Cyber Security
Sandworm Fake Job Interview Campaign Targets Ukrainian IT Workers
Kimwolf v7 Android Botnet Evades DDoS Mitigation Using HTTP/2 C2
SharePoint RCE CVE-2026-55040 First Confirmed Ransomware Exploit
Polish Power Plant Turbine Stopped After Cellular ICS Network Breach
Metabase Zero-Day SQL Injection Exploited Against Framework, Tally
Attackers Reach Managed Endpoints as N-able Ships N-central Hotfix 2
CISA Adds Exploited Kemp LoadMaster Command Injection to KEV
Atlassian Rovo One-Click Flaw Exposes Jira, Confluence Data
CSS Attacks Break Webmail Boundaries to Capture Passwords, Tokens
Head Mare Breaches TrueConf Servers, Trojanizes Client Installers
Belgian Connective eID Flaws Let Websites Forge Signatures
Solidity Pro VS Code Extensions Steal Wallets, API Keys From Devs
OpenAI Pauses Astra Work After Evaluation Flags Cyber Capabilities
AitM Phishing Campaign Steals Microsoft 365 Finance Emails
Swiss Government SharePoint Breach Compromised 200 Accounts
UNC6671 Extortion Group Rebrands After Targeting Hedge Funds
3.8 Million Impacted by Unlimited Technology Systems Breach
4,407 Rockwell PLCs Exposed Online, 22 in Water Cities
Zapscape KVM Flaw Lets Privileged L1 Guest Escape to Host
TONTOU Interrupt Injection Bypasses Spectre v2 Fixes on AMD Zen 2
NatJack Attacks Hijack TCP Sessions and Spoof DNS via NAT
Claude Code and Gemini CLI Flaws Expose CI Workflow Secrets
AI-Assisted HTTP Terminator Finds Apache Traffic Server Zero-Day
TeamPCP Tied to Redis Attacks Dating Back to 2020
CryptoJS Weak RNG Behind $5.7M in Five Wallet App Drains
iCloud Private Relay WebKit Bypasses Expose Users’ Real IPs
ClickFix Campaign Pushes Go-Based macOS Crypto Drainer
China Launches Probe Into Palo Alto Networks Product Security
Attackers Compile khunt Inside Oracle to Reach Windows SYSTEM
Zbtlink Routers Ship With ENDLESSDOORS Backdoor Opening Root Shells
China Denies State-Sponsored Cyberattack on US Treasury
News
China Denies State-Sponsored Cyberattack on US Treasury
China denies US accusations of a state-sponsored cyberattack on US Treasury, calling the claims "groundless," while the US points to a compromised third-party service provider.
Pro-Russian Hackers NoName057 Launch Coordinated Cyberattacks Against Italy
News
Pro-Russian Hackers NoName057 Launch Coordinated Cyberattacks Against Italy
: Pro-Russian hackers NoName057 targeted Italian websites, including Milan airports, in a series of DDoS attacks.
Massive Healthcare Breaches Prompt Overhaul of US Cybersecurity Rules
Cybersecurity
Massive Healthcare Breaches Prompt Overhaul of US Cybersecurity Rules
The US is overhauling its cybersecurity rules following a surge in healthcare breaches. New regulations will mandate encryption, multi-factor authentication, and network segmentation to protect ...
Harley-Davidson Data Breach Exposes Thousands of Customer Records: 888 Claims Cyberattack
News
Harley-Davidson Data Breach Exposes Thousands of Customer Records: 888 Claims Cyberattack
Harley-Davidson data breach has allegedly exposed the personal information of over 66,700 customers. Learn about the leaked data and the potential risks.
US Treasury Department Hacked: Cyber Attack On US Treasury Blamed on Chinese State-Sponsored Actors
News
US Treasury Department Hacked: Cyber Attack On US Treasury Blamed on Chinese State-Sponsored Actors
The US Treasury Department was hacked, with Chinese state-sponsored actors gaining access to employee workstations and unclassified documents. Learn
AT&T and Verizon Secure Networks Following Devastating Salt Typhoon Breach
News
AT&T and Verizon Secure Networks Following Devastating Salt Typhoon Breach
The Salt Typhoon breach impacted AT&T and Verizon, but both companies claim to have successfully contained the Chinese state-sponsored hacking campaign and secured their networks. ...
Japan Airlines Cyberattack Causes Flight Delays
News
Japan Airlines Cyberattack Causes Flight Delays
A distributed denial-of-service (DDoS) attack on Japan Airlines (JAL) caused significant flight delays, highlighting the vulnerability of the aviation industry to cyber threats. Learn about ...
OpenAI ChatGPT Outage: Thousands Report Disruption
News
OpenAI ChatGPT Outage: Thousands Report Disruption
OpenAI ChatGPT outage hit on December 26th, 2024, impacting millions of users. Downdetector showed over 50,000 outage reports. OpenAI attributed the problem to an internet ...
Volkswagen Data Breach Exposes Location Data of 800,000 Electric Vehicles
News
Volkswagen Data Breach Exposes Location Data of 800,000 Electric Vehicles
A data breach at Volkswagen has exposed the location data of around 800,000 electric vehicles from VW, Audi, Seat, and Skoda. The vulnerability, reported by ...
USAA Bank Data Breach Lawsuit Settles for $3.25 Million
News
USAA Bank Data Breach Lawsuit Settles for $3.25 Million
USAA Bank paid $3.25 million to settle a data breach lawsuit stemming from a 2021 incident exposing customer data obtained from motor vehicle records. The ...
Indonesia Government Data Breach: 82 GB of Sensitive Data Leaked Online
News
Indonesia Government Data Breach: 82 GB of Sensitive Data Leaked Online
Indonesia government data breach leaked 82 GB of sensitive data, including financial records, taxpayer information, and employee details, raising serious security and privacy concerns.
News
ConnectOnCall Healthcare Data Breach Exposes Sensitive Healthcare Information
A massive data breach at ConnectOnCall, a healthcare communications provider, has exposed sensitive patient information, raising serious concerns about data security in the healthcare sector.
Kay Adams' NFL Broadcast Interrupted by Netflix Technical Glitch
News
Kay Adams’ NFL Broadcast Interrupted by Netflix Technical Glitch
Kay Adams' NFL broadcast on Netflix was disrupted due to a technical glitch on Christmas Day, leaving viewers frustrated and highlighting the challenges of streaming ...
WhatsApp Wins Against NSO Group: Judge Finds NSO Liable for Pegasus
Cybersecurity
WhatsApp Wins Against NSO Group: Judge Finds NSO Liable for Pegasus
WhatsApp secured a major legal victory against NSO Group, creators of Pegasus spyware, with a US court ruling them liable for hacking 1,400 devices. This ...
Ascension Cyberattack Update: New Details Emerge, Patient and Employee Data Exposed
News
Ascension Cyberattack Update: New Details Emerge, Patient and Employee Data Exposed
A new update reveals the full extent of the June Ascension cyberattack, exposing patient and employee data including medical records, payment information, and Social Security ...
Halton Long-Term Care Home Breach Exposes Resident Data
News
Halton Long-Term Care Home Breach Exposes Resident Data
A cybersecurity incident at Allendale Long-Term Care Home in Milton, overseen by Halton Region, exposed the health information of residents from 2005 to July 2024. ...
Krispy Kreme Breach: Play Ransomware Gang Claims Data Theft, Threatens Data Leak
News
Krispy Kreme Breach: Play Ransomware Gang Claims Data Theft, Threatens Data Leak
The Play ransomware gang claims responsibility for a November Krispy Kreme data breach, alleging theft of sensitive customer and financial data. Krispy Kreme confirmed operational ...
2nd Equifax Data Breach Settlement: Additional Pro Rata Payments Now Available
News
2nd Equifax Data Breach Settlement: Additional Pro Rata Payments Now Available
Equifax data breach settlement is distributing additional pro rata payments to eligible individuals. Claimants who received a verified email with instructions on how to redeem ...
Duke Energy Data Breach Exposes Customer Information: What You Need to Know
News
Duke Energy Data Breach Exposes Customer Information: What You Need to Know
Duke Energy confirms a data breach exposing customer account numbers, birthdates, addresses, and partial Social Security numbers. Free credit monitoring is offered.
Meezan Bank Data Breach: Bank Compensates Victims, Highlights Third-Party Security Risks
News
Meezan Bank Data Breach: Bank Compensates Victims, Highlights Third-Party Security Risks
Meezan Bank, a PCI-certified bank with EMV and 3D Secure compliant cards, clarifies its position on recent unauthorized transactions, attributing them to unsecured e-commerce activities. ...
Application Security
SAP Patches Zero-Day in Commerce Cloud Data Hub Adapter
Cybersecurity
Gunra Ransomware Exploits Fortinet and Schneider Flaws for MFA Bypass
Application Security
SharePoint RCE CVE-2026-55040 First Confirmed Ransomware Exploit

TOP CYBERSECURITY HEADLINES

This Week’s Security Spotlight

Trending

Daily Briefing Newsletter

Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Featured Videos​

Podcasts

Sorry, we couldn't find any posts. Please try a different search.

  • All
  • Application Security
  • Blog
  • CVE Vulnerability Alerts
  • Cybersecurity
  • Cybersecurity Newsletter
  • Data Security
  • Endpoint Security
  • Identity and Access Management
  • Information Security
  • Network Security
  • News
  • Phishing
  • Podcasts
  • Product Reviews
  • Ransomware
  • Ransomware Victims
  • Resources
  • Security Spotlight
  • Sponsored
  • Threat Actors
  • Threat Actors
  • Threat Detection Tools
Cybercrime Losses in the U.S. Reached $16.6 Billion in 2024, FBI Reports
Cybercrime losses in the U.S. hit $16.6 billion in 2024, with older adults and businesses suffering the most, according to new FBI complaint data.
Marks & Spencer Cyberattack Disrupts Services and Delays Customer Orders
Marks & Spencer confirms a cyberattack disrupting services, leading to delayed orders and affecting contactless payments, while assuring customers of ongoing efforts to resolve the ...
Qilin Ransomware: Tactics, Techniques, Procedures and Mitigation
Qilin ransomware, a potent threat emerging in 2022, has rapidly gained notoriety. This blog post delves into its advanced tactics, techniques, and procedures (TTPs), providing ...
Cookie-Bite Attack Uses Chrome Extension to Steal Microsoft Session Tokens and Bypass MFA
Varonis researchers reveal Cookie-Bite, a proof-of-concept Chrome extension attack that steals Azure Entra ID session cookies to bypass MFA and access Microsoft 365 services.
SK Telecom Malware Incident Targets USIM Customer Data
SK Telecom has disclosed a malware attack that exposed sensitive USIM data, prompting swift containment, investigation, and enhanced security measures for its 34 million subscribers. ...
Baltimore City Public Schools Data Breach Impacts 25,000 Individuals After Ransomware Attack
Baltimore City Public Schools confirms 25,000 people were impacted by a February ransomware attack that exposed sensitive employee and student information, including identification documents.
Active! Mail Zero-Day RCE Vulnerability Exploited in Ongoing Attacks on Japanese Organizations
A zero-day flaw in Active! Mail is under active exploitation in Japan, affecting major providers and exposing data across enterprise, education, and government sectors.
The Second Scam: FBI Warns of IC3 Impersonators Targeting Fraud Victims
The FBI has issued a stark warning about a growing scam targeting individuals who’ve already been victimized. In this episode, we unpack how fraudsters are ...
Ad Fraud Operation ‘Scallywag’ Used WordPress Plugins to Generate 1.4 Billion Daily Ad Requests
The Scallywag ad fraud network used WordPress plugins to generate 1.4 billion daily ad requests, monetizing piracy and redirect sites before being dismantled.
FBI Warns of IC3 Impersonation Scam Targeting Victims of Online Fraud
The FBI warns of a scam where criminals impersonate IC3 officials, targeting prior fraud victims with false promises of fund recovery to steal financial information. ...
Abilene, Texas Shuts Down City Systems Following Cyberattack
Abilene, Texas has taken key systems offline after a cyberattack. City services are disrupted but emergency response remains intact. Investigation and recovery efforts continue.
Imaflex Inc. Data Breach Exposes Personal and Employment Data
Imaflex Inc. Data Breach Exposes Personal and Employment Data: Legal Investigation Underway Imaflex Inc. has disclosed a data breach that exposed sensitive personal and employment-related ...
Google Confirms Sophisticated Phishing Attack Targeting Gmail Users Through DKIM and OAuth Abuse
Google confirms a phishing campaign targeting Gmail users that abused DKIM and Google Sites to send spoofed legal requests and steal user credentials undetected.
Evil Corp (UNC2165): The Russian Syndicate Behind Global Cyber Chaos
Evil Corp, a prolific Russian cybercrime syndicate, deploys sophisticated malware and ransomware, targeting diverse sectors globally, including healthcare and finance, for financial gain and potential ...
This Week In Cybersecurity: April 1st to 5th, 2025
This week in cybersecurity covers a range of incidents, including the shutdown of openSNP over privacy concerns, a data breach affecting 173,000 patients, and a ...
This Week In Cybersecurity: March 3rd to 7th, 2025
This Week in Cybersecurity: Data Breaches, Ransomware, Threat Actors, Ransomware Protection and more!
Ransomware Victims on Dark Web – 10th March, 2025
This report summarizes recent ransomware attacks across various sectors, detailing the victims, threat actors, and available information on the incidents. Due to the nature of ...
Ransomware Victims on Dark Web – 04th March, 2025
This report summarizes recent ransomware attacks across various sectors, detailing the victims, threat actors, and available information on the incidents. Due to the nature of ...
Ransomware Victims on Dark Web – 05th March, 2025
This report summarizes recent ransomware attacks across various sectors, detailing the victims, threat actors, and available information on the incidents. Due to the nature of ...
Ransomware Victims on Dark Web – 06th March, 2025
This report summarizes recent ransomware attacks across various sectors, detailing the victims, threat actors, and available information on the incidents. Due to the nature of ...