Developer Security Supply Chain Attack3 Min Read June 23, 2026 Malicious npm Packages Pose as PostCSS Tools to Deliver Windows RAT Cybersecurity researchers have discovered a set of malicious npm packages that are designed to deliver a Windows-based remote access trojan (RAT). The lis…
2 Min Read June 23, 2026 WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool Direct messages sent via WhatsApp are being used to distribute malicious… Malware Social Engineering
4 Min Read June 23, 2026 OpenAI Expands Daybreak With GPT-5.5-Cyber to Help Defenders Patch Security Flaws OpenAI on Monday said it's releasing an improved version of its… Artificial Intelligence Codex Security
2 Min Read June 22, 2026 ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack Multiple WordPress plugins from ShapedPlugin were compromised in a… Malware Supply Chain Attack
August 25, 2025 August 2025 Patch Tuesday: One Publicly Disclosed Zero-Day and 13 Critical Vulnerabilities Among 107 CVEs Microsoft has addressed 107 vulnerabilities in its August 2025 security update release. This month’s patches include fixes for one…
Apple Malware Ransomware2 Min Read August 25, 2025 Fake macOS Help Sites Seek to Spread Infostealer in Targeted Campaign A sophisticated malvertising campaign which sought to deploy a variant of Atomic macOS Stealer (AMOS) has targeted hundreds of…
Cybersecurity Recap22 Min Read August 25, 2025 Weekly Recap: Password Manager Flaws, Apple 0-Day, Hidden AI Prompts, In-the-Wild Exploits & More Cybersecurity today moves at the pace of global politics. A single breach can ripple across supply chains, turn a software flaw into leverage,…
Threat Hunting Threat Intelligence3 Min Read August 25, 2025 Empowering The Soc: Stop Detecting Potential Threats, Start Signaling Real Attacks The cybersecurity landscape is constantly evolving, and security operations centers (SOCs) are feeling the pressure to stay ahead of…
Zero-Day4 Min Read August 25, 2025 Don’t Wait Too Long to Patch: How Organizations Can Stay Ahead of Zero-Day Exploits Among the variety of cyber-attacks that we witness happening around us, Zero-day attacks are remarkably insidious in nature. Due to the fact…
Network Security3 Min Read August 25, 2025 Firewall Bug Under Active Attack Triggers CISA Warning CISA is warning that Palo Alto Networks’ PAN-OS is under active attack and needs to be patched ASAP. Software running Palo Alto…
Cybercrime2 Min Read August 25, 2025 Cybercriminal Linked to Notorious Scattered Spider Gang Gets 10-Year Sentence A young Florida-based man has been sentenced to 10 years in prison after pleading guilty to federal charges linked to cybercrime, including…
Cloud Security Server Security2 Min Read August 25, 2025 Attackers Abuse Virtual Private Servers to Compromise SaaS Accounts Threat actors are abusing virtual private servers (VPS) to compromise software-as-a-service (SaaS) accounts, according to an investigation by…
Cybercrime3 Min Read August 25, 2025 Interpol-Led African Cybercrime Crackdown Leads to 1209 Arrests A large-scale law enforcement operation coordinated by Interpol has taken down a 1000-person cybercriminal network and recovered $97.4m in…
Supply Chain Security2 Min Read August 25, 2025 CISA Seeks Biden Era's SBOM Minimum Requirements Guideline Change The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a request for comment on an updated version of a government…
Cybercrime Malware2 Min Read August 25, 2025 Chinese Developer Jailed for Deploying Malicious Code at US Company A Chinese software developer has been sentenced after being convicted of causing intentional damage to protected computers by deploying…
Supply Chain Security4 Min Read August 25, 2025 How Secure Is the Software Supply Chain? Less Secure Than You Might Think. Software is the invisible infrastructure of our world, powering everything from critical systems to everyday devices. But its ubiquity makes…
Supply Chain Security Zero-Day5 Min Read August 25, 2025 Data Is a Dish Best Served Fresh: “In the Wild” Versus Active Exploitation The term “In the Wild” is broadly used to refer to any activity that has been observed outside of a controlled environment.…
Malware Zero Trust4 Min Read August 25, 2025 Why Enterprises Need Preemptive Cybersecurity to Combat Modern Phishing Phishing isn’t what it used to be. It’s no longer fake emails with bad grammar and sketchy links. With AI, modern phishing attacks…
Data Breach3 Min Read August 25, 2025 How Dealerships Can Protect Their Customers’ Financial Data Dealerships handle sensitive information, such as credit applications and personal financial records, daily. A data breach can lead to…
Cloud Security Data Protection4 Min Read August 25, 2025 Vegas, Vulnerabilities, and Voices: Black Hat and Squadcon 2025 The week of August 4th, I had the opportunity to attend two exciting conferences in the cybersecurity world: Black Hat USA 2025 and Squadcon…
Data Breach6 Min Read August 25, 2025 How to Develop a Business Continuity Plan for Cyber Security: A Step-by-Step Guide The figures are appalling – 60% of small businesses fail within six months of a cyber-attack. Cyber attackers are all around us, and…
Cybersecurity4 Min Read August 25, 2025 Cyber Security Simulation Training Mistakes That CISOs Must Avoid Your team’s ability to identify phishing attempts in their inboxes has the potential to make or break your entire security posture,…
Cybercrime Cybersecurity4 Min Read August 25, 2025 Healthcare Organizations at Risk: Managing Human Vulnerability in Cybersecurity The battle against cybercrime continues to be a significant topic for organizations across all industries, however the threat to the health…
Cyber Attack Malware3 Min Read August 25, 2025 Transparent Tribe Targets Indian Govt With Weaponized Desktop Shortcuts via Phishing The advanced persistent threat (APT) actor known as Transparent Tribe has been observed targeting both Windows and BOSS (Bharat Operating…
Network Security5 Min Read August 25, 2025 Why SIEM Rules Fail and How to Fix Them: Insights from 160 Million Attack Simulations Security Information and Event Management (SIEM) systems act as the primary tools for detecting suspicious activity in enterprise networks,…
Malware4 Min Read August 25, 2025 Watering Hole Attacks Push ScanBox Keylogger Researchers uncover a watering hole attack likely carried out by APT TA423, which attempts to plant the ScanBox JavaScript-based…
Browser Security Zero-Day3 Min Read August 25, 2025 Google Patches Chrome’s Fifth Zero-Day of the Year An insufficient validation input flaw, one of 11 patched in an update this week, could allow for arbitrary code execution and is under active…
Mobile Security3 Min Read August 25, 2025 iPhone Users Urged to Update to Patch 2 Zero-Days Separate fixes to macOS and iOS patch respective flaws in the kernel and WebKit that can allow threat actors to take over devices and are…
Malware3 Min Read August 25, 2025 Fake Reservation Links Prey on Weary Travelers Fake travel reservations are exacting more pain from the travel weary, already dealing with the misery of canceled flights and overbooked…
Cybersecurity2 Min Read August 25, 2025 Cybercriminals Are Selling Access to Chinese Surveillance Cameras Tens of thousands of cameras have failed to patch a critical, 11-month-old CVE, leaving thousands of organizations exposed. New research…
Malware2 Min Read August 25, 2025 Ransomware Attacks are on the Rise Lockbit is by far this summer’s most prolific ransomware group, trailed by two offshoots of the Conti group. After a recent dip,…
Breach2 Min Read August 25, 2025 Student Loan Breach Exposes 2.5M Records 2.5 million people were affected, in a breach that could spell more trouble down the line. EdFinancial and the Oklahoma Student Loan Authority…
Hacks Privacy3 Min Read August 25, 2025 Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms Over 130 companies tangled in sprawling phishing campaign that spoofed a multi-factor authentication system. Targeted attacks on Twilio and…
Identity Security3 Min Read August 25, 2025 Twitter Whistleblower Complaint: The TL;DR Version Twitter is blasted for security and privacy lapses by the company’s former head of security who alleges the social media giant’s…
Malware Supply Chain Attack3 Min Read August 25, 2025 Malicious PyPI and npm Packages Discovered Exploiting Dependencies in Supply Chain Attacks Cybersecurity researchers have discovered a malicious package in the Python Package Index (PyPI) repository that introduces malicious behavior…
Cloud Security Vulnerability3 Min Read August 25, 2025 Microsoft Windows Vulnerability Exploited to Deploy PipeMagic RansomExx Malware Cybersecurity researchers have lifted the lid on the threat actors’ exploitation of a now-patched security flaw in Microsoft Windows to…
Enterprise Security Malware2 Min Read August 25, 2025 Noodlophile Malware Campaign Expands Global Reach with Copyright Phishing Lures The threat actors behind the Noodlophile malware are leveraging spear-phishing emails and updated delivery mechanisms to deploy the…
Supply Chain Security2 Min Read August 25, 2025 PyPI Blocks 1,800 Expired-Domain Emails to Prevent Account Takeovers and Supply Chain Attacks The maintainers of the Python Package Index (PyPI) repository have announced that the package manager now checks for expired domains to…
Security Culture Security Training4 Min Read August 25, 2025 Why Your Security Culture is Critical to Mitigating Cyber Risk After two decades of developing increasingly mature security architectures, organizations are running up against a hard truth: tools and…
Cloud Security Encryption2 Min Read August 25, 2025 U.K. Government Drops Apple Encryption Backdoor Order After U.S. Civil Liberties Pushback The U.K. government has apparently abandoned its plans to force Apple to weaken encryption protections and include a backdoor that would have…
Cyber Espionage Vulnerability2 Min Read August 25, 2025 Public Exploit for Chained SAP Flaws Exposes Unpatched Systems to Remote Code Execution A new exploit combining two critical, now-patched security flaws in SAP NetWeaver has emerged in the wild, putting organizations at risk of…
Cyber Attack Malware3 Min Read August 25, 2025 New GodRAT Trojan Targets Trading Firms Using Steganography and Gh0st RAT Code Financial institutions like trading and brokerage firms are the target of a new campaign that delivers a previously unreported remote access…
Linux Malware2 Min Read August 25, 2025 Apache ActiveMQ Flaw Exploited to Deploy DripDropper Malware on Cloud Linux Systems Threat actors are exploiting a nearly two-year-old security flaw in Apache ActiveMQ to gain persistent access to cloud Linux systems and…
Botnet Cybercrime2 Min Read August 25, 2025 DOJ Charges 22-Year-Old for Running RapperBot Botnet Behind 370,000 DDoS Attacks A 22-year-old man from the U.S. state of Oregon has been charged with allegedly developing and overseeing a distributed denial-of-service…
Artificial Intelligence Cyber Espionage4 Min Read August 25, 2025 North Korea Uses GitHub in Diplomat Cyber Attacks as IT Worker Scheme Hits 320+ Firms North Korean threat actors have been attributed to a coordinated cyber espionage campaign targeting diplomatic missions in their southern…
Business Continuity Data Protection6 Min Read August 25, 2025 From Impact to Action: Turning BIA Insights Into Resilient Recovery Modern businesses face a rapidly evolving and expanding threat landscape, but what does this mean for your business? It means a growing number…