
KillSec Ransomware Hits Indian Teaching Hospital and Mexican Insurer
KillSec ransomware posted an Indian teaching hospital and a Mexican insurance firm as victims, exposing patient data under India’s DPDPA

KillSec ransomware posted an Indian teaching hospital and a Mexican insurance firm as victims, exposing patient data under India’s DPDPA

Nova ransomware publicly apologized and banned an affiliate for attacking Eriell Group, an Uzbekistan oilfield firm, violating the CIS safe

Trump signed an executive order directing US national security agencies to assess top AI foundation models for offensive cyber and

Huntress disclosed a Windows Search URI handler flaw that silently sends NTLMv2 hashes to attacker servers with one click. Microsoft

Qilin ransomware posted six victims across five countries over two days, including Nova Medical Products and MEISA Sines at Portugal’s

APT73 (Bashe), a LockBit-linked RaaS, posted Armenia’s elections.mia.gov.am as a victim, threatening voter registration and electoral administration data.

Russia’s FSB claimed foreign spies installed surveillance malware on senior officials’ smartphones, naming Cloudflare and Fastly as alleged C2 infrastructure.

Europol’s seven-month Operation KRATOS 2 arrested 29 suspects, targeted 4,370 piracy domains, and removed 27,000 illegal streaming URLs across 13

CVE-2026-8206 in the Kirki WordPress plugin is under active attack, with Wordfence detecting 222 exploitation attempts targeting admin account takeover.

CVE-2026-0826 allows unauthenticated root-level RCE on HP Poly VVX and Trio VoIP phones via a crafted SIP INVITE request targeting
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.