ZCyberNews
中文

Articles

460 articles

Copperhelm Raises $7M for Agentic Cloud Security Platform
Industry News

Copperhelm Raises $7M for Agentic Cloud Security Platform

Copperhelm, an Israel-based startup founded by ex-RSA and McAfee engineers, raised $7 million in seed funding for an agentic AI platform that autonomously hunts cloud…

2 min read
Docker Desktop ECI Flaw CVE-2026-6406 Lets Attackers EscalateHIGH
Vulnerabilities

Docker Desktop ECI Flaw CVE-2026-6406 Lets Attackers Escalate

CVE-2026-6406 (CVSS 8.8) in Docker Desktop's Enhanced Container Isolation allows local attackers with low-privileged code execution inside a container to escalate privileges on…

CVE-2026-6406
3 min read
DORA Mandates Credential Management as Financial Risk ControlHIGH
Industry News

DORA Mandates Credential Management as Financial Risk Control

EU's DORA Article 9 legally requires financial firms to enforce authentication and access controls. A breach at a UK bank shows the cost of non-compliance.

2 min read
LMDeploy SSRF Flaw CVE-2026-33626 Exploited 13 Hours After DisclosureHIGH
Vulnerabilities

LMDeploy SSRF Flaw CVE-2026-33626 Exploited 13 Hours After Disclosure

CVE-2026-33626 (CVSS 7.5) in LMDeploy, an open-source LLM toolkit, was exploited in the wild within 13 hours of public disclosure, enabling SSRF attacks to access sensitive…

CVE-2026-33626
3 min read
Pre-Stuxnet Malware 'Fast16' Targeted Iranian Precision SoftwareHIGH
Malware

Pre-Stuxnet Malware 'Fast16' Targeted Iranian Precision Software

Security researchers uncovered 'Fast16,' a pre-Stuxnet sabotage malware that targeted high-precision calculation software in Iran, tampering with results and self-propagating.

2 min readFast16
Shadow AI and SaaS Expand Enterprise Attack SurfaceHIGH
Industry News

Shadow AI and SaaS Expand Enterprise Attack Surface

Forgotten integrations, shadow IT, and unmanaged SaaS agents create new attack vectors. Dark Reading reports attackers exploit these gaps without sophisticated AI.

2 min read
Siemens SINEC NMS Authentication Bypass CVE-2026-24032 Gets 7.3 CVSSHIGH
Vulnerabilities

Siemens SINEC NMS Authentication Bypass CVE-2026-24032 Gets 7.3 CVSS

ZDI disclosed CVE-2026-24032, a 7.3-CVSS authentication bypass in Siemens SINEC NMS that requires no authentication to exploit. Affects industrial network management systems.

CVE-2026-24032
3 min read
Toronto Police Bust SMS Blaster Phishing OperationHIGH
Industry News

Toronto Police Bust SMS Blaster Phishing Operation

Three men arrested in Canada's first SMS blaster case — device impersonated cell towers to send mass phishing messages and disrupt mobile networks in Toronto.

2 min read
US Vows Crackdown on Chinese Firms Exploiting American AI ModelsMEDIUM
Industry News

US Vows Crackdown on Chinese Firms Exploiting American AI Models

Trump administration announces policy to penalize Chinese companies exploiting U.S. AI models via reverse engineering or unauthorized access, citing national security risks.

2 min read
Apple Patches iOS Flaw That Stored Deleted Signal NotificationsHIGH
Vulnerabilities

Apple Patches iOS Flaw That Stored Deleted Signal Notifications

CVE-2026-28950 in iOS Notification Services retained deleted Signal messages on device, accessible via forensic tools. Apple fixed the logging flaw in iOS 18.4.1 and iPadOS 18.4.1.

CVE-2026-28950
3 min read
Bitwarden CLI Compromised in Checkmarx Supply Chain AttackCRITICAL
Malware

Bitwarden CLI Compromised in Checkmarx Supply Chain Attack

JFrog and Socket found malicious code in @bitwarden/[email protected] — the same campaign that hijacked Checkmarx npm packages.

3 min read
CanisterSprawl Worm Hijacks npm Packages, Steals Developer TokensHIGH
Malware

CanisterSprawl Worm Hijacks npm Packages, Steals Developer Tokens

The CanisterSprawl supply chain worm hijacks npm packages, uses stolen developer tokens to self-propagate, and exfiltrates data to an ICP canister, according to Socket and…

2 min readCanisterSprawl
← PrevPage 26 of 39Next →