CyberNews

Cybersecurity News Dashboard

Category

Filter the feed by target type (multi-select)
Clear
Showing 41–50 of 122 articles
WEBAPP CISA

CISA Unveils New Cybersecurity Resources for K-12 Schools and Districts

Official websites use .gov A .gov website belongs to an official government organization in the United States. Secure .gov websites use HTTPS A lock (LockA locked padlock) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites. Staying Secure at Eventsno-cost Cyber Servicessecure your businessKnown Exploited Vulnerabilities CatalogReport A Cyber Issue WASHINGTON - The Cybersecurity and Infrastructure Security Agency (CISA) today released the K-12 Cybersecurity Foundations Resource Package, a comprehensive collection of guides, videos and supplemental materials to help K‑12 schools and districts prevent, mitigate and respond to prevalent cyber threats. Based on current cybersecurity best practices and frameworks, the resource package outlines cost-effective, actionable and customizable steps that K-12 institutions can take to develop and maintain effective cybersecurity programs.

Aug 12, 2026, 12:00 PM Read more →
API The Hacker News

OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning

A newly disclosed flaw in the way OpenAI, Anthropic, and Google carried hidden AI reasoning between API calls let researchers recover internal reasoning and secrets from session logs, including API keys and passwords. The weakness affected encrypted reasoning objects used by the providers' reasoning APIs, where a block created in one session could be replayed into another and, during testing,

Aug 12, 2026, 11:47 AM Read more →
RANSOMWARE BleepingComputer Ransomware

DeadLock ransomware uses blockchain to resist infrastructure takedown

The DeadLock ransomware operation is using a decentralized infrastructure that relies on blockchain-backed services to protect its communication with victims and data-leak activity. The threat actor emerged in mid-2025 and uses double-extortion tactics (data theft/leak and file encryption) to pressure victims into paying a ransom. By July this year, DeadLock's data leak site listed 80 organizations, mostly from Europe. Victims include companies in the IT, mining, transportation, manufacturing, hospitality, and consumer goods sectors. Microsoft researchers observed the malware being deployed by multiple groups, including an affiliate previously linked to the Lynx and INC ransomware ecosystems. The DeadLock ransomware operators adopted a new approach that uses the Polygon blockchain to store configuration data and the posts on the leak site.

Aug 11, 2026, 10:15 PM Read more →
RANSOMWARE Security Affairs

ExfilSquad Targets New Victims, Shares Data via Torrents

ExfilSquad targets 13 organizations, exploiting cloud portals for data theft and using torrents to spread stolen information and amplify damage. Resecurity is tracking the activity of ExfilSquad – the group announced new victims this week. ExfilSquad is a new cybercrime group that emerged in mid-2026. Instead of using ransomware, it steals data and threatens to […]

Aug 11, 2026, 04:44 PM Read more →
RANSOMWARE The Hacker News Ransomware

DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt

The ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data leak operations in a bid to improve operational resilience. "Its recovery ecosystem combines the Session messaging network with blockchain-backed services that store and deliver resources used throughout the extortion process," the Microsoft Threat

Aug 11, 2026, 04:35 PM Read more →
RANSOMWARE The Hacker News Ransomware

DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt - The Hacker News

The ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data leak operations in a bid to improve operational resilience. "Its recovery ecosystem combines the Session messaging network with blockchain-backed services that store and deliver resources used throughout the extortion process," the Microsoft Threat Intelligence team said. The tech giant said it observed the ransomware being deployed by multiple threat actors, including an affiliate for Lynx and INC ransomware. DeadLock was first detected in July 2025, employing double extortion tactics to encrypt victim environments and apply pressure by threatening to publicly release exfiltrated data. As of this month, the group has claimed 96 victims, with most of them located in Italy, Spain, Poland, Türkiye, and the U.S.

Aug 11, 2026, 04:35 PM Read more →
RANSOMWARE BleepingComputer

Vague Task, Total Access: When AI Delegation Becomes a Security Risk

AI agents can improvise beyond the intended scope of a task when they are given broad access to enterprise systems and data. Token Security explains why organizations need to define agent intent and continuously enforce permissions around what each agent was actually created to do. [...]

Aug 11, 2026, 01:15 PM Read more →
IOT The Hacker News

A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices - thehackernews.com

A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices  thehackernews.com

Aug 11, 2026, 12:22 PM Read more →
RANSOMWARE BleepingComputer Ransomware

CISA: Microsoft SharePoint flaw now exploited in ransomware attacks

CISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagged as actively exploited since early July. Tracked as CVE-2026-45659, this security flaw stems from a deserialization of untrusted data weakness and allows attackers with low privileges to execute arbitrary code on unpatched SharePoint servers. It can also be exploited in low-complexity attacks because (as Microsoft explained in May when it released security updates for SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition) "an attacker does not require significant prior knowledge of the system and can achieve repeatable success with the payload against the vulnerable component." The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities Catalog (KEV) on July 1, ordering Federal Civilian Executive Branch (FCEB) agencies to secure their servers within three days.

Aug 11, 2026, 12:12 PM Read more →
IOT The Hacker News

A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices

A malicious SIM card can order the device it sits in to run commands of the attacker's choosing. On the cellular modules built into electric-vehicle chargers, industrial routers, and car telematics units, that is enough to take the whole device over. Researchers at the University of Birmingham and the security firm Fuzzware tested 26 phones and cellular modules for the capability, found it

Aug 11, 2026, 12:05 PM Read more →