Cybersecurity 2026
Global headlines curated by our intelligent agents.
Latest News
OpenAI doubles down on decision to fire three AI safety researchers
The AI lab insisted the decision was about a ‘breach of trust,’ not raising safety issues.
Three Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2Own
Three teams demonstrated remote exploits against fully patched Pixel 10 phones at Pwn2Own Ireland, earning $562,500 in total.
Researchers uncover new DarkSword spyware variant affecting unpatched iPhones
iVerify released a report today detailing P7 DarkSword, a new variant of the malware associated with the DarkSword iPhone exploit chain uncovered earlier this year.
FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails
FBI says Integrity Technology Group-linked hackers stole email in Southeast Asia using custom tools and a scanner with over 1,300 scripts.
ThreatsDay: Ransomware Affiliate Betrayal, WhatsApp RAT, Exposed Hacker Tools and 12 More Stories
ThreatsDay: Malicious VS Code themes, npm supply-chain attacks, AI phishing, ransomware betrayal, exposed hacker tools, and more cybersecurity news.
UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML
TrendAI links UAC-0099 to ASHVEIN, a .NET stealer and RAT used in attacks targeting Ukrainian government personnel.
ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms
Attackers used ARTEX and LLMs against South Korean financial organizations in a campaign that resulted in data exfiltration.
Some cheap Android phones are shipping with malware baked in
Midnight Mimosa malware arrives pre-served.
Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia
Wazza filters visitors with session tokens and browser checks before serving Adobe-themed Device Code phishing pages.
16 Malicious Firefox Extensions Pose as Rabby and OKX Wallets to Steal Recovery Phrases
Sixteen malicious Firefox extensions imitate Rabby and OKX wallets to intercept recovery phrases and private keys during wallet imports.
Asos warns customers about full extent of data breach after BBC contacted by hackers
Names, addresses, phone numbers, emails and customer numbers are now in the hands of cyber criminals.
MonsterCloud Owner Accused of Billing Over $19M While Secretly Paying Ransoms to Decrypt Data
MonsterCloud's owner is accused of charging ransomware victims over $19 million while secretly paying attackers over $8 million for decryptors.
Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm
Malicious tensorlake npm version 0.5.144 contained a Shai-Hulud worm that harvests credentials and can republish compromised packages.
Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer
Eight malicious npm packages downloaded 40,767 times deliver Overlord RAT, a Node.js stealer, and a downloader to Windows systems.
Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely
LMCache CVE-2026-105192 lets unauthenticated attackers run code when the multiprocess server is bound to a routable address; no fix exists.
PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet
Canto Incognito has infected over 3,400 servers, using exposed AI and LLM infrastructure for crypto mining and botnet growth.
The Beast Review
Samuel L. Jackson brings a mix of badassery and vulnerability to the role of President of the United States in The Beast, director Renny Harlin's a fun throwback to high-concept action movies of the past.
The Sixth Voice of the CISO Data Shows Cyber Risk Has Moved Inside the Workflow
Proofpoint says 79% of CISOs rank human risk as their biggest cyber vulnerability, while 78% view GenAI as a security risk in 2026.
Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details
Attackers are exploiting an Atlassian Data Center flaw that enables unauthenticated access to specific webroot files.
Anthropic Expands Claude Access for Vetted Cyber Teams as Glasswing Finds 129,000 Flaws
Anthropic expands reduced-safeguard AI access for vetted cyber teams after Project Glasswing verified at least 129,000 software flaws.
Hackers leak info on 3,615 Trump Mobile subscribers, and that’s all they seemingly had
Hackers leaked data of thousands of Trump Mobile customers, allegedly exposing full subscriber records and abandoned checkout data.
100+ Compromised Websites Use Fake Cloudflare Checks to Deliver LunexStealer
CERT-UA found 100+ compromised sites using ClickFix lures to distribute LunexStealer to Windows search visitors.
Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes
A human-operated phishing platform impersonates AI ad tools to capture credentials and MFA codes through browser-in-the-browser login windows.
A Trump Mobile breach may have exposed data of more than 3,600 people
The BYOD hacking group claims responsibility.