CyberNews

Cybersecurity News Dashboard

Showing 21–30 of 270 articles
NEWS The Hacker News

Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE - The Hacker News

Security researchers found a way to enter Microsoft SharePoint servers as any user, including an administrator, with no valid account. A significant part of the work that found it was done through an AI agent. The flaw, tracked as CVE-2026-55040 (CVSS 9.1), affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Microsoft's affected-product list covers only those three on-premises editions, and SharePoint Online is not among them. It lets a remote unauthenticated attacker assume a chosen user's identity. The attack has one prerequisite: the intruder has to know which account they want to become, either by its Active Directory security identifier (SID) or its user principal name (UPN), which is formatted like an email address. Rapid7 then chained the bypass to a separate remote code execution flaw and ran code on the server with no credentials. Microsoft and the firm disclosed that second flaw on August 11 as CVE-2026-63520 (CVSS 8.1), an unsafe .NET type instantiation in SharePoint's Business Connectivity Services.

Aug 11, 2026, 04:47 PM Read more →
NEWS Security Affairs

ExfilSquad Targets New Victims, Shares Data via Torrents

ExfilSquad targets 13 organizations, exploiting cloud portals for data theft and using torrents to spread stolen information and amplify damage. Resecurity is tracking the activity of ExfilSquad – the group announced new victims this week. ExfilSquad is a new cybercrime group that emerged in mid-2026. Instead of using ransomware, it steals data and threatens to […]

Aug 11, 2026, 04:44 PM Read more →
NEWS The Hacker News Ransomware

DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt

The ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data leak operations in a bid to improve operational resilience. "Its recovery ecosystem combines the Session messaging network with blockchain-backed services that store and deliver resources used throughout the extortion process," the Microsoft Threat

Aug 11, 2026, 04:35 PM Read more →
NEWS The Hacker News Ransomware

DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt - The Hacker News

The ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data leak operations in a bid to improve operational resilience. "Its recovery ecosystem combines the Session messaging network with blockchain-backed services that store and deliver resources used throughout the extortion process," the Microsoft Threat Intelligence team said. The tech giant said it observed the ransomware being deployed by multiple threat actors, including an affiliate for Lynx and INC ransomware. DeadLock was first detected in July 2025, employing double extortion tactics to encrypt victim environments and apply pressure by threatening to publicly release exfiltrated data. As of this month, the group has claimed 96 victims, with most of them located in Italy, Spain, Poland, Türkiye, and the U.S.

Aug 11, 2026, 04:35 PM Read more →
NEWS Security Affairs

Iran-Linked Hackers Target More US Water Infrastructure in New Jersey and Alabama

Iran-linked hackers targeted Water Infrastructure in New Jersey and Alabama, bringing confirmed attacks to at least 12 states, with limited disruption. The wave of cyberattacks targeting US water infrastructure has reached New Jersey and Alabama, bringing the confirmed count to at least 12 states since late July. The attacks are linked to Iranian hackers targeting […]

Aug 11, 2026, 04:23 PM Read more →
NEWS Security Affairs

The inconvenient truth about AI pentesting: someone has to check all the work

AI pentesting can flood teams with findings they cannot validate. The real challenge is managing “validation debt” as discovery scales. AI pentesting has a ‘Sorcerer’s Apprentice’ problem. Enchant a broom to fetch water, and it will fetch water, relentlessly, long after the workshop has flooded. The industry is busy measuring how fast AI finds vulnerabilities […]

Aug 11, 2026, 04:19 PM Read more →
NEWS Security Affairs CVE-2026-20337

Cisco Warns of Seven ClamAV Flaws, Two With Public PoCs

Cisco warns that seven ClamAV flaws affect Secure Endpoint Connector products, with two having public PoCs that could enable remote DoS attacks. Cisco warned that seven ClamAV vulnerabilities affect its Secure Endpoint Connector on Windows, macOS and Linux. ClamAV is an open-source antivirus engine widely used to scan files and emails for malware. The company […]

Aug 11, 2026, 04:05 PM Read more →
NEWS BleepingComputer

Wesco confirms security incident after ExfilSquad claims data theft

Global supply chain and distribution giant Wesco has confirmed in a statement to BleepingComputer that it is investigating a cybersecurity incident. The company's statement comes after data extortion group ExfilSquad claimed to have stolen sensitive information from Wesco and leaked it on their data leak site. Jennifer Sniderman, Vice President of Corporate Communications at Wesco, said that the incident involves the company's cloud CRM environment. “Wesco is aware of a claim of CRM data exfiltration by a third party,” Sniderman told BleepingComputer. “We have worked with our cloud CRM vendor on the matter, and we do not believe that there is a risk to sensitive data.” The company representative added that Wesco has not experienced any business disruption, and all operations continue as normal.

Aug 11, 2026, 03:59 PM Read more →
NEWS BleepingComputer

Mozilla updates GPG signing key for Firefox releases after exposure

Mozilla announced today that it updated the GPG key used to sign Firefox and Thunderbird releases after it was accidentally exposed on GitHub. However, in a Monday blog post, it noted that the risk of a supply chain attack in which threat actors could distribute malicious installers signed with the exposed key is low because only a limited number of individuals had access to the GitHub repository. Additionally, Mozilla has yet to find evidence that the previous GPG key was accessed by unauthorized parties while being exposed. After discovering the incident, the organization revoked the key used to sign Linux tarballs, RPM packages, and checksum files, and has taken measures to prevent similar issues in the future. "Today, we moved to a new GPG signing subkey used to sign certain Firefox and Thunderbird artifacts (namely Linux tarballs, RPM packages, checksums files) after an unencrypted copy of the previous subkey was inadvertently committed to a private GitHub repository," it noted.

Aug 11, 2026, 01:20 PM Read more →
NEWS BleepingComputer

Vague Task, Total Access: When AI Delegation Becomes a Security Risk

AI agents can improvise beyond the intended scope of a task when they are given broad access to enterprise systems and data. Token Security explains why organizations need to define agent intent and continuously enforce permissions around what each agent was actually created to do. [...]

Aug 11, 2026, 01:15 PM Read more →