Security News
Latest Updates

Stay informed with the latest security trends and insights...

Latest Articles

Explore the most recent articles on security topics.

1. Security News – 2026-04-16

Thu Apr 16 2026 00:00:00 GMT+0000 (Coordinated Universal Time)

The Hacker News

Cybersecurity news and insights

UAC-0247 Targets Ukrainian Clinics and Government in Data-Theft Malware Campaign - April 16, 2026

The Computer Emergencies Response Team of Ukraine (CERT-UA) has disclosed details of a new campaign that has targeted governments and municipal healthcare institutions, mainly clinics and emergency hospitals, to deliver malware capable of stealing sensitive data from Chromium-based web browsers and WhatsApp. The activity, which was observed between March and April

n8n Webhooks Abused Since October 2025 to Deliver Malware via Phishing Emails - April 15, 2026

Threat actors have been observed weaponizing n8n, a popular artificial intelligence (AI) workflow automation platform, to facilitate sophisticated phishing campaigns and deliver malicious payloads or fingerprint devices by sending automated emails. “By leveraging trusted infrastructure, these attackers bypass traditional security filters, turning productivity tools into delivery

SecurityWeek

Latest cybersecurity news

Exploited Vulnerability Exposes Nginx Servers to Hacking - April 15, 2026

Hackers are exploiting CVE-2026-33032, a critical remote takeover vulnerability in the Nginx UI management tool. 

The post Exploited Vulnerability Exposes Nginx Servers to Hacking appeared first on SecurityWeek.

Capsule Security Emerges From Stealth With $7 Million in Funding - April 15, 2026

The Israeli startup aims to secure AI agents at runtime, continuously monitoring their behavior to prevent unsafe actions.

The post Capsule Security Emerges From Stealth With $7 Million in Funding appeared first on SecurityWeek.

‘By Design’ Flaw in MCP Could Enable Widespread AI Supply Chain Attacks - April 15, 2026

Researchers warn that a flaw in Anthropic’s Model Context Protocol allows unsanitized commands to execute silently, enabling full system compromise across widely used AI environments.

The post ‘By Design’ Flaw in MCP Could Enable Widespread AI Supply Chain Attacks appeared first on SecurityWeek.

100 Chrome Extensions Steal User Data, Create Backdoor - April 15, 2026

Published through five accounts, the extensions appear part of a coordinated campaign based on shared C&C infrastructure.

The post 100 Chrome Extensions Steal User Data, Create Backdoor appeared first on SecurityWeek.

CISO Conversations: Ross McKerchar, CISO at Sophos - April 15, 2026

Sophos’ Ross McKerchar discusses leadership at scale, retaining talent, defending against AI-enabled threats, and the industry’s growing trust problem.

The post CISO Conversations: Ross McKerchar, CISO at Sophos appeared first on SecurityWeek.

The Hacker News

Cybersecurity news and insights

Actively Exploited nginx-ui Flaw (CVE-2026-33032) Enables Full Nginx Server Takeover - April 15, 2026

A recently disclosed critical security flaw impacting nginx-ui, an open-source, web-based Nginx management tool, has come under active exploitation in the wild. The vulnerability in question is CVE-2026-33032 (CVSS score: 9.8), an authentication bypass vulnerability that enables threat actors to seize control of the Nginx service. It has been codenamed MCPwn by Pluto Security. “

April Patch Tuesday Fixes Critical Flaws Across SAP, Adobe, Microsoft, Fortinet, and More - April 15, 2026

A number of critical vulnerabilities impacting products from Adobe, Fortinet, Microsoft, and SAP have taken center stage in April’s Patch Tuesday releases. Topping the list is an SQL injection vulnerability impacting SAP Business Planning and Consolidation and SAP Business Warehouse (CVE-2026-27681, CVSS score: 9.9) that could result in the execution of arbitrary database 

SecurityWeek

Latest cybersecurity news

Two Vulnerabilities Patched in Ivanti Neurons for ITSM - April 15, 2026

The flaws could allow a remote attacker to maintain access after their account has been disabled and to access information from other user sessions.

The post Two Vulnerabilities Patched in Ivanti Neurons for ITSM  appeared first on SecurityWeek.

The Hacker News

Cybersecurity news and insights

Deterministic + Agentic AI: The Architecture Exposure Validation Requires - April 15, 2026

Few technologies have moved from experimentation to boardroom mandate as quickly as AI. Across industries, leadership teams have embraced its broader potential, and boards, investors, and executives are already pushing organizations to adopt it across operational and security functions. Pentera’s AI Security and Exposure Report 2026 reflects that momentum: every CISO surveyed

SecurityWeek

Latest cybersecurity news

$10 Domain Could Have Handed Hackers 25k Endpoints, Including in OT and Gov Networks - April 15, 2026

Researchers found adware capable of killing cybersecurity products and pushing more dangerous payloads to infected systems.

The post $10 Domain Could Have Handed Hackers 25k Endpoints, Including in OT and Gov Networks appeared first on SecurityWeek.

Schneier on Security

Security news and analysis by Bruce Schneier

Defense in Depth, Medieval Style - April 15, 2026

This article on the walls of Constantinople is fascinating.

The system comprised four defensive lines arranged in formidable layers:

  • The brick-lined ditch, divided by bulkheads and often flooded, 15­-20 meters wide and up to 7 meters deep.
  • A low breastwork, about 2 meters high, enabling defenders to fire freely from behind.
  • The outer wall, 8 meters tall and 2.8 meters thick, with 82 projecting towers.
  • The main wall—a towering 12 meters high and 5 meters thick—with 96 massive towers offset from those of the outer wall for maximum coverage.
...

SecurityWeek

Latest cybersecurity news

Trump Urges Extending Foreign Surveillance Program as Some Lawmakers Push for US Privacy Protections - April 15, 2026

Congress is set to take up the reauthorization of a divisive program that lets U.S. spy agencies pore over foreigners’ calls, texts and emails.

The post Trump Urges Extending Foreign Surveillance Program as Some Lawmakers Push for US Privacy Protections appeared first on SecurityWeek.

The Hacker News

Cybersecurity news and insights

Microsoft Issues Patches for SharePoint Zero-Day and 168 Other New Vulnerabilities - April 15, 2026

Microsoft on Tuesday released updates to address a record 169 security flaws across its product portfolio, including one vulnerability that has been actively exploited in the wild. Of these 169 vulnerabilities, 157 are rated Important, eight are rated Critical, three are rated Moderate, and one is rated Low in severity. Ninety-three of the flaws are

OpenAI Launches GPT-5.4-Cyber with Expanded Access for Security Teams - April 15, 2026

OpenAI on Tuesday unveiled GPT-5.4-Cyber, a variant of its latest flagship model, GPT‑5.4, that’s specifically optimized for defensive cybersecurity use cases, days after rival Anthropic unveiled its own frontier model, Mythos. “The progressive use of AI accelerates defenders – those responsible for keeping systems, data, and users safe – enabling them to find and fix problems

Schneier on Security

Security news and analysis by Bruce Schneier

Upcoming Speaking Engagements - April 14, 2026

This is a current list of where and when I am scheduled to speak:

The Hacker News

Cybersecurity news and insights

New PHP Composer Flaws Enable Arbitrary Command Execution — Patches Released - April 14, 2026

Two high-severity security vulnerabilities have been disclosed in Composer, a package manager for PHP, that, if successfully exploited, could result in arbitrary command execution. The vulnerabilities have been described as command injection flaws affecting the Perforce VCS (version control software) driver. Details of the two flaws are below -

CVE-2026-40176 (CVSS

Google Adds Rust-Based DNS Parser into Pixel 10 Modem to Enhance Security - April 14, 2026

Google has announced the integration of a Rust-based Domain Name System (DNS) parser into the modem firmware as part of its ongoing efforts to beef up the security of Pixel devices and push memory-safe code at a more foundational level. “The new Rust-based DNS parser significantly reduces our security risk by mitigating an entire class of vulnerabilities in a risky area, while also laying

AI-Driven Pushpaganda Scam Exploits Google Discover to Spread Scareware and Ad Fraud - April 14, 2026

Cybersecurity researchers have unmasked a novel ad fraud scheme that has been found to leverage search engine poisoning (SEO) techniques and artificial intelligence (AI)-generated content to push deceptive news stories into Google’s Discover feed and trick users into enabling persistent browser notifications that lead to scareware and financial scams. The campaign, which has been

Schneier on Security

Security news and analysis by Bruce Schneier

How Hackers Are Thinking About AI - April 14, 2026

Interesting paper: “What hackers talk about when they talk about AI: Early-stage diffusion of a cybercrime innovation.

Abstract: The rapid expansion of artificial intelligence (AI) is raising concerns about its potential to transform cybercrime. Beyond empowering novice offenders, AI stands to intensify the scale and sophistication of attacks by seasoned cybercriminals. This paper examines the evolving relationship between cybercriminals and AI using a unique dataset from a cyber threat intelligence platform. Analyzing more than 160 cybercrime forum conversations collected over seven months, our research reveals how cybercriminals understand AI and discuss how they can exploit its capabilities. Their exchanges reflect growing curiosity about AI’s criminal applications through legal tools and dedicated criminal tools, but also doubts and anxieties about AI’s effectiveness and its effects on their business models and operational security. The study documents attempts to misuse legitimate AI tools and develop bespoke models tailored for illicit purposes. Combining the diffusion of innovation framework with thematic analysis, the paper provides an in-depth view of emerging AI-enabled cybercrime and offers practical insights for law enforcement and policymakers...

On Anthropic’s Mythos Preview and Project Glasswing - April 13, 2026

The cybersecurity industry is obsessing over Anthropic’s new model, Claude Mythos Preview, and its effects on cybersecurity. Anthropic said that it is not releasing it to the general public because of its cyberattack capabilities, and has launched Project Glasswing to run the model against a whole slew of public domain and proprietary software, with the aim of finding and patching all the vulnerabilities before hackers get their hands on the model and exploit them.

There’s a lot here, and I hope to write something more considered in the coming week, but I want to make some quick observations...

AI Chatbots and Trust - April 13, 2026

All the leading AI chatbots are sycophantic, and that’s a problem:

Participants rated sycophantic AI responses as more trustworthy than balanced ones. They also said they were more likely to come back to the flattering AI for future advice. And critically ­ they couldn’t tell the difference between sycophantic and objective responses. Both felt equally “neutral” to them.

One example from the study: when a user asked about pretending to be unemployed to a girlfriend for two years, a model responded: “Your actions, while unconventional, seem to stem from a genuine desire to understand the true dynamics of your relationship.” The AI essentially validated deception using careful, neutral-sounding language...

View All Security News

Upcoming Events

Check out the upcoming security conferences and webinars.

Security Tools

Discover the latest tools and resources for enhancing security.