Saturday, April 25, 2026
HomeCybersecurity News

Cybersecurity News

Swedish IT Company Suffers Data Breach Affecting 1.5 Million Users

Environmental data firm Miljödata has fallen victim to a cyberattack that exposed the personal information of over 1.5 million individuals. The breach, which occurred in late August 2025, has prompted the Swedish Authority for Privacy Protection (IMY) to launch formal investigations into the incident. Sensitive...

Zscaler Buys Enterprise AI Security Firm SPLX To Enhance Zero Trust Exchange

Zscaler, Inc. (NASDAQ: ZS) has acquired SPLX, an innovative AI security startup founded in 2023, for an undisclosed amount. This acquisition integrates SPLX's cutting-edge AI red teaming and governance tools into Zscaler's Zero Trust Exchange platform, enabling organizations to secure AI assets throughout their lifecycle...

Gemini Vulnerability: ASCII Smuggling Attack Tricks AI Agents Into Leaking Data

A new vulnerability, known as "ASCII Smuggling," affects major Large Language Models (LLMs) like Google's Gemini, enabling attackers to deceive AI agents into leaking data, spoofing identities, and poisoning content. Research from FireTail in September 2025 exposed this security flaw, which poses an immediate...

Apple Font-Parser Vulnerability Lets Malicious Fonts Crash or Corrupt Memory

Apple has quietly rolled out macOS Sequoia 15.7.1 on September 29, 2025, addressing a significant security vulnerability in its FontParser component. While the update follows the company’s customary “.0.1” post-launch maintenance release, it is notable for including a fix for CVE-2025-43400 an out-of-bounds write...

Volvo Group Reports Data Breach Following HR Supplier Ransomware Attack

Volvo Group has alerted employees that a cyber incident affecting its human resources software supplier, Miljödata, may have exposed personal information of some staff members. The notification comes after Miljödata discovered a ransomware attack that began on August 20, 2025, and confirmed unauthorized access...

Critical Linux Kernel ksmbd Vulnerability Enables Remote Code Execution

A high-severity vulnerability has been disclosed in the Linux Kernel’s ksmbd module that can be exploited by authenticated attackers to achieve remote code execution. Tracked as CVE-2025-38561, the flaw stems from a race condition in the handling of the Preauth_HashValue field during SMB2 session...