Cyber Security
Anthropic’s Project Glasswing Finds 10,000+ CVEs in One Month
LiteSpeed cPanel Plugin CVE-2026-48172 CVSS 10.0 Exploited
ShinyHunters Claims 42M Charter Records, Sets May 27 Deadline
Netherlands Seizes 800 Stark Industries Servers, Arrests Two
ShinyHunters Claims 260K Baker Distributing Salesforce Records
Ubiquiti Patches 3 Max-Severity UniFi OS Flaws, 100K Exposed
Trump Mobile Exposes 27,000 Customer Records via Insecure API
Mysk: WhatsApp Stores Chats Unencrypted, Meta Apps Can Read Them
Wireshark 4.6.6 Patches ROHC Crash and MACsec Buffer Overflow
FBI Warns Kali365 PhaaS Platform Bypasses Microsoft 365 MFA
Lenovo BootRepair.sys Driver Exposes BYOVD Attack on CrowdStrike
Splunk CVE-2026-20239 Logs Session Cookies in Plaintext
DPRK npm Packages Use Hugging Face to Exfiltrate Developer Credentials
Deleted Google API Keys Stay Active for Up to 23 Minutes
Chromium Service Worker PoC Exploit Published for 42-Month-Old Bug
Texas AG Sues Meta Over WhatsApp Encryption Claims
Banana RAT Hijacks Brazil Pix QR Codes via NF-e Lures
UNG0002 Hides Cobalt Strike in macOS Folder Structures
INJ3CTOR3 Deploys JOMANGY Webshell in FreePBX Campaign
Operation Dragon Whistle Uses VS Code Tunnels as C2
Cisco Secure Workload CVE-2026-20223 Earns CVSS 10.0
NGINX 1.31.0 Zero-Day nginx-poolslip Bypasses ASLR
WantToCry Ransomware Hits SMB Ports, Evades EDR Tools
DOJ Secures Guilty Pleas From Tech-Support Fraud Executives
BadIIS Malware-as-a-Service Hijacks IIS Servers for SEO Fraud
GhostTree Exploit Hangs Windows Defender With NTFS Junctions
SilverFox APT Spreads ValleyRAT via Fake Microsoft Teams Sites
TamperedChef Hides Malware Inside Signed Apps
Chrome 148 Patches Critical WebRTC Use-After-Free
P2PInfect Botnet Infiltrates Kubernetes Clusters via Redis
Pokemon Data Breach Reveals Secrets of Unannounced Games and Nintendo Switch 2 Codename
News
Pokemon Data Breach Reveals Secrets of Unannounced Games and Nintendo Switch 2 Codename
A massive Pokemon data breach reveals unreleased game details, the Nintendo Switch 2 codename, and even a canceled Detective Pikachu sequel. The Pokemon data leak ...
This Week In Cybersecurity: 7th October to 11th October
Cybersecurity
This Week In Cybersecurity: 7th October to 11th October
MoneyGram Cyberattack: No Ransomware Evidence Found, Social Engineering Suspected In September 2024, MoneyGram experienced a cyberattack leading to a five-day ...
Internet Archive Breach Exposes Data of 31 Million Users
News
Internet Archive Breach Exposes Data of 31 Million Users
The internet archive breach exposed data of 31 million users. The attack involved the theft of a user authentication database containing sensitive information like email ...
Salt Typhoon APT Subverts Law Enforcement Wiretapping
Cybersecurity
Salt Typhoon APT Subverts Law Enforcement Wiretapping
The Chinese state-sponsored Salt Typhoon APT infiltrated US broadband providers, accessing law enforcement wiretapping systems and general internet traffic, potentially for months. This represents a ...
ADT Discloses Second Breach in 2 Months: Stolen Credentials Fuel Data Exfiltration
News
ADT Discloses Second Breach in 2 Months: Stolen Credentials Fuel Data Exfiltration
Casio's network suffered a significant breach on October 5th, 2024, causing IT system failures and service disruptions. The investigation is ongoing to determine the extent ...
MoneyGram Cyberattack: Hackers Confirmed to Have Stolen Customer Data
News
MoneyGram Cyberattack: Hackers Confirmed to Have Stolen Customer Data
The MoneyGram cyberattack resulted in the theft of customer data, including transaction details, personal information, and government IDs. The attackers used social engineering to gain ...
Casio Network Breach: IT Systems Fail After CyberAttack
News
Casio Network Breach: IT Systems Fail After CyberAttack
Casio's network suffered a significant breach on October 5th, 2024, causing IT system failures and service disruptions. The investigation is ongoing to determine the extent ...
American Water Cyberattack: Major US Utility Shuts Down Systems After Security Breach
Cybersecurity
American Water Cyberattack: Major US Utility Shuts Down Systems After Security Breach
American Water cyberattack has forced the largest water and wastewater utility company in the US to shut down some of its ...
FBCS Data Breach Impacts Millions, Including Comcast and Truist Bank Customers
News
FBCS Data Breach Impacts Millions, Including Comcast and Truist Bank Customers
The FBCS data breach exposed the personal information of millions, including Comcast and Truist Bank customers, highlighting the vulnerability of sensitive data within third-party systems.
Highline Public Schools Ransomware Attack Forces the School to Shut Down Classes
News
Highline Public Schools Ransomware Attack Forces the School to Shut Down Classes
Highline Public Schools confirmed a ransomware attack caused its September shutdown, impacting over 17,500 students. The district is rebuilding systems and re-imaging devices, offering employees ...
MoneyGram Cyberattack: No Ransomware Evidence Found, Social Engineering Suspected
News
MoneyGram Cyberattack: No Ransomware Evidence Found, Social Engineering Suspected
MoneyGram's recent cyberattack, initially suspected to be ransomware, was instead caused by a social engineering attack targeting the company's internal help desk.
Red Barrels, Outlast Developer, Suffers Data Breach: Source Code, Employee Data Compromised
News
Red Barrels, Outlast Developer, Suffers Data Breach: Source Code, Employee Data Compromised
Red Barrels, the Outlast developer, suffered a major data breach, compromising source code, employee data, and financial information, causing significant production delays.
This Week In Cybersecurity: 30th September to 4th October
Cybersecurity
This Week In Cybersecurity: 30th September to 4th October
This Week In Cybersecurity: 30th September to 04th October highlights major incidents, including Bank of America's outage causing $0 balance displays, CF Medical's data breach, ...
Bank of America Outage: Is Your Account Balance Zero?
News
Bank of America Outage: Is Your Account Balance Zero?
A Bank of America outage left many customers seeing $0 balances, sparking widespread concern and frustration. The issue, which affected Zelle payments, is largely resolved, ...
Urgent Security Alert: Critical Ivanti Endpoint Manager Vulnerabilities Discovered
News
Urgent Security Alert: Critical Ivanti Endpoint Manager Vulnerabilities Discovered
Critical Ivanti Endpoint Manager vulnerabilities (CVE-2023-35083 & CVE-2023-35084) allow unauthorized file access and exfiltration. Immediate patching is crucial
Wayne County Cyberattack Cripples Government Services; Ransom Demand Fuels Investigation
News
Wayne County Cyberattack Cripples Government Services: Ransom Demand Fuels Investigation
Wayne County cyberattack crippled government services, with hackers demanding a ransom. The FBI and Michigan State Police are investigating.
Verizon Outage Leaves Hundreds of Thousands Without Service
News
Verizon Outage Leaves Hundreds of Thousands Without Service
A major Verizon outage left over 200,000 customers without cell service for over 10 hours. Verizon cited a "network issue" but offered no further details ...
Feldstein & Stewart Data Breach Letter Sent to 8,171 Individuals
News
Feldstein & Stewart Data Breach Letter Sent to 8,171 Individuals
Feldstein & Stewart sent a data breach letter to 8,171 individuals following a serious security incident that compromised sensitive consumer information.
CF Medical Announces Data Breach Stemming from FBCS Data Breach
News
CF Medical Announces Data Breach Stemming from FBCS Data Breach
CF Medical announced a data breach linked to FBCS data breach, exposing sensitive consumer information. Notifications have been sent to affected individuals.
Wells Fargo Announces Data Breach Cause by Unauthorized Access by Former Employee
News
Wells Fargo Announces Data Breach Cause by Unauthorized Access by Former Employee
Wells Fargo has reported a data breach due to unauthorized access by a former employee. Sensitive customer information was compromised, prompting immediate notifications.
Application Security
Ghost CMS CVE-2026-26980 Exploited in ClickFix Campaign

TOP CYBERSECURITY HEADLINES

This Week’s Security Spotlight

Application Security
Anthropic’s Project Glasswing Finds 10,000+ CVEs in One Month
Application Security
Trump Mobile Exposes 27,000 Customer Records via Insecure API
CVE Vulnerability Alerts
Cisco Secure Workload CVE-2026-20223 Earns CVSS 10.0
Cybersecurity
NYC Health + Hospitals Breach Exposes 1.8M Patients’ Fingerprints
Trending

Daily Briefing Newsletter

Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Featured Videos​

  • All
  • Application Security
  • Blog
  • CVE Vulnerability Alerts
  • Cybersecurity
  • Cybersecurity Newsletter
  • Data Security
  • Endpoint Security
  • Identity and Access Management
  • Information Security
  • Network Security
  • News
  • Phishing
  • Podcasts
  • Product Reviews
  • Ransomware
  • Ransomware Victims
  • Resources
  • Security Spotlight
  • Sponsored
  • Threat Actors
  • Threat Actors
  • Threat Detection Tools
Ransomware Victims on Dark Web – 13th March, 2025
This report summarizes recent ransomware attacks across various sectors, detailing the victims, threat actors, and available information on the incidents. Due to the nature of ...
LockBit Linked SuperBlack Ransomware Exploits Fortinet Authentication Bypass Flaws
New SuperBlack ransomware leverages Fortinet authentication bypass flaws (CVE-2024-55591 and CVE-2025-24472), showing strong ties to LockBit. Immediate patching is crucial.
ClickFix Phishing Campaign Targets Booking.com Using Infostealers and RATs
A sophisticated ClickFix phishing campaign uses fake Booking.com emails to deliver infostealers and RATs, targeting hospitality businesses. Strong security measures are crucial.
Volt Typhoon Energy Grid Cyberattack Exposes US Infrastructure Vulnerabilities
The Volt Typhoon advanced persistent threat (APT) group maintained access to a Massachusetts power utility's OT network for almost a year, highlighting critical infrastructure vulnerabilities.
Australian Financial Firm FIIG Securities Faces Lawsuit After Massive Financial Data Breach
FIIG Securities faces legal action from ASIC for inadequate cybersecurity, leading to a data breach exposing 18,000 clients' sensitive information. The breach highlights the critical ...
Exploring the Dark Web: Unveiling the Hidden Internet 🌐💻
Ever wondered what lies beneath the surface of the internet? 🤔 In this deep dive, we uncover the mysteries of the Dark Web—a hidden part ...
Security vulnerabilities: Key Steps for secure Workflows
Ever wondered how sensitive credentials—like API keys, passwords, and certificates—end up scattered across your systems? 🤔 This hidden cybersecurity risk, known as secret sprawl, makes ...
The Hidden Threat of Wi-Fi Tracking: How Your Devices Reveal Your Location
Did you know your phone is constantly mapping Wi-Fi hotspots around you—even when you’re not using GPS? In this deep dive, we uncover the unsettling ...
MassJacker Malware: Clipboard Hijacking Malware Tartgets 778,000 CryptoWallets
MassJacker malware uses clipboard hijacking to steal cryptocurrency from 778,000 wallets, highlighting sophisticated obfuscation and a potentially massive financial impact.
Cyberattack on Sunflower Medical Group and Multiple Healthcare Providers Suffer Data Breaches
Multiple healthcare providers suffered significant cyberattacks and data breaches in 2025, exposing sensitive patient information, highlighting the urgent need for enhanced cybersecurity measures.
Rhode Island’s Community Care Alliance Data Breach Exposes 114K Records, Central Texas Pediatric Orthopedics and Whitman Hospital Report Cyberattacks
Community Care Alliance Data Breach with 114,975 Records Exposed, Central Texas Pediatric Orthopedics and Whitman Hospital Report Cyberattacks
PowerSchool Hacked Way Back in August, Before December’s Data Breach
PowerSchool's December 2024 data breach was preceded by hacks in August and September, exposing sensitive data for millions of students and teachers. A CrowdStrike investigation ...
Hillcrest Convalescent Center, Bay Cove Human Services and SMC Corporation of America Report Data Breaches
Hillcrest Convalescent Center, Bay Cove Human Services and SMC Corporation of America have all reported Data Breaches
Zero Trust & Data Security: The Future of Protecting Government Information
In this episode, we dive into a crucial topic—data security for government agencies. With evolving cyber threats, traditional security measures no longer cut it. We ...
X Hit by Cyberattack: DDoS Assault by Dark Storm Group Causes Worldwide Outages
X faced a massive cyberattack, with Dark Storm claiming responsibility for a significant DDoS assault, causing widespread outages and prompting the use of Cloudflare's DDoS ...
Elon Musk Claims ‘Massive Cyberattack’ on X Originated from Ukraine
Elon Musk confirmed a massive cyberattack on X, originating from the Ukraine area, causing widespread service disruptions and highlighting the vulnerability of major tech platforms.
New York Sues Allstate and National General Over Data Breaches
New York sues Allstate and National General for failing to protect consumer data, resulting in two major data breaches exposing thousands of driver's license numbers.
Cl0p Ransomware Published Rackspace Files on Leak Site
Cl0p ransomware publishes Rackspace files after ignored demands, exposing hundreds of Cleo victims. This data breach highlights the ongoing threat to enterprise and cloud security.
WordPress Vulnerability Expolited to Hack Moroccan Data Protection Authority Website
Morocco's data protection authority website suffered a WordPress plugin vulnerability exploit, resulting in reputational damage despite no sensitive data loss.
Japanese telco NTT Communications hacked hackers accessed details of almost 18,000 organizations
panese telecommunications giant NTT Communications Corporation (NTT Com) has disclosed a data breach affecting information from nearly 18,000 corporate clients. The breach was identified on ...