Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

Cyber Security News
cybersecuritynews.com > hackers-exploit-sap-commerce-cloud > amp

Hackers Started to Exploit Critical SAP Commerce Cloud, Still No Public PoC

22+ hour, 1+ min ago   (309+ words) Threat actors have begun actively probing and attempting to exploit a maximum-severity flaw in SAP Commerce Cloud, just three days after official security fixes were released. Defused honeypot telemetry captured the first wave of unauthenticated remote-execution traffic circulating across the…...

Cyber Security News
cybersecuritynews.com > post-hugging-face-reflections-the-agentic-attacker-is-already-here > amp

Post-Hugging Face Reflections: The Agentic Attacker Is Already Here

21+ hour, 26+ min ago   (830+ words) Bill Robbins, CEO of Menlo Security An AI agent broke out of the sandbox built to contain it and put itself on the open internet. Then it attacked another company. The attack wasn’t executed by a human. Instead, the AI…...

Cyber Security News
cybersecuritynews.com > shell-investigating-data-breach > amp

Shell Investigating Data Breach Following Cl0p Ransomware Group Claim

23+ hour, 4+ min ago   (267+ words) Security researchers and enterprise defenders are closely monitoring the situation as forensic teams work to assess the legitimacy and operational scope of the cyberattack. “We are working with our security teams and relevant experts to investigate the situation,” a Shell…...

Cyber Security News
cybersecuritynews.com > microsoft-make-passkeys-default-in-entra-id > amp

Microsoft to Make Passkeys Default in Entra ID and Retires SMS and Voice Authentication

1+ day, 1+ hour ago   (515+ words) Microsoft will make passkeys the default authentication experience in Microsoft Entra ID as part of a broader move away from phishing-prone sign-in methods. Beginning September 1, 2026, users currently enabled for SMS or voice authentication will be automatically enabled for passkeys. During…...

Cyber Security News
cybersecuritynews.com > hackerai-malware

HACKERAI Malware Turns GitHub Gists Into a Command-and-Control Channel

2+ day, 1+ hour ago   (704+ words) A newly identified malware framework called HACKERAI C2 Agent is using GitHub Gists as a hidden channel for attacker commands and stolen data. The technique lets operators blend malicious traffic with a service that many organizations allow on their networks. The…...

Cyber Security News
cybersecuritynews.com > bring-your-own-edr-attack > amp

Bring Your Own EDR Attack Turns SentinelOne Into PPL-Protected Trojan Horse to Shield Malware

1+ day, 22+ hour ago   (623+ words) A “Bring Your Own EDR” attack abuses trusted SentinelOne components to turn endpoint protection into a powerful malware shield. The research was presented at DEF CON 34 in Las Vegas, and SentinelOne fixed the reported issue in Agent version 26.1.1. Endpoint detection…...

Cyber Security News
cybersecuritynews.com > dcrat-campaign

DCRat Campaign Hides Malware Archive Inside SVG Using HTML Smuggling

2+ day, 2+ min ago   (615+ words) A new DCRat campaign is using a familiar image format to hide a dangerous malware archive. The operation begins with phishing emails that pose as legal notifications and urge recipients to open an attached SVG file. The attachment looks harmless…...

Cyber Security News
cybersecuritynews.com > multiple-tp-link-bypass-authentication-vulnerabilities

Multiple TP-Link Vulnerabilities Allow Attackers to Bypass Authentication and Escalate Privileges

1+ day, 22+ hour ago   (455+ words) The flaws could allow attackers with network access to bypass authentication, escalate privileges, steal sensitive information, read device files, and execute operating system commands. The most serious flaw, CVE-2025-30237, is an authentication bypass vulnerability in the web management interface. It…...

Cyber Security News
cybersecuritynews.com > dysphoria-botnet

Dysphoria Botnet Turns Compromised Routers and Cameras Into DDoS Bots and C2 Relay Nodes

1+ day, 23+ hour ago   (632+ words) Dysphoria has turned a large number of everyday internet-connected devices into a potential attack network. The botnet is linked to roughly 296,000 compromised devices, placing routers, cameras, gateways, and other connected equipment at risk of being used against targets chosen by…...

Cyber Security News
cybersecuritynews.com > ai-agents

AI Agents Don’t Stop When Malware Fails, They Write Another Tool and Keep Attacking

1+ day, 23+ hour ago   (698+ words) AI agents are changing the shape of cyberattacks. Instead of relying on a fixed piece of malware, an agent can test an approach, see it fail, write a replacement tool, and continue toward the same goal. Recent incidents show that…...