Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Cybersecurity researchers have disclosed a new Android banking trojan called StreamRat, promoted to Spanish-speaking users via fake television-streaming advertisements on Meta that can grant attackers near-complete control of infected devices. The campaign reached an estimated 570,950 Meta accounts in the European Union, and device takeover requires victims to sideload an APK and grant successive permissions including accessibility access.
U.S. and European authorities disrupted the long-running botnet Sality, turning the malware’s peer-to-peer architecture against itself to cut thousands of infected computers off from operators.
Developed by CISA, the Federal Bureau of Investigation, and international partners, this guidance describes how organizations can plan and execute clear, timely, accurate, and audience-appropriate communications during IT and operational technology (OT) outages. Whether caused by cyber threat actors, human error, equipment failure, or natural hazards, service outages can create disruption and societal panic even without speculation from end users and the public as added factors.
CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities catalog, including CVE-2026-9586, CVE-2026-82329, and others. These vulnerabilities are actively exploited and pose significant risks.
Don’t panic if you spot an illegally created image or video of you online – there are ways to request its removal
The debate about whether AI delivers business value is over; the challenge now is implementing it at scale and securely across every function while meeting board-level pressure to move fast. Organizations must focus on adopting AI at business speed without losing control of cyber risk.