CyberNews

Cybersecurity News Dashboard

Category

Filter the feed by target type (multi-select)
Clear
Showing 1–10 of 133 articles
NETWORK BleepingComputer

Police arrests dozens of suspects in global cybercrime crackdown

Law enforcement agencies from 22 countries helped identify 263 suspects and arrested 58 individuals linked to cybercrime networks coordinated by African crime groups. The "Operation Jackal IV" international joint action targeted West African criminal networks between November 2025 and June 2026. The operation also focused on disrupting the Black Axe cybercrime syndicate, known for its involvement in global-scale cyber-enabled financial fraud. Most commonly, Black Axe and similar criminal rings are targeting victims in romance scams, cryptocurrency and investment scams, or business email compromise fraud, but they've often also been linked to violent crimes. During Operation Jackal IV, Argentinian law officers made 17 arrests, and they linked 196 suspects to a major Crime-as-a-Service network that provided West African organized crime groups with web domains and money-laundering support.

Aug 25, 2026, 10:53 AM Read more →
API Palo Alto Unit 42 Ransomware

The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution

Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution. The post The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution appeared first on Unit 42.

Aug 25, 2026, 10:00 AM Read more →
NETWORK Security Affairs CVE-2026-21962 ↗

U.S. CISA adds maximum-severity Oracle flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Oracle flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in flaw, tracked as CVE-2026-21962 (CVSS score of 10,0), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-21962 is a critical, unauthenticated vulnerability affecting the Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in for Apache HTTP Server and IIS. An attacker does not need an account or valid credentials. With network access, they can exploit the flaw remotely through HTTP and potentially compromise the affected server. Successful exploitation could allow the attacker to access, modify or delete critical data, potentially gaining broad access to information available through the affected components. “Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion, or modification access to critical data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in accessible data,” CISA reports. The vulnerability also has a scope-change impact, meaning an attacker who exploits it could potentially affect other systems or applications connected to the vulnerable Oracle components. The flaw affects versions: 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. In practical terms, this is dangerous because an internet-accessible Oracle WebLogic proxy component could provide an attacker with a path into critical backend systems without requiring authentication. In March 2026, CloudSEK researchers detected attacks targeting several known flaws in Oracle WebLogic against its honeypot network. Attackers also targeted CVE-2026-21962 along with older WebLogic RCE vulnerabilities, including CVE-2020-14882/14883, CVE-2020-2551 and CVE-2017-10271. “This report analyzes attack data collected from a high-interaction honeypot simulating a vulnerable Oracle WebLogic Server (v14.1.1.0.0) over a 12-day period (Jan 22 – Feb 3, 2026). The primary focus is the immediate and widespread exploitation of the newly disclosed, critical unauthenticated Remote Code Execution (RCE) vulnerability, CVE-2026-21962 (CVSS: 10.0).” ” reads the report published CloudSEK. “In addition to CVE-2026-21962, the honeypot captured attacks targeting other persistent, critical WebLogic RCE flaws, including CVE-2020-14882/14883 (Console RCE), CVE-2020-2551 (IIOP RCE), and CVE-2017-10271 (WLS-WSAT RCE). This confirms that threat actors continue to rely on a small set of highly-effective, simple-to-exploit vulnerabilities to compromise WebLogic environments.” According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog. Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure. CISA orders federal agencies to fix the flaw by August 27, 2026. Follow me on Twitter: @securityaffairs and Facebook and Mastodon Pierluigi Paganini (SecurityAffairs – hacking, CISA)

Aug 25, 2026, 08:48 AM Read more →
NETWORK The Hacker News

Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode

Marimo has addressed a high-severity security flaw in its notebook software that allowed an attacker to execute an attacker-supplied Model Context Protocol (MCP) command in a specially crafted notebook, according to VulnCheck's CVE Numbering Authority (CNA) record. The CNA record says the command can run as a local subprocess when the notebook is opened in edit mode. The vulnerability, tracked

Aug 25, 2026, 12:43 PM Read more →
NETWORK The Hacker News

E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands

Cybersecurity researchers are calling attention to a new campaign that employs FTP banners as dead drop resolvers (DDRs) to deliver two previously unreported remote access trojans (RATs) tracked as E4del and PINHOLE. While threat actors are known to abuse legitimate services to point to additional command-and-control (C2) infrastructure and blend in with regular network traffic, the development

Aug 25, 2026, 11:33 AM Read more →
NETWORK The Hacker News CVE-2026-21962 ↗

Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-21962 (CVSS score: 10.0), allows an unauthenticated attacker with network access via HTTP to

Aug 25, 2026, 06:12 AM Read more →
NETWORK BleepingComputer

Unpatched Calix flaw lets hackers bypass NAT to expose internal devices

An unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers used by multiple U.S. broadband providers allows remote, unauthenticated attackers to create port-forwarding rules that can expose local network devices to the public internet.

Aug 24, 2026, 09:14 PM Read more →
API BleepingComputer

South Korean startup platform breach exposes key management failures

A breach at South Korea's government-backed startup platform exposed encrypted personal data after an encryption key was included in an API. Penta Security explains why encryption keys must be securely managed and kept separate from the data they protect.

Aug 24, 2026, 02:00 PM Read more →
ICS The Hacker News

⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More

A package gets installed. A login prompt opens. A box sits exposed to the internet. Nothing looks unusual yet. That’s roughly the mood this week. Trusted tools turn hostile, old weak spots get fresh attention, AI makes exploit work cheaper, and researchers keep finding attacks that sound harder than they actually are. Plenty to clean up. Here’s the short version. ⚡ Threat of the Week U.S.

Aug 24, 2026, 02:32 PM Read more →
NETWORK BleepingComputer

ToxicPanda Android malware uses VPN permissions to block Google Play

The ToxicPanda Android malware has evolved with new malicious functionality, expanding its targeting to 349 applications and adding support for 167 remote commands. The malware now requests VPN service permissions to create a local interface that allows it to control network traffic passing through it. The feature enables ToxicPanda 2.0 to block communication from Google Play and Google Play Services. Control at the network level permits the malware to interfere with various security checks and actions, such as app verifications, updates, Play Protect communication, or legitimate disruptions designed to protect users. After obtaining VPN service permissions, ToxicPanda 2.0 blocks communications to Google Play before extracting and installing its payload, then requests Accessibility Service permissions.

Aug 23, 2026, 02:23 PM Read more →