
Fake IT Help Desk Calls Target Microsoft 365 Executives
Vishing campaign targets directors and VPs with fake IT help desk calls, using adversary-in-the-middle token theft and residential proxies.

Vishing campaign targets directors and VPs with fake IT help desk calls, using adversary-in-the-middle token theft and residential proxies.

TantoSec released a PoC exploit chaining Telerik UI padding oracle to unauthenticated RCE two months after Progress Software shipped a

Elastic Security Labs found four REVSTEALER persistence modules that remain after the stealer deletes itself, disabling Defender to run a

Russian-speaking Aurora ransomware group leveraged Cursor AI coding assistant to conduct hands-on exploitation against 10 targets between April and May

Five critical vulnerabilities in WPMU DEV Dashboard, Avada Theme, TranslatePress, Pods, and GiveWP allow authentication bypass, privilege escalation, and RCE.

Anthropic warns Vidar, Lumma, StealC, RedLine, and AMOS malware are stealing Claude session tokens, enabling attackers to drain user credits

August 25 cyberattack hit Boston Scientific’s on-premises IT, disrupting manufacturing, order processing, and some cardiac monitor remote activations.

FulcrumSec claims theft of 86 gigabytes from Manchester Airports Group, exposing booking data for 8.7 million customers from a third-party

CVE-2026-81578 and CVE-2026-82078 allow unauthenticated RCE on PaperCut NG/MF versions 24-26; WatchTowr found patch bypasses forcing second emergency patch.

ShinyHunters demands $55 million for 284 million McKesson records containing PHI, prescriptions, and billing data; threatens release by September 1.
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.