RSS Amplifier

News source

CySecurity News - Latest Information Security and Hacking Incidents

CySecurity News is leading portal for IT Security and Hacker News. Get Cyber Security, hacker and cyber crime updates.

cysecurity.newsSource feed ↗20 articles

Overdue Last read · last published · next check
Last read 3 days ago, longer than this feed's 10 hours schedule.

Written by

Latest articles

Ultra-Wealthy Turn to Premium Services to Erase Their Digital Footprints

For the ultra-wealthy, protecting personal information is increasingly becoming a premium service. High-net-worth individuals and corporations are paying specialized privacy firms to track down and remove personally identifiable information (PII) from search engines, data-broker databases and even the dark web. Unlike automated privacy tools, these high-end services combine data removal with…

Siemens S7 PLCs Face Emerging Threat From AI-Generated Exploit Scripts

A cyber threat targeting critical infrastructure has been reported by the U.S. government utilizing AI-generated exploit scripts aimed at Siemens programmable logic controllers (PLCs) of the S7 Series. Reconnaissance and exploit development are among the activities, with malicious scripts masquerading as legitimate monitoring tools used to monitor PLC installations in the country. The NSA, CISA,…

North Korean Hackers Target 1,640 Companies Across 57 Countries, Researcher Finds

North Korean hackers have been targeting the infrastructure and cryptocurrency wallets worldwide. Greek security expert Vangelis Stykas identified 1,640 organizations across 57 countries hit by the attack. His investigation, which gained unauthorized access to the networks run by North Korean hackers, took about 22 months. At the Black Hat conference in Las Vegas, Stykas spoke about the attacks,…

Loud Phone Use is Becoming A New Battleground for Public-space Etiquette

For commuters, a journey on public transport can now come with an unexpected soundtrack: someone else's smartphone. A passenger watching videos without headphones, streaming music through a phone speaker or taking a call on loudspeaker turns what should be a private activity into something everyone nearby can hear. The habit has acquired names including “ loudcasting ” and “sodcasting”, and…

Here's Why Skipping Windows Updates Puts Your PC at Risk

Skipping Windows updates may seem harmless, especially when an update requires a restart or temporarily changes familiar settings. Many users postpone updates because they fear slower performance, bugs, or interruptions during work. However, Windows updates are not limited to new features and interface changes. They also contain important security patches that repair weaknesses discovered by…

AI Proves Decades-Old Math Problems With Machine-Checkable Results

The cost of generating new results on some of mathematics’ long-standing open problems has dropped dramatically, with OpenAI claiming that its Astra model produced machine-checkable proofs for 10 questions that had remained unresolved for at least a decade. OpenAI published the research on August 1, using the name Astra for its next major model family. The work spans several areas of advanced…

Phishing-as-a-Service Is Turning Credential Theft Into a Scalable Cybercrime Business

Phishing is no longer limited to technically skilled criminals building fraudulent campaigns from scratch. Through phishing-as-a-service (PhaaS), attackers can rent ready-made infrastructure and tools that allow them to impersonate trusted organisations, harvest credentials and target victims at scale. Phishing attacks use social engineering to persuade victims to surrender sensitive information.…

Malware Attacks Google-Synced Passkeys

Security researchers have uncovered three attack techniques that could allow malware on compromised Windows computers to abuse passkeys synchronized through Google Password Manager. The attacks, collectively called “Pass-ta-key,” target Chrome devices equipped with a Trusted Platform Module (TPM). Rather than breaking the cryptography behind passkeys, the techniques exploit weaknesses in device…

BTMOB Android RAT Ecosystem Expands With Resellers, Source-Code Sellers and Impersonators

The Android remote access trojan known as BTMOB most likely began as a centralized malware-as-a-service operation but transformed into a wider ecosystem, with resellers, source code buyers, rogue operators, and possibly even impersonators, according to the Flare researchers. BTMOB is a remote access trojan for Android devices that takes the form of malware-as-a-service. It offers an “exploit…

Coldcard Bitcoin Wallets Hit by Ongoing Attack Exploiting Key Generation Flaw

A software flaw in Coldcard hardware wallets has raised fresh concerns about the security of offline cryptocurrency storage after a software flaw in Coldcard hardware wallets allowed attackers to drain millions of dollars in Bitcoin.The attack has affected thousands of wallets using Coinkite’s Coldcard devices. By August 3, about 1,367 Bitcoin worth US$86 million had been stolen from more than…

Launching a Consulting Business? It’s Time to Get Some Skin in the Game

Starting a consulting business can look deceptively simple. You have expertise, you know there are businesses that need it, and unlike a product company, you do not need a warehouse full of inventory before you can start selling. But turning expertise into a functioning consulting business is another matter. There is a point when consulting stops being an idea and becomes a business. It is usually…

Bitcoin Could Face Quantum Computing Threat Within Years, Experts Warn

Bitcoin faces existential threat from quantum computers, according to some experts. With the passage of time, researchers have voiced growing concerns that hackers could utilize these powerful processors to decrypt the cryptographic functions that protect Bitcoin. David McAlvany, the CEO of gold app Vaulted, believes that Bitcoin could be gone in four years because of quantum computing. However,…

AI Pricing Explained: Why Token-Based Costs Are Challenging Businesses

Artificial intelligence is rapidly becoming an essential business tool, but companies are still struggling to decide how much AI services should cost. Unlike traditional software, which is often sold through monthly subscriptions or licences, AI systems can consume different amounts of computing power depending on the complexity of each task. This makes pricing difficult for both technology…

Claude AI Agents Escalate Into Malware Conflict During Anthropic Tests

During anthropopic’s latest testing, the company discovered a unique security risk associated with autonomous artificial intelligence systems. AI agents working toward different goals may attack one another in conflicting instructions. Three instances of the agent Claude were observed running on separate virtual machines during a “multiagent turf war”. The test was intended to examine how the…

Cloudflare Workers Spectre Attack Exposed JWT at 12 Bits Per Second

Cybersecurity researchers have uncovered a remote Spectre attack targeting Cloudflare Workers that was capable of extracting a JSON Web Token (JWT) from a co-located Worker in a production environment at speeds of up to 12 bits per second. This represents a significant increase over an earlier attack demonstrated in 2021, which achieved just 2 bits per minute. The researchers conducted an…

Microsoft Copilot Flaws Could Expose User Data With One Click

Microsoft Copilot Personal contains three vulnerabilities that could allow an attacker to execute a malicious prompt with one click and exfiltrate data from connected applications, according to Varonis Threat Labs. The researchers collectively named the flaws CoSnitch and reported them to Microsoft in December 2025. Microsoft patched the vulnerabilities on August 18, 2026, with the issue tracked…

Critical Snowflake GitHub Actions Flaw Exposes Projects to Command Injection

Snowflake’s public snowflakedb/snowflake-connector-net repository has been identified as vulnerable to GitHub Actions workflow injection. This vulnerability could be exploited to trigger command execution within CI/CD workflow through specially crafted GitHub issues. In this case, the flaw is attributed to the repository’s automatic workflow, jira_issue.yml, which runs automatically when a public…

Apple Patches Dozens of WebKit Flaws in Latest Security Updates

Apple has issued a major set of security updates for macOS, iOS, and iPadOS after discovering dozens of vulnerabilities in WebKit, the browser engine that powers Safari and many apps across its platforms. The latest macOS Tahoe update fixes 28 flaws, 21 of them in WebKit, while older-device releases such as iOS 18.7.10 and iPadOS 18.7.10 address more than 120 bugs, including more than 40 WebKit…

Clop-Linked Web Shell Targets PTC Windchill Servers in Data Theft Attacks

A custom Java web shell, associated with the Clop ransomware group, was created to target the PTC Windchill and FlexPLM servers by decrypting their credentials, enumerating file repositories, and stealing data. Researchers at cybersecurity firm ReliaQuest discovered the web shell after analyzing the recent data-theft campaign that abused the critical remote code execution vulnerability,…

Vatican’s Official Prayer App Exposed Data of Over 700,000 Users

There was a security flaw in the Vatican's official Click to Pray application that exposed personal information linked to more than 700,000 registered users, but the vulnerability remained unknown until it was detected by an independent security researcher earlier this year. A worldwide prayer network developed by La Machi Communication for Good Causes for the Pope's Worldwide Prayer Network,…