Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Swiss prosecutors are seeking a 12-year prison sentence for a 52-year-old Ukrainian software developer accused of participating in an international ransomware operation that caused hundreds of millions of dollars in damage. The defendant went on trial at Zurich District Court for his alleged involvement in attacks using LockerGoga, MegaCortex, and Nefilim ransomware against victims including Swiss train manufacturer Stadler Rail, banking software developer Crealogix, and building technology company Meier Tobler.
Researchers found that by combining two vulnerabilities, they could take over an Android device by delivering a payload and getting the victim to answer their phone.
GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauthenticated attacker to remotely modify or delete public projects and user data. The flaw, tracked as CVE-2026-19478, has been rated Critical by GitLab and assigned a CVSS score of 9.4.
Three testing models with the same goal but different directives engaged in "increasingly aggressive" territorial attacks on one another, according to Anthropic.
The breach affected anyone who received a loan through the company or inquired about a loan product through a third party.
A threat actor is selling employee databases allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies after gaining access using compromised credentials.