Latest Cybersecurity News and Articles


Anthropic’s Mythos Preview Just Changed The Threat Landscape In Ways The Security Industry Isn’t Fully Prepared For

23 April 2026
The attacker’s blind spot just disappeared –Mayuresh Ektare, Senior Vice President, Product Management San Jose, Calif. – Apr. 23, 2026 Today’s attackers largely treat software as a black box. Some study open-source software (OSS) to tailor their techniques, but doing this at scale has always The post Anthropic’s Mythos Preview Just Changed The Threat Landscape In Ways The Security Industry Isn’t Fully Prepared For appeared first on Cybercrime Magazine.

UNC6692 Impersonates IT Helpdesk via Microsoft Teams to Deploy SNOW Malware

23 April 2026
A previously undocumented threat activity cluster known as UNC6692 has been observed leveraging social engineering tactics via Microsoft Teams to deploy a custom malware suite on compromised hosts. "As with many other intrusions in recent years, UNC6692 relied heavily on impersonating IT helpdesk employees, convincing their victim to accept a Microsoft Teams chat invitation from an account

Cloudsmith Raises $72 Million in Series C Funding

23 April 2026
The company will use the investment to accelerate product development and grow go-to-market efforts. The post Cloudsmith Raises $72 Million in Series C Funding appeared first on SecurityWeek.

Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign

23 April 2026
Bitwarden CLI has been compromised as part of the newly discovered and ongoing Checkmarx supply chain campaign, according to new findings from Socket. "The affected package version appears to be @bitwarden/cli@2026.4.0, and the malicious code was published in 'bw1.js,' a file included in the package contents," the application security company said. "The attack appears to have leveraged a

Private health records of half a million Britons offered for sale on Chinese website

23 April 2026
Private health records of half a million Britons offered for sale on Chinese website Technology minister tells Commons ‘de-identified’ information from UK Biobank advertised for sale on AlibabaUK politics live – latest updatesThe confidential health records of half a million British volunteers have been offered for sale on Chinese website Alibaba, the UK government has confirmed.The data, belonging to participants in the UK Biobank project, was found for sale on three separate listings last week. The records have now been removed and it is not believed any sales were made. Continue reading...

ThreatsDay Bulletin: $290M DeFi Hack, macOS LotL Abuse, ProxySmart SIM Farms +25 New Stories

23 April 2026
You scroll past one incident and see another that feels familiar, like it should have been fixed years ago, but it still works with small changes. Same bugs. Same mistakes. The supply chain is messy. Packages you did not check are stealing data, adding backdoors, and spreading. Attacking the systems behind apps is easier than breaking the apps themselves. The exploits are simple but still work

Chinese Cybersecurity Firm’s AI Hacking Claims Draw Comparisons to Claude Mythos

23 April 2026
360 Digital Security Group claims to have uncovered 1,000 vulnerabilities using AI, including at the Tianfu Cup hacking contest. The post Chinese Cybersecurity Firm’s AI Hacking Claims Draw Comparisons to Claude Mythos appeared first on SecurityWeek.

Keeper Security: The Identity Security Platform For Humans, Machines, And AI Agents

23 April 2026
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Apr. 23, 2026 – Watch the YouTube video Keeper Security is transforming cybersecurity for people and organizations around the world. The company’s next-generation privileged access management solution deploys in minutes and seamlessly integrates The post Keeper Security: The Identity Security Platform For Humans, Machines, And AI Agents appeared first on Cybercrime Magazine.

[Webinar] Mythos Reality Check: Beating Automated Exploitation at AI Speed

23 April 2026
Imagine a world where hackers don't sleep, don't take breaks, and find weak spots in your systems instantly. Well, that world is already here. Thanks to AI, attackers are now launching automated, large-scale exploits faster than ever before. The time you have to fix a vulnerability before it gets attacked is shrinking to zero. We call this the Collapsing Exploit Window, and it means your

Executive Summary: Defending against China-nexus covert networks of compromised devices

23 April 2026
Organisations should map and baseline their edge device traffic, especially VPN and remote access connections, and adopt dynamic threat feed filtering that includes known covert network indicators.

International cyber agencies share fresh advice to defend against China-linked covert networks

23 April 2026
New advisory highlights how to defend against attacker tactics believed to be used by China-linked actors to hide malicious cyber activity.

Defending against China-nexus covert networks of compromised devices

23 April 2026
Explaining the widespread shift in tactics, techniques and procedures (TTPs) towards networks of compromised infrastructure, and how to defend against it

NCSC: Leave passwords in the past - passkeys are the future

23 April 2026
Passkeys are the more secure and user-friendly login method and should be the default authentication option for consumers.

Rilian Raises $17.5 Million for AI-Native Security Orchestration

23 April 2026
The company will hire new talent and expand operations across the US and other allied countries. The post Rilian Raises $17.5 Million for AI-Native Security Orchestration appeared first on SecurityWeek.

Project Glasswing Proved AI Can Find the Bugs. Who's Going to Fix Them?

23 April 2026
Last week, Anthropic announced Project Glasswing, an AI model so effective at discovering software vulnerabilities that they took the extraordinary step of postponing its public release. Instead, the company has given access to Apple, Microsoft, Google, Amazon, and a coalition of others to find and patch bugs before adversaries can. Mythos Preview, the model that led to Project Glasswing, found

The Behavioral Shift: Why Trusted Relationships Are the Newest Attack Surface

23 April 2026
New analysis from Abnormal AI reveals how attackers have abandoned technical exploits to weaponize routine workflows and internal trust. The post The Behavioral Shift: Why Trusted Relationships Are the Newest Attack Surface appeared first on SecurityWeek.

Luxury Cosmetics Giant Rituals Discloses Data Breach

23 April 2026
The company is notifying My Rituals members that hackers downloaded part of their data, including names and addresses. The post Luxury Cosmetics Giant Rituals Discloses Data Breach appeared first on SecurityWeek.

AI Can Autonomously Hack Cloud Systems With Minimal Oversight: Researchers 

23 April 2026
Palo Alto Networks has developed Zealot, a multi-agent penetration testing PoC capable of reconnaissance, exploitation, and exfiltration.  The post AI Can Autonomously Hack Cloud Systems With Minimal Oversight: Researchers  appeared first on SecurityWeek.

China-Linked GopherWhisper Infects 12 Mongolian Government Systems with Go Backdoors

23 April 2026
Mongolian governmental institutions have emerged as the target of a previously undocumented China-aligned advanced persistent threat (APT) group tracked as GopherWhisper. "The group wields a wide array of tools mostly written in Go, using injectors and loaders to deploy and execute various backdoors in its arsenal," Slovakian cybersecurity company ESET said in a report shared with The Hacker

Apple Patches iOS Flaw Allowing Recovery of Deleted Chats

23 April 2026
Apple rolled out the security patches for dozens of iPhone and iPad models and generations. The post Apple Patches iOS Flaw Allowing Recovery of Deleted Chats appeared first on SecurityWeek.