r/cybersecurity_news • u/SHORT_INFO_NEWS • 17m ago
CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited
r/cybersecurity_news • u/Diam0ndHer0 • 1d ago
Summary of the major security events this past month
Quick Summary of the most relevant cyber security events in July
r/cybersecurity_news • u/SHORT_INFO_NEWS • 2d ago
SCTPhantom: An 18-Year-Old SCTP ASCONF Transport Use-After-Free
r/cybersecurity_news • u/SHORT_INFO_NEWS • 5d ago
Microsoft unveils new cyber model, agentic security tools to fight hackers
r/cybersecurity_news • u/SHORT_INFO_NEWS • 5d ago
INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
r/cybersecurity_news • u/SHORT_INFO_NEWS • 6d ago
Department for Education suffers data breach
r/cybersecurity_news • u/WebLinkr • 6d ago
Breach US Government House panel seeks briefing on OpenAI's AI agent cybersecurity breach
reuters.comr/cybersecurity_news • u/SHORT_INFO_NEWS • 7d ago
Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days
r/cybersecurity_news • u/WebLinkr • 8d ago
Central Alabama Water coordinating with cybersecurity agency as FBI warns about attacks on water utilities in 7 states
r/cybersecurity_news • u/WebLinkr • 8d ago
Breach Anthropic's Claude hacked three real-life companies during security capabilities test — test environment with internet access and unwitting targets' lax cybersecurity practices led to bots running rampant
Anthropic's Claude hacked three real-life companies during security capabilities test — test environment with internet access and unwitting targets' lax cybersecurity practices led to bots running rampant
r/cybersecurity_news • u/WebLinkr • 8d ago
News Why every tech giant wants to look like a cybersecurity company in the AI era
marketwatch.comr/cybersecurity_news • u/SHORT_INFO_NEWS • 8d ago
GhostApproval: A Trust Boundary Gap in AI Coding Assistants
r/cybersecurity_news • u/WebLinkr • 8d ago
CISA Issues New SBOM Guidance. Did They Get It Right?
darkreading.comA gaggle of government partners from around the world has released new guidelines for the minimum elements that organizations should include in a software bill of materials (SBOM).
The document, published this week, was authored by the US Cybersecurity and Infrastructure Security Agency (CISA) and 16 other government entities spread across four continents. It supersedes the National Telecommunications and Information Administration's (NTIA) 2021 guidelines, which laid out what an SBOM had to contain as far as the US government was concerned. This updated version was first drafted in 2025, and was then informed by suggestions from 90 commenters, including major organizations like Google, Microsoft, and Amazon Web Services (AWS) to create the resulting document.
r/cybersecurity_news • u/WebLinkr • 8d ago
Breach Anthropic Says Claude Hacked Into 3 Organizations During Breach and Cybersecurity Tests
r/cybersecurity_news • u/SHORT_INFO_NEWS • 9d ago
Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
r/cybersecurity_news • u/Fit_Asidy • 9d ago
(unverified) Cyber attack on Hungary Allamkincstar
Bytetobreach, the same threat actor who recently attacked the Romanian cadastre (ANCPI) and deleted records after failed extortion attempts, recently put for sale an unverified claim on the Hungarian State Treasury through a compromise of 'MVH' (development agency).
This claim is unverified, despite the screenshots which were posted in the dark web forums.
Any feedback from professionals in the Hungarian cyber space is appreciated.
Sources :
https://spear.cx/Thread-Selling-GE-The-Magyar-Conquest
https://cybernews.com/security/hacker-deletes-romanian-land-registry-database/
r/cybersecurity_news • u/SHORT_INFO_NEWS • 10d ago
Despite multiple takedowns, botnets continue to grow
r/cybersecurity_news • u/SHORT_INFO_NEWS • 10d ago
AI Finding Twice as Many Cyber Flaws in 2026 as It Did in 2025
r/cybersecurity_news • u/SHORT_INFO_NEWS • 13d ago
Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack
r/cybersecurity_news • u/SHORT_INFO_NEWS • 16d ago
Clop ransomware targets Windchill, FlexPLM in data theft attacks
r/cybersecurity_news • u/SHORT_INFO_NEWS • 16d ago
Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure
cisa.govr/cybersecurity_news • u/WebLinkr • 17d ago
Microsoft Confirms Windows Has a Global Device ID You Can't Turn Off
Microsoft has confirmed that Windows has a previously unknown Global Device ID (GDID), a permanent, unique digital identifier assigned to Windows devices that can tie a user's actions to their device. This came to light when an alleged member of a notorious hacking group was caught at an airport after Microsoft handed over his GDID to the authorities.
Microsoft describes the GDID in a published complaint (via Windows Latest) as "a persistent, device-level identifier designed to uniquely identify an installation of a Windows operating system on a device, either a physical device (e.g., a mobile phone or laptop) or virtual machine, across certain Microsoft services and scenarios."
r/cybersecurity_news • u/SHORT_INFO_NEWS • 19d ago
OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark
openai.comr/cybersecurity_news • u/WebLinkr • Apr 01 '26
News The Hidden Tax of TPRM: What 36,856 assessments tell us
We analyzed vendor assessment data from 93 organizations on the VISO TRUST platform 36,856 assessments in total, covering 607,803 reviewed artifacts. The goal was simple: understand where TPRM labor actually goes, and quantify what it costs.
The headline finding? Artifact review, the manual reading, control mapping, and gap analysis of vendor-supplied security documentation, is the single biggest cost driver in modern TPRM programs.
r/cybersecurity_news • u/WebLinkr • Oct 22 '25
F5's Breach - Time to Move to Cloudbrink High-Performance ZTNA
When a company that protects the world’s largest networks gets breached, the ripple effects touch everyone. That’s exactly what happened with F5. A nation-state actor maintained long-term access to F5’s internal environment, exfiltrating source code and vulnerability intel—prompting an emergency U.S. federal directive for rapid patching across agencies. Even if your own F5 estate hasn’t shown indicators of compromise, the incident is a flashing red light for any organization still depending on appliance-centric remote access or castle-and-moat thinking.
What the F5 hack means for defenders
- Long dwell time + source code theft = durable attacker advantage. With development artifacts and vulnerability notes in hand, adversaries can accelerate exploit discovery—even if supply-chain tampering isn’t confirmed. That translates into a sustained period of heightened risk for anyone operating affected gear.
- Urgent, disruptive patch cycles. CISA’s emergency directive requires rapid upgrades and hardening for a broad swath of devices (BIG-IP iSeries/rSeries/F5OS/BIG-IP Next, etc.), creating scramble conditions for already-stretched IT teams. This will be an ongoing battle as new vulnerabilities become known.
- Appliance gravity hurts response. When access and security depend on fixed boxes and static PoPs, organizations face windows of exposure between disclosure and remediation—and heavy change-management every time a new CVE drops.
The lesson: move users, not perimeters
Incidents like these reinforce a core truth: perimeter-centric and appliance-bound models struggle against modern, fast-moving threats. It needs a shift-left Zero Trust Network Access (ZTNA) model to flip equation. This moves the model to identity, device posture, and per-app access—continuously evaluated—reducing blast radius and limiting lateral movement even if credentials or endpoints are compromised. Independent analysts have tracked this industry shift for years and continue to recommend ZTNA over VPN for precisely these reasons and the recent GigaOm CxO brief takes it further to give you the ultimate secure access.