blog.  – Read More  – GRAHAM CLULEY 

Hackers Exploit Critical Langflow Bug in Just 20 Hours –

Posted on March 20, 2026 By Joe-W
Hackers Exploit Critical Langflow Bug in Just 20 Hours –
Privacy/Governance Feed

Sysdig details how threat actors exploited a critical CVE in Langflow in less than a day – Read More  –  

NCA Boss Warns That Teens Are Being “Radicalized” Into Cybercrime Online –

Posted on March 20, 2026 By Joe-W
NCA Boss Warns That Teens Are Being “Radicalized” Into Cybercrime Online –
Privacy/Governance Feed

The National Crime Agency’s director general warns that technology is rapidly reshaping crime – Read More  –  

DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks  – The Hacker News

Posted on March 20, 2026 By [email protected] (The Hacker News)
DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks  – The Hacker News
Attack Feeds

The U.S. Department of Justice (DoJ) on Thursday announced the disruption of command-and-control (C2) infrastructure used by several Internet of Things (IoT) botnets like AISURU, Kimwolf, JackSkid, and Mossad as part of a court-authorized law enforcement operation. The effort also saw authorities from Canada and Germany targeting the operators behind these botnets, with a number … Read More “DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks  – The Hacker News” »

North Carolina tech worker found guilty of insider attack netting $2.5M ransom  – CyberScoop

Posted on March 19, 2026 By Matt Kapko
North Carolina tech worker found guilty of insider attack netting $2.5M ransom  – CyberScoop
Attack Feeds

A 27-year-old North Carolina man was found guilty of six counts of extortion for a series of crimes he committed while working as a data analyst contractor for a D.C.-based international technology company, the Justice Department said Thursday. Cameron Nicholas Curry, also known as “Loot,” stole a trove of corporate data, including sensitive employee and … Read More “North Carolina tech worker found guilty of insider attack netting $2.5M ransom  – CyberScoop” »

Feds Disrupt IoT Botnets Behind Huge DDoS Attacks  – Krebs on Security

Posted on March 19, 2026 By BrianKrebs
Feds Disrupt IoT Botnets Behind Huge DDoS Attacks  – Krebs on Security
Attack Feeds

The U.S. Justice Department joined authorities in Canada and Germany in dismantling the online infrastructure behind four highly disruptive botnets that compromised more than three million Internet of Things (IoT) devices, such as routers and web cameras. The feds say the four botnets — named Aisuru, Kimwolf, JackSkid and Mossad — are responsible for a … Read More “Feds Disrupt IoT Botnets Behind Huge DDoS Attacks  – Krebs on Security” »

Can Zero Trust survive the AI era?  – CyberScoop

Posted on March 19, 2026 By djohnson
Can Zero Trust survive the AI era?  – CyberScoop
Attack Feeds

For the past decade, cybersecurity experts in the federal government have argued that trust, or a lack of it, was key to developing effective security policies for agency systems and data. But today, cybercriminals and state-sponsored hackers are using artificial intelligence to develop and launch cyberattacks more quickly and efficiently. Governments and businesses are facing … Read More “Can Zero Trust survive the AI era?  – CyberScoop” »

Speagle Malware Hijacks Cobra DocGuard to Steal Data via Compromised Servers  – The Hacker News

Posted on March 19, 2026 By [email protected] (The Hacker News)
Speagle Malware Hijacks Cobra DocGuard to Steal Data via Compromised Servers  – The Hacker News
Attack Feeds

Cybersecurity researchers have flagged a new malware dubbed Speagle that hijacks the functionality and infrastructure of a legitimate program called Cobra DocGuard. “Speagle is designed to surreptitiously harvest sensitive information from infected computers and transmit it to a Cobra DocGuard server that has been compromised by the attackers, masking the data exfiltration process as legitimate  … Read More “Speagle Malware Hijacks Cobra DocGuard to Steal Data via Compromised Servers  – The Hacker News” »

54 EDR Killers Use BYOVD to Exploit 34 Signed Vulnerable Drivers and Disable Security  – The Hacker News

Posted on March 19, 2026 By [email protected] (The Hacker News)
54 EDR Killers Use BYOVD to Exploit 34 Signed Vulnerable Drivers and Disable Security  – The Hacker News
Attack Feeds

A new analysis of endpoint detection and response (EDR) killers has revealed that 54 of them leverage a technique known as bring your own vulnerable driver (BYOVD) by abusing a total of 34 vulnerable drivers. EDR killer programs have been a common presence in ransomware intrusions as they offer a way for affiliates to neutralize … Read More “54 EDR Killers Use BYOVD to Exploit 34 Signed Vulnerable Drivers and Disable Security  – The Hacker News” »

Feds keep eyes peeled for Iran cyberattacks, respond to Stryker breach  – CyberScoop

Posted on March 19, 2026 By Tim Starks
Feds keep eyes peeled for Iran cyberattacks, respond to Stryker breach  – CyberScoop
Attack Feeds

Federal cyber officials aren’t seeing a significant change in attacks tied to Iran since the conflict there began, at least not yet, but they are on the lookout for any uptick and are focusing on the Stryker attack in particular. Terry Kalka — director of the Defense Industrial Base Collaborative Information Sharing Environment at The … Read More “Feds keep eyes peeled for Iran cyberattacks, respond to Stryker breach  – CyberScoop” »

Ransomware Affiliate Exposes Details of ‘The Gentlemen’ Operation –

Posted on March 19, 2026 By Joe-W
Ransomware Affiliate Exposes Details of ‘The Gentlemen’ Operation –
Privacy/Governance Feed

Hastalamuerte leaks The Gentlemen RaaS ops: FortiGate exploits, BYOVD evasion, Qilin split tactics – Read More  –  

SpyCloud’s 2026 Identity Exposure Report Reveals Explosion of Non-Human Identity Theft  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on March 19, 2026 By CyberNewswire
SpyCloud’s 2026 Identity Exposure Report Reveals Explosion of Non-Human Identity Theft  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

Austin, TX, USA, 19th March 2026, CyberNewswire  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

CISO Whisperer Names 11 Vendors Leading the Shift from Tools to Outcomes at RSA Conference 2026  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on March 19, 2026 By CyberNewswire
CISO Whisperer Names 11 Vendors Leading the Shift from Tools to Outcomes at RSA Conference 2026  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

Austin, United States, 19th March 2026, CyberNewswire  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

ThreatsDay Bulletin: FortiGate RaaS, Citrix Exploits, MCP Abuse, LiveChat Phish & More  – The Hacker News

Posted on March 19, 2026 By [email protected] (The Hacker News)
ThreatsDay Bulletin: FortiGate RaaS, Citrix Exploits, MCP Abuse, LiveChat Phish & More  – The Hacker News
Attack Feeds

ThreatsDay Bulletin is back on The Hacker News, and this week feels off in a familiar way. Nothing loud, nothing breaking everything at once. Just a lot of small things that shouldn’t work anymore but still do. Some of it looks simple, almost sloppy, until you see how well it lands. Other bits feel a … Read More “ThreatsDay Bulletin: FortiGate RaaS, Citrix Exploits, MCP Abuse, LiveChat Phish & More  – The Hacker News” »

SEC Consult SA-20260317-0 :: Multiple vulnerabilities in PEGA Infinity platform  – Full Disclosure

Posted on March 19, 2026 By Joe-W
SEC Consult SA-20260317-0 :: Multiple vulnerabilities in PEGA Infinity platform  – Full Disclosure
Alert Feeds

  Posted by SEC Consult Vulnerability Lab via Fulldisclosure on Mar 19 SEC Consult Vulnerability Lab Security Advisory < 20260317-0 > ======================================================================= title: Multiple vulnerabilities           product: PEGA Infinity platform vulnerable version: CVE-2025-62181: Pega Platform versions 7.1.0 through Infinity 25.1.0                     CVE-2025-9559: … Read More “SEC Consult SA-20260317-0 :: Multiple vulnerabilities in PEGA Infinity platform  – Full Disclosure” »

SEC Consult SA-20260318-0 :: Multiple Privilege Escalation Vulnerabilities in Arturia Software Center MacOS  – Full Disclosure

Posted on March 19, 2026 By Joe-W
SEC Consult SA-20260318-0 :: Multiple Privilege Escalation Vulnerabilities in Arturia Software Center MacOS  – Full Disclosure
Alert Feeds

  Posted by SEC Consult Vulnerability Lab via Fulldisclosure on Mar 19 SEC Consult Vulnerability Lab Security Advisory < 20260318-0 > ======================================================================= title: Multiple Privilege Escalation Vulnerabilities product: Arturia Software Center MacOS vulnerable version: 2.12.0.3157 fixed version: – CVE number: CVE-2026-24062, CVE-2026-24063              impact: high homepage:… – Read More  – Full … Read More “SEC Consult SA-20260318-0 :: Multiple Privilege Escalation Vulnerabilities in Arturia Software Center MacOS  – Full Disclosure” »

APPLE-SA-03-17-2026-1 Background Security Improvements for iOS 26.3.1, iPadOS 26.3.1, macOS 26.3.1, and macOS 26.3.2  – Full Disclosure

Posted on March 19, 2026 By Joe-W
APPLE-SA-03-17-2026-1 Background Security Improvements for iOS 26.3.1, iPadOS 26.3.1, macOS 26.3.1, and macOS 26.3.2  – Full Disclosure
Alert Feeds

  Posted by Apple Product Security via Fulldisclosure on Mar 19 APPLE-SA-03-17-2026-1 Background Security Improvements for iOS 26.3.1, iPadOS 26.3.1, macOS 26.3.1, and macOS 26.3.2 Background Security Improvements for iOS 26.3.1, iPadOS 26.3.1, macOS 26.3.1, and macOS 26.3.2 addresses the following issues. Information about the security content is also available at https://support.apple.com/126604. Apple maintains a … Read More “APPLE-SA-03-17-2026-1 Background Security Improvements for iOS 26.3.1, iPadOS 26.3.1, macOS 26.3.1, and macOS 26.3.2  – Full Disclosure” »

snap-confine + systemd-tmpfiles = root (CVE-2026-3888)  – Full Disclosure

Posted on March 19, 2026 By Joe-W
snap-confine + systemd-tmpfiles = root (CVE-2026-3888)  – Full Disclosure
Alert Feeds

  Posted by Qualys Security Advisory via Fulldisclosure on Mar 19 Qualys Security Advisory Good things come to those who wait: snap-confine + systemd-tmpfiles = root (CVE-2026-3888) ======================================================================== Contents ======================================================================== Summary Case study: Ubuntu Desktop 24.04 – Analysis – Exploitation Case study: Ubuntu Desktop 25.10 – Overview – Exploitation A quick note on the uutils … Read More “snap-confine + systemd-tmpfiles = root (CVE-2026-3888)  – Full Disclosure” »

Financial Brands Targeted in Global Mobile Banking Malware Surge –

Posted on March 19, 2026 By Joe-W
Financial Brands Targeted in Global Mobile Banking Malware Surge –
Privacy/Governance Feed

Mobile banking malware targets over 1200 financial apps globally, shifting fraud to user devices – Read More  –  

New Perseus Android Banking Malware Monitors Notes Apps to Extract Sensitive Data  – The Hacker News

Posted on March 19, 2026 By [email protected] (The Hacker News)
New Perseus Android Banking Malware Monitors Notes Apps to Extract Sensitive Data  – The Hacker News
Attack Feeds

Cybersecurity researchers have disclosed a new Android malware family called Perseus that’s being actively distributed in the wild with an aim to conduct device takeover (DTO) and financial fraud. Perseus is built upon the foundations of Cerberus and Phoenix, at the same time evolving into a “more flexible and capable platform” for compromising Android devices … Read More “New Perseus Android Banking Malware Monitors Notes Apps to Extract Sensitive Data  – The Hacker News” »

Fake Windsurf IDE Extension Uses Solana Blockchain to Steal Developer Data  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on March 19, 2026 By Deeba Ahmed
Fake Windsurf IDE Extension Uses Solana Blockchain to Steal Developer Data  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

Cybersecurity researchers at Bitdefender have discovered a malicious Windsurf IDE extension using the Solana blockchain to steal developer credentials.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

How to secure your online meetings  – All Feed

Posted on March 19, 2026 By Joe-W
Gov/ISAC Feeds

Post Content – Read More – All Feed 

How Ceros Gives Security Teams Visibility and Control in Claude Code  – The Hacker News

Posted on March 19, 2026 By [email protected] (The Hacker News)
How Ceros Gives Security Teams Visibility and Control in Claude Code  – The Hacker News
Attack Feeds

Security teams have spent years building identity and access controls for human users and service accounts. But a new category of actor has quietly entered most enterprise environments, and it operates entirely outside those controls. Claude Code, Anthropic’s AI coding agent, is now running across engineering organizations at scale. It reads files, executes shell commands, … Read More “How Ceros Gives Security Teams Visibility and Control in Claude Code  – The Hacker News” »

DarkSword iOS Exploit Kit Uses 6 Flaws, 3 Zero-Days for Full Device Takeover  – The Hacker News

Posted on March 19, 2026 By [email protected] (The Hacker News)
DarkSword iOS Exploit Kit Uses 6 Flaws, 3 Zero-Days for Full Device Takeover  – The Hacker News
Attack Feeds

A new exploit kit for Apple iOS devices designed to steal sensitive data from is being wielded by multiple threat actors since at least November 2025, according to reports from Google Threat Intelligence Group (GTIG), iVerify, and Lookout. According to GTIG, multiple commercial surveillance vendors and suspected state-sponsored actors have utilized the full-chain exploit kit, … Read More “DarkSword iOS Exploit Kit Uses 6 Flaws, 3 Zero-Days for Full Device Takeover  – The Hacker News” »

AWS Warns Hackers Have Abused Cisco Firewall Zero-Day Since January –

Posted on March 19, 2026 By Joe-W
AWS Warns Hackers Have Abused Cisco Firewall Zero-Day Since January –
Privacy/Governance Feed

Notorious ransomware group Interlock has been exploiting a Cisco zero-day bug since January, AWS says – Read More  –  

FCA Updates Cyber Incident and Third-Party Reporting Rules –

Posted on March 19, 2026 By Joe-W
FCA Updates Cyber Incident and Third-Party Reporting Rules –
Privacy/Governance Feed

The UK’s financial regulator has issued new rules to make incident and third-party reporting clearer – Read More  –  

UK: Regulation Drives Cyber Spending for Critical Infrastructure Orgs –

Posted on March 19, 2026 By Joe-W
UK: Regulation Drives Cyber Spending for Critical Infrastructure Orgs –
Privacy/Governance Feed

35% of security leaders working in the UK’s critical infrastructure said regulatory requirements are the primary influence on their security programs – Read More  –  

CISA Warns of Zimbra, SharePoint Flaw Exploits; Cisco Zero-Day Hit in Ransomware Attacks  – The Hacker News

Posted on March 19, 2026 By [email protected] (The Hacker News)
CISA Warns of Zimbra, SharePoint Flaw Exploits; Cisco Zero-Day Hit in Ransomware Attacks  – The Hacker News
Attack Feeds

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has urged government agencies to apply patches for two security flaws impacting Synacor Zimbra Collaboration Suite (ZCS) and Microsoft Office SharePoint, stating they have been actively exploited in the wild. The vulnerabilities in question are as follows – CVE-2025-66376 (CVSS score: 7.2) – A stored cross-site scripting  … Read More “CISA Warns of Zimbra, SharePoint Flaw Exploits; Cisco Zero-Day Hit in Ransomware Attacks  – The Hacker News” »

Smashing Security podcast #459: This clever scam nearly hijacked a tech CEO’s Apple ID  – GRAHAM CLULEY

Posted on March 18, 2026 By Graham Cluley
Attack Feeds

In episode 459 of Smashing Security, we dive into a chillingly clever account takeover attempt targeting WordPress co-founder Matt Mullenweg – involving MFA fatigue, real Apple alerts, a convincing support call, and a phishing page that oh-so-nearly worked. If a famous techie could have this happen to you, can you be sure you’re immune? Plus: … Read More “Smashing Security podcast #459: This clever scam nearly hijacked a tech CEO’s Apple ID  – GRAHAM CLULEY” »

Posts pagination

Previous 1 … 25 26 27 … 40 Next
  • Attack Feeds
  • Privacy/Governance Feed
  • Gov/ISAC Feeds
  • Alert Feeds
  • Privacy Policy
  • Wagner Cybersecurity

Copyright © 2026 AttackFeed by Joe Wagner.

Theme: Oceanly News Dark by ScriptsTown

We are using cookies for analytics purposes only.  We do not store, track or sell user information.

You can find out more about which cookies we are using or switch them off in .

AttackFeed by Joe Wagner
Powered by  GDPR Cookie Compliance
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.