Cyber Security
Application Security
Exchange Online Mailbox Access Issues Impact Outlook Users
Mitchell Langley
April 7, 2026
Exchange Online access issues have affected Outlook mobile and macOS users. Microsoft is actively working on a resolution.
Application Security
Shadow AI and Zero-Click Exploits Are Reshaping Mobile Security Threats
Gabby Lee
April 7, 2026
The expansion of Shadow AI within daily apps and outdated mobile devices increases exposure to unseen mobile vulnerabilities.
Cybersecurity
Third-Party Vendors Are the New Breach Vector Organizations Should Fear
Gabby Lee
April 7, 2026
Organizations face growing cybersecurity risks from trusted vendors, SaaS tools, and subcontractors that bypass traditional security measures.
Application Security
Critical ShareFile Flaws Open the Door to Unauthenticated RCE
Andrew Doyle
April 7, 2026
Analysis reveals critical ShareFile flaws allowing server access and arbitrary file uploads.
Application Security
Strapi CMS Plugins Face Exploitation by Malicious npm Packages
Andrew Doyle
April 7, 2026
Researchers found 36 harmful npm packages posing as Strapi CMS plugins to exploit Redis, PostgreSQL, and execute further cyber attacks.
News
Bogus Traffic Violation Text Scam Targeting Americans
Andrew Doyle
April 7, 2026
Fraudulent "Notice of Default" text scams impersonate U.S. state courts, leading victims to phishing sites.
News
Qilin Ransomware Group Targets German Political Party Die Linke
Mitchell Langley
April 7, 2026
Qilin ransomware group claims responsibility for a cyberattack on German political party Die Linke.
Cybersecurity
Analysis Reveals .cmd Malware Escalating Privileges and Bypassing Antivirus
Gabby Lee
April 7, 2026
Detailed analysis of a .cmd malware found in an email, escalating privileges and bypassing antivirus.
CVE Vulnerability Alerts
Fortinet Acts Quickly on Zero-Day Vulnerability Impacting FortiClient EMS Users
Mitchell Langley
April 7, 2026
Fortinet issues emergency patches for a critical vulnerability (CVE-2026-35616) in FortiClient EMS, already exploited in the wild.
Cybersecurity
North Korean Cyber Operatives Drain $285 Million from Drift Exchange
Gabby Lee
April 7, 2026
A North Korean orchestrated cyber attack stole $285 million from Drift, a Solana-based exchange, on April 1, 2026.
Application Security
Axios HTTP Client Developer Targeted in North Korean Social Engineering Campaign
Andrew Doyle
April 7, 2026
The popular Axios HTTP client faced a social engineering attack attributed to North Korean actors, exposing serious security risks within open-source ...
Cybersecurity
Free Android VPNs Are Quietly Working Against You
Gabby Lee
April 3, 2026
Free VPNs on Android promise protection, but often jeopardize user privacy with tracking, permissions, and risky servers.
Cybersecurity
Residential Proxies Are Breaking IP Reputation Systems for Malware Traffic
Andrew Doyle
April 3, 2026
Residential proxies confuse IP reputation systems, obscuring differences between malicious traffic and legitimate users.
Cybersecurity
Drift Protocol Hit by Calculated Attack Resulting in $280 Million Loss
Gabby Lee
April 3, 2026
Drift Protocol faces a substantial breach, leading to administrative control loss and financial damages exceeding $280 million.
Cybersecurity
Apple Rolls Out DarkSword Exploit Protection to More Devices
Mitchell Langley
April 3, 2026
Apple enhances its defenses against the DarkSword exploit kit, a threat linked to state-sponsored hackers and commercial spyware vendors.
Application Security
Critical Vulnerability in Claude Code Surfaces Days After Source Code Leak
Gabby Lee
April 3, 2026
Claude Code faces a critical vulnerability discovered by Adversa AI just days after its source code was unintentionally leaked by Anthropic.
Cybersecurity
Cybercriminals Exploit Empty Properties for Postal Fraud
Andrew Doyle
April 3, 2026
Threat actors use vacant homes to snatch mail and perpetrate fraud using Flare's findings.
Cybersecurity
Cisco Releases Patches for Critical and High-Severity Vulnerabilities
Mitchell Langley
April 3, 2026
Cisco fixes critical vulnerabilities threatening authentication, code execution, and more.
Cybersecurity
Stryker Corporation Restores Operations After Cyberattack
Gabby Lee
April 3, 2026
Stryker Corporation resumes operations after a cyberattack by Handala hacktivists.
Cybersecurity
Cybersecurity M&A Activity Surges With 38 Deals Closing in March 2026
Mitchell Langley
April 3, 2026
Explore prominent cybersecurity M&A deals announced in March 2026 by Airbus, Cellebrite, and others.
Application Security
Exchange Online Mailbox Access Issues Impact Outlook Users
Mitchell Langley
April 7, 2026
Cybersecurity
Third-Party Vendors Are the New Breach Vector Organizations Should Fear
Gabby Lee
April 7, 2026
News
DeepLoad Malware Poses a Multifaceted Threat with Credential Theft and Extension Installation
Andrew Doyle
April 2, 2026
TOP CYBERSECURITY HEADLINES
This Week’s Security Spotlight
Cybersecurity
Apple Rolls Out DarkSword Exploit Protection to More Devices
Mitchell Langley
April 3, 2026
Application Security
Critical Vulnerability in Claude Code Surfaces Days After Source Code Leak
Gabby Lee
April 3, 2026
Cybersecurity
Anthropic Confirms Internal Claude Code Leak Was Caused by Human Error
Mitchell Langley
April 2, 2026
Trending
Daily Briefing Newsletter
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.
Featured Videos
Podcasts
Cyber Security News
- All
- Application Security
- Blog
- CVE Vulnerability Alerts
- Cybersecurity
- Cybersecurity Newsletter
- Data Security
- Endpoint Security
- Identity and Access Management
- Information Security
- Network Security
- News
- Phishing
- Podcasts
- Product Reviews
- Ransomware
- Ransomware Victims
- Resources
- Security Spotlight
- Sponsored
- Threat Actors
- Threat Actors
- Threat Detection Tools
Critical ShareFile Flaws Open the Door to Unauthenticated RCE
April 7, 2026
Analysis reveals critical ShareFile flaws allowing server access and arbitrary file uploads.
Strapi CMS Plugins Face Exploitation by Malicious npm Packages
April 7, 2026
Researchers found 36 harmful npm packages posing as Strapi CMS plugins to exploit Redis, PostgreSQL, and execute further cyber attacks.
Bogus Traffic Violation Text Scam Targeting Americans
April 7, 2026
Fraudulent "Notice of Default" text scams impersonate U.S. state courts, leading victims to phishing sites.
Qilin Ransomware Group Targets German Political Party Die Linke
April 7, 2026
Qilin ransomware group claims responsibility for a cyberattack on German political party Die Linke.
Analysis Reveals .cmd Malware Escalating Privileges and Bypassing Antivirus
April 7, 2026
Detailed analysis of a .cmd malware found in an email, escalating privileges and bypassing antivirus.
Fortinet Acts Quickly on Zero-Day Vulnerability Impacting FortiClient EMS Users
April 7, 2026
Fortinet issues emergency patches for a critical vulnerability (CVE-2026-35616) in FortiClient EMS, already exploited in the wild.
North Korean Cyber Operatives Drain $285 Million from Drift Exchange
April 7, 2026
A North Korean orchestrated cyber attack stole $285 million from Drift, a Solana-based exchange, on April 1, 2026.
Axios HTTP Client Developer Targeted in North Korean Social Engineering Campaign
April 7, 2026
The popular Axios HTTP client faced a social engineering attack attributed to North Korean actors, exposing serious security risks within open-source ...
Free Android VPNs Are Quietly Working Against You
April 3, 2026
Free VPNs on Android promise protection, but often jeopardize user privacy with tracking, permissions, and risky servers.
Residential Proxies Are Breaking IP Reputation Systems for Malware Traffic
April 3, 2026
Residential proxies confuse IP reputation systems, obscuring differences between malicious traffic and legitimate users.
Apple Rolls Out DarkSword Exploit Protection to More Devices
April 3, 2026
Apple enhances its defenses against the DarkSword exploit kit, a threat linked to state-sponsored hackers and commercial spyware vendors.
Drift Protocol Hit by Calculated Attack Resulting in $280 Million Loss
April 3, 2026
Drift Protocol faces a substantial breach, leading to administrative control loss and financial damages exceeding $280 million.
Critical Vulnerability in Claude Code Surfaces Days After Source Code Leak
April 3, 2026
Claude Code faces a critical vulnerability discovered by Adversa AI just days after its source code was unintentionally leaked by Anthropic.
Cybercriminals Exploit Empty Properties for Postal Fraud
April 3, 2026
Threat actors use vacant homes to snatch mail and perpetrate fraud using Flare's findings.
Cisco Releases Patches for Critical and High-Severity Vulnerabilities
April 3, 2026
Cisco fixes critical vulnerabilities threatening authentication, code execution, and more.
Stryker Corporation Restores Operations After Cyberattack
April 3, 2026
Stryker Corporation resumes operations after a cyberattack by Handala hacktivists.
Cybersecurity M&A Activity Surges With 38 Deals Closing in March 2026
April 3, 2026
Explore prominent cybersecurity M&A deals announced in March 2026 by Airbus, Cellebrite, and others.
Anthropic Confirms Internal Claude Code Leak Was Caused by Human Error
April 2, 2026
Anthropic confirms internal code leak of Claude Code due to human error, no sensitive data involved.
Microsoft Releases Emergency Fix for KB5079391 Update Installation Failures
April 2, 2026
Microsoft has released an emergency fix for the March 2026 KB5079391 non-security preview update, which was pulled over the weekend due to widespread ...
Google Rolls Out Gmail Address Change and Alias Feature in the U.S.
April 2, 2026
Google introduces a feature to change Gmail addresses, enhancing user email customization options in the U.S.






















