ZCyberNews
中文

Articles

460 articles

NIST Overhauls National Vulnerability Database, Prioritizes High-Risk CVEINFORMATIONAL
Industry News

NIST Overhauls National Vulnerability Database, Prioritizes High-Risk CVE

NIST will cease comprehensive analysis for all CVEs, shifting to enrich only the highest-risk vulnerabilities due to a 263% surge in submissions, fundamentally altering how the security community uses the NVD.

3 min read
OpenAI Expands Access to GPT-5.4-Cyber for Defensive Security TasksINFORMATIONAL
AI Security

OpenAI Expands Access to GPT-5.4-Cyber for Defensive Security Tasks

OpenAI is expanding access to its GPT-5.4-Cyber model, a specialized AI for reverse engineering and malware analysis, following the reveal of Anthropic's offensive-capable 'Mythos' model. The move aims to lower barriers for legitimate security research.

3 min read
Pentera Report Warns of Critical Security Gaps in Agentic AI ArchitecturesHIGH
AI Security

Pentera Report Warns of Critical Security Gaps in Agentic AI Architectures

Pentera's 2026 AI Security and Exposure Report finds that 100% of surveyed organizations have AI security gaps, with agentic AI architectures introducing novel risks like prompt injection and data exfiltration through deterministic workflows.

4 min read
PowMix Botnet Targets Czech Workforce with Randomized C2 TrafficHIGH
Malware

PowMix Botnet Targets Czech Workforce with Randomized C2 Traffic

Cisco Talos researchers identify the PowMix botnet, active since December 2025, targeting Czech workers with randomized C2 beaconing to evade detection and deploy additional payloads.

3 min read
SAP Patches Critical SQL Injection Flaw in Business Planning and ConsolidationCRITICAL
Vulnerabilities

SAP Patches Critical SQL Injection Flaw in Business Planning and Consolidation

SAP has patched a critical SQL injection vulnerability (CVE-2026-27681, CVSS 9.9) in its Business Planning and Consolidation and Business Warehouse applications, allowing attackers to execute arbitrary database commands.

CVE-2026-27681
4 min read
Unmanaged Non-Human Identities Fuel Majority of Cloud BreachesHIGH
Industry News

Unmanaged Non-Human Identities Fuel Majority of Cloud Breaches

A 2024 analysis reveals 68% of cloud breaches stem from compromised, orphaned non-human identities like service accounts and API keys, not phishing or weak passwords, highlighting a critical gap in automated credential lifecycle management.

4 min read
Wireless Broadband Alliance Publishes Wi-Fi Roaming Security GuidelinesINFORMATIONAL
Industry News

Wireless Broadband Alliance Publishes Wi-Fi Roaming Security Guidelines

The Wireless Broadband Alliance has released new security guidelines for public Wi-Fi roaming networks, aiming to standardize authentication and encryption practices to prevent credential theft and man-in-the-middle attacks.

3 min read
Adware Campaign Hijacks DNS to Expose Thousands of OT and Government EndpointsHIGH
Malware

Adware Campaign Hijacks DNS to Expose Thousands of OT and Government Endpoints

A malicious adware campaign, active since at least 2023, hijacked DNS settings on over 25,000 systems to redirect traffic through attacker-controlled servers, exposing endpoints in critical OT and government networks to further compromise.

4 min read
AgingFly Malware Targets Ukrainian Government and HospitalsHIGH
Malware

AgingFly Malware Targets Ukrainian Government and Hospitals

A new malware family dubbed 'AgingFly' is stealing authentication data from Chromium browsers and WhatsApp in targeted attacks against Ukrainian local government bodies and hospitals.

3 min read
Asia's Digital Supply Chain Poses Distinct Security ChallengesMEDIUM
Industry News

Asia's Digital Supply Chain Poses Distinct Security Challenges

Asia's interconnected digital ecosystems, divergent regulatory regimes, and rapid AI adoption are creating unique and complex security risks for regional and global supply chains, according to a new analysis.

3 min read
Bitdefender Unifies Endpoint and Email Security in GravityZone PlatformINFORMATIONAL
Industry News

Bitdefender Unifies Endpoint and Email Security in GravityZone Platform

Bitdefender has integrated continuous email threat protection into its GravityZone platform, combining endpoint detection and response (EDR) with email security to combat phishing, BEC, and ransomware.

3 min read
Critical etcd Authentication Bypass Exposes Kubernetes Cluster SecretsCRITICAL
Vulnerabilities

Critical etcd Authentication Bypass Exposes Kubernetes Cluster Secrets

A critical authentication bypass flaw in etcd, CVE-2026-33413 (CVSS 8.8), allows unauthorized access to sensitive cluster APIs, potentially exposing secrets and configurations in Kubernetes and cloud-native environments.

CVE-2026-33413
4 min read
← PrevPage 34 of 39Next →