Mobile Security Vulnerability1 Min Read June 2, 2026 Google June 2026 Android Update Patches 124 Flaws, One Actively Exploited Google on Monday released patches for 124 security vulnerabilities impacting its Android operating system for the month of June 2026, including one high-s…
2 Min Read June 2, 2026 Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine The Russian hacking group known as Gamaredon has been attributed to the… Malware Threat Intelligence
1 Min Read June 2, 2026 Oracle WebLogic CVE-2024-21182 Added to KEV Catalog After Active Exploitation The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on… Network Security Vulnerability
5 Min Read June 2, 2026 AI-Driven Exploitation is Destroying Vulnerability Management. Here’s How to Handle It. AI-driven exploitation timelines are rapidly shrinking, and they are not… Enterprise Security Vulnerability Management
Cyber Resilience Security Operations4 Min Read June 2, 2026 How Leading Organizations Are Turning EDR Into Operational Resilience Most organizations now recognize that endpoint protection alone is no longer sufficient. That's why adoption of endpoint detection and…
Cyber Espionage Threat Intelligence2 Min Read June 2, 2026 Pakistan-Linked SideCopy Targets Afghanistan Finance Ministry with Xeno RAT Cybersecurity researchers have disclosed details of a spear-phishing campaign likely undertaken by the Pakistan-aligned SideCopy group…
Data Protection Identity Security1 Min Read June 2, 2026 Dashlane Discloses Brute-Force Attack, Encrypted Vaults of Fewer Than 20 Users Downloaded Password manager Dashlane has disclosed that "fewer than" 20 users on the personal subscription plan had their encrypted vaults downloaded…
Software Security Supply Chain Attack3 Min Read June 1, 2026 Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm A new Mini Shai-Hulud supply chain attack campaign, codenamed Miasma, has compromised @redhat-cloud-services packages to steal credentials and…
Cybersecurity Hacking11 Min Read June 1, 2026 ⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More Monday hit like a cron job with anger issues. A busted auth path here, a repo-side faceplant there, some "patched-ish" thing already getting…
Endpoint Security Threat Intelligence3 Min Read June 1, 2026 China-Aligned Groups Ramp Up Attacks: Dragon Weave Hits Czech Republic & Taiwan A new cyber espionage campaign codenamed Operation Dragon Weave has been observed targeting officials and citizens in the Czech Republic and…
Security Automation SMB Security7 Min Read June 1, 2026 The Security Growth Platform: Why MSPs Are Moving Beyond vCISO Tools Three years ago, the practical question for an MSP building a cybersecurity practice was which "vCISO platform" to buy. The term was good…
API Security Cloud Security4 Min Read June 1, 2026 OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack Cybersecurity researchers have disclosed details of a new malicious supply chain campaign that's targeting developers using OpenAI Codex…
Vulnerability Website Security,2 Min Read June 1, 2026 Critical WP Maps Pro Flaw Actively Exploited to Create Admin Accounts Threat actors are attempting to actively exploit a critical security flaw impacting WP Maps Pro, a WordPress plugin that has had over 15,000…
IoT Security Network Security2 Min Read May 31, 2026 Dutch Authorities Dismantle Botnet Linked to 17 Million Infected Devices Dutch authorities have announced the takedown of a botnet that enslaved millions of infected devices, including computers, tablets,…
Network Security Vulnerability2 Min Read May 30, 2026 PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation Palo Alto Networks has warned that a recently disclosed medium-severity security flaw impacting PAN-OS and Prisma Access has come under active…
Artificial Intelligence Vulnerability Research6 Min Read May 29, 2026 ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface Cybersecurity researchers have disclosed details of a vulnerability in OpenAI ChatGPT that leverages the artificial intelligence (AI)…
Artificial Intelligence Vulnerability3 Min Read May 29, 2026 Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit An unknown threat actor has been observed using a large language model (LLM) agent to conduct post-compromise actions after obtaining initial…
Artificial Intelligence Cyber Espionage4 Min Read May 29, 2026 New Russia-Linked GREYVIBE Targets Ukraine with AI-Powered Cyberattacks A previously undocumented threat actor dubbed GREYVIBE has been attributed to ongoing and persistent attacks targeting Ukraine and…
Shadow AI Vibe Coding5 Min Read May 29, 2026 What 2,000 Exposed Vibe-Coded Apps Reveal About the Limits of Most Security Stacks Shadow AI used to mean employees pasting things they shouldn't into ChatGPT. It now means something bigger: employees building full…
Software Supply Chain Threat Intelligence4 Min Read May 29, 2026 Malicious Sicoob NuGet Steals Banking Credentials as npm Packages Target Cloud Secrets Cybersecurity researchers have discovered a malicious NuGet package that masquerades as a C# software development kit for Sicoob, one of…
Endpoint Security Threat Intelligence5 Min Read May 29, 2026 Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels The North Korean state-sponsored threat actor known as Kimsuky (aka Velvet Chollima) has been attributed to a fresh set of cyber attacks…
Open Source Vulnerability3 Min Read May 28, 2026 Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code A critical security vulnerability has been disclosed in Gogs, a popular open-source self-hosted Git service, that allows an authenticated user…
Endpoint Security Vulnerability2 Min Read May 28, 2026 Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer Threat actors are continuing to exploit a critical, now-patched security flaw impacting FortiClient Endpoint Management Server (EMS)…
Vulnerability Disclosure Zero Day2 Min Read May 28, 2026 Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal Microsoft has come out strongly in favor of Coordinated Vulnerability Disclosure (CVD), urging the research community to share their findings…
Cybersecurity News Hacking News11 Min Read May 28, 2026 ThreatsDay Bulletin: Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 More Every time you think the industry has finally stopped doing some reckless, low-effort crap, somebody spins up a fresh box full of sketchy…
Artificial Intelligence Enterprise Security6 Min Read May 28, 2026 New AI Usage Report: Enterprise AI Risk Is Heavily Concentrated Among a Small Group of AI "Power users" State of AI Usage Report 2026 (full report here) by LayerX Security reveals the extent of the enterprise AI visibility gap and why most…
Malware Supply Chain Attack3 Min Read May 28, 2026 JINX-0164 Targets Cryptocurrency Firms with Fake Recruiter Lures and macOS Malware A new campaign orchestrated by a previously undocumented threat actor has targeted cryptocurrency organizations with an aim to facilitate…
Financial Fraud Malware5 Min Read May 27, 2026 Grandoreiro Malware and BTMOB RAT Campaigns Target Windows and Android Users Latin America and Europe become the target of two banking trojan campaigns that are designed to infect Windows and Android devices with…
Supply Chain Attack Threat Intelligence2 Min Read May 27, 2026 Malicious npm Package Stole Files From Claude AI User Directory via GitHub Cybersecurity researchers have discovered a new malicious package on the npm registry that comes with information stealing capabilities.…
Artificial Intelligence Enterprise Security6 Min Read May 27, 2026 5 Steps to Managing Shadow AI Tools Without Slowing Down Employees When an employee installs an AI writing assistant, connects a coding copilot to their IDE, or starts summarizing meetings with a new browser…
Malware Threat Intelligence3 Min Read May 27, 2026 GlassWorm Malware Takedown Disrupts Developer Supply Chain Attack Infrastructure CrowdStrike, in partnership with Google and the Shadowserver Foundation, has announced the simultaneous disruption of all command-and-control…
Incident Response Threat Intelligence5 Min Read May 27, 2026 3 SOC Steps that Shut Down Incident Risks Early Most organizations still picture cyber defense as a fortress problem: build stronger walls, add more guards, buy another detection engine. But…
Software Security Vulnerability2 Min Read May 27, 2026 Gitea Vulnerability Exposes Private Container Images without Authentication Cybersecurity researchers have disclosed a security flaw in Gitea, an open-source, self-hosted platform for version control, that allows…
Artificial Intelligence Threat Intelligence4 Min Read May 27, 2026 AI Chatbot Recommendations Redirect Users to Cryptojacking Malware Sites Microsoft has warned of an active cryptojacking campaign that makes use of artificial intelligence (AI) chatbot interactions as a mechanism…
Cyber Espionage Threat Intelligence4 Min Read May 26, 2026 MuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting 9 Countries The Iranian hacking group known as MuddyWater has been linked to a new campaign affecting at least nine organizations across nine countries on…
Artificial Intelligence Web Security2 Min Read May 26, 2026 [THN Webinar] New AI DDoS Attacks Are Smarter. Learn How to Fight Back Every single day, hackers are finding new ways to crash websites and steal data. But right now, something has changed. Hackers are no longer…
Enterprise Security Vulnerability1 Min Read May 26, 2026 Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions Microsoft has rolled out updates to fix a remote code execution vulnerability impacting SharePoint that could be exploited by bad actors in…
Password Security Social Engineering4 Min Read May 26, 2026 MFA Prompt Bombing: Why Your Second Factor Isn't Saving You Multi-factor authentication (MFA) was supposed to close a critical gap in identity security. It meant that, even if an attacker possessed the…
Artificial Intelligence Cloud Security,3 Min Read May 26, 2026 CERT-In Recommends 12-Hour Patching for Internet-Facing Flaws Amid AI-Assisted Attacks The Indian Computer Emergency Response Team (CERT-In) has issued new guidelines requiring organizations to patch critical security…
Artificial Intelligence Cyber Espionage4 Min Read May 26, 2026 Iranian Hackers Deploy MiniFast and MiniJunk V2 via Phishing and SEO Poisoning The Iranian state-sponsored threat actor known as Nimbus Manticore (aka Screening Serpens and UNC1549) has been attributed to a fresh campaign…
Threat Intelligence Vulnerability2 Min Read May 26, 2026 KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt Strike A now-patched high-severity security flaw affecting Digital Knowledge KnowledgeDeliver, a Learning Management System (LMS) popular in Japan,…
Cybersecurity Hacking14 Min Read May 25, 2026 ⚡ Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaos Monday recap. Same mess, new week. A sketchy dev tool got people pwned, old bugs came back from the dead, and security products somehow needed…
Vulnerability Web Security3 Min Read May 25, 2026 Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks Threat actors are exploiting a recently disclosed critical security flaw in Ghost CMS to inject malicious JavaScript code with an aim to fuel…
Agentic AI Threat Detection4 Min Read May 25, 2026 The Alert Firehose Finally Meets Its Match Ask a cybersecurity pro about Network Detection and Response (NDR) and you might still hear "Noisy," "Too much data." But ask the teams…
Endpoint Security Threat Intelligence3 Min Read May 25, 2026 Lazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto Firms Cybersecurity researchers have shed light on a cross-platform malware called RemotePE that has been put to use by the North Korea-linked…
Malware Supply Chain Attack3 Min Read May 25, 2026 TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO A new coordinated cross-ecosystem software supply chain attack campaign has targeted npm, PyPI, and Crates.io to distribute…