Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
A new CVE drops. Your scanner finds it.
The U.S. Federal Bureau of Investigation (FBI) seized the domains used by NightmareStresser, one of the world's longest-running distributed denial-of-service (DDoS) platforms.
The Manhattan District Attorney’s Office has seized the domains of 12 deepfake websites in what it called the largest known seizure of celebrity deepfake sites in history. The sites, which marketed themselves as deepfake pornography platforms, hosted AI-generated videos of over 1,200 people, including those in the public eye, ranging from politicians to actors, musicians, and social justice advocates.
Attackers now weaponize new vulnerabilities in about five days (Mandiant, part of Google Cloud). The median organization takes 43 days to patch one (Verizon DBIR 2026).
Since early May 2026, we’ve been monitoring a large phishing campaign based on T-Mobile rewards points. The messages falsely warn that a customer’s rewards points are about to expire.
The China-aligned state-sponsored threat actor known as FamousSparrow has been observed deploying a previously unreported backdoor called SparroWocky in attacks targeting multiple countries in Latin America since at least August 2025. "SparroWocky is a modular, C++ backdoor," ESET security researchers Alexandre Côté Cyr and Romain Dumont said in a technical report shared with The Hacker News ahead of publication.