
Law Enforcement Dismantles Tycoon2FA Phishing-as-a-Service Platform
Europol disables Tycoon2FA, a PhaaS platform responsible for tens of millions of phishing messages monthly.

Europol disables Tycoon2FA, a PhaaS platform responsible for tens of millions of phishing messages monthly.

LexisNexis confirms a breach in its Legal & Professional division using React2Shell, claiming 2 GB of stolen data.

Hundreds of Sangoma FreePBX systems compromised with web shells due to command injection flaw.

A 22-year-old from Alabama pleaded guilty to cyberstalking, extortion, and computer fraud after hijacking the social media accounts of hundreds

Cybercriminals deploy fake Google security pages to harvest one-time passcodes and cryptocurrency wallet addresses.

A Chrome vulnerability allowed malicious extensions to exploit Gemini Live, potentially hijacking the AI assistant to spy on users and

Google Chrome rolls out an experimental program to improve HTTPS certificate security against future quantum threats.

Florida resident sentenced to 22 months in prison for trafficking thousands of stolen Microsoft COA labels over several years.

Understand how deepfake and injection attacks affect identity verification processes and what enterprises can do to defend against them.

Russia-linked APT28 may have exploited MSHTML zero-day CVE-2026-21513, a high-severity flaw, before Microsoft issued a fix.
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.