Cybersecurity

Cybersecurity
Gentlemen RaaS Group Maintains Purpose-Built EDR Killers
Gentlemen ransomware-as-a-service operation develops and maintains purpose-built endpoint detection kill tools to disable security protections before ransomware deployment.
Cybersecurity
Nintendo Confirms Employee Survey Data Stolen via TinyPulse
Nintendo confirms employee survey data stolen from TinyPulse, the WebMD subsidiary, through a third-party vendor breach affecting corporate HR integration.
Application Security
Klue OAuth Breach Impacts Huntress, Recorded Future and Others
Klue's OAuth breach enabled the Icarus threat group to extract Salesforce CRM data from cybersecurity companies including Huntress and Recorded Future.
Cybersecurity
Operation Endgame Dismantles SocGholish Botnet, Cleans 15K Sites
International law enforcement destroys 15K SocGholish-infected WordPress sites and 106 C2 servers in coordinated takedown of Evil Corp-linked cybercrime network.
ShapedPlugin Update System Compromised, Malicious WordPress Plugins Pushed to Customers
Cybersecurity
ShapedPlugin Update System Compromised, Malicious WordPress Plugins Pushed to Customers
Attackers hijacked ShapedPlugin update distribution system to inject malicious code into legitimate plugin releases delivered directly to paying WordPress customers through official update channels.
Cybersecurity
F5 Patches Critical NGINX RCE in QUIC Module, CVSS 9.2 Use-After-Free Fixed
F5 emergency patches address CVE-2026-42530, a critical CVSS 9.2 unauthenticated RCE in NGINX QUIC HTTP3 module that can be exploited remotely without credentials on NGINX ...
Cybersecurity
Microsoft Details Windows Clipper USB LNK Worm with Tor Command-and-Control
Microsoft disclosed a Windows Clipper malware campaign active since February using clipboard interception, USB LNK self-spreading, and Tor command-and-control infrastructure to steal cryptocurrency addresses.
Cybersecurity
Check Point Documents Crypto Clipper Using Fake Reviews and AI Narrators
Check Point Research uncovered a crypto clipper distribution campaign using fake reviews on GitHub and SourceForge, AI-narrated YouTube videos, and fabricated VirusTotal comments to build ...
Cybersecurity
Microsoft Confirms RoguePlanet Defender Zero-Day EoP, Patch in Development
Microsoft confirmed CVE-2026-50656, a CVSS 7.8 elevation of privilege zero-day in Microsoft Defender Malware Protection Engine actively exploited by the Nightmare-Eclipse threat group.
Blog
What Is Data Security Posture Management? A Complete DSPM Guide
Data security posture management (DSPM) continuously discovers and classifies sensitive data to reduce breach risk in multi-cloud environments.