Security
Headlines
HeadlinesLatestCVEs

Source

DARKReading

AI-Powered Voice Cloning Raises Vishing Risks

A researcher-developed framework could enable attackers to conduct real-time conversations using simulated audio to compromise organizations and extract sensitive information.

DARKReading
IoT Security Flounders Amid Churning Risk

The Internet of Things (IoT) has made everything more interconnected than ever, but an important US government security initiative is stuck in limbo even as threat actors step up attacks on everything from medical gear to printers.

Sneaky, Malicious MCP Server Exfiltrates Secrets via BCC

The first known malicious MCP server is an AI integration tool that automatically sends email such as those related to password resets, account confirmations, security alerts, invoices, and receipts to threat actors.

Akira Hits SonicWall VPNs in Broad Ransomware Campaign

Akira ransomware actors are currently targeting SonicWall firewall customers vulnerable to a bug discovered last year.

Ukrainian Cops Spoofed in Fileless Phishing Attacks on Kyiv

Attackers impersonate the National Police of Ukraine to deploy Amatera Stealer and PureMiner, using malicious Scalable Vector Graphics to trick victims.

Volvo Employee SSNs Stolen in Supplier Ransomware Attack

Three international vehicle manufacturers have fallen to supply chain cyberattacks in the past month alone.

Iranian State Hackers Use SSL.com Certificates to Sign Malware

Security researchers say multiple threat groups, including Iran's Charming Kitten APT offshoot Subtle Snail, are deploying malware with code-signing certificates from the Houston-based company.

#ssl
Prep is Underway, But 2026 FIFA World Cup Poses Significant Cyber Challenges

The world's most-popular sports contest starts in June 2026 across 16 venues in three countries: Securing the event infrastructure from cyber threats will require massive collaboration.

Cisco's Wave of Actively Exploited Zero-Day Bugs Targets Firewalls, IOS

Patch now: Cisco recently disclosed four actively exploited zero-days affecting millions of devices, including three targeted by a nation-state actor previously discovered to be behind the "ArcaneDoor" campaign.

Chinese APT Drops 'Brickstorm' Backdoors on Edge Devices

The China-linked cyber-espionage group UNC5221 is compromising network appliances that cannot run traditional EDR agents to deploy new versions of the "Brickstorm" backdoor.