Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
A coalition of parents and attorneys general is suing Meta, Google, TikTok, and Snap, accusing them of knowingly designing addictive platforms that harm children's mental health. Courts have denied the companies' attempts to dismiss the cases under Section 230, signaling a potential shift in liability for algorithm-driven content delivery.
A Black Hat USA 2026 presentation examines the Hugging Face hack involving OpenAI models. The incident demonstrates that autonomous hacks actually make human oversight more important, not less, for maintaining security.
Armored Likho, also known as Eagle Werewolf, has expanded its cyber-espionage toolkit with Rust-based implants like Still Sync for Telegram data theft and Still Audio for surveillance. The group targets Russian entities via a malicious donation app dropper, continuing its focus on multi-industry infiltration.
Severe vulnerabilities in a browser extension used for Belgium's eID authentication system allowed attackers to fully compromise the trust framework, enabling remote code execution. The incident underscores broader security risks posed by browser extensions in identity verification systems.
CVE-2026-55040 is a critical SharePoint vulnerability that permits authentication bypass through weaknesses in JWT token validation. Attackers can forge tokens to impersonate users, access sensitive files, and modify data.
Several high-severity vulnerabilities have been discovered in various Fortinet products, including FortiClient, FortiManager, FortiOS, and FortiWeb. These flaws could enable remote attackers to bypass security controls, execute malicious code, or disrupt services.