Category index

Cyber Security

4276 articles

4276 ARTICLES

FEATURED REPORT

Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy

A technical analysis of three chained zero-day vulnerabilities in Siemens ROX II OT switches that allow privilege escalation and persistent root access. The post Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy appeared first on Unit 42.

BY Emmanuel Zhou, Adam Robbie, Rick Wyble and Miguel Pereira
MIN READ 1 MIN READ
EXPLORE north_east
Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy
Claude can now sign into websites with 1Password without exposing your credentials
CYBERSECURITY

Claude can now sign into websites with 1Password without exposing your credentials

1Password has introduced 1Password for Claude, a beta integration that lets Anthropic’s AI assistant complete browser tasks requiring authentication without accessing users’ passwords or other secrets. The integration is available to paid Claude subscribers (Pro, Max, Team, and Enterprise) using Claude Desktop on macOS and to 1Password customers on individual, family, and business plans. It requires a Mac, Claude Desktop, Claude in Chrome, the 1Password desktop app, and the 1Password browser extension. For Team and … More → The post Claude can now sign into websites with 1Password without exposing your credentials appeared first on Help Net Security.

1 MIN READ arrow_forward
ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files
CYBERSECURITY

ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files

ACR Stealer, an infostealer in circulation since 2024, is walking out of enterprise networks with saved browser passwords, live session tokens, PDFs, Microsoft 365 documents, and files from synced OneDrive and SharePoint folders. It gets in because someone pasted a command into a Run box and pressed Enter. Microsoft laid out two of the delivery chains on Thursday. Its Defender Experts team, the

1 MIN READ arrow_forward
New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage
CYBERSECURITY

New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage

Cybersecurity researchers have discovered a previously undocumented malware called GoSerpent that has been put to use in cyber attacks targeting entities in Southeast Asia since late 2025 with a focus on long-term access and intelligence gathering. Russian cybersecurity company Kaspersky, which uncovered the activity in February 2026, said it was aimed at government and diplomatic entities in

1 MIN READ arrow_forward
Ransomware attack halts Coca-Cola’s Fairlife US milk production
CYBERSECURITY

Ransomware attack halts Coca-Cola’s Fairlife US milk production

A ransomware attack has stopped milk production at Fairlife, the Coca-Cola dairy brand known for its high-protein milk, protein shakes, and nutrition drinks. Coca-Cola disclosed the incident on July 16, 2026, in a Form 8-K filed with the U.S. Securities and Exchange Commission (SEC). “Product quality and safety have not been impacted. However, as a result of the incident, production operations at fairlife in the United States are temporarily suspended. fairlife’s Canada production operations are … More → The post Ransomware attack halts Coca-Cola’s Fairlife US milk production appeared first on Help Net Security.

1 MIN READ arrow_forward
CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
CYBERSECURITY

CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly patched security flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by July 19, 2026. The vulnerability in question is CVE-2026-58644 (CVSS score: 9.8), a critical deserialization

1 MIN READ arrow_forward