Cyber News
Read latestCN

Cyber News

Know what happened in cybersecurity today. Source-driven intelligence, AI-assisted reporting, editorially reviewed.

Sections

Latest newsCVE trackerThreat actorsMalware

Feeds

RSSSitemapNews sitemapllms.txt

© 2026 Cyber News.

CCISA AdvisoriesinCVE·Aug 20high

Siemens Solid Edge Multiple File Parsing Vulnerabilities - Seven CVEs Rated HIGH

Siemens Solid Edge versions SE2025 prior to V225.0.15 and SE2026 prior to V226.0.7 are affected by seven CVEs (CVE-2026-50058 through CVE-2026-50064) involving out-of-bounds read, out-of-bounds write, and use-after-free vulnerabilities in file parsing routines. The flaws are triggered when the application processes specially crafted files in PAR, PSM, or DFT format. Exploitation could allow an attacker to execute code in the context of the current process, crash the application, or potentially gain control of affected systems. CVSS v3.1 base scores are 7.8 (HIGH) for all seven vulnerabilities. Siemens has released updates and recommends immediate patching.

42m
CCISA AdvisoriesinCVE·Sep 16critical

Six Critical Vulnerabilities Discovered in Digital Watchdog VMAX DVR and NVR Product Lineups

CISA has issued an advisory detailing six vulnerabilities affecting Digital Watchdog VMAX DVR and NVR product lines. Exploitation could allow unauthenticated remote attackers to gain full administrative control, access live and recorded surveillance footage, alter device configurations, and use compromised devices as network pivot points. CVSS scores range from 6.5 to 9.6, with CVE-2026-66890 rated CRITICAL. Digital Watchdog has released updated firmware to address the flaws.

32m
CCISA AdvisoriesinVulnerability·Aug 20critical

Critical OS Command Injection Vulnerability Discovered in Haiwell IoT Cloud HMI Gateway

A critical command injection vulnerability (CVE-2026-19188) has been identified in the Haiwell IoT Cloud HMI Gateway product. The flaw exists in the Net Check feature accessible via the /setting endpoint, where the cmdPing Socket.io event fails to properly sanitize user-supplied input before passing it to the underlying operating system. Successful exploitation may allow an attacker to inject and execute arbitrary OS commands with root privileges. The vulnerability affects Haiwell IoT Cloud HMI Gateway version 3.40.1.12 and earlier. Haiwell has addressed the issue in patch version Scada-v3.50.1.19. The vulnerability has been reported to CISA by Fiqram Akmal. No known public exploitation has been reported to CISA at the time of publication. The vulnerability is classified as critical with CVSS scores of 3.1 and 4.0. Affected sectors include Energy, Critical Manufacturing, and Water and Wastewater.

32m
CCISA AdvisoriesinCVE·Sep 2high

Rockwell Automation PLC Firmware Vulnerability CVE-2021-42260 - Denial of Service Risk

A denial-of-service vulnerability (CVE-2021-42260) affects multiple Rockwell Automation programmable automation controller firmware versions. The flaw, categorized as a 'Loop with Unreachable Exit Condition (Infinite Loop)' (CWE-835), can be triggered via corrupt crafted data. Exploitation may result in a major nonrecoverable fault (MNRF), requiring a program download for safety controllers or a stage 2 reset for non-safety controllers to recover. CVSS v3 base score is 7.5 (HIGH). Rockwell Automation has released firmware updates to address the issue.

22m
TThe Hacker NewsinMalware·Aug 21high

Rust Supply Chain Attack Distributes Build-Time Malware via Compromised Crates.io Accounts

A supply chain attack targeting the Rust ecosystem has resulted in the deletion of malicious versions of three popular crates from crates.io. Analysis indicates a compromised maintainer account was used to push updates that introduced a typosquatted dependency. The build script of this dependency downloaded and executed a remote payload during the build process, potentially compromising downstream projects. The Rust Project confirmed the removal of the affected releases, though details regarding actor attribution and the origin of the remote payload remain unverified.

21m
CCISA AdvisoriesinCVE·Sep 15high

CISA Adds Cisco Secure Email Gateway SQL Injection Vulnerability to Known Exploited Catalog

The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-76461, a SQL injection vulnerability in Cisco Secure Email Gateway, to its Known Exploited Vulnerabilities (KEV) Catalog. The addition is based on evidence of active exploitation. Binding Operational Directive 26-04 requires Federal Civilian Executive Branch agencies to prioritize rapid remediation of this vulnerability on publicly exposed assets that could grant total system control post-exploitation. CISA encourages all organizations to adopt similar risk-based prioritization.

22m
BBleepingComputerinData Breaches·Sep 30high

Times Car Confirms Data Breach Affecting 6.6 Million User Accounts

Times Car, a Japanese car-sharing service, has confirmed a data breach compromising approximately 6.6 million user accounts. The incident was disclosed late last week, with the exact attack vector and nature of exposed personal information yet to be fully specified. Authorities and the company are reportedly investigating the breach.

11m
TThe Hacker NewsinVulnerability·Sep 30high

Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials

The maintainers of the official MCP Python SDK disclosed a security vulnerability that could allow a malicious server to trick applications into divulging OAuth credentials. The issue affects the handling of client secrets, authorization codes, and PKCE proof keys when communicating with token endpoints.

11m
BBleepingComputerinCyber Attacks·Sep 30high

Former US Air Force Members Sentenced to Prison for Business Email Compromise Scams

Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and phishing campaigns. The sentencing, reported by BleepingComputer in September 2026, concluded a federal case targeting individuals who abused their military backgrounds to conduct financially motivated email fraud. The attacks spanned multiple years prior to sentencing, though specific victim counts and total financial losses were not detailed in the reporting. The case underscores the legal consequences of using military credentials and training for cyber-enabled fraud.

11m
TThe Hacker Newsindata-breaches·Sep 30high

French Tax Administration Data Breach Exposed Hundreds of Thousands of Records via Stolen Staff Credentials

An unauthorized access incident at France's Direction Générale des Finances Publiques (DGPP) compromised tax data belonging to hundreds of thousands of taxpayers and businesses between June and July 2026. According to a report published by France's national cybersecurity agency ANSSI on 29 September 2026, the attacker used stolen staff passwords to gain entry. The agency stated the attack was 'not sophisticated' and went undetected for seven weeks due to weak security controls. ANSSI noted that neither the tax administration nor the agency itself observed data exfiltration, though the breach resulted in unauthorized access to sensitive fiscal information.

11m
TThe Hacker NewsinCyber Attacks·Sep 30high

Star Blizzard Campaign Targets 100+ Organizations with Fake Event Invitations

Microsoft reports that the Russian state-sponsored threat actor Star Blizzard has been conducting a sustained campaign since January 2026, using fake event invitations to trick targets into installing a backdoor on Windows computers. The operation has affected more than 100 organizations, primarily in the U.S. and U.K., with victims tied to Ukraine. At least one infection has been confirmed, though the full extent of breaches and data exfiltration remains unverified.

11m
CCISA AdvisoriesinCVE·Sep 30high

CISA Adds Two Citrix NetScaler Vulnerabilities to Known Exploited Catalog

The Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. CVE-2026-88771 involves improper input validation and CVE-2026-88772 involves improper restriction of operations within the bounds of a memory buffer, both affecting Citrix NetScaler products. The additions trigger remediation requirements under Binding Operational Directive 26-04 for Federal Civilian Executive Branch agencies.

12m

Quick answers

What is Cyber News?
Cyber News is a cybersecurity current-affairs publication at cyber.techvoid.dev. It covers attacks, data breaches, vulnerabilities, malware, and threat actors.
How often is Cyber News updated?
The homepage and latest-news feed are updated through the day as new cybersecurity stories are published.
Where do Cyber News stories come from?
Each story lists its original sources, publication time, and later updates. Reporting is source-driven and editorially reviewed.
Where can I track CVEs, malware, and threat actors?
Cyber News keeps a CVE tracker, a malware watch, and a threat-actor index. Each profile links to related news.