Cyber Security
Sandworm Fake Job Interview Campaign Targets Ukrainian IT Workers
Kimwolf v7 Android Botnet Evades DDoS Mitigation Using HTTP/2 C2
SharePoint RCE CVE-2026-55040 First Confirmed Ransomware Exploit
Polish Power Plant Turbine Stopped After Cellular ICS Network Breach
Metabase Zero-Day SQL Injection Exploited Against Framework, Tally
Attackers Reach Managed Endpoints as N-able Ships N-central Hotfix 2
CISA Adds Exploited Kemp LoadMaster Command Injection to KEV
Atlassian Rovo One-Click Flaw Exposes Jira, Confluence Data
CSS Attacks Break Webmail Boundaries to Capture Passwords, Tokens
Head Mare Breaches TrueConf Servers, Trojanizes Client Installers
Belgian Connective eID Flaws Let Websites Forge Signatures
Solidity Pro VS Code Extensions Steal Wallets, API Keys From Devs
OpenAI Pauses Astra Work After Evaluation Flags Cyber Capabilities
AitM Phishing Campaign Steals Microsoft 365 Finance Emails
Swiss Government SharePoint Breach Compromised 200 Accounts
UNC6671 Extortion Group Rebrands After Targeting Hedge Funds
3.8 Million Impacted by Unlimited Technology Systems Breach
4,407 Rockwell PLCs Exposed Online, 22 in Water Cities
Zapscape KVM Flaw Lets Privileged L1 Guest Escape to Host
TONTOU Interrupt Injection Bypasses Spectre v2 Fixes on AMD Zen 2
NatJack Attacks Hijack TCP Sessions and Spoof DNS via NAT
Claude Code and Gemini CLI Flaws Expose CI Workflow Secrets
AI-Assisted HTTP Terminator Finds Apache Traffic Server Zero-Day
TeamPCP Tied to Redis Attacks Dating Back to 2020
CryptoJS Weak RNG Behind $5.7M in Five Wallet App Drains
iCloud Private Relay WebKit Bypasses Expose Users’ Real IPs
ClickFix Campaign Pushes Go-Based macOS Crypto Drainer
China Launches Probe Into Palo Alto Networks Product Security
Attackers Compile khunt Inside Oracle to Reach Windows SYSTEM
Zbtlink Routers Ship With ENDLESSDOORS Backdoor Opening Root Shells
GGG Data Breach: Path of Excile 2 Dev Grinding Gear Games Apologizes for Security Lapse
News
GGG Data Breach: Path of Excile 2 Dev Grinding Gear Games Apologizes for Security Lapse
Grinding Gear Games revealed a Path of Exile 2 data breach, compromising 66 accounts and potentially exposing personal information like emails and addresses. The developer ...
Telefonica Breach Exposes 20,000 Employees' Data and Jira Details: Hellcat Ransomware's Infostealer Malware at Play
News
Telefonica Breach Exposes 20,000 Employees’ Data and Jira Details: Hellcat Ransomware’s Infostealer Malware at Play
Telefonica breach impacts 20,000 employees through customer data theft and infostealer malware tactics in this detailed analysis.
WazirX Hack: North Korea's Lazarus Blamed for WazirX's $235 Million Cryptocurrency Theft
News
WazirX Hack: North Korea’s Lazarus Blamed for WazirX’s $235 Million Cryptocurrency Theft
The US, Japan, and South Korea blame North Korea's Lazarus group for the WazirX hack, a $235 million cryptocurrency theft. WazirX CEO calls for global ...
PowerSchool Data Breach Exposes Social Security Numbers of 60 Million Students and Teachers
News
PowerSchool Data Breach Exposes Social Security Numbers of 60 Million Students and Teachers
PowerSchool data breach cyberattack exposed SSNs and PII of 60 million students and teachers, including medical information.
West Haven, Connecticut, Battles a Devastating Qilin Ransomware Cyberattack
News
West Haven, Connecticut, Battles a Devastating Qilin Ransomware Cyberattack
West Haven, Connecticut, is recovering from a cyberattack attributed to the Qilin ransomware group, which temporarily shut down city IT systems. The investigation is ongoing ...
Manitou Springs School District 14 Joins District 49 in PowerSchool Data Breach
News
Manitou Springs School District 14 Joins District 49 in PowerSchool Data Breach
Manitou Springs District 14 and District 49 experienced a PowerSchool data breach exposing student and parent names and addresses. PowerSchool is investigating with cybersecurity experts. ...
Ransomware Attack Paralyzes Slovakian Land Registry, Souring Slovakia-Ukraine Relations
News
Ransomware Attack Paralyzes Slovakian Land Registry, Souring Slovakia-Ukraine Relations
A ransomware attack has severely impacted Slovakia's Geodesy, Cartography and Cadastre Office (UGKK), causing widespread disruption to land registry services and related public functions. The ...
Pro-Russian Hacker Group Targets Italian Banks and Public Services in DDoS Attacks
News
Pro-Russian Hacker Group Targets Italian Banks and Public Services in DDoS Attacks
A wave of cyberattacks on Italian banks, including Intesa Sanpaolo and Monte dei Paschi, along with public services, were launched by the pro-Russian hacker group, ...
Gravy Analytics Data Breach Exposes Location Data: iOS 14.5 and App Tracking Transparency Offer Some Protection
News
Gravy Analytics Data Breach Exposes Location Data: iOS 14.5 and App Tracking Transparency Offer Some Protection
The Gravy Analytics data breach exposed the precise location information of millions of users, impacting both iOS and Android devices. Popular apps, including dating apps ...
Top 10 Ransomware Groups of 2024 The Year's Most Active Cyber Threats
Blog
Top 10 Ransomware Groups of 2024: The Year’s Most Active Cyber Threats
This in-depth analysis reveals the Top 10 Ransomware groups that dominated the cyberattack landscape in 2024, examining their methods, impact on businesses, and the implications ...
PowerSchool Data Breach: Millions of Student Records Compromised in January 2025
News
PowerSchool Data Breach: Millions of Student Records Compromised in January 2025
PowerSchool had a data breach in December 2025, compromising the personal data of millions of students and parents. Hackers exploited stolen credentials to access sensitive ...
Vermont School Breached in PowerSchool Hack
News
Vermont School Breached in PowerSchool Hack
PowerSchool data breach exposed the personal data of Vermont school students and staff. The impact varies, but cybersecurity concerns are high. Schools are taking steps ...
This Week In Cybersecurity: 06th January to 10th January
News
This Week In Cybersecurity: 06th January to 10th January
Casio Data Breach Ransomware Attack Compromised 8,500 Individuals A ransomware attack on Casio in October 2024 compromised personal data of ...
PowerSchool Data Breach Impacts Bozeman Public Schools
News
PowerSchool Data Breach Impacts Bozeman Public Schools
PowerSchool data breach impacted Bozeman Public Schools, compromising student, family, and teacher data including contact details and employment information. PowerSchool and the district are working ...
PowerSchool Data Breach Hits Louisiana School Districts: Ascension Parish Schools, Livingston Parish Schools Among the Ones Affected
News
PowerSchool Data Breach Hits Louisiana School Districts: Ascension Parish Schools, Livingston Parish Schools Among the Ones Affected
PowerSchool data breach impacted Louisiana school districts, potentially exposing sensitive student and staff information. PowerSchool claims the data has been deleted, but the incident highlights ...
New Mirai Botnet Leverages Zero-Day Exploits to Target Industrial Routers
News
New Mirai Botnet Leverages Zero-Day Exploits to Target Industrial Routers
A new Mirai botnet is using zero-day exploits to target industrial routers and smart home devices, launching high-intensity DDoS attacks. Learn about the vulnerabilities and ...
UK's Nominet Hit by Cyber Attack: Hackers Exploited Zero-Day Ivanti VPN Vulnerability
News
UK’s Nominet Hit by Cyber Attack: Hackers Exploited Zero-Day Ivanti VPN Vulnerability
The UK Internet Domain Registry, Nominet, suffered a cyber attack exploiting a zero-day vulnerability in Ivanti VPN software. While no data breach is confirmed, the ...
BayMark Health Services Data Breach: Ransomware Attack Exposes Patient Data
News
BayMark Health Services Data Breach: Ransomware Attack Exposes Patient Data
BayMark Health Services suffered a significant data breach after a ransomware attack, exposing sensitive patient information. The company is working to mitigate the damage and ...
Medusind Breach Exposes Sensitive Patient Data of Over 360,000 Customers
News
Medusind Breach Exposes Sensitive Patient Data of Over 360,000 Customers
US dental and medical billing firm Medusind suffered a significant data breach, exposing the personal, financial, and medical data of over 360,000 customers. The breach, ...
PowerSchool Hack Compromises Alabama K-12 Student Data
News
PowerSchool Hack Compromises Alabama K-12 Student Data
PowerSchool data breach has affected Alabama K-12 schools, raising concerns about student and teacher data security. The incident highlights the ongoing vulnerability of educational institutions ...
Application Security
SAP Patches Zero-Day in Commerce Cloud Data Hub Adapter
Cybersecurity
Gunra Ransomware Exploits Fortinet and Schneider Flaws for MFA Bypass
Application Security
SharePoint RCE CVE-2026-55040 First Confirmed Ransomware Exploit

TOP CYBERSECURITY HEADLINES

This Week’s Security Spotlight

Trending

Daily Briefing Newsletter

Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Featured Videos​

Podcasts

Sorry, we couldn't find any posts. Please try a different search.

  • All
  • Application Security
  • Blog
  • CVE Vulnerability Alerts
  • Cybersecurity
  • Cybersecurity Newsletter
  • Data Security
  • Endpoint Security
  • Identity and Access Management
  • Information Security
  • Network Security
  • News
  • Phishing
  • Podcasts
  • Product Reviews
  • Ransomware
  • Ransomware Victims
  • Resources
  • Security Spotlight
  • Sponsored
  • Threat Actors
  • Threat Actors
  • Threat Detection Tools
MTN Ghana Data Breach Impacts 5,700 Customers, Investigation Underway
MTN Ghana confirms a data breach affecting 5,700 customers, with investigations ongoing and direct outreach underway to mitigate potential risks and prevent further exposure.
SK Telecom Offers Free SIM Replacements After Malware Breach Impacts USIM Data
SK Telecom is replacing SIM cards for 25 million users after a malware breach exposed USIM data. Supply limits restrict replacements to 6 million by ...
CISA Flags Broadcom, CommVault, and Active! Mail Vulnerabilities as Actively Exploited
CISA adds Broadcom, CommVault, and Active! Mail vulnerabilities to KEV catalog following active exploitation reports, urging immediate patching by enterprise and critical infrastructure operators.
M&S Cyberattack Halts Online Sales, Triggers Major Financial Impact
Marks & Spencer suspended online orders after a cyberattack over Easter weekend caused major disruptions, wiping £500 million off its stock and impacting daily sales. ...
The Silent Majority: Why 51% of Internet Traffic Is Now Bots
The bots have taken over—and they’re not just crawling your website. In this episode, we dig into the alarming reality that automated bots now generate ...
From 1,382 to 4 Million: What VeriSource Didn’t Know (or Say)
In this episode, we investigate the massive data breach at VeriSource Services, Inc. (VSI), a Houston-based HR outsourcing and employee benefits administrator. Initially reported as ...
Actively Exploited: Commvault Web Shells, Active! mail RCE, and Brocade Code Injection Now in KEV
Three actively exploited vulnerabilities—CVE-2025-42599 (Qualitia Active! mail), CVE-2025-3928 (Commvault Web Server), and CVE-2025-1976 (Broadcom Brocade Fabric OS)—have been added to CISA’s KEV catalog. The Qualitia ...
Over 1,200 SAP NetWeaver Servers Exposed to Actively Exploited Critical Vulnerability
A critical SAP NetWeaver flaw (CVE-2025-31324) is being actively exploited. Over 1,200 servers are exposed, with hundreds already compromised by remote webshell deployments.
27 Million Records Allegedly Leaked from French Retailer Boulanger
Personal data linked to over 27 million customer records of French electronics giant Boulanger has been leaked on a public hacking forum, with no ransom ...
Marks & Spencer Cyberattack Tied to Scattered Spider Ransomware Group
Marks & Spencer is battling an ongoing outage caused by Scattered Spider ransomware attackers, who breached its systems, stole password data, and encrypted virtual machines. ...
VeriSource Confirms Data Breach Impacted 4 Million People After Year-Long Investigation
VeriSource Confirms Data Breach Impacted 4 Million People After Year-Long Investigation
Darcula: AI-Enhanced Phishing Platform Targets Users Worldwide
The Darcula phishing platform has been upgraded with AI, enabling cybercriminals to quickly generate multilingual phishing scams and harvest user credentials on a global scale. ...
Major AI Vulnerability Exposed: Single Prompt Grants Full Control
Researchers uncovered a major AI vulnerability allowing attackers to bypass safeguards with a single prompt, gaining control over AI systems to generate dangerous content.
Hard-Coded Havoc: The Fatal Flaws in Planet’s Network Devices
A wave of critical vulnerabilities in Planet Technology’s industrial switches and network management systems could let attackers hijack devices, steal data, and sabotage industrial networks—with ...
Craft CMS Crisis: The 10.0-Rated RCE Flaw Every Developer Must Patch Now
A critical, actively exploited vulnerability (CVE-2025-32432) is wreaking havoc on Craft CMS—allowing attackers to execute arbitrary PHP code on unpatched servers with no authentication required. ...
Policy Puppetry: How a Single Prompt Can Trick ChatGPT, Gemini & More Into Revealing Secrets
Recent research by HiddenLayer has uncovered a shocking new AI vulnerability—dubbed the “Policy Puppetry Attack”—that can bypass safety guardrails in all major LLMs, including ChatGPT, ...
13 Cybersecurity Assumptions That Are Getting You Hacked (And What to Do Instead)
Cybersecurity myths are more dangerous than you think. Here are 13 common myths that are silently sabotaging your security—and what to do instead.
WooCommerce Admins Targeted by Fake Security Patches Delivering WordPress Backdoors
A new phishing campaign is targeting WooCommerce administrators with fake security alerts designed to hijack websites by installing hidden backdoors and persistent malware.
Marks & Spencer Halts Online Orders Following Cyberattack
Marks & Spencer suspended online orders following a cyberattack impacting digital and in-store services, while investigations continue in collaboration with external cybersecurity specialists.
Pro-Russian Hackers NoName Intensify DDoS Attacks Against German Organizations
Pro-Russian hackers NoName057(16) have intensified DDoS attacks against German organizations, targeting banks, manufacturers, and government websites in retaliation for political decisions related to Ukraine.