Cyber News

DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

DeadLock matters because Microsoft is describing more than another ransomware name. The operation uses decentralized infrastructure for communications, negotiation, and…

Defending Against an Active Threat to Siemens S7 Series PLCs

Defending Against an Active Threat to Siemens S7 Series PLCs

CISA, NSA, FBI, DOE, and EPA say actors are actively targeting Siemens S7 PLCs by scanning for internet-exposed devices and…

New SynkLoader malware pushed in Microsoft Teams phishing campaign

New SynkLoader malware pushed in Microsoft Teams phishing campaign

Expel says the campaign uses Microsoft Teams messages to push a fake "PowerShell Cleaner" MSI from Azure, then drops a…

GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure

GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure

GitLab CVE-2026-19478 is not a minor project-integrity issue. It is a 9.4 unauthenticated code-injection path against public projects, which means…

UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations

UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations

Cisco Talos is describing a change in attacker workflow, not just another flashy AI label. UAT-10147 appears to be using…

CISA warns of hackers exploiting critical MLflow vulnerability

CISA warns of hackers exploiting critical MLflow vulnerability

MLflow is now important enough that an exposed default deployment can become a cloud-credentials problem, not just an AI-tooling problem.…

GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure

GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure

GitLab CVE-2026-19478 is not a minor project-integrity issue. It is a 9.4 unauthenticated code-injection path against public projects, which means…

August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs

August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs

CrowdStrike's August Patch Tuesday analysis matters because it turns a wall of Microsoft CVEs into a prioritization map. The real…

Critical Zimbra RCE flaw now actively exploited in attacks

Critical Zimbra RCE flaw now actively exploited in attacks

CVE-2026-73570 is the kind of email-infrastructure issue that creates immediate cleanup pressure because it combines unauthenticated remote code execution with…

#StopRansomware: Gunra Ransomware

#StopRansomware: Gunra Ransomware

CISA's Gunra advisory is useful because it gives defenders more than a ransomware name. It maps how the group gets…

Phishing 3.0: The Fight Moves to Agent Versus Agent

Phishing 3.0: The Fight Moves to Agent Versus Agent

This story is valuable when read as a change in attack economics, not as another vague AI warning. The important…

Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities

Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities

Cisco Talos adds something the broader Patch Tuesday roundups often miss: a defender's view of which Microsoft flaws are likely…

August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs

August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs

CrowdStrike's August Patch Tuesday analysis matters because it turns a wall of Microsoft CVEs into a prioritization map. The real…