Latest Cybersecurity News and Articles


LastPass Warns of New Phishing Campaign

04 March 2026
The attackers are sending out fake alerts claiming unauthorized access or master password changes. The post LastPass Warns of New Phishing Campaign appeared first on SecurityWeek.

Webinar Today: Designing an OT SOC for Safety, Reliability, and Business Continuity

04 March 2026
Join the webinar as we explore a blueprint for an OT SOC leveraging an integrated OT Security Platform to safeguard operations and maintain business continuity. The post Webinar Today: Designing an OT SOC for Safety, Reliability, and Business Continuity appeared first on SecurityWeek.

Google Plans Two-Week Release Schedule for Chrome

04 March 2026
Starting September 2026, new Chrome iterations will be released twice as fast, part of a two-week cycle. The post Google Plans Two-Week Release Schedule for Chrome appeared first on SecurityWeek.

New RFP Template for AI Usage Control and AI Governance 

04 March 2026
As AI becomes the central engine for enterprise productivity, security leaders are finally getting the green light — and the budget — to secure it. But there’s a quiet crisis unfolding in the boardroom: many organizations know they need "AI Governance," but they have no idea what they are actually looking for. The CISO’s Dilemma: You Have the AI Budget, but Do You Have the Requirements? As AI

Global Coalition Publishes 6G Security and Resilience Principles

04 March 2026
The principles cover security, resilience against attacks and disasters, AI, and openness and interoperability. The post Global Coalition Publishes 6G Security and Resilience Principles appeared first on SecurityWeek.

Coupang Data Breach Leads to Q4 Losses

04 March 2026
Coupang reported Q4 losses, with revenue totaling below the estimates of analysts.

Fake Laravel Packages on Packagist Deploy RAT on Windows, macOS, and Linux

04 March 2026
Cybersecurity researchers have flagged malicious Packagist PHP packages masquerading as Laravel utilities that act as a conduit for a cross-platform remote access trojan (RAT) that's functional on Windows, macOS, and Linux systems. The names of the packages are listed below - nhattuanbl/lara-helper (37 Downloads) nhattuanbl/simple-queue (29 Downloads) nhattuanbl/lara-swagger (49 Downloads)

Critical FreeScout Vulnerability Leads to Full Server Compromise

04 March 2026
A patch bypass for an authenticated code execution bug, the flaw leads to zero-click remote code execution attacks. The post Critical FreeScout Vulnerability Leads to Full Server Compromise appeared first on SecurityWeek.

APT41-Linked Silver Dragon Targets Governments Using Cobalt Strike and Google Drive C2

04 March 2026
Cybersecurity researchers have disclosed details of an advanced persistent threat (APT) group dubbed Silver Dragon that has been linked to cyber attacks targeting entities in Europe and Southeast Asia since at least mid-2024. "Silver Dragon gains its initial access by exploiting public-facing internet servers and by delivering phishing emails that contain malicious attachments," Check Point said

VMware Aria Operations Vulnerability Exploited in the Wild

04 March 2026
The recently patched CVE-2026-22719 can be exploited by an unauthenticated attacker for remote code execution.  The post VMware Aria Operations Vulnerability Exploited in the Wild appeared first on SecurityWeek.

CISA Adds Actively Exploited VMware Aria Operations Flaw CVE-2026-22719 to KEV Catalog

03 March 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a recently disclosed security flaw impacting Broadcom VMware Aria Operations to its Known Exploited Vulnerabilities (KEV) catalog, citing active exploitation in the wild. The high-severity vulnerability, CVE-2026-22719 (CVSS score: 8.1), has been described as a case of command injection that could allow an

Iranian Strikes on Amazon Data Centers Highlight Industry’s Vulnerability to Physical Disasters

03 March 2026
Two AWS data centers in the United Arab Emirates were “directly struck” and another facility in Bahrain was also damaged after a drone landed nearby. The post Iranian Strikes on Amazon Data Centers Highlight Industry’s Vulnerability to Physical Disasters appeared first on SecurityWeek.

1M Impacted by University of Hawaii Cancer Center Breach

03 March 2026
The University of Hawaiʻi Cancer Center’s Epidemiology Division revealed it experienced a data breach. 

Fake Tech Support Spam Deploys Customized Havoc C2 Across Organizations

03 March 2026
Threat hunters have called attention to a new campaign as part of which bad actors masqueraded as fake IT support to deliver the Havoc command-and-control (C2) framework as a precursor to data exfiltration or ransomware attack. The intrusions, identified by Huntress last month across five partner organizations, involved the threat actors using email spam as lures, followed by a phone call from

Fig Security Launches With $38 Million to Bolster SecOps Resilience

03 March 2026
The company was founded in March 2025 and it has now emerged from stealth mode. The post Fig Security Launches With $38 Million to Bolster SecOps Resilience appeared first on SecurityWeek.

Honeywell, Researcher Clash Over Impact of Building Controller Vulnerability

03 March 2026
The researcher says he has identified thousands of internet-exposed IQ4 building management controllers. The post Honeywell, Researcher Clash Over Impact of Building Controller Vulnerability appeared first on SecurityWeek.

New Research: 45% Cybersecurity Leaders Work a “Sixth Day”

03 March 2026
Nearly half of cybersecurity leaders are working 11 or more extra hours per week. 

Building a High-Impact Tier 1: The 3 Steps CISOs Must Follow

03 March 2026
Every CISO knows the uncomfortable truth about their Security Operations Center: the people most responsible for catching threats in real time are the people with the least experience. Tier 1 analysts sit at the front line of detection, and yet they are also the most vulnerable to the cognitive and organizational pressures that quietly erode SOC performance over time. The Paradox at the Gate:

Open-Source CyberStrikeAI Deployed in AI-Driven FortiGate Attacks Across 55 Countries

03 March 2026
The threat actor behind the recently disclosed artificial intelligence (AI)-assisted campaign targeting Fortinet FortiGate appliances leveraged an open-source, AI-native security testing platform called CyberStrikeAI to execute the attacks. The new findings come from Team Cymru, which detected its use following an analysis of the IP address ("212.11.64[.]250") that was used by the suspected

Quantum Decryption of RSA is Much Closer than Expected

03 March 2026
For decades, the quantum threat to RSA and ECC encryption has been tied to Shor’s algorithm and the assumption that we would need million-qubit quantum computers to make it practical. A newly announced algorithm challenges that assumption and suggests the breaking point could arrive far sooner than expected. The post Quantum Decryption of RSA is Much Closer than Expected appeared first on SecurityWeek.