Latest Cybersecurity News and Articles


CISO DEMO: Cybersecurity Vendors Pitch Chief Information Security Officers On YouTube

17 March 2026
Security chiefs watch short videos produced by Cybercrime Magazine – Steve Morgan, Founder of Cybersecurity Ventures Sausalito, Calif. – Mar. 17, 2026 Around a year ago, Cybersecurity Ventures asked AI “Why use YouTube for marketing?” and it replied “YouTube is a powerful marketing tool because The post CISO DEMO: Cybersecurity Vendors Pitch Chief Information Security Officers On YouTube appeared first on Cybercrime Magazine.

AI Flaws in Amazon Bedrock, LangSmith, and SGLang Enable Data Exfiltration and RCE

17 March 2026
Cybersecurity researchers have disclosed details of a new method for exfiltrating sensitive data from artificial intelligence (AI) code execution environments using domain name system (DNS) queries. In a report published Monday, BeyondTrust revealed that Amazon Bedrock AgentCore Code Interpreter's sandbox mode permits outbound DNS queries that an attacker can exploit to enable interactive shells

Tech Giants Invest $12.5 Million in Open Source Security

17 March 2026
Anthropic, AWS, Google, Microsoft, and OpenAI fund the Linux Foundation’s long-term security initiatives focused on open source software. The post Tech Giants Invest $12.5 Million in Open Source Security appeared first on SecurityWeek.

UK Companies House Exposed Details of Millions of Firms 

17 March 2026
The government agency confirmed the vulnerability could have been exploited to obtain company details and alter records.   The post UK Companies House Exposed Details of Millions of Firms  appeared first on SecurityWeek.

LeakNet Ransomware Uses ClickFix via Hacked Sites, Deploys Deno In-Memory Loader

17 March 2026
The ransomware operation known as LeakNet has adopted the ClickFix social engineering tactic delivered through compromised websites as an initial access method. The use of ClickFix, where users are tricked into manually running malicious commands to address non-existent errors, is a departure from relying on traditional methods for obtaining initial access, such as through stolen credentials

Surf AI Raises $57 Million for Agentic Security Operations Platform

17 March 2026
The company has announced its launch, backed by funding from Accel, Cyberstarts, and Boldstart Ventures. The post Surf AI Raises $57 Million for Agentic Security Operations Platform appeared first on SecurityWeek.

Robotic Surgery Giant Intuitive Discloses Cyberattack

17 March 2026
The company says some of its internal business applications were accessed after an employee fell victim to a phishing attack. The post Robotic Surgery Giant Intuitive Discloses Cyberattack appeared first on SecurityWeek.

Growing Threat Of Scams Hits Australia’s Not-For-Profit (NFP) Sector Hard

17 March 2026
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Mar. 17, 2026 – Read the full story in Eureka Street Mark Gaetani, National President of the St Vincent de Paul Society in Australia, recently read in Cybercrime Magazine that cybercrime is considered The post Growing Threat Of Scams Hits Australia’s Not-For-Profit (NFP) Sector Hard appeared first on Cybercrime Magazine.

174 Vulnerabilities Targeted by RondoDox Botnet

17 March 2026
The botnet has increased its activity, peaking at 15,000 exploitation attempts per day, and taking a more targeted approach. The post 174 Vulnerabilities Targeted by RondoDox Botnet appeared first on SecurityWeek.

Google, Meta, Microsoft Among Signatories of Pact to Combat Scams

17 March 2026
Several major tech and retail companies have signed an industry accord against online scams and fraud. The post Google, Meta, Microsoft Among Signatories of Pact to Combat Scams appeared first on SecurityWeek.

Tracebit Raises $20M for Cloud-Native Deception Technology

17 March 2026
The company plans to scale its products, expand to new markets, and grow its marketing and engineering teams. The post Tracebit Raises $20M for Cloud-Native Deception Technology appeared first on SecurityWeek.

AI is Everywhere, But CISOs are Still Securing It with Yesterday's Skills and Tools, Study Finds

17 March 2026
A majority of security leaders are struggling to defend AI systems with tools and skills that are not fit for the challenge, according to the AI and Adversarial Testing Benchmark Report 2026 from Pentera. The report, based on a survey of 300 US CISOs and senior security leaders, examines how organizations are securing AI infrastructure and highlights critical gaps tied to skills shortages and

CISA Flags Year-Old Wing FTP Vulnerability as Exploited

17 March 2026
Tracked as CVE-2025-47813, the flaw leads to the disclosure of the full local installation path of the application. The post CISA Flags Year-Old Wing FTP Vulnerability as Exploited appeared first on SecurityWeek.

AI, APIs and DDoS Collide in New Era of Coordinated Cyberattacks

17 March 2026
Akamai warns that Layer 7 DDoS, API abuse and AI-powered attacks are merging into coordinated, multi-vector campaigns that are harder to detect and defend against. The post AI, APIs and DDoS Collide in New Era of Coordinated Cyberattacks appeared first on SecurityWeek.

Konni Deploys EndRAT Through Phishing, Uses KakaoTalk to Propagate Malware

17 March 2026
North Korean threat actors have been observed sending phishing to compromise targets and obtain access to a victim's KakaoTalk desktop application to distribute malicious payloads to certain contacts. The activity has been attributed by South Korean threat intelligence firm Genians to a hacking group referred to as Konni. "Initial access was achieved through a spear-phishing email disguised as a

CISA Flags Actively Exploited Wing FTP Vulnerability Leaking Server Paths

17 March 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a medium-severity security flaw impacting Wing FTP to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, CVE-2025-47813 (CVSS score: 4.3), is an information disclosure vulnerability that leaks the installation path of the application under certain conditions

Verizon Retail Customer Database Allegedly for Sale by Hackers: 6.3M Customers at Risk

17 March 2026
One of the United States’ largest Verizon Authorized Retailers may have been compromised. 

GlassWorm Attack Uses Stolen GitHub Tokens to Force-Push Malware Into Python Repos

16 March 2026
The GlassWorm malware campaign is being used to fuel an ongoing attack that leverages the stolen GitHub tokens to inject malware into hundreds of Python repositories. "The attack targets Python projects — including Django apps, ML research code, Streamlit dashboards, and PyPI packages — by appending obfuscated code to files like setup.py, main.py, and app.py," StepSecurity said. "Anyone who runs

Oracle EBS Hack: Only 4 Corporate Giants Still Silent on Potential Impact

16 March 2026
Broadcom, Bechtel, Estée Lauder, and Abbott Technologies are the only major companies that have yet to issue a public statement.  The post Oracle EBS Hack: Only 4 Corporate Giants Still Silent on Potential Impact appeared first on SecurityWeek.

Targeted Phishing Attack Breaches Biotech Company Data

16 March 2026
Intuitive faced a data breach due to a phishing attack.