Cyber Security
Anthropic’s Project Glasswing Finds 10,000+ CVEs in One Month
LiteSpeed cPanel Plugin CVE-2026-48172 CVSS 10.0 Exploited
ShinyHunters Claims 42M Charter Records, Sets May 27 Deadline
Netherlands Seizes 800 Stark Industries Servers, Arrests Two
ShinyHunters Claims 260K Baker Distributing Salesforce Records
Ubiquiti Patches 3 Max-Severity UniFi OS Flaws, 100K Exposed
Trump Mobile Exposes 27,000 Customer Records via Insecure API
Mysk: WhatsApp Stores Chats Unencrypted, Meta Apps Can Read Them
Wireshark 4.6.6 Patches ROHC Crash and MACsec Buffer Overflow
FBI Warns Kali365 PhaaS Platform Bypasses Microsoft 365 MFA
Lenovo BootRepair.sys Driver Exposes BYOVD Attack on CrowdStrike
Splunk CVE-2026-20239 Logs Session Cookies in Plaintext
DPRK npm Packages Use Hugging Face to Exfiltrate Developer Credentials
Deleted Google API Keys Stay Active for Up to 23 Minutes
Chromium Service Worker PoC Exploit Published for 42-Month-Old Bug
Texas AG Sues Meta Over WhatsApp Encryption Claims
Banana RAT Hijacks Brazil Pix QR Codes via NF-e Lures
UNG0002 Hides Cobalt Strike in macOS Folder Structures
INJ3CTOR3 Deploys JOMANGY Webshell in FreePBX Campaign
Operation Dragon Whistle Uses VS Code Tunnels as C2
Cisco Secure Workload CVE-2026-20223 Earns CVSS 10.0
NGINX 1.31.0 Zero-Day nginx-poolslip Bypasses ASLR
WantToCry Ransomware Hits SMB Ports, Evades EDR Tools
DOJ Secures Guilty Pleas From Tech-Support Fraud Executives
BadIIS Malware-as-a-Service Hijacks IIS Servers for SEO Fraud
GhostTree Exploit Hangs Windows Defender With NTFS Junctions
SilverFox APT Spreads ValleyRAT via Fake Microsoft Teams Sites
TamperedChef Hides Malware Inside Signed Apps
Chrome 148 Patches Critical WebRTC Use-After-Free
P2PInfect Botnet Infiltrates Kubernetes Clusters via Redis
List of 15 Networking Certifications by Security Vendors to Supercharge Your Career in 2025
Blog
Top 15 Networking Certifications to Supercharge Your Career in 2025
Safeguarding networks is no longer a luxury; it’s a necessity. Expertise in cybersecurity is in incredibly high demand. So making ...
Windows BitLocker Vulnerability (CVE-2025-21210) Exploited in Randomization Attack
News
Windows BitLocker Vulnerability (CVE-2025-21210) Exploited in Randomization Attack
A critical Windows BitLocker vulnerability (CVE-2025-21210) allows attackers with physical access to bypass AES-XTS encryption, exposing sensitive data through a novel randomization attack.
Nash County Public Schools Data Breach Compromised Student Information
News
Nash County Public Schools Data Breach Compromised Student Information
A data breach at Nash County Public Schools exposed student information via PowerSchool's PowerSource.
Blacon High School Temporarily Closes Due to Ransomware Attack
News
Blacon High School Temporarily Closes Due to Ransomware Attack
Blacon High School temporarily closed due to a ransomware attack. Further closures are possible as investigations continue. The incident highlights the rising threat of ransomware ...
Otelier Data Breach Exposes Millions of Hotel Reservations and Personal Information
News
Otelier Data Breach Exposes Millions of Hotel Reservations and Personal Information
The Otelier data breach affected millions of hotel reservations, exposed personal information from major hotel chains. The breach, originating from compromised employee credentials.
HPE Data Breached by IntelBroker: HPE Data on Sale on Dark Web
News
HPE Data Breached by IntelBroker: HPE Data on Sale on Dark Web
IntelBroker, a notorious threat actor, is selling data stolen from Hewlett-Packard Enterprise (HPE), including source code, private keys, and personal information. The HPE data breach ...
FBI Warns AT&T Data Breach Exposed Agent Call Logs Risking Informants
News
FBI Warns AT&T Data Breach Exposed Agent Call Logs Risking Informants
AT&T data breach exposed six months of FBI agent call logs, potentially revealing confidential informants. The FBI warning highlights vulnerabilities in telecommunications security and the ...
Gateshead Council Cyber-Attack: Personal Data Stolen
News
Gateshead Council Cyber-Attack: Personal Data Stolen
A cyber-attack on Gateshead Council resulted in a data breach affecting an unknown number of residents. The council urges vigilance against phishing emails and advises ...
GGG Data Breach: Path of Excile 2 Dev Grinding Gear Games Apologizes for Security Lapse
News
GGG Data Breach: Path of Excile 2 Dev Grinding Gear Games Apologizes for Security Lapse
Grinding Gear Games revealed a Path of Exile 2 data breach, compromising 66 accounts and potentially exposing personal information like emails and addresses. The developer ...
Telefonica Breach Exposes 20,000 Employees' Data and Jira Details: Hellcat Ransomware's Infostealer Malware at Play
News
Telefonica Breach Exposes 20,000 Employees’ Data and Jira Details: Hellcat Ransomware’s Infostealer Malware at Play
Telefonica breach impacts 20,000 employees through customer data theft and infostealer malware tactics in this detailed analysis.
WazirX Hack: North Korea's Lazarus Blamed for WazirX's $235 Million Cryptocurrency Theft
News
WazirX Hack: North Korea’s Lazarus Blamed for WazirX’s $235 Million Cryptocurrency Theft
The US, Japan, and South Korea blame North Korea's Lazarus group for the WazirX hack, a $235 million cryptocurrency theft. WazirX CEO calls for global ...
PowerSchool Data Breach Exposes Social Security Numbers of 60 Million Students and Teachers
News
PowerSchool Data Breach Exposes Social Security Numbers of 60 Million Students and Teachers
PowerSchool data breach cyberattack exposed SSNs and PII of 60 million students and teachers, including medical information.
West Haven, Connecticut, Battles a Devastating Qilin Ransomware Cyberattack
News
West Haven, Connecticut, Battles a Devastating Qilin Ransomware Cyberattack
West Haven, Connecticut, is recovering from a cyberattack attributed to the Qilin ransomware group, which temporarily shut down city IT systems. The investigation is ongoing ...
Manitou Springs School District 14 Joins District 49 in PowerSchool Data Breach
News
Manitou Springs School District 14 Joins District 49 in PowerSchool Data Breach
Manitou Springs District 14 and District 49 experienced a PowerSchool data breach exposing student and parent names and addresses. PowerSchool is investigating with cybersecurity experts. ...
Ransomware Attack Paralyzes Slovakian Land Registry, Souring Slovakia-Ukraine Relations
News
Ransomware Attack Paralyzes Slovakian Land Registry, Souring Slovakia-Ukraine Relations
A ransomware attack has severely impacted Slovakia's Geodesy, Cartography and Cadastre Office (UGKK), causing widespread disruption to land registry services and related public functions. The ...
Pro-Russian Hacker Group Targets Italian Banks and Public Services in DDoS Attacks
News
Pro-Russian Hacker Group Targets Italian Banks and Public Services in DDoS Attacks
A wave of cyberattacks on Italian banks, including Intesa Sanpaolo and Monte dei Paschi, along with public services, were launched by the pro-Russian hacker group, ...
Gravy Analytics Data Breach Exposes Location Data: iOS 14.5 and App Tracking Transparency Offer Some Protection
News
Gravy Analytics Data Breach Exposes Location Data: iOS 14.5 and App Tracking Transparency Offer Some Protection
The Gravy Analytics data breach exposed the precise location information of millions of users, impacting both iOS and Android devices. Popular apps, including dating apps ...
Top 10 Ransomware Groups of 2024 The Year's Most Active Cyber Threats
Blog
Top 10 Ransomware Groups of 2024: The Year’s Most Active Cyber Threats
This in-depth analysis reveals the Top 10 Ransomware groups that dominated the cyberattack landscape in 2024, examining their methods, impact on businesses, and the implications ...
PowerSchool Data Breach: Millions of Student Records Compromised in January 2025
News
PowerSchool Data Breach: Millions of Student Records Compromised in January 2025
PowerSchool had a data breach in December 2025, compromising the personal data of millions of students and parents. Hackers exploited stolen credentials to access sensitive ...
Vermont School Breached in PowerSchool Hack
News
Vermont School Breached in PowerSchool Hack
PowerSchool data breach exposed the personal data of Vermont school students and staff. The impact varies, but cybersecurity concerns are high. Schools are taking steps ...
Application Security
Ghost CMS CVE-2026-26980 Exploited in ClickFix Campaign

TOP CYBERSECURITY HEADLINES

This Week’s Security Spotlight

Application Security
Anthropic’s Project Glasswing Finds 10,000+ CVEs in One Month
Application Security
Trump Mobile Exposes 27,000 Customer Records via Insecure API
CVE Vulnerability Alerts
Cisco Secure Workload CVE-2026-20223 Earns CVSS 10.0
Cybersecurity
NYC Health + Hospitals Breach Exposes 1.8M Patients’ Fingerprints
Trending

Daily Briefing Newsletter

Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Featured Videos​

  • All
  • Application Security
  • Blog
  • CVE Vulnerability Alerts
  • Cybersecurity
  • Cybersecurity Newsletter
  • Data Security
  • Endpoint Security
  • Identity and Access Management
  • Information Security
  • Network Security
  • News
  • Phishing
  • Podcasts
  • Product Reviews
  • Ransomware
  • Ransomware Victims
  • Resources
  • Security Spotlight
  • Sponsored
  • Threat Actors
  • Threat Actors
  • Threat Detection Tools
Ascension Discloses Data Breach Affecting 5.6 Million Individuals
Ascension, a major U.S. healthcare provider, confirmed a ransomware breach affecting 5.6 million individuals, compromising medical, financial, and personal data.
Harrods Confirms Cyberattack Amid Growing Wave Targeting UK Retail Sector
Harrods joins M&S and Co-op as the latest UK retailer targeted in a cyberattack, prompting immediate security measures amid a surge in retail-focused intrusions.
LayerX Secures $45M Total to Battle Data Leaks, One Browser at a Time
LayerX just raised another $11 million — and it’s not to build another antivirus. With $45 million in total funding, the company is betting that ...
AirBorne: How a Zero-Click Bug Threatens Millions of Apple and Third-Party Devices
In this episode, we dive deep into AirBorne — a critical set of vulnerabilities in Apple’s AirPlay protocol and SDK, recently uncovered by security researchers ...
$10.5M to Fight AI-Phishing: The Rise of Pistachio’s Cybersecurity Training Platform
In this episode, we dive into the story of Pistachio, the Norwegian cybersecurity startup that just raised $7 million in new funding—bringing its total to ...
Hitachi Vantara Takes Servers Offline Following Akira Ransomware Attack
Hitachi Vantara shut down servers to contain an Akira ransomware attack that disrupted systems and led to stolen data across corporate and government-related operations.
Vulnerability Alert – 30th April, 2025
Staying ahead of emerging cyber threats requires continuous monitoring of newly disclosed vulnerabilities, exploitation trends, and post-compromise behaviors. This page provides a detailed breakdown of ...
Fighting AI with AI: Using Artificial Intelligence to Strengthen Enterprise Cybersecurity
The rise of AI-driven cyberattacks necessitates a proactive approach. This blog explores how AI can combat AI cybersecurity threats, highlighting its benefits and risks ...
MTN Ghana Data Breach Impacts 5,700 Customers, Investigation Underway
MTN Ghana confirms a data breach affecting 5,700 customers, with investigations ongoing and direct outreach underway to mitigate potential risks and prevent further exposure.
SK Telecom Offers Free SIM Replacements After Malware Breach Impacts USIM Data
SK Telecom is replacing SIM cards for 25 million users after a malware breach exposed USIM data. Supply limits restrict replacements to 6 million by ...
CISA Flags Broadcom, CommVault, and Active! Mail Vulnerabilities as Actively Exploited
CISA adds Broadcom, CommVault, and Active! Mail vulnerabilities to KEV catalog following active exploitation reports, urging immediate patching by enterprise and critical infrastructure operators.
M&S Cyberattack Halts Online Sales, Triggers Major Financial Impact
Marks & Spencer suspended online orders after a cyberattack over Easter weekend caused major disruptions, wiping £500 million off its stock and impacting daily sales. ...
The Silent Majority: Why 51% of Internet Traffic Is Now Bots
The bots have taken over—and they’re not just crawling your website. In this episode, we dig into the alarming reality that automated bots now generate ...
From 1,382 to 4 Million: What VeriSource Didn’t Know (or Say)
In this episode, we investigate the massive data breach at VeriSource Services, Inc. (VSI), a Houston-based HR outsourcing and employee benefits administrator. Initially reported as ...
Actively Exploited: Commvault Web Shells, Active! mail RCE, and Brocade Code Injection Now in KEV
Three actively exploited vulnerabilities—CVE-2025-42599 (Qualitia Active! mail), CVE-2025-3928 (Commvault Web Server), and CVE-2025-1976 (Broadcom Brocade Fabric OS)—have been added to CISA’s KEV catalog. The Qualitia ...
Over 1,200 SAP NetWeaver Servers Exposed to Actively Exploited Critical Vulnerability
A critical SAP NetWeaver flaw (CVE-2025-31324) is being actively exploited. Over 1,200 servers are exposed, with hundreds already compromised by remote webshell deployments.
27 Million Records Allegedly Leaked from French Retailer Boulanger
Personal data linked to over 27 million customer records of French electronics giant Boulanger has been leaked on a public hacking forum, with no ransom ...
Marks & Spencer Cyberattack Tied to Scattered Spider Ransomware Group
Marks & Spencer is battling an ongoing outage caused by Scattered Spider ransomware attackers, who breached its systems, stole password data, and encrypted virtual machines. ...
VeriSource Confirms Data Breach Impacted 4 Million People After Year-Long Investigation
VeriSource Confirms Data Breach Impacted 4 Million People After Year-Long Investigation
Darcula: AI-Enhanced Phishing Platform Targets Users Worldwide
The Darcula phishing platform has been upgraded with AI, enabling cybercriminals to quickly generate multilingual phishing scams and harvest user credentials on a global scale. ...