ZCyberNews
中文

Articles

460 articles

VoidLink Rootkit Framework Combines LKM and eBPF for Linux PersistenceHIGH
Malware

VoidLink Rootkit Framework Combines LKM and eBPF for Linux Persistence

Elastic Security Labs dissects VoidLink, a Linux rootkit framework that blends Loadable Kernel Modules with eBPF hooks to evade detection and maintain stealthy persistence on…

3 min readVoidLink
ADT Breach Exposes Customer Data in Cyber IntrusionHIGH
Industry News

ADT Breach Exposes Customer Data in Cyber Intrusion

ADT confirmed cybercriminals breached its systems on April 20, 2026, stealing a limited set of customer and prospect data. No financial info or credentials compromised.

2 min read
CISA Adds 4 Exploited Flaws to KEV, Sets May 2026 DeadlineCRITICAL
Vulnerabilities

CISA Adds 4 Exploited Flaws to KEV, Sets May 2026 Deadline

CISA added 4 actively exploited vulnerabilities to its KEV catalog — SimpleHelp, Samsung MagicINFO 9, and D-Link DIR-823X — with a May 2026 federal remediation deadline.

CVE-2024-57726
3 min read
Cyberattackers Weaponize Voltage Fluctuations Against Power GridsHIGH
Industry News

Cyberattackers Weaponize Voltage Fluctuations Against Power Grids

Dark Reading reports attackers are manipulating voltage to destabilize power grids — a growing cyber-physical threat vector targeting electricity infrastructure with no patch…

2 min readSandworm
Delta ASDA-Soft PAR Buffer Overflow Hits 7.8 CVSSHIGH
Vulnerabilities

Delta ASDA-Soft PAR Buffer Overflow Hits 7.8 CVSS

CVE-2026-5726: A stack-based buffer overflow in Delta Electronics ASDA-Soft PAR file parsing scores 7.8 CVSS and enables remote code execution via crafted PAR files.

CVE-2026-5726
3 min read
Elastic Security Backs UK MoD Defence Cyber Marvel 2026 ExerciseINFORMATIONAL
Industry News

Elastic Security Backs UK MoD Defence Cyber Marvel 2026 Exercise

Elastic Security Labs deployed AI-driven detection pipelines for the UK Ministry of Defence's Defence Cyber Marvel 2026 exercise, processing 1.2TB of telemetry across 50 simulated…

2 min read
FortiGate SSO Bypass CVE-2025-59718 Exploited in Active AttacksCRITICAL
Vulnerabilities

FortiGate SSO Bypass CVE-2025-59718 Exploited in Active Attacks

Rapid7 IR confirms active exploitation of CVE-2025-59718 — a 9.8-CVSS FortiGate SSO bypass — enabling attackers to gain persistent admin access on unpatched appliances.

CVE-2025-59718
2 min read
Locked Shields 2026: 41 Nations Train in Largest Cyber Defense
Industry News

Locked Shields 2026: 41 Nations Train in Largest Cyber Defense

Locked Shields 2026 involved 41 nations in the largest live-fire cyber defense exercise, testing response to critical infrastructure attacks including power grid and telecom…

2 min read
Microsoft Patches Critical ASP.NET Core CVE-2026-40372 PrivilegeCRITICAL
Vulnerabilities

Microsoft Patches Critical ASP.NET Core CVE-2026-40372 Privilege

Microsoft released out-of-band patches for CVE-2026-40372, a 9.1-CVSS privilege escalation flaw in ASP.NET Core affecting all supported versions.

CVE-2026-40372
3 min read
ADT Confirms Breach as ShinyHunters Leaks Customer DataHIGH
Industry News

ADT Confirms Breach as ShinyHunters Leaks Customer Data

ADT confirmed a data breach after ShinyHunters leaked 30,000+ customer records including names, emails, and account details from a compromised Salesforce instance.

2 min readShinyHunters
AI Agent Authority Gap Creates New Enterprise Security Blind SpotsHIGH
Industry News

AI Agent Authority Gap Creates New Enterprise Security Blind Spots

The Hacker News reports AI agents create a structural security gap: delegated actors lack continuous oversight, enabling lateral movement and privilege escalation without human…

3 min read
AI-Powered Phishing Surges as Attackers Personalize Lures at ScaleHIGH
Industry News

AI-Powered Phishing Surges as Attackers Personalize Lures at Scale

Enterprises report a sharp rise in AI-generated phishing campaigns that craft personalized lures at scale, moving from broad sprays to 1-to-1 targeting in the last six months.

2 min read
← PrevPage 25 of 39Next →