News & Map
1,189 items on Cyberstrategy — showing 281–320 · 1,077 without coordinates · Across the network · RSS
PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug
Attackers are exploiting a critical flaw in a third-party WooCommerce plugin to upload PHP webshells
No location · Sep 16, 2026 · WedgetailCoast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks
The agencies issued a joint statement saying the “joint security boardings” came in response to “indications that the ne...
No location · Sep 16, 2026 · WedgetailOne Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude
Security researchers at Forever Security have shown that one ordinary browser extension could take control of the AI ass...
No location · Sep 16, 2026 · WedgetailCISA and NIST Issue Guidance to Protect Cloud Identity Tokens
CISA and NIST issued final guidance to help protect cloud identity tokens and assertions
No location · Sep 16, 2026 · WedgetailAttacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
Mandiant says an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider an...
No location · Sep 16, 2026 · WedgetailParallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix
Parallels Desktop for Mac has a flaw that lets an ordinary local account run code as root, the highest level of access o...
No location · Sep 16, 2026 · WedgetailN0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security
N0va is targeting organizations across North America and Europe with phishing campaigns that impersonate trusted service...
No location · Sep 16, 2026 · WedgetailFake CAPTCHA Scams
New variant of an old scam: Use the framing of a CAPTCHA to get an unsuspecting user to download and run a malicious pro...
No location · Sep 16, 2026 · WedgetailGoogle Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation
Google has disclosed that a high-severity security flaw in its Pixel Cellular Modem has come under exploitation in the w...
No location · Sep 16, 2026 · WedgetailThreat Intelligence Alone Won't Close the Exploitation Gap
A leaked credential shows up in a criminal marketplace, or a vulnerability gets a disclosure advisory, and either one ca...
No location · Sep 16, 2026 · WedgetailAcronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks
Acronis has warned that a high-severity security flaw in its Backup plugin for cPanel and Web Host Manager (WHM) deploym...
No location · Sep 16, 2026 · WedgetailCyber-Attacks Cost Organizations $52,000 on Average
Hiscox highlighted the huge financial and operational costs of cyber-attacks, with the average cost of an incident at $5...
No location · Sep 16, 2026 · WedgetailSecuring the unpatchable in an age of AI-driven vulnerabilities
Advances in AI technology will continue to identify vulnerabilities that in some circumstances are difficult, or effecti...
No location · Sep 16, 2026 · WedgetailNightEagle targets Russian companies
Kaspersky GERT experts have uncovered a new campaign by the NightEagle APT, featuring the GhostContainer backdoor and to...
No location · Sep 16, 2026 · WedgetailZero-Day Flaw in TP-Link Cameras Enables Eavesdropping
OPSWAT researchers find two zero-days in TP-Link cameras
No location · Sep 16, 2026 · WedgetailCyberthreats are moving faster than SMBs: Readiness must accelerate
As AI adoption expands the attack surface and adds to the security workload, businesses need automation backed by expert...
No location · Sep 16, 2026 · WedgetailMajor Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes
A group of cyber threat detection providers, including CrowdStrike, Palo Alto Networks and Sophos, have joined SE Labs’ ...
No location · Sep 16, 2026 · WedgetailNCSC and Allies Warn of Iranian Spyware Campaign
The UK’s National Cyber Security Centre says Iranian Chosen Brick spyware is designed to snoop on dissidents
No location · Sep 16, 2026 · WedgetailAttackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin ...
No location · Sep 16, 2026 · WedgetailActive Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens
A critical security flaw in WSO2 API Manager has come under active exploitation in the wild, according to findings from ...
No location · Sep 16, 2026 · WedgetailRisky Business #853 -- We're all gonna die, apparently
On this week’s show Patrick Gray and James Wilson are joined by former US Cyber Command executive director turned PwC’s ...
No location · Sep 16, 2026 · WedgetailCyber Op Targets South Korean Media & Automotive Sectors
A likely North Korean advanced persistent threat (APT) group used a previously undocumented Linux espionage toolkit to c...
No location · Sep 16, 2026 · WedgetailNGA official takes top AI job at Cyber Command
Ronzelle Green succeeds Reid Novotny, who pushed the combatant command to embrace the technology.
No location · Sep 15, 2026 · WedgetailMicrosoft Issues Emergency Fixes After Massive Patch Tuesday
You can't make an omelet without breaking a few eggs, and you can't patch nearly 1,000 CVEs without a few glitches.
No location · Sep 15, 2026 · WedgetailBlack Hat USA 2026 | OpenAI's Deep Dive Into Hugging Face Incident
At Black Hat USA, OpenAI engineers reconstruct the Hugging Face incident and explore lessons learned about AI safeguards...
No location · Sep 15, 2026 · WedgetailKREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers...
No location · Sep 15, 2026 · WedgetailVectraRAT Can Hack Windows Enterprises for $250 per Month
The full-service malware-as-a-service (MaaS) platform offers a Windows implant, command-and-control (C2) infrastructure,...
No location · Sep 15, 2026 · WedgetailTrump administration orders Kalshi to scrap AI price tracker over national security concerns
The futures market for computer power lets buyers and sellers lock in prices, and gives traders a way to bet on where th...
No location · Sep 15, 2026 · WedgetailIranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists
Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware tha...
No location · Sep 15, 2026 · WedgetailAI agents collude to bypass guardrails, a new study shows
Enterprise AI lab, Emergence AI, ran eight simulations testing how frontier models handle cybersecurity threats.
No location · Sep 15, 2026 · WedgetailBambooToken Malware Uses MQTT to Control Windows and Linux Systems
Cybersecurity researchers have disclosed details of a multi-platform campaign that uses the Message Queueing Telemetry T...
No location · Sep 15, 2026 · WedgetailMost Fraudulent Hires Receive Credentials Before Detection
A new report highlights the vast growth in fraudulent candidates, presenting significant insider threat challenges to or...
No location · Sep 15, 2026 · WedgetailMost Firms Unable to Recover Quickly from Ransomware
Fenix24 found only four of more than 800 clients came close to stated ransomware recovery targets of 24-48 hours
No location · Sep 15, 2026 · WedgetailBlack Axe Members Extradited to US Over Internet Fraud Claims
Alleged Black Axe leaders extradited to the US over romance scams, BEC and money laundering claims
No location · Sep 15, 2026 · WedgetailAI the Top Priority for New Spend as Cyber Budgets Flatline
IANS finds AI is dominating net-new budgets even as overall funding for the function is flat
No location · Sep 15, 2026 · WedgetailGive every teammate and agent the right level of access to your Workers
You can now scope access to individual Workers and assign narrower Developer Platform roles, so teammates, CI tokens, an...
No location · Sep 15, 2026 · WedgetailHave it both ways: stay discoverable in search while disallowing AI training
Cloudflare is giving site owners a way to stay discoverable while disallowing AI training. New controls and an Accountab...
No location · Sep 15, 2026 · Wedgetail25 Years of Mass Surveillance Is Enough
This essay was written with Cindy Cohn, and originally appeared in Lawfare. One of the many legacies of the terrorist at...
No location · Sep 15, 2026 · WedgetailPolitical and business leaders back AI
US President Donald Trump called Nvidia CEO Jensen Huang during a live panel discussion to argue that worries about AI’s...
No location · Sep 15, 2026 · WedgetailOn the NSA’s Supercomputer from the 1960s
Really interesting story about Harvest, a specialized code breaking computer built in the 1960s by IBM for the NSA.
No location · Sep 15, 2026 · Wedgetail1,077 of 1,189 items have no coordinates and so are listed but not mapped.