ZCyberNews
中文

Articles

460 articles

Instructure Breach: Student Data Stolen, Services DisruptedHIGH
Industry News

Instructure Breach: Student Data Stolen, Services Disrupted

Instructure disclosed a breach where hackers stole names, emails, student IDs, and messages, and disrupted Canvas platform services. Data leak threats follow.

2 min read
Loan Fraud Rings Exploit Credit Union Verification GapsHIGH
Industry News

Loan Fraud Rings Exploit Credit Union Verification Gaps

Flare details how fraudsters bypass credit union loan verification using stolen identities and synthetic SSNs, costing institutions millions in chargebacks.

3 min read
Medtronic Discloses Cyberattack on Corporate IT SystemsHIGH
Industry News

Medtronic Discloses Cyberattack on Corporate IT Systems

Medtronic reported unauthorized access to its corporate IT systems in a cyberattack, with no impact on medical devices or patient care operations. Data was compromised.

2 min read
OpenAI Strengthens ChatGPT Login Security With New ControlsMEDIUM
Industry News

OpenAI Strengthens ChatGPT Login Security With New Controls

OpenAI rolls out Advanced Account Security for ChatGPT: mandatory passkeys, shorter sessions, and account recovery changes. Affects all users globally.

2 min read
Polymarket Gamblers Threaten Journalist Over Event VerificationHIGH
Industry News

Polymarket Gamblers Threaten Journalist Over Event Verification

Polymarket gamblers threatened a journalist whose story was used to verify a real-world event for betting settlements, highlighting oracle manipulation risks on the prediction…

3 min read
Pro-Orbán Media Firm Mediaworks Breached by Ransomware GroupHIGH
Industry News

Pro-Orbán Media Firm Mediaworks Breached by Ransomware Group

Ransomware group claims breach of Mediaworks, a pro-Orbán Hungarian media conglomerate. The firm confirmed unauthorized access and potential data exfiltration on Friday.

2 min readLockBit
Weaver E-cology Zero-Day CVE-2026-22679 Exploited Since MarchCRITICAL
Vulnerabilities

Weaver E-cology Zero-Day CVE-2026-22679 Exploited Since March

CVE-2026-22679 (CVSS 9.8) in Weaver E-cology OA has been exploited in the wild since mid-March 2026. Attackers run discovery commands post-exploit. No patch available.

CVE-2026-22679
3 min read
Instructure Data Breach: ShinyHunters Claims TheftHIGH
Industry News

Instructure Data Breach: ShinyHunters Claims Theft

ShinyHunters claims to have stolen data from Instructure, the edtech firm behind Canvas LMS. Instructure confirms a breach involving unauthorized access to certain systems and…

2 min readShinyHunters
Microsoft Defender False Positives Flag DigiCert Certs as TrojansMEDIUM
Industry News

Microsoft Defender False Positives Flag DigiCert Certs as Trojans

Microsoft Defender is flagging legitimate DigiCert root certificates as Trojan:Win32/Cerdigent.A!dha, triggering false-positive alerts and certificate removal on Windows systems.

2 min read
Flowise RCE Vulnerability CVE-2026-41265 Carries CVSS 9.8CRITICAL
Vulnerabilities

Flowise RCE Vulnerability CVE-2026-41265 Carries CVSS 9.8

CVE-2026-41265 in Flowise Airtable_Agent allows unauthenticated remote code execution with CVSS 9.8. ZDI advisory details code injection in default installations.

CVE-2026-41265
3 min read
Instructure Probes Cyber Incident Impacting Canvas PlatformHIGH
Industry News

Instructure Probes Cyber Incident Impacting Canvas Platform

Instructure, maker of the Canvas LMS used by over 30 million students, disclosed a cybersecurity incident and is investigating potential data exposure across its infrastructure.

2 min read
Poisoned Ruby Gems, Go Modules Hijack CI/CD PipelinesHIGH
Malware

Poisoned Ruby Gems, Go Modules Hijack CI/CD Pipelines

BufferZoneCorp account published malicious Ruby gems and Go modules that steal credentials, tamper with GitHub Actions, and establish SSH persistence in CI pipelines.

2 min readBufferZoneCorp
← PrevPage 18 of 39Next →