Vulnerability Web Security2 Min Read June 20, 2026 Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys Threat actors are exploiting a recently patched security flaw impacting Gravity SMTP, a WordPress plugin that's installed on about 100,000 sites. The vuln…
3 Min Read June 19, 2026 Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chain Security researchers at Paradigm Shift have published a… Hardware Security Vulnerability
3 Min Read June 19, 2026 The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes The Gentlemen ransomware-as-a-service (RaaS) operation is actively… Endpoint Security Ransomware
3 Min Read June 19, 2026 AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution Microsoft researchers have detailed an exploit chain,… Software Supply Chain Vulnerability
Patch Management Software Security2 Min Read November 26, 2025 Webinar: Learn to Spot Risks and Patch Safely with Community-Maintained Tools If you're using community tools like Chocolatey or Winget to keep systems updated, you're not alone. These platforms are fast, flexible, and…
Browser Security Cryptocurrency2 Min Read November 26, 2025 Chrome Extension Caught Injecting Hidden Solana Transfer Fees Into Raydium Swaps Cybersecurity researchers have discovered a new malicious extension on the Chrome Web Store that's capable of injecting a stealthy Solana…
Cyber Espionage Malware2 Min Read November 26, 2025 RomCom Uses SocGholish Fake Update Attacks to Deliver Mythic Agent Malware The threat actors behind a malware family known as RomCom targeted a U.S.-based civil engineering company via a JavaScript loader dubbed…
Artificial Intelligence Online Security4 Min Read November 26, 2025 FBI Reports $262M in ATO Fraud as Researchers Cite Growing AI Phishing and Holiday Scams The U.S. Federal Bureau of Investigation (FBI) has warned that cybercriminals are impersonating financial institutions with an aim to steal…
Cloud Security Data Exposure2 Min Read November 25, 2025 Years of JSONFormatter and CodeBeautify Leaks Expose Thousands of Passwords and API Keys New research has found that organizations in various sensitive sectors, including governments, telecoms, and critical infrastructure, are…
Malvertising Windows Security4 Min Read November 25, 2025 JackFix Uses Fake Windows Update Pop-Ups on Adult Sites to Deliver Multiple Stealers Cybersecurity researchers are calling attention to a new campaign that's leveraging a combination of ClickFix lures and fake adult websites to…
Anti-Malware Research5 Min Read November 25, 2025 Fake Battlefield 6 Pirated Versions and Game Trainers Used to Deploy Stealers and C2 Agents Bitdefender Labs has identified malware campaigns exploiting the popularity of EA's Battlefield 6 first-person shooter, distributed via…
Malware Vulnerability3 Min Read November 25, 2025 ToddyCat’s New Hacking Tools Steal Outlook Emails and Microsoft 365 Access Tokens The threat actor known as ToddyCat has been observed adopting new methods to obtain access to corporate email data belonging to target…
Security Automation Threat Intelligence4 Min Read November 25, 2025 3 SOC Challenges You Need to Solve Before 2026 2026 will mark a pivotal shift in cybersecurity. Threat actors are moving from experimenting with AI to making it their primary weapon, using…
Browser Security Malware2 Min Read November 25, 2025 Hackers Hijack Blender 3D Assets to Deploy StealC V2 Data-Stealing Malware Cybersecurity researchers have disclosed details of a new campaign that has leveraged Blender Foundation files to deliver an information…
Container Security Vulnerability2 Min Read November 24, 2025 New Fluent Bit Flaws Expose Cloud to RCE and Stealthy Infrastructure Intrusions Cybersecurity researchers have discovered five vulnerabilities in Fluent Bit, an open-source and lightweight telemetry agent, that could be…
Cloud Security Vulnerability3 Min Read November 24, 2025 Second Sha1-Hulud Wave Affects 25,000+ Repositories via npm Preinstall Credential Theft Multiple security vendors are sounding the alarm about a second wave of attacks targeting the npm registry in a manner that's reminiscent of…
Cybersecurity Hacking News14 Min Read November 24, 2025 ⚡ Weekly Recap: Fortinet Exploit, Chrome 0-Day, BadIIS Malware, Record DDoS, SaaS Breach & More This week saw a lot of new cyber trouble. Hackers hit Fortinet and Chrome with new 0-day bugs. They also broke into supply chains and SaaS…
Cloud Security Cyber Espionage3 Min Read November 22, 2025 China-Linked APT31 Launches Stealthy Cyberattacks on Russian IT Using Cloud Services The China-linked advanced persistent threat (APT) group known as APT31 has been attributed to cyber attacks targeting the Russian information…
Browser Security Cybercrime3 Min Read November 22, 2025 Matrix Push C2 Uses Browser Notifications for Fileless, Cross-Platform Phishing Attacks Bad actors are leveraging browser notifications as a vector for phishing attacks to distribute malicious links by means of a new…
Software Security Zero-Day2 Min Read November 22, 2025 CISA Warns of Actively Exploited Critical Oracle Identity Manager Zero-Day Vulnerability The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical security flaw impacting Oracle Identity Manager to…
Threat Mitigation Vulnerability2 Min Read November 21, 2025 Grafana Patches CVSS 10.0 SCIM Flaw Enabling Impersonation and Privilege Escalation Grafana has released security updates to address a maximum severity security flaw that could allow privilege escalation or user impersonation…
Data Protection Technology3 Min Read November 21, 2025 Google Brings AirDrop Compatibility to Android’s Quick Share Using Rust-Hardened Security In a surprise move, Google on Thursday announced that it has updated Quick Share, its peer-to-peer file transfer service, to work with Apple's…
Data Protection Mobile Security3 Min Read November 21, 2025 Why IT Admins Choose Samsung for Mobile Security Ever wonder how some IT teams keep corporate data safe without slowing down employees? Of course you have. Mobile devices are essential for…
Malware Threat Intelligence5 Min Read November 21, 2025 APT24 Deploys BADAUDIO in Years-Long Espionage Hitting Taiwan and 1,000+ Domains A China-nexus threat actor known as APT24 has been observed using a previously undocumented malware dubbed BADAUDIO to establish persistent…
Compliance Cyber Attack2 Min Read November 21, 2025 SEC Drops SolarWinds Case After Years of High-Stakes Cybersecurity Scrutiny The U.S. Securities and Exchange Commission (SEC) has abandoned its lawsuit against SolarWinds and its chief information security officer,…
Data Breach SaaS Security2 Min Read November 21, 2025 Salesforce Flags Unauthorized Data Access via Gainsight-Linked OAuth Activity Salesforce has warned of detected "unusual activity" related to Gainsight-published applications connected to the platform. "Our investigation…
Cloud Computing Vulnerability3 Min Read November 20, 2025 ShadowRay 2.0 Exploits Unpatched Ray Flaw to Build Self-Spreading GPU Cryptomining Botnet Oligo Security has warned of ongoing attacks exploiting a two-year-old security flaw in the Ray open-source artificial intelligence (AI)…
Botnet Malware3 Min Read November 20, 2025 Tsundere Botnet Expands Using Game Lures and Ethereum-Based C2 on Windows Cybersecurity researchers have warned of an actively expanding botnet dubbed Tsundere that's targeting Windows users. Active since mid-2025,…
Cybersecurity Hacking News11 Min Read November 20, 2025 ThreatsDay Bulletin: 0-Days, LinkedIn Spies, Crypto Crimes, IoT Flaws and New Malware Waves This week has been crazy in the world of hacking and online security. From Thailand to London to the US, we've seen arrests, spies at work,…
Online Fraud Web Security2 Min Read November 20, 2025 CTM360 Exposes a Global WhatsApp Hijacking Campaign: HackOnChat CTM360 has identified a rapidly expanding WhatsApp account-hacking campaign targeting users worldwide via a network of deceptive…
Malware Mobile Security3 Min Read November 20, 2025 New Sturnus Android Trojan Quietly Captures Encrypted Chats and Hijacks Devices Cybersecurity researchers have disclosed details of a new Android banking trojan called Sturnus that enables credential theft and full device…
Cyber Warfare Threat Intelligence3 Min Read November 20, 2025 Iran-Linked Hackers Mapped Ship AIS Data Days Before Real-World Missile Strike Attempt Threat actors with ties to Iran engaged in cyber warfare as part of efforts to facilitate and enhance physical, real-world attacks, a trend…
Artificial Intelligence Malvertising3 Min Read November 20, 2025 TamperedChef Malware Spreads via Fake Software Installers in Ongoing Global Campaign Threat actors are leveraging bogus installers masquerading as popular software to trick users into installing malware as part of a global…
Threat Intelligence Vulnerability2 Min Read November 19, 2025 NHS Warns of PoC Exploit for 7-Zip Symbolic Link–Based RCE Vulnerability Update: The NHS England Digital, in an updated advisory on November 20, 2025, said it has not observed in-the-wild exploitation of…
Cyber Attack Malware4 Min Read November 19, 2025 Python-Based WhatsApp Worm Spreads Eternidade Stealer Across Brazilian Devices Cybersecurity researchers have disclosed details of a new campaign that leverages a combination of social engineering and WhatsApp hijacking…
Threat Intelligence Vulnerability2 Min Read November 19, 2025 WrtHug Exploits Six ASUS WRT Flaws to Hijack Tens of Thousands of EoL Routers Worldwide A newly discovered campaign has compromised tens of thousands of outdated or end-of-life (EoL) ASUS routers worldwide, predominantly in…
Endpoint Security Network Security4 Min Read November 19, 2025 Application Containment: How to Use Ringfencing to Prevent the Weaponization of Trusted Software The challenge facing security leaders is monumental: Securing environments where failure is not an option. Reliance on traditional security…
Cyber Espionage Malware3 Min Read November 19, 2025 EdgeStepper Implant Reroutes DNS Queries to Deploy Malware via Hijacked Software Updates The threat actor known as PlushDaemon has been observed using a previously undocumented Go-based network backdoor codenamed EdgeStepper to…
AI Security SaaS Security2 Min Read November 19, 2025 ServiceNow AI Agents Can Be Tricked Into Acting Against Each Other via Second-Order Prompts Malicious actors can exploit default configurations in ServiceNow's Now Assist generative artificial intelligence (AI) platform and leverage…
Cloud Security Compliance2 Min Read November 18, 2025 Learn How Leading Companies Secure Cloud Workloads and Infrastructure at Scale You've probably already moved some of your business to the cloud—or you're planning to. That's a smart move. It helps you work faster,…
Malware Social Engineering2 Min Read November 18, 2025 Researchers Detail Tuoni C2's Role in an Attempted 2025 Real-Estate Cyber Intrusion Cybersecurity researchers have disclosed details of a cyber attack targeting a major U.S.-based real-estate company that involved the use of a…
Cyber Espionage Malware3 Min Read November 18, 2025 Iranian Hackers Use DEEPROOT and TWOSTROKE Malware in Aerospace and Defense Attacks Suspected espionage-driven threat actors from Iran have been observed deploying backdoors like TWOSTROKE and DEEPROOT as part of continued…
Enterprise Security Zero Trust8 Min Read November 18, 2025 Beyond IAM Silos: Why the Identity Security Fabric is Essential for Securing AI and Non-Human Identities Identity security fabric (ISF) is a unified architectural framework that brings together disparate identity capabilities. Through ISF,…
Malware Web Security2 Min Read November 18, 2025 Seven npm Packages Use Adspect Cloaking to Trick Victims Into Crypto Scam Pages Cybersecurity researchers have discovered a set of seven npm packages published by a single threat actor that leverages a cloaking service…
Cybersecurity Hacking News20 Min Read November 17, 2025 ⚡ Weekly Recap: Fortinet Exploited, China's AI Hacks, PhaaS Empire Falls & More This week showed just how fast things can go wrong when no one's watching. Some attacks were silent and sneaky. Others used tools we trust…
Cloud Security Social Engineering6 Min Read November 17, 2025 5 Reasons Why Attackers Are Phishing Over LinkedIn Phishing attacks are no longer confined to the email inbox, with 1 in 3 phishing attacks now taking place over non-email channels like social…