Skip to content

A Technology Innovation Partners Inc. company.

Live Feed · Updated Hourly

Cybersecurity News

The latest threats, breaches, and advisories — aggregated from trusted sources so you can stay ahead of what is happening. Headlines link out to the original reporting at Krebs on Security, The Hacker News, BleepingComputer, SANS Internet Storm Center.

SANS Internet Storm Center · 1h ago

A Closer Look at Malware From the Macfinger ClickFix Campaign, (Fri, Sep 25th)

Introduction
…

Read at source »

BleepingComputer · 2h ago

Microsoft plans to deprecate Windows Deployment Services

Microsoft announced it will deprecate the Windows Deployment Services (WDS) server role starting with the next Windows Server release. [...]…

Read at source »

BleepingComputer · 3h ago

Rydox marketplace admin pleads guilty, faces 22 years in prison

A Kosovar national has pleaded guilty to operating Rydox, a large illegal online marketplace that sold stolen personal information, login credentials, credit card details, and cybercrime tools. [...]…

Read at source »

The Hacker News · 3h ago

The SOC Doesn't Need to Start Over with Every Alert

Security leaders keep debating whether AI will produce an entirely new class of cyberattack. The nearer change is quieter and already visible: AI has made a failed attack cheap to retry. The routine version looks like th…

Read at source »

The Hacker News · 4h ago

Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise

Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets. "At 18:31 UTC on September 24, 2026, Bitget's security systems identified unauthorized tr…

Read at source »

BleepingComputer · 4h ago

Microsoft: Recent Windows updates cause desktop loading issues

Microsoft has confirmed that some users may experience desktop loading issues, including black screens, after installing the August 2026 preview updates and subsequent updates. [...]…

Read at source »

The Hacker News · 4h ago

Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild. The vulnerability in question is CVE-2026-48842 (CVSS score: 8.1), a pre-authe…

Read at source »

BleepingComputer · 6h ago

Hackers steal $351.6 million in Bitget crypto exchange hack

​Cryptocurrency exchange Bitget disclosed today that suspected North Korean hackers have stolen $351.6 million from its hot and warm wallets. [...]…

Read at source »

The Hacker News · 9h ago

Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data

A flaw in Cloudflare Containers let a paying customer read data that other customers' containers had left behind on the same server, Cloudflare and the researchers who found it said on Thursday. The data came from disk s…

Read at source »

The Hacker News · 9h ago

WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog, based o…

Read at source »

SANS Internet Storm Center · 10h ago

ISC Stormcast For Friday, September 25th, 2026 https://isc.sans.edu/podcastdetail/10110, (Fri, Sep 25th)

Read at source »

BleepingComputer · 17h ago

MacSync malware uses public iCloud calendars to deliver new payloads

A new variant of the MacSync malware targeting macOS systems now uses public iCloud calendar events to deliver new native payloads. [...]…

Read at source »

BleepingComputer · 18h ago

New Carbonato malware uses AI agents to hijack exposed Docker hosts

A new botnet malware called Carbonato is targeting insecure hosts running Docker daemons to install the Hermes Agent AI framework and take control. [...]…

Read at source »

The Hacker News · 20h ago

Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions

A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions. A researcher, Rasmus Moorats, chained two flaws in OnePlus's own software to gain ro…

Read at source »

The Hacker News · 20h ago

ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories

This week, the dangerous stuff keeps arriving dressed as something boring. An update. A login box. A search answer. A coding tool. A link you have clicked a hundred times before. That is the thread running through the pi…

Read at source »

BleepingComputer · 20h ago

Exposed GitLab project email addresses let attackers push code

Private GitLab email addresses that allow developers to push issues or tasks to a project are being deliberately exposed in READMEs, contributing guides, and support pages used to collect bug reports. [...]…

Read at source »

The Hacker News · 23h ago

Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content

The "third-party[.]com" domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure to Windows browsers while displaying a harmless decoy to other users. "third-party[.]com has been a …

Read at source »

The Hacker News · 1d ago

Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer

An active ClickFix campaign has been observed compromising legitimate Ukrainian business websites to inject bogus Cloudflare verification pages and trick victims into downloading a previously undocumented information ste…

Read at source »

BleepingComputer · 1d ago

FedRAMP VDR & VER: Daily Scans Are Only the Beginning

FedRAMP's new VDR and VER requirements make vulnerability management more continuous, with faster scanning, tighter remediation deadlines, and stronger evidence requirements. Anecdotes explains why the December 7 deadlin…

Read at source »

BleepingComputer · 1d ago

Hackers now exploit critical Roundcube flaw in code injection attacks

A high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security. [...]…

Read at source »

BleepingComputer · 1d ago

Windows 11 KB5124010 update released with 46 changes and fixes

Microsoft released the KB5124010 September 2026 non-security preview update for Windows 11 24H2 and 25H2, with 46 changes including Bluetooth improvements and the ability to remap the Copilot key. [...]…

Read at source »

The Hacker News · 1d ago

Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects Calls

The logistics sector has become the target of a new malicious cyber campaign that distributes an Android spyware codenamed Corp MDM. According to Have I Been Squatted, the campaign uses fake Google Play pages branded as …

Read at source »

The Hacker News · 1d ago

Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore

AI coding agents are changing how quickly developers can build and ship software as well as how quickly credentials can become exposed. According to GitGuardian’s 2026 State of Secrets Sprawl Report, commits identified a…

Read at source »

BleepingComputer · 1d ago

CISA: Ransomware gangs now exploiting critical TeamCity flaw

​The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies on Wednesday that ransomware gangs are now also exploiting a critical JetBrains TeamCity vulnerability patched in July. [...]…

Read at source »

Headlines and summaries are provided by their respective publishers and link to the original articles. Quantum Shield Secure is not affiliated with these sources.

Worried About a Threat You Just Read About?

Talk with our team about whether your organization is exposed — and what to do about it.

Get Started