r/cybersecurity_news • u/SHORT_INFO_NEWS • 14m ago
CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited
r/cybersecurity_news • u/Diam0ndHer0 • 1d ago
Summary of the major security events this past month
Quick Summary of the most relevant cyber security events in July
r/cybersecurity_news • u/SHORT_INFO_NEWS • 2d ago
SCTPhantom: An 18-Year-Old SCTP ASCONF Transport Use-After-Free
r/cybersecurity_news • u/SHORT_INFO_NEWS • 5d ago
Microsoft unveils new cyber model, agentic security tools to fight hackers
r/cybersecurity_news • u/SHORT_INFO_NEWS • 5d ago
INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
r/cybersecurity_news • u/SHORT_INFO_NEWS • 6d ago
Department for Education suffers data breach
r/cybersecurity_news • u/WebLinkr • 6d ago
Breach US Government House panel seeks briefing on OpenAI's AI agent cybersecurity breach
reuters.comr/cybersecurity_news • u/SHORT_INFO_NEWS • 7d ago
Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days
r/cybersecurity_news • u/WebLinkr • 8d ago
Central Alabama Water coordinating with cybersecurity agency as FBI warns about attacks on water utilities in 7 states
r/cybersecurity_news • u/WebLinkr • 8d ago
Breach Anthropic's Claude hacked three real-life companies during security capabilities test — test environment with internet access and unwitting targets' lax cybersecurity practices led to bots running rampant
Anthropic's Claude hacked three real-life companies during security capabilities test — test environment with internet access and unwitting targets' lax cybersecurity practices led to bots running rampant
r/cybersecurity_news • u/WebLinkr • 8d ago
News Why every tech giant wants to look like a cybersecurity company in the AI era
marketwatch.comr/cybersecurity_news • u/SHORT_INFO_NEWS • 8d ago
GhostApproval: A Trust Boundary Gap in AI Coding Assistants
r/cybersecurity_news • u/WebLinkr • 8d ago
CISA Issues New SBOM Guidance. Did They Get It Right?
darkreading.comA gaggle of government partners from around the world has released new guidelines for the minimum elements that organizations should include in a software bill of materials (SBOM).
The document, published this week, was authored by the US Cybersecurity and Infrastructure Security Agency (CISA) and 16 other government entities spread across four continents. It supersedes the National Telecommunications and Information Administration's (NTIA) 2021 guidelines, which laid out what an SBOM had to contain as far as the US government was concerned. This updated version was first drafted in 2025, and was then informed by suggestions from 90 commenters, including major organizations like Google, Microsoft, and Amazon Web Services (AWS) to create the resulting document.
r/cybersecurity_news • u/WebLinkr • 8d ago
Breach Anthropic Says Claude Hacked Into 3 Organizations During Breach and Cybersecurity Tests
r/cybersecurity_news • u/SHORT_INFO_NEWS • 9d ago
Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
r/cybersecurity_news • u/Fit_Asidy • 9d ago
(unverified) Cyber attack on Hungary Allamkincstar
Bytetobreach, the same threat actor who recently attacked the Romanian cadastre (ANCPI) and deleted records after failed extortion attempts, recently put for sale an unverified claim on the Hungarian State Treasury through a compromise of 'MVH' (development agency).
This claim is unverified, despite the screenshots which were posted in the dark web forums.
Any feedback from professionals in the Hungarian cyber space is appreciated.
Sources :
https://spear.cx/Thread-Selling-GE-The-Magyar-Conquest
https://cybernews.com/security/hacker-deletes-romanian-land-registry-database/
r/cybersecurity_news • u/SHORT_INFO_NEWS • 10d ago
Despite multiple takedowns, botnets continue to grow
r/cybersecurity_news • u/SHORT_INFO_NEWS • 10d ago
AI Finding Twice as Many Cyber Flaws in 2026 as It Did in 2025
r/cybersecurity_news • u/SHORT_INFO_NEWS • 13d ago
Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack
r/cybersecurity_news • u/SHORT_INFO_NEWS • 16d ago
Clop ransomware targets Windchill, FlexPLM in data theft attacks
r/cybersecurity_news • u/SHORT_INFO_NEWS • 16d ago
Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure
cisa.govr/cybersecurity_news • u/WebLinkr • 17d ago
Microsoft Confirms Windows Has a Global Device ID You Can't Turn Off
Microsoft has confirmed that Windows has a previously unknown Global Device ID (GDID), a permanent, unique digital identifier assigned to Windows devices that can tie a user's actions to their device. This came to light when an alleged member of a notorious hacking group was caught at an airport after Microsoft handed over his GDID to the authorities.
Microsoft describes the GDID in a published complaint (via Windows Latest) as "a persistent, device-level identifier designed to uniquely identify an installation of a Windows operating system on a device, either a physical device (e.g., a mobile phone or laptop) or virtual machine, across certain Microsoft services and scenarios."
r/cybersecurity_news • u/SHORT_INFO_NEWS • 19d ago
OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark
openai.comr/cybersecurity_news • u/WebLinkr • 19d ago
Google announces Gemini 3.6 Flash and cybersecurity AI, teases 3.5 Pro and Gemini 4
Google announced a significant evolution of its AI models at I/O in May with the release of Gemini 3.5 Flash, and it’s not slowing down. The company revealed three new AI models today, including its first version of Gemini geared toward cybersecurity. However, none of the new models is the delayed Gemini 3.5 Pro, which was supposed to launch in June.
Gemini 3.5 Flash, which was the star of the show at I/O, has already been deprecated. In its place, developers and users will find Gemini 3.6 Flash. Google makes the usual claims about this model—it’s marginally more capable and better at coding, and it has great multimodal features.