Cyber Attacks
75 stories · back to Cybersecurity

FBI reportedly declares 'cyber security incident' after hackers steal agents' personal data
The bureau has not yet publicly confirmed a breach, but has told its agents that their personal information and Social Security numbers were exposed.

ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks
The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat actors to resume widespread exploitation of a flaw on vulnerable servers.

ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw
The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has learned is an unauthenticated path traversal vulnerability.

CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks
The Cybersecurity and Infrastructure Security Agency (CISA) warns that hackers are exploiting a critical authentication bypass vulnerability (CVE-2026-5430) affecting multiple products from enterprise software provider WSO2.

Kiteworks urges customers to shut down their servers amid 'imminent' threat of cyberattack
The tech giant, which allows companies to send large datasets over the internet, said it received a "credible threat" from law enforcement about an imminent attack.

Asus confirms eShop data breach exposed customer order records and contact details — payment data safe, but firm warns of targeted phishing scams
Asus has confirmed a data breach affecting its eShop, with customer order records and contact details exposed, though the company says payment information was not compromised.

Party Invite Phishing Scams Are the New Missed Connections
Email scams that look like an Evite or Paperless Post invitation are meant to snatch your data. For some, they've become an excuse to reconnect with old friends or flames.

MacSync malware uses public iCloud calendars to deliver new payloads
A new variant of the MacSync malware targeting macOS systems now uses public iCloud calendar events to deliver new native payloads.

ShinyHunters hackers claim to have 2-3TB of sensitive information about FBI employees
The hacking group ShinyHunters claims to have taken a large cache of sensitive data belonging to the US Federal Bureau of Investigation, including records on employees and job applicants.

Malicious npm packages evade install-script defenses at runtime
An ongoing npm malware campaign involving the 'indexed-btree' package shows how threat actors bypass supply chain defenses by hiding malicious code in a package's normal runtime behavior rather than in installation scripts.
Our Latest Articles
Attackers Shift From Ransom to Reach Across Three Fronts
11 hours ago
AI Malware, Stolen Passwords and the Human Gap in Cyber Attacks
1 day ago
Cyberattackers Keep Choosing the Path of Least Resistance
2 days agoAI Agents Have Become the Attack Surface
3 days ago