15 Articles

Cybersecurity News

Latest threats, vulnerabilities, tools, research, and policy updates from across the security world.

BreakingTop stories right now

Showing 13 articles

AI-Powered Phishing Campaigns Bypass Traditional Email Security Filters
AI Security

AI-Powered Phishing Campaigns Bypass Traditional Email Security Filters

Threat actors are leveraging large language models to craft hyper-personalized spear-phishing emails that evade standard detection. Researchers report a 340% increase in AI-generated phishing attempts in Q1 2026.

Dark ReadingMar 17, 2026
Major Healthcare Provider Suffers 4.5M Patient Data Breach via Third-Party Vendor
Data Breaches

Major Healthcare Provider Suffers 4.5M Patient Data Breach via Third-Party Vendor

A leading US healthcare network disclosed a breach affecting 4.5 million patients after attackers compromised a third-party billing software vendor. Exposed data includes SSNs, medical records, and insurance information.

Krebs on SecurityMar 16, 2026
CISA Releases New Binding Directive on Secure Software Development Practices
Policy

CISA Releases New Binding Directive on Secure Software Development Practices

The Cybersecurity and Infrastructure Security Agency issued a new binding operational directive requiring federal agencies to adopt memory-safe programming languages and mandatory SBOM requirements by Q4 2026.

CISAMar 16, 2026
Burp Suite 2026 Introduces AI-Assisted Vulnerability Discovery Engine
Tools

Burp Suite 2026 Introduces AI-Assisted Vulnerability Discovery Engine

PortSwigger released Burp Suite 2026 with an AI-assisted scanning engine that leverages machine learning to identify complex logical vulnerabilities and chained attack paths previously undetectable by automated scanners.

PortSwiggerMar 15, 2026
New Android Banking Trojan 'HydraX' Steals OTP Codes from 200+ Banking Apps
Malware

New Android Banking Trojan 'HydraX' Steals OTP Codes from 200+ Banking Apps

Security analysts at Zimperium identified a sophisticated Android banking trojan targeting customers of 200+ financial institutions. HydraX uses accessibility services to intercept OTP codes and exfiltrate credentials.

ZimperiumMar 15, 2026
Researchers Demonstrate Practical Attack Against ML-Based Intrusion Detection Systems
Research

Researchers Demonstrate Practical Attack Against ML-Based Intrusion Detection Systems

Academic researchers published a paper demonstrating adversarial machine learning attacks capable of evading state-of-the-art neural network-based IDS/IPS solutions with a 94% evasion success rate.

IEEE Security & PrivacyMar 14, 2026
Microsoft Patches 6 Zero-Days in March Patch Tuesday — One Under Active Exploitation
Vulnerabilities

Microsoft Patches 6 Zero-Days in March Patch Tuesday — One Under Active Exploitation

Microsoft's March 2026 Patch Tuesday addressed 87 vulnerabilities including 6 zero-days. CVE-2026-21334, a Windows kernel privilege escalation flaw, is confirmed to be actively exploited in targeted attacks.

SecurityWeekMar 14, 2026
State-Sponsored Threat Actor 'SilverFox' Targets Critical Infrastructure in 12 Countries
Threats

State-Sponsored Threat Actor 'SilverFox' Targets Critical Infrastructure in 12 Countries

Mandiant published research on a sophisticated APT group linked to a nation-state actor conducting long-term espionage campaigns against energy, water, and telecommunications infrastructure across Europe and Asia.

MandiantMar 13, 2026
EU Cyber Resilience Act Enters Enforcement Phase — Fines Up to €15M for Non-Compliance
Policy

EU Cyber Resilience Act Enters Enforcement Phase — Fines Up to €15M for Non-Compliance

The European Union's Cyber Resilience Act has entered its enforcement phase, requiring manufacturers of digital products to meet mandatory cybersecurity requirements. Non-compliance penalties can reach €15 million or 2.5% of global annual turnover.

EU Agency for CybersecurityMar 12, 2026
Google Project Zero Releases MemSafe: Open-Source Memory Safety Analysis Tool
Tools

Google Project Zero Releases MemSafe: Open-Source Memory Safety Analysis Tool

Google's Project Zero team released MemSafe, an open-source static analysis tool designed to detect memory safety vulnerabilities in C/C++ codebases with significantly lower false-positive rates than existing tools.

Google Project ZeroMar 11, 2026
Novel 'QuantumStealer' Infostealer Targets Cryptocurrency Wallets and Password Managers
Malware

Novel 'QuantumStealer' Infostealer Targets Cryptocurrency Wallets and Password Managers

Threat intelligence firm Recorded Future identified a new infostealer malware sold on dark web forums targeting 50+ cryptocurrency wallets, browser password managers, and 2FA authenticator apps.

Recorded FutureMar 10, 2026
Researchers Break RSA-2048 Simulation Using Quantum Algorithm — Real-World Implications Analyzed
Research

Researchers Break RSA-2048 Simulation Using Quantum Algorithm — Real-World Implications Analyzed

A research team from MIT demonstrated a quantum algorithm that could theoretically break RSA-2048 encryption. While current quantum hardware remains insufficient, experts warn cryptographic agility must be prioritized now.

MIT Technology ReviewMar 9, 2026
Supply Chain Attack Compromises 3 Popular npm Packages with Combined 12M Weekly Downloads
Threats

Supply Chain Attack Compromises 3 Popular npm Packages with Combined 12M Weekly Downloads

Security researchers discovered a sophisticated supply chain attack targeting three widely-used npm packages. The malicious versions exfiltrated environment variables and CI/CD secrets from affected build pipelines.

Socket SecurityMar 8, 2026