News

Cyber Insider
cyberinsider. com > google-wont-fix-api-key-staying-active-for-23-mins-after-deletion

Google "Won't Fix" API key staying active for 23 mins after deletion

1+ hour, 5+ min ago  (320+ words) Deleted Google API keys remain valid for up to 23 minutes after revocation, potentially allowing attackers to continue accessing Google Cloud services and Gemini data long after the credentials have been disabled. Google acknowledged the behavior following a report by Aikido,…...

Symbols: nasdaq:googl
Cyber Insider
cyberinsider. com > europol-dismantles-first-vpn-service-used-by-ransomware-gangs

Europol dismantles "First VPN" service used by ransomware gangs

7+ hour, 8+ min ago  (350+ words) European law enforcement agencies have dismantled a long-running VPN service allegedly used by ransomware gangs and cybercriminals to conceal attacks, steal data, and evade investigators. The operation, coordinated by France and the Netherlands with support from Europol and Eurojust, resulted…...

Cyber Insider
cyberinsider. com > discord-enables-e2ee-by-default-for-all-voice-and-video-communications

Discord enables E2 EE by default for all voice and video communications

2+ day, 8+ hour ago  (375+ words) Discord announced that all voice and video calls on its platform are now protected with end-to-end encryption (E2 EE) by default. The rollout applies to direct messages, group calls, voice channels, and Go Live streams, with Stage channels remaining the only…...

Symbols: nasdaq:naka,nasdaq:snap
Cyber Insider
cyberinsider. com > poland-urges-officials-to-ditch-signal-for-state-run-messaging-apps

Poland urges officials to ditch Signal for state-run messaging apps

3+ day, 34+ min ago  (243+ words) The Ministry of Digital Affairs is recommending two nationally operated systems: According to the advisory, both systems operate entirely under Polish jurisdiction, with their infrastructure hosted in Poland and administered in accordance with national cybersecurity standards. The move mirrors a…...

Cyber Insider
cyberinsider. com > pwn2own-berlin-2026-concludes-with-1-29-million-paid-for-47-zero-days

Pwn2 Own Berlin 2026 concludes with $1. 29 million paid for 47 zero-days

4+ day, 7+ hour ago  (251+ words) Pwn2 Own Berlin 2026 wrapped up with another string of successful enterprise-targeted exploits, bringing the contest's final tally to $1, 298, 250 awarded for 47 unique zero-day vulnerabilities discovered over three days. DEVCORE secured the "Master of Pwn" title with 50. 5 points and $505, 000 in winnings after dominating…...

Symbols: btc-usd
Cyber Insider
cyberinsider. com > microsoft-exchange-zero-day-chain-nets-devcore-200k-at-pwn2own

Microsoft Exchange zero-day chain nets DEVCORE $200 K at Pwn2 Own

5+ day, 22+ hour ago  (393+ words) Pwn2 Own Berlin 2026 continued with another wave of successful zero-day demonstrations on Thursday, as security researchers earned $385, 750 for 15 unique vulnerabilities targeting enterprise software, AI platforms, operating systems, and developer tools. The biggest payout of the day went to DEVCORE's Orange Tsai,…...

Symbols: cwe-20
Cyber Insider
cyberinsider. com > researchers-claim-the-first-macos-kernel-exploit-on-apple-m5-chips

Researchers claim the first mac OS kernel exploit on Apple M5 chips

6+ day, 5+ hour ago  (387+ words) Security researchers have announced what they describe as the first public mac OS kernel memory corruption exploit capable of bypassing Apple's Memory Integrity Enforcement (MIE) protections on the latest M5 chip. The disclosure was published after members of the team met…...

Cyber Insider
cyberinsider. com > openai-confirms-exposure-in-recent-shai-hulud-supply-chain-attack

Open AI confirms exposure in recent "Shai-Hulud" supply-chain attack

6+ day, 9+ hour ago  (424+ words) Open AI says a recent software supply-chain attack tied to the "Mini Shai-Hulud" malware campaign impacted two employee devices and exposed limited internal credentials, prompting the company to rotate code-signing certificates for its desktop applications. The company said it found…...

Symbols: btc-usd,eth-usd,xrp-usd,btc-cad
Cyber Insider
cyberinsider. com > windows-11-and-nvidia-hacked-on-the-first-day-of-pwn2own-berlin-2026

Windows 11 and NVIDIA hacked on the first day of Pwn2 Own Berlin 2026

6+ day, 14+ hour ago  (333+ words) Researchers earned more than half a million dollars on the opening day of Pwn2 Own Berlin 2026 after successfully demonstrating 24 previously unknown vulnerabilities across AI platforms, NVIDIA software, Windows 11, Linux systems, and developer tools. The first day of the hacking competition saw…...

Cyber Insider
cyberinsider. com > microsoft-russian-hackers-evolved-kazuar-malware-into-stealthy-p2p-botnet

Microsoft: Russian hackers evolved Kazuar malware into stealthy P2 P botnet

1+ week, 2+ hour ago  (350+ words) Kazuar," a long-running malware platform linked to the Russian state-sponsored threat group Secret Blizzard, has evolved into a stealthy peer-to-peer botnet designed for persistent intelligence collection. Secret Blizzard, which the US Cybersecurity and Infrastructure Security Agency (CISA) attributes to Center…...

Symbols: aic.sh,ncsc-uk