
Klue OAuth Breach Impacts Huntress, Recorded Future and Others
Klue’s OAuth breach enabled the Icarus threat group to extract Salesforce CRM data from cybersecurity companies including Huntress and Recorded

Klue’s OAuth breach enabled the Icarus threat group to extract Salesforce CRM data from cybersecurity companies including Huntress and Recorded

International law enforcement destroys 15K SocGholish-infected WordPress sites and 106 C2 servers in coordinated takedown of Evil Corp-linked cybercrime network.

Attackers hijacked ShapedPlugin update distribution system to inject malicious code into legitimate plugin releases delivered directly to paying WordPress customers

F5 emergency patches address CVE-2026-42530, a critical CVSS 9.2 unauthenticated RCE in NGINX QUIC HTTP3 module that can be exploited

Microsoft disclosed a Windows Clipper malware campaign active since February using clipboard interception, USB LNK self-spreading, and Tor command-and-control infrastructure

Check Point Research uncovered a crypto clipper distribution campaign using fake reviews on GitHub and SourceForge, AI-narrated YouTube videos, and

Microsoft confirmed CVE-2026-50656, a CVSS 7.8 elevation of privilege zero-day in Microsoft Defender Malware Protection Engine actively exploited by the

Attackers hijacked a dormant npm contributor account and backdoored 144 Mastra AI packages, exposing 1.1 million weekly downloads to a

Fifteen malicious JetBrains Marketplace plugins stole OpenAI, DeepSeek, and SiliconFlow API keys from 70,000 IDE users across an eight-month campaign.

ShinyHunters claimed 2.2 million stolen Kodak records and set a publication deadline; Kodak confirmed a breach and engaged external cybersecurity
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.