ZCyberNews
中文

Industry News

132 articles

Grafana GitHub Token

GRAFANA

Grafana GitHub Token Breach Lets Attacker Download Full Codebase

May 17 · HIGH

grafanagithubtoken-theft

AI Agents Automate

AI SECURITY

AI Agents Automate Exploitation of Obscure Vulnerabilities

May 16 · HIGH

ai-securityvulnerability-discoveryai-generated-code

AI Hallucinations Exploit

AI SECURITY

AI Hallucinations Exploit Human Trust in Critical Infrastructure

May 14 · HIGH

ai-securityhallucinationcritical-infrastructure

AI Security Startup

AI SECURITY

AI Security Startup Funding Surpasses Acquisitions by $1B in 1Q26

May 14 · INFORMATIONAL

ai-securitystartup-fundingventure-capital

Malwarebytes Blocks Suspicious

YAHOO MAIL

Malwarebytes Blocks Suspicious Yahoo Mail Redirects to Opaque Domains

May 14 · MEDIUM

yahoo-mailmalwarebytesredirects

NIST NVD Enrichment

NIST

NIST NVD Enrichment Change Creates CVSS Gap for 80% of CVEs

May 14 · MEDIUM

nistnvdcvss

OpenAI Breached

OPENAI

OpenAI Breached in TanStack Supply Chain Attack

May 14 · HIGH

openaiteampcptanstack

Pwn2Own Berlin

PWN2OWN

Pwn2Own Berlin 2026: Researchers Earn $523K Hacking Windows 11, Edge

May 14 · CRITICAL

pwn2ownzero-daymicrosoft-edge

UK

COMPUTER MISUSE ACT

UK to Shield Security Researchers in Computer Misuse Act Overhaul

May 14 · INFO

computer-misuse-actuk-legislationsecurity-research

AI-Driven Attacks Compromise

AI DRIVEN ATTACKS

AI-Driven Attacks Compromise Systems in 73 Seconds, Outpacing Patching

May 13 · HIGH

ai-driven-attacksautonomous-validationpicus-security

Congress Probes

SURVEILLANCE PRICING

Congress Probes 25 Food Retailers Over Surveillance Pricing

May 13 · INFORMATIONAL

surveillance-pricingconsumer-privacyftc

Foxconn Confirms Ransomware

FOXCONN

Foxconn Confirms Ransomware Attack on North American Factories

May 13 · HIGH

foxconnransomwarenitrogen

Apple Patches Everything

APPLE

Apple Patches Everything: 0-Days, RCS Encryption Rollout

May 12 · CRITICAL

applezero-dayrcs

EU States Export

SURVEILLANCE TECH

EU States Export Spyware to Abusive Regimes, HRW Report Finds

May 12 · INFO

surveillance-techspywarehuman-rights

Instructure Pays Ransom

INSTRUCTURE

Instructure Pays Ransom to ShinyHunters After Canvas Breach

May 12 · CRITICAL

instructurecanvasshinyhunters

Instructure Pays ShinyHunters

SHINYHUNTERS

Instructure Pays ShinyHunters to Halt 3.65TB Canvas Data Leak

May 12 · HIGH

shinyhuntersinstructurecanvas

Ivanti Patches Flaws

IVANTI

Ivanti Patches Flaws in Secure Access Client, EPM, Xtraction, VTM

May 12 · HIGH

ivantipatch-advisorysecure-access-client

Škoda

DATA BREACH

Škoda Discloses Customer Data Breach After Online Shop Hack

May 12 · HIGH

škodadata-breachautomotive

Microsoft Patches

MICROSOFT

Microsoft Patches 120 Flaws in May 2026 Patch Tuesday Update

May 12 · HIGH

microsoftpatch-tuesdaywindows-11

UK Fines South

ICO

UK Fines South Staffordshire Water $1.3M for 2022 Breach

May 12 · HIGH

icosouth-staffordshire-watercl0p

West Pharma Hit

RANSOMWARE

West Pharma Hit by Ransomware, Systems Disrupted Globally

May 12 · HIGH

ransomwarewest-pharmaceutical-servicesunit-42

Active Directory Password

ACTIVE DIRECTORY

Active Directory Password Resets Fail to Expel Attackers

May 11 · HIGH

active-directorykerberospassword-reset

FCC Delays Ban

FCC

FCC Delays Ban on Security Updates for Foreign-Made Routers to 2029

May 11 · MEDIUM

fccrouter-securitysupply-chain

SailPoint Discloses GitHub

SAILPOINT

SailPoint Discloses GitHub Repo Breach via Third-Party App

May 11 · HIGH

sailpointgithubsupply-chain

Braintrust Breach Exposes

BRAINTRUST

Braintrust Breach Exposes AI Provider API Keys, Urges Rotation

May 8 · HIGH

braintrustapi-key-breachsupply-chain-risk

Boost Security Raises

BOOST SECURITY

Boost Security Raises $4M, Acquires SecureIQx and Korbit.ai

May 7 · INFO

boost-securitysdlc-securityfunding

USB Drop Attack

SOCIAL ENGINEERING

USB Drop Attack That Defined Social Engineering Turns 20

May 6 · INFORMATIONAL

social-engineeringusb-drop-attackphysical-security

EOL Open Source

OPEN SOURCE SECURITY

EOL Open Source Blind Spots Hide 400K+ Unflagged CVEs

May 5 · HIGH

open-source-securityeol-softwaresca-tools

Persistent OAuth Tokens

OAUTH

Persistent OAuth Tokens: The Back Door Attackers Exploit

May 5 · HIGH

oauthtoken-securityidentity-threats

ShinyHunters Breaches Vimeo

SHINYHUNTERS

ShinyHunters Breaches Vimeo, Leaks 119K User Records

May 5 · HIGH

shinyhuntersvimeoanodot

Student Hacked Taiwan

TETRA

Student Hacked Taiwan High-Speed Rail TETRA System, Triggered

May 5 · HIGH

tetracritical-infrastructuresdr

Trellix Source Code

TRELLIX

Trellix Source Code Breach Exposes Security Product Internals

May 5 · HIGH

trellixsource-code-breachsupply-chain-attack

Cisco Acquires Astrix

CISCO

Cisco Acquires Astrix Security for Non-Human Identity Protection

May 4 · INFO

ciscoastrix-securityidentity-security

Cyber Tax Raises

CYBER TAX

Cyber Tax Raises Consumer Prices After Breaches, Podcast Warns

May 4 · MEDIUM

cyber-taxsmall-businesssupply-chain

Cybersecurity M

MERGERS AND ACQUISITIONS

Cybersecurity M&A Roundup: 33 Deals Announced in April 2026

May 4 · INFO

mergers-and-acquisitionscybersecurity-industryairbus

Infrastructure Breach

INFRASTRUCTURE

Infrastructure Breach: Hackers Steal Student Data from Canvas Platform

May 4 · HIGH

infrastructurecanvasdata-breach

Instructure Breach

INSTRUCTURE

Instructure Breach: Student Data Stolen, Services Disrupted

May 4 · HIGH

instructurecanvasdata-breach

Loan Fraud Rings

CREDIT UNIONS

Loan Fraud Rings Exploit Credit Union Verification Gaps

May 4 · HIGH

credit-unionsloan-fraudsynthetic-identity

Medtronic Discloses Cyberattack

MEDTRONIC

Medtronic Discloses Cyberattack on Corporate IT Systems

May 4 · HIGH

medtronichealthcaredata-breach

OpenAI Strengthens ChatGPT

OPENAI

OpenAI Strengthens ChatGPT Login Security With New Controls

May 4 · MEDIUM

openaichatgptaccount-security

Polymarket Gamblers Threaten

POLYMARKET

Polymarket Gamblers Threaten Journalist Over Event Verification

May 4 · HIGH

polymarketoracle-manipulationprediction-market

Pro-Orb

RANSOMWARE

Pro-Orbán Media Firm Mediaworks Breached by Ransomware Group

May 4 · HIGH

ransomwaremediaworkshungary

Instructure Data Breach

INSTRUCTURE

Instructure Data Breach: ShinyHunters Claims Theft

May 3 · HIGH

instructureshinyhuntersdata-breach

Microsoft Defender False

MICROSOFT DEFENDER

Microsoft Defender False Positives Flag DigiCert Certs as Trojans

May 3 · MEDIUM

microsoft-defenderdigicertfalse-positive

Instructure Probes Cyber

INSTRUCTURE

Instructure Probes Cyber Incident Impacting Canvas Platform

May 2 · HIGH

instructurecanvasedtech-breach

Trellix Breach

TRELLIX

Trellix Breach: Source Code Repository Compromised

May 2 · HIGH

trellixsource-code-breachsupply-chain-security

AI Agents Wreck

AI SECURITY

AI Agents Wreck Production Databases Due to Poor Access Controls

May 1 · HIGH

ai-securityaccess-controldatabase-security

Ex-Incident Responders Sentenced

RANSOMWARE

Ex-Incident Responders Sentenced to 4 Years for Ransomware Attacks

May 1 · HIGH

ransomwareincident-responseinsider-threat

Ex-Ransomware Negotiators Sentenced

BLACKCAT

Ex-Ransomware Negotiators Sentenced to 4 Years for BlackCat Attacks

May 1 · HIGH

blackcatalphvransomware

UK Cyber Agency

NCSC

UK Cyber Agency Warns AI Will Trigger 'Patch Wave' of Urgent Fixes

May 1 · MEDIUM

ncscaipatch-management

BHIS Pentest Data

PENETRATION TESTING

BHIS Pentest Data: Same Top Flaws Plague Orgs in 2025

Apr 30 · HIGH

penetration-testingbhisvulnerability-trends

Brazilian DDoS Firm

DDOS

Brazilian DDoS Firm Behind Botnet Attacks on ISPs

Apr 30 · HIGH

ddosbotnetbrazil

CISA Details FCEB

CISA

CISA Details FCEB Agency Breach Response Lessons Learned

Apr 30 · HIGH

cisafcebincident-response

CISA

US COAST GUARD

CISA, USCG Detail Cyber Hygiene Gaps Found in Critical Infrastructure

Apr 30 · HIGH

cisaus-coast-guardcritical-infrastructure

FBI Warns Cybercriminals

FBI

FBI Warns Cybercriminals Driving $725M Cargo Theft Surge

Apr 30 · HIGH

fbicargo-thefttransportation

French Police Arrest

DATA BREACH

French Police Arrest 15-Year-Old in ANTS Data Breach Probe

Apr 30 · HIGH

data-breachfranceants

Inc Ransom Breach

INC RANSOM

Inc Ransom Breach at Sandhills Medical Exposes 170K Records

Apr 30 · HIGH

inc-ransomransomwarehealthcare-breach

Moldova Health Agency

MOLDOVA

Moldova Health Agency Breach: Possible Data Theft Confirmed

Apr 30 · MEDIUM

moldovahealthcaredata-breach

SMS Blaster Busts

SMS BLASTER

SMS Blaster Busts, OpenEMR Flaws, 600K Roblox Hacks in ThreatsDay

Apr 30 · HIGH

sms-blasteropenemrroblox

Trump Cyber Ambassador

STATE DEPARTMENT

Trump Cyber Ambassador Nominee Advances to Senate Vote

Apr 30 · INFORMATIONAL

state-departmentcyber-diplomacyadam-cassady

Chrome

FIREFOX

Chrome 147, Firefox 150 Patch Critical Code Execution Flaws

Apr 29 · CRITICAL

chromefirefoxbrowser-security

EU Accuses Meta

META

EU Accuses Meta of Breaching DSA Child Safety Rules

Apr 29 · HIGH

metadigital-services-actchild-safety

Project Zero Dusts

VIRTUALBOX

Project Zero Dusts Off 2017 VirtualBox Escape Draft With

Apr 29 · HIGH

virtualboxproject-zerocve-2017-3558

Swiss Police Arrest

BLACK AXE

Swiss Police Arrest 10 Suspected Black Axe Cybercrime Members

Apr 29 · HIGH

black-axelaw-enforcementcybercrime

Zero-Window Era

AI SECURITY

Zero-Window Era: NDR Playbooks for Post-Mythos Exploits

Apr 29 · HIGH

ai-securityzero-dayndr

Cyber Command

ELECTION SECURITY

Cyber Command, NSA Chief Warns Foreign Adversaries Will Target US

Apr 28 · HIGH

election-securitycyber-commandnsa

Medtronic

SHINYHUNTERS

ShinyHunters Breaches Medtronic, Steals 9M Records

Apr 28 · HIGH

medtronicshinyhuntersdata-breach

Ukraine Police Arrest

CYBERCRIME

Ukraine Police Arrest Hackers Behind Roblox Account Theft Ring

Apr 28 · MEDIUM

cybercrimeaccount-takeoverdigital-theft

Vimeo Breach Tied

VIMEO

Vimeo Breach Tied to Anodot Vendor Hack, No Video Data Exposed

Apr 28 · MEDIUM

vimeoanodotvendor-breach

ADT Breach

ADT

ADT Breach: ShinyHunters Steals Data of 5.5 Million

Apr 27 · HIGH

adtshinyhuntersdata-breach

AI Assistants Reshape

AI

AI Assistants Reshape Security Priorities for Enterprises

Apr 27 · HIGH

aiidentity-securityzero-trust

Canada Arrests Three

SMS BLASTER

Canada Arrests Three Over SMS Blaster Phishing Device

Apr 27 · HIGH

sms-blasterphishinglaw-enforcement

Checkmarx Confirms GitHub

CHECKMARX

Checkmarx Confirms GitHub Data Leak After March 23 Supply Chain Attack

Apr 27 · HIGH

checkmarxsupply-chain-attackgithub-breach

Crypto Launderer Gets

CRYPTOCURRENCY

Crypto Launderer Gets 5 Years for $260M Cyber Theft Role

Apr 27 · MEDIUM

cryptocurrencymoney-launderingsentencing

Deepfake Voice Attacks

DEEPFAKE

Deepfake Voice Attacks Outpace Defenses, Bypass MFA

Apr 27 · HIGH

deepfakevoice-cloningsocial-engineering

ESET

MDR

ESET: SMBs Gain Defensive Edge via Threat Research, MDR

Apr 27 · INFORMATIONAL

esetmdrthreat-research

FTC

SOCIAL MEDIA SCAMS

FTC: Social Media Scams Cost Americans $2.1B in 2025

Apr 27 · HIGH

ftcsocial-media-scamsinvestment-fraud

Mobile App Permissions

MOBILE SECURITY

Mobile App Permissions Still Expose Users to Privacy Risks

Apr 27 · MEDIUM

mobile-securityapp-permissionsprivacy

Silk Typhoon Hacker

SILK TYPHOON

Silk Typhoon Hacker Extradited to US on Cyberespionage Charges

Apr 27 · HIGH

silk-typhooncyberespionagechina

US Sanctions Cambodian

CYBERCRIME

US Sanctions Cambodian Senator in Southeast Asia Cyberscam Crackdown

Apr 27 · HIGH

cybercrimesanctionssoutheast-asia

Vercel Breach

VERCEL

Vercel Breach via Context.ai OAuth Token Theft

Apr 27 · HIGH

vercelcontext.aioauth

ESET

CLOUD SECURITY

ESET: Cloud VMs Expose Critical Security Gaps in Enterprise

Apr 26 · HIGH

cloud-securityvirtual-machineseset

ESET

CYBER RESILIENCE

ESET: March 2026 Cyber Threats Show Resilience Gaps

Apr 26 · MEDIUM

cyber-resilienceransomwaresupply-chain

Feds Disrupt IoT

BOTNET

Feds Disrupt IoT Botnets Behind Record DDoS Attacks

Apr 26 · HIGH

botnetddosiot

Itron Breach

ITRON

Itron Breach: Utility Firm Discloses Internal IT Network Intrusion

Apr 26 · HIGH

itronsec-filingcritical-infrastructure

ADT Breach Exposes

ADT

ADT Breach Exposes Customer Data in Cyber Intrusion

Apr 25 · HIGH

adtdata-breachcustomer-data

Cyberattackers Weaponize Voltage

CRITICAL INFRASTRUCTURE

Cyberattackers Weaponize Voltage Fluctuations Against Power Grids

Apr 25 · HIGH

critical-infrastructurepower-gridcyber-physical-attacks

Elastic Security Backs

ELASTIC

Elastic Security Backs UK MoD Defence Cyber Marvel 2026 Exercise

Apr 25 · INFORMATIONAL

elasticuk-ministry-of-defencedefence-cyber-marvel

Locked Shields

LOCKED SHIELDS

Locked Shields 2026: 41 Nations Train in Largest Cyber Defense

Apr 25 · INFO

locked-shieldsnatocyber-exercise

ADT Confirms Breach

ADT

ADT Confirms Breach as ShinyHunters Leaks Customer Data

Apr 24 · HIGH

adtshinyhuntersdata-breach

AI Agent Authority

AI AGENTS

AI Agent Authority Gap Creates New Enterprise Security Blind Spots

Apr 24 · HIGH

ai-agentsenterprise-securityidentity-and-access-management

AI-Powered Phishing Surges

AI PHISHING

AI-Powered Phishing Surges as Attackers Personalize Lures at Scale

Apr 24 · HIGH

ai-phishinggenerative-aiphishing-campaigns

Copperhelm Raises

COPPERHELM

Copperhelm Raises $7M for Agentic Cloud Security Platform

Apr 24 · INFO

copperhelmagentic-aicloud-security

DORA Mandates Credential

DORA

DORA Mandates Credential Management as Financial Risk Control

Apr 24 · HIGH

doracredential-managementfinancial-regulation

Shadow AI

SHADOW IT

Shadow AI and SaaS Expand Enterprise Attack Surface

Apr 24 · HIGH

shadow-itsaasshadow-ai

Toronto Police Bust

SMS BLASTER

Toronto Police Bust SMS Blaster Phishing Operation

Apr 24 · HIGH

sms-blasterphishinglaw-enforcement

US Vows Crackdown

AI SECURITY

US Vows Crackdown on Chinese Firms Exploiting American AI Models

Apr 24 · MEDIUM

ai-securityus-china-tech-policymodel-exploitation

Cyberattacks

SUPPLY CHAIN RISK

Cyberattacks on Firms Cascade to Consumers, Malwarebytes Warns

Apr 23 · MEDIUM

supply-chain-riskconsumer-impactdata-breach

ICE Admits Using

SURVEILLANCE

ICE Admits Using Graphite Spyware for Surveillance

Apr 23 · MEDIUM

surveillancegovernmentspyware

Rituals Cosmetics Breach

DATA BREACH

Rituals Cosmetics Breach Exposes Customer Membership Data

Apr 23 · HIGH

data-breachritualscosmetics

French Police Arrest

DATA BREACH

French Police Arrest Hacker Behind Dozens of Data Breaches

Apr 22 · HIGH

data-breacharrestfrance

UK Cyber Agency

NCSC

UK Cyber Agency Handles Four Major Incidents Weekly

Apr 22 · HIGH

ncscnation-stateespionage

BreachLock Named

PENTESTING

BreachLock Named in Gartner Market Guide for Adversarial Exposure Validation

Apr 21 · INFO

pentestinggartnerbreachlock

Grupo Seguritech Mexican

SURVEILLANCE

Grupo Seguritech Mexican Surveillance Firm Expands into US Market

Apr 21 · INFORMATIONAL

surveillanceprivacyhuman-rights

IPQS Combines Identity

FRAUD PREVENTION

IPQS Combines Identity, Device, and Network Signals for Frictionless Fraud

Apr 21 · INFORMATIONAL

fraud-preventionidentity-verificationrisk-scoring

Ofcom Investigates Telegram

TELEGRAM

Ofcom Investigates Telegram for CSAM Sharing and Encryption Non-Compliance

Apr 21 · INFORMATIONAL

telegramregulationencryption

Datto Warns Traditional

RANSOMWARE

Datto Warns Traditional Backups Fail to Maintain Business Operations During

Apr 20 · HIGH

ransomwarebusiness-continuitybackup

NIST Abandons Comprehensive

NIST

NIST Abandons Comprehensive NVD Analysis for Risk-Based Prioritization

Apr 20 · INFORMATIONAL

nistnvdcve

Senate Extends Section

SURVEILLANCE

Senate Extends Section 702 Surveillance Authority for 48 Hours

Apr 20 · INFORMATIONAL

surveillancepolicyfisa

Axonius Expands Asset

ASSET MANAGEMENT

Axonius Expands Asset Cloud with AI Remediation and OT Security

Apr 17 · INFORMATIONAL

asset-managementexposure-managementiot-security

Google Tightens Android

ANDROID

Google Tightens Android 17 Privacy Rules, Blocks 8.3 Billion Ads in 2025

Apr 17 · INFORMATIONAL

androidprivacyad-fraud

NIST Limits CVE

NIST

NIST Limits CVE Enrichment Amid Overwhelming Surge in Submissions

Apr 17 · INFORMATIONAL

nistnvdcve

Social Media Age

PRIVACY

Social Media Age Bans May Increase Cybersecurity Risks for Children

Apr 17 · MEDIUM

privacysocial-mediaregulation

U

CRITICAL INFRASTRUCTURE

U.S. Coast Guard Mandate Offers Blueprint for OT Security

Apr 17 · INFORMATIONAL

critical-infrastructureregulationoperational-technology

Workplace Stress Remains

INSIDER THREAT

Workplace Stress Remains Elevated, Posing Persistent Insider Threat Risk

Apr 17 · MEDIUM

insider-threathuman-factorrisk-management

AI SOC Tools

AI

AI SOC Tools Criticized for Automating Triage, Not Reducing Analyst Workload

Apr 16 · INFORMATIONAL

aisocautomation

ETSI Warns EU

REGULATION

ETSI Warns EU Cybersecurity Act 2 Risks Fragmenting Global Standards

Apr 16 · INFORMATIONAL

regulationeustandards

NIST Overhauls National

NIST

NIST Overhauls National Vulnerability Database, Prioritizes High-Risk CVE

Apr 16 · INFORMATIONAL

nistnvdvulnerability-management

Unmanaged Non-Human Identities

CLOUD SECURITY

Unmanaged Non-Human Identities Fuel Majority of Cloud Breaches

Apr 16 · HIGH

cloud-securityidentity-and-access-managementrisk-management

Wireless Broadband Alliance

WI FI

Wireless Broadband Alliance Publishes Wi-Fi Roaming Security Guidelines

Apr 16 · INFORMATIONAL

wi-fiauthenticationwireless

Asia's Digital Supply

SUPPLY CHAIN

Asia's Digital Supply Chain Poses Distinct Security Challenges

Apr 15 · MEDIUM

supply-chainasiaregulation

Bitdefender Unifies Endpoint

EMAIL SECURITY

Bitdefender Unifies Endpoint and Email Security in GravityZone Platform

Apr 15 · INFORMATIONAL

email-securityendpoint-securitybitdefender

Cryptography Experts Warn

POST QUANTUM CRYPTOGRAPHY

Cryptography Experts Warn Quantum Risk Management Must Begin Immediately

Apr 15 · HIGH

post-quantum-cryptographyencryptionrisk-management

ENISA Official Warns

VULNERABILITY DISCLOSURE

ENISA Official Warns of Fragile Global CVE Infrastructure Amid EU Regulatory

Apr 15 · INFORMATIONAL

vulnerability-disclosureregulationcve

FISA Section

SURVEILLANCE

FISA Section 702 Reauthorization Debate Intensifies Amid Privacy and Security

Apr 15 · INFORMATIONAL

surveillancepolicyprivacy

Major Tech Giants

PRIVACY

Major Tech Giants Ignore Legally Mandated Privacy Opt-Out Signals

Apr 15 · HIGH

privacytrackingregulation

Zero Trust Architecture

ZERO TRUST

Zero Trust Architecture as a Critical Defense Against Credential-Based Attacks

Apr 14 · INFORMATIONAL

zero-trustidentity-securitycredential-theft

WhatsApp's End-to-End Encryption

ENCRYPTION

WhatsApp's End-to-End Encryption Claims Challenged as 'Major Consumer Fraud'

Apr 13 · MEDIUM

encryptionprivacymessaging

Cloudflare Block Disrupts

CLOUDFLARE

Cloudflare Block Disrupts Docker Hub Access in Spain During Football Match

Apr 12 · MEDIUM

cloudflaredockercdn

FINRA Launches Intelligence

FINANCIAL

FINRA Launches Intelligence Fusion Center to Counter Financial Cyber Threats

Apr 12 · INFORMATIONAL

financialintelligence-sharingregulation

Iranian Internet Outage

CENSORSHIP

Iranian Internet Outage Exceeds 1,000 Hours Amid State-Imposed Censorship

Apr 12 · HIGH

censorshipirannetwork-disruption

Orange Business Integrates

TELECOM

Orange Business Integrates AI into Enterprise Voice, Raises Security Questions

Apr 12 · MEDIUM

telecomgenerative-aisupply-chain