A newly disclosed SQL injection vulnerability in GeoServer could allow unauthenticated attackers to access backend PostgreSQL databases and, in high-risk configurations, execute operating-system commands on...
Welcome to this edition of the CyberPress weekly cybersecurity newsletter — your cybersecurity bulletin covering the 50 most important stories from August 10 to 14, 2026, organized...
A new data-extortion group known as ExfilSquad has leaked 382.64GB of data allegedly stolen from 13 organizations using Microsoft Dynamics 365 CRM and ERP environments....
A newly identified MessiahGPT is a criminal AI service marketed on BreachForums as an unrestricted platform for generating ransomware, phishing kits, stealers, crypters, and rootkits....
The HoneyMyte APT group, also known as Mustang Panda, has upgraded its CoolClient backdoor with a kernel-mode rootkit that hides command-and-control (C2) infrastructure on compromised...
A targeted fake-job campaign compromised a cryptocurrency organization after an employee was approached through LinkedIn while changing jobs.
The attacker posed as a recruiter for...
Threat actors have begun actively probing for a maximum-severity vulnerability in SAP Commerce Cloud only three days after security updates were released, signaling an urgent...
A new npm supply-chain campaign, tracked as ChainDrop and also called Mini Shai-Hulud, shows how attackers can turn trusted developer tools into a worm delivery...
Security researchers have identified a new modular remote access trojan (RAT) named Abyssos, a C++ malware family that gives attackers broad control over infected Windows systems.
Zscaler ThreatLabz first observed...
A coordinated campaign used 77 counterfeit VS Code extensions to collect developer and CI environment data through Open VSX.
The packages copied trusted extension names, namespaces, and descriptions, but...