Arch Linux Packages Compromised
Over 400 Arch Linux packages have been compromised to distribute a Linux rootkit and infostealer malware, targeting credentials and access tokens.
The traditional model of finding and patching vulnerabilities is no longer effective, prompting a shift towards risk-based disclosure and prioritization.
Over 400 Arch Linux packages have been compromised to distribute a Linux rootkit and infostealer malware, targeting credentials and access tokens.
The US, France, and Italy collaborated to seize domains CFAKE.com and SOCFAKE.com, which hosted thousands of AI-generated nude images and videos of women without their consent.
Iranian cyber group Handala has claimed responsibility for hacking California Water Service, leaking 5GB of stolen data in retaliation for US actions in Iran.
Cisco's SD-WAN management software is affected by a seventh actively exploited zero-day vulnerability this year, marked as CVE-2026-20245, allowing authenticated attackers to execute commands as root.
Microsoft released updates to fix nearly 200 security vulnerabilities, including 32 critical bugs, with exploit code publicly available for at least three weaknesses.
The Gentlemen ransomware group has been identified as the second most active ransomware gang, with at least 332 published victims, and its administrator's real-life identity has been uncovered as Alexander Andreevich Yapaev.
OnyxC2 stealer is available for hire starting at $250 per month, offering stealth and extensive reach to cybercriminals, with access to 210 applications and extensions across nine categories.
AI-driven threats are outpacing traditional security operations, with Gartner predicting a 50% reduction in exploit time by 2027, emphasizing the need for unified, AI-powered security stacks.
A proposal to establish a US Cyber Force as the country's latest military branch was narrowly defeated in the Senate Armed Services Committee with a 14-13 vote.