CyberNews

Cybersecurity News Dashboard

Category

Filter the feed by target type (multi-select)
Clear
Showing 11–20 of 330 articles
OS BleepingComputer

Microsoft shares temporary fix for Windows 11 gaming issues

Microsoft has shared a temporary fix for ongoing gaming issues caused by Windows 11 updates released during the August 2026 Patch Tuesday. On impacted PCs, users reported games crashing or failing to launch, as well as game freezes, "EXCEPTION_ACCESS_VIOLATION" errors, and even unexpected system restarts. When it confirmed it was investigating this known issue on Wednesday, Microsoft said it affects games like ARC Raiders, MARVEL Tōkon: Fighting Souls, and The Finals on systems running Windows 11 24H2 and 25H2. "Following the release of Windows updates on August 11, 2026 (KB5121003) and later, Microsoft received reports of issues involving inability to run games as expected," Microsoft noted. In a Thursday update, the company linked the gaming issues to drivers or components installed by RGB devices on affected Windows systems.

Aug 24, 2026, 09:42 AM Read more →
OS Security Affairs

TikTok Settles U.S. Child Privacy Case for $400 Million

TikTok will pay $400 million to settle U.S. claims that it violated child privacy laws by collecting data from users under 13. The U.S. Department of Justice announced that TikTok will pay $400 million to settle a 2024 lawsuit over children’s privacy. “Today, the Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated entities (TikTok) resolving litigation concerning compliance with the Children’s Online Privacy Protection Act and its implementing regulations (COPPA).” reads the press release published by DoJ. “Under the settlement, TikTok will pay $300 million immediately and an additional $100 million upon entry of an order vacating a prior consent decree entered against TikTok’s predecessor, Musical.ly. The settlement represents one of the largest recoveries ever obtained in a COPPA case.” TikTok will pay $300 million immediately and another $100 million after a court order removes an earlier consent decree involving Musical.ly. The 2024 case, brought by the DoJ and FTC, accused TikTok of knowingly allowing children under 13 to create accounts and illegally collecting data from children using Kids Mode. Since the Justice Department filed its lawsuit against TikTok in 2024, the company has made major changes to its ownership, management, compliance, and privacy practices. It has also introduced stronger safeguards for younger users, improved age controls, and expanded parental oversight. The DOJ said these measures have advanced the goals of its case and strengthened protections for millions of U.S. families. The settlement reflects a focus on practical results, securing a significant recovery while recognizing TikTok’s compliance improvements. The case was filed in California and handled by the DOJ’s Civil Division following a referral from the FTC. “This settlement is a major victory for American children and parents,” said Associate Attorney General Stanley E. Woodward Jr. “The Department’s priority is ensuring that children are protected online and that companies entrusted with their personal information meet their legal obligations. This resolution secures a substantial recovery while reinforcing the protections that families expect and deserve.” TikTok has faced regulatory scrutiny over children’s privacy before. In September 2023, Ireland’s Data Protection Commission fined the company €345 million for breaching the GDPR through its handling of children’s personal data. Follow me on Twitter: @securityaffairs and Facebook and Mastodon Pierluigi Paganini (SecurityAffairs – hacking, privacy)

Aug 24, 2026, 07:23 AM Read more →
OS The Hacker News

Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning

Cybersecurity researchers have found that several websites are still actively distributing a malware family known as Weedhack to gamers by masquerading as Minecraft clients. McAfee Labs said it detected and blocked more than 6,300 attempts to access malicious sites, adding that it found lookalike gaming websites designed to mimic legitimate projects, including branding, feature lists, FAQs,

Aug 24, 2026, 05:41 PM Read more →
ICS The Hacker News

⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More

A package gets installed. A login prompt opens. A box sits exposed to the internet. Nothing looks unusual yet. That’s roughly the mood this week. Trusted tools turn hostile, old weak spots get fresh attention, AI makes exploit work cheaper, and researchers keep finding attacks that sound harder than they actually are. Plenty to clean up. Here’s the short version. ⚡ Threat of the Week U.S.

Aug 24, 2026, 02:32 PM Read more →
OS The Hacker News

Shipping More AI Code Than You Can Secure? Watch How to Control Remediation Debt

If your developers are using AI coding tools, you are probably already seeing the upside: faster development, more code, and less time spent on routine work. The harder part is what comes after. AI can also introduce open-source packages at a pace your security team was never built to handle. More dependencies mean more vulnerabilities to review, more remediation work, and a backlog that can

Aug 24, 2026, 11:58 AM Read more →
OS The Hacker News

Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor

Cybersecurity researchers have flagged a cyber espionage campaign targeting Myanmar that uses graduation ceremony invitation lures to deliver a Go backdoor called QUICAgent. The campaign, codenamed Operation QUICSILVER, has been found to target government and information technology sectors, per Seqrite Labs. The activity is assessed to be the work of a China-nexus threat actor with moderate

Aug 24, 2026, 11:51 AM Read more →
OS The Hacker News

The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Risk

Big security risks come in small packages. While enterprise security teams focus on policing the proliferation of employees using ChatGPT and Claude for quick drafting tasks, a more urgent threat is posed by a handful of AI super-adopters who are quietly hardcoding unvetted tools into critical business operations. According to new research published by Akamai, the top 5% of enterprise power

Aug 24, 2026, 11:30 AM Read more →
OS The Hacker News

UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit

Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that's targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors. The vast majority of the targets are located in Brazil, Bolivia, China, Canada, and Vietnam. Details of the threat activity came to light following the discovery of an open

Aug 24, 2026, 08:08 AM Read more →
NETWORK BleepingComputer

ToxicPanda Android malware uses VPN permissions to block Google Play

The ToxicPanda Android malware has evolved with new malicious functionality, expanding its targeting to 349 applications and adding support for 167 remote commands. The malware now requests VPN service permissions to create a local interface that allows it to control network traffic passing through it. The feature enables ToxicPanda 2.0 to block communication from Google Play and Google Play Services. Control at the network level permits the malware to interfere with various security checks and actions, such as app verifications, updates, Play Protect communication, or legitimate disruptions designed to protect users. After obtaining VPN service permissions, ToxicPanda 2.0 blocks communications to Google Play before extracting and installing its payload, then requests Accessibility Service permissions.

Aug 23, 2026, 02:23 PM Read more →
OS Security Affairs

Security Affairs newsletter Round 591 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. ToxicPanda 2.0 Gets a Major Upgrade, Expanding Attacks Across 16 CountriesMalware Hijacks Android Car Head UnitsCritical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command ExecutionU.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalogYour Shredded Visa Card May Still Work at the CheckoutSix Maximum-Severity Flaws Found in Cisco ProductsFake Conferences, OAuth and WhatsApp: Inside Russia’s New Espionage TacticsGitLab Warns of Active Exploitation of Critical GraphQL FlawPoland’s CERT Warns of Active Exploitation of Critical Zimbra Collaboration Suite FlawU.S. CISA adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalogCl0p Targets 40+ Organizations Through PTC Windchill FlawManic: The Android Malware That Exfiltrates Data Even When the Phone Is OfflineNSA, CISA, FBI, DOE, and EPA Warn of Active AI-Assisted Attacks on Siemens S7 PLCsU.S. CISA adds an MLflow flaw to its Known Exploited Vulnerabilities catalogUS Indicts 17 Iranians Over Years-Long Cyber Espionage CampaignStopAndProtect Turns 2,000 Hacked WordPress Sites Into a Criminal NetworkInside Operation CameraSwarm: How One Actor Took Over 14,000 Dahua CamerasMicrosoft Tracks MacSync Stealer by Its Behavior, Not Its Domains50,000 Stripe Secrets Leaked in Public CodeU.S. CISA adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalogHackers Expose Data of 1.2 Million Heights Finance CustomersProject noRecognition: Teaching AI to Fool Surveillance CamerasGitLab Patches Critical Unauthenticated GraphQL VulnerabilityU.S. CISA adds a Ray-Project Ray flaw to its Known Exploited Vulnerabilities catalogNew Mirai-Based Evooo1Bot Botnet Targets Linux DevicesSafePal Says 39,798 Customers Hit by Data BreachLiteLLM Supply-Chain Attack – Technology, Banking and Healthcare the Most AffectedInvisible AI Prompts Trigger Court SanctionsMcDonald’s Employee Data Appears in Leak, Seller Claims 1.7M Records StolenAkira Ransomware Uses Safe Mode to Bypass EDRDDoS Attacks Cause Major Threema OutagesMustang Panda Upgrades CoolClient With a Kernel RootkitSophisticated Cyberattack Exposes Data of 678,000 French TaxpayersAPT36 Suspected in PATCHCORD Espionage Campaign Using Google Sheets C2 International Press – Newsletter Cybercrime McDonald’s employee data listed for sale in wider Entra campaign       $7 Million in Expired Domains Fuel a Streaming Empire with a Malware Secret  Live Stripe keys for 659 merchants, published for free   Clop Returns with Custom Implant in Mass-Extortion Campaign   Justice Department Secures $400M Settlement with TikTok and ByteDance to Resolve Children’s Privacy Litigation        Malware Akira Hits Safe Mode: Ransomware Rebooting Around EDR  Hunting MacSync Stealer infrastructure through behavioral pivots  Manic: Blend between Banking Malware & Spyware   The ToxicPanda Never Sleeps: ToxicPanda 2.0 Prepares its Next Strike on Mobile The invisible passenger in your car Grandoreiro goes north: From Brazil to Mexico with a new DLL sideloading campaign   Hacking Large-scale DDoS attacks disrupted Threema secure messaging service The LiteLLM Supply-Chain Attack — TeamPCP “SANDCLOCK” CI/CD Credential-Harvesting Campaign via a Backdoored Trivy GitHub Action   Actively exploited vulnerability in Zimbra Collaboration Suite AI-assisted tool helped secure satellite communication system after 2022 Russian hacking Expired credit cards revived by researchers to make unauthorized payments      CDN Tsunami: Exploiting HTTP/3-HTTP/1.1 Conversion for DoS Attacks When the NASA Ground Station Has No Lock on the Door: Unauthenticated Command Execution in AIT-GUI (GHSA-p9r8-2q67-fp86)       Zero-click Grok data theft: Cryptographic Context Injection attack leaks chat histories   Intelligence and Information Warfare   Operation CameraSwarm:  Over 14,000 Dahua cameras compromised across Ukraine and Russia  17 Iranians Charged with Conducting Massive Cyber Theft Campaign on Behalf of the Islamic Revolutionary Guard Corps and Other Iranian Entities   Defending Against an Active Threat to Siemens S7 Series PLCs   Rust Supply Chain Attack on arrayref: Significant Overlap with DPRK Campaigns   Going with the Flow(s): Distinct Clusters Target Individuals of Interest to Russia   SilkParasite: Tracking a China-Nexus APT Across Central Asia Revealed: Cyber spies used malware from GitHub to hack EncroChat cryptophone network     Cybersecurity France probes unprecedented cyberattack after tax data of 678,000 users stolen  Person Hides Prompt Injection in Legal Filing Telling AI to Side With Them   SafePal Unauthorized Access To A Subset Of Customer Order Information  This ‘adversarial’ pattern can prevent surveillance cameras from detecting you  France’s cybersecurity problem demands strong political will   The Powerful Chinese AI Model Experts Warned About—and Waited for—Is Here  OpenAI president says companies should do 10 things ASAP to defend against AI cyber threats  Follow me on Twitter: @securityaffairs and Facebook and Mastodon Pierluigi Paganini (SecurityAffairs – hacking, newsletter)

Aug 23, 2026, 08:29 AM Read more →