Cyber Security
Sandworm Fake Job Interview Campaign Targets Ukrainian IT Workers
Kimwolf v7 Android Botnet Evades DDoS Mitigation Using HTTP/2 C2
SharePoint RCE CVE-2026-55040 First Confirmed Ransomware Exploit
Polish Power Plant Turbine Stopped After Cellular ICS Network Breach
Metabase Zero-Day SQL Injection Exploited Against Framework, Tally
Attackers Reach Managed Endpoints as N-able Ships N-central Hotfix 2
CISA Adds Exploited Kemp LoadMaster Command Injection to KEV
Atlassian Rovo One-Click Flaw Exposes Jira, Confluence Data
CSS Attacks Break Webmail Boundaries to Capture Passwords, Tokens
Head Mare Breaches TrueConf Servers, Trojanizes Client Installers
Belgian Connective eID Flaws Let Websites Forge Signatures
Solidity Pro VS Code Extensions Steal Wallets, API Keys From Devs
OpenAI Pauses Astra Work After Evaluation Flags Cyber Capabilities
AitM Phishing Campaign Steals Microsoft 365 Finance Emails
Swiss Government SharePoint Breach Compromised 200 Accounts
UNC6671 Extortion Group Rebrands After Targeting Hedge Funds
3.8 Million Impacted by Unlimited Technology Systems Breach
4,407 Rockwell PLCs Exposed Online, 22 in Water Cities
Zapscape KVM Flaw Lets Privileged L1 Guest Escape to Host
TONTOU Interrupt Injection Bypasses Spectre v2 Fixes on AMD Zen 2
NatJack Attacks Hijack TCP Sessions and Spoof DNS via NAT
Claude Code and Gemini CLI Flaws Expose CI Workflow Secrets
AI-Assisted HTTP Terminator Finds Apache Traffic Server Zero-Day
TeamPCP Tied to Redis Attacks Dating Back to 2020
CryptoJS Weak RNG Behind $5.7M in Five Wallet App Drains
iCloud Private Relay WebKit Bypasses Expose Users’ Real IPs
ClickFix Campaign Pushes Go-Based macOS Crypto Drainer
China Launches Probe Into Palo Alto Networks Product Security
Attackers Compile khunt Inside Oracle to Reach Windows SYSTEM
Zbtlink Routers Ship With ENDLESSDOORS Backdoor Opening Root Shells
Maxar Space Systems Data Breach: Employee Data Compromised
News
Maxar Space Systems Data Breach: Employee Data Compromised
Maxar Space Systems suffered a data breach exposing employee personal data, including Social Security numbers and addresses. The hacker, using a Hong Kong-based IP, accessed ...
Ford Customer Data Breach: Threat Actors Claim Exfiltration of Internal Database
News
Ford Customer Data Breach: Threat Actors Claim Exfiltration of Internal Database
A threat actor claims a Ford Motor Company data breach, exposing 44,000 customer records including names, addresses, and purchase details. Ford has yet to comment.
Sitting Ducks Cyber Attacks: 800,000+ Domains at Risk
News
Sitting Ducks Cyber Attacks: 800,000+ Domains at Risk
A new report reveals over 800,000 domains are vulnerable to "Sitting Ducks" cyberattacks, a DNS hijacking technique used by cybercriminals to gain control of websites ...
TEAM Software Data Breach Exposes Sensitive Information of Nearly 100,000 Individuals
News
TEAM Software Data Breach Exposes Sensitive Information of Nearly 100,000 Individuals
A data breach at TEAM Software exposed the sensitive personal information of approximately 99,525 individuals, including Social Security numbers, driver's license numbers, and medical information. ...
T-Mobile Data Breach Confirmed Amidst Wave of Telecom Hacks
News
T-Mobile Data Breach Confirmed Amidst Wave of Telecom Hacks
T-Mobile confirms a data breach in a recent wave of attacks targeting US telecom companies. Learn about the extent of the T-Mobile hack and the ...
Hungary Defense Procurement Agency Hacked by INC Ransomware
News
Hungary Defense Procurement Agency Hacked by INC Ransomware
Hungarian officials confirmed a cyberattack on its defense procurement agency, with the INC Ransomware group claiming responsibility and demanding a $5 million ransom. Sensitive procurement ...
Mirai Malware Spreads Via GeoVision Zero-Day Exploit
News
Mirai Malware Spreads Via GeoVision Zero-Day Exploit
A Mirai malware botnet is leveraging a zero-day vulnerability (CVE-2024-11120) in outdated GeoVision devices to deploy malware, potentially for DDoS attacks or cryptomining. Thousands of ...
This Week In Cybersecurity: 11th November to 15th November
Cybersecurity
This Week In Cybersecurity: 11th November to 15th November
Stop and Shop Parent Company ‘Ahold Delhaize’ hit by Cyberattack Ahold Delhaize confirmed a significant cyberattack impacting its U.S. network, ...
300,000 Patients Impacted by Major Law Firm Data Breach at Thompson Coburn
News
300,000 Patients Impacted by Major Law Firm Data Breach at Thompson Coburn
A massive law firm data breach exposed the personal information of 300,000 patients, leading to a class-action lawsuit highlighting cybersecurity failures and the high value ...
₹2,000 Crore WazirX Cyberattack Culprit Arrested
Cybersecurity
₹2,000 Crore WazirX Cyberattack Culprit Arrested
A Bengal man, SK Masud Alam, has been arrested by Delhi Police in connection with the ₹2,000 crore WazirX cyberattack. The investigation highlights vulnerabilities in ...
Alltech Consulting Data Breach Exposes Over 216,000 Job Seekers' Personal Information
News
Alltech Consulting Data Breach Exposes Over 216,000 Job Seekers’ Personal Information
Alltech Consulting, a recruitment firm, suffered a major data breach exposing personal information of over 216,000 job seekers. The breach was uncovered by cybersecurity researcher ...
Volt Typhoon Rebuilds Malware Botnet After FBI Disruption
News
Volt Typhoon Rebuilds Malware Botnet After FBI Disruption
The Chinese state-sponsored hacking group Volt Typhoon has successfully rebuilt its KV-Botnet malware botnet, targeting outdated Cisco and Netgear routers, despite an FBI disruption earlier ...
Stop and Shop Parent Company Ahold Delhaize hit by Cyberattack
News
Stop and Shop Parent Company ‘Ahold Delhaize’ hit by Cyberattack
Ahold Delhaize, parent company of Stop & Shop and Hannaford, confirms a significant cybersecurity incident impacting its US network. Learn about the ongoing disruption and ...
Set Forth Data Breach: 1.5 Million Individuals Affected by Cyberattack
News
Set Forth Data Breach: 1.5 Million Individuals Affected by Cyberattack
Debt relief company Set Forth suffered a major data breach, exposing the sensitive personal information of roughly 1.5 million individuals. The cyberattack compromised crucial data.
SelectBlinds Data Breach: 200,000 Customers Impacted by E-Skimming Attack
News
SelectBlinds Data Breach: 200,000 Customers Impacted by E-Skimming Attack
The SelectBlinds data breach exposed 206,238 customers' payment card details and personal information via a sophisticated e-skimming attack lasting nearly nine months.
Halliburton Ransomware Attack Costs Energy Giant $35 Million
News
Halliburton Ransomware Attack Costs Energy Giant $35 Million
Halliburton's August ransomware attack crippled IT systems, causing $35 million in losses and highlighting the vulnerability of even the largest corporations to cyber threats. The ...
Halliburton Confirms Data Breach in Recent Cyberattack
News
Halliburton Confirms Data Breach in Recent Cyberattack
Oil Giant Halliburton Confirms RansomHub Involvement in Data Breach in its Latest SEC Filing Oil and gas giant Halliburton has ...
Amazon Data Breach: Employee Information Exposed After Vendor Hack
News
Amazon Data Breach: Employee Information Exposed After Vendor Hack
A massive Amazon data breach exposes millions of employee records after a third-party vendor was compromised. Learn about the extent of the breach and the ...
Schneider Electric Dev Platform Hack Confirmed 400k Rows of User Data Stolen
News
Schneider Electric Dev Platform Hack Confirmed: 400k Rows of User Data Stolen
Schneider Electric, a global leader in energy management and automation solutions, recently confirmed it was targeted by the Hellcat ransomware ...
Palo Alto Networks PAN-OS RCE Vulnerability
News
Palo Alto Networks PAN-OS Remote Code Execution Vulnerability Advisory
On November 6, 2024, Palo Alto Networks published a security advisory in response to claims regarding a potential remote code ...
Application Security
SAP Patches Zero-Day in Commerce Cloud Data Hub Adapter
Cybersecurity
Gunra Ransomware Exploits Fortinet and Schneider Flaws for MFA Bypass
Application Security
SharePoint RCE CVE-2026-55040 First Confirmed Ransomware Exploit

TOP CYBERSECURITY HEADLINES

This Week’s Security Spotlight

Trending

Daily Briefing Newsletter

Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Featured Videos​

Podcasts

Sorry, we couldn't find any posts. Please try a different search.

  • All
  • Application Security
  • Blog
  • CVE Vulnerability Alerts
  • Cybersecurity
  • Cybersecurity Newsletter
  • Data Security
  • Endpoint Security
  • Identity and Access Management
  • Information Security
  • Network Security
  • News
  • Phishing
  • Podcasts
  • Product Reviews
  • Ransomware
  • Ransomware Victims
  • Resources
  • Security Spotlight
  • Sponsored
  • Threat Actors
  • Threat Actors
  • Threat Detection Tools
Urgent Security Update: Authentication Bypass Vulnerability in VMware Tools for Windows (CVE-2025-22230)
Critical VMware Tools vulnerability (CVE-2025-22230) enables privilege escalation on Windows VMs. Immediate patching is paramount for enterprise security.
South Carolina Eye Clinic Suffers Data Breach: Ransomware Suspected
Columbia Eye Clinic in South Carolina suffered a data breach, potentially a ransomware attack, exposing patient data including names, contact information, and procedure codes.
Sydney Tools Data Breach Exposes 34 Million+ Customer Orders
A massive data breach at Sydney Tools exposed over 34 million customer orders and sensitive employee data, including names, addresses, and salaries. The unsecured database ...
Numotion Data Breach Impacts Nearly 500,000 Individuals
Numotion's latest data breach exposed the personal and health information of nearly 500,000 individuals, following a series of similar incidents, leading to multiple lawsuits.
Cloudflare R2 Service Outage: A Case Study in Human Error and System Design
Cloudflare's R2 service suffered a 77-minute outage due to a password rotation error, highlighting the risks of human error in cloud infrastructure.
Cyberattack Roundup: Lessons from the Latest Breaches & Ransomware Strikes
From data breaches at major banks to ransomware crippling healthcare and tech companies, cyber threats are hitting harder than ever. In this episode, we break ...
Mastering Incident Response: A Guide to Building a Resilient Plan
Cyber threats are inevitable, but a strong incident response plan can make all the difference. In this episode, we explore the essential steps for creating ...
Next.js Flaw Allows Unauthorized Access
Critical Next.js vulnerability (CVE-2025-29927) lets attackers bypass authorization, impacting versions before 15.2.3. Urgent updates are needed.
Ukraine Railway Hit by Cyberattack: Online Systems Disrupted
A major cyberattack targeted Ukraine's railway system, disrupting online services but not train operations. Restoration efforts are ongoing.
Chinese Weaver Ant Hackers Spied on Telco Network for Four Years
Chinese Weaver Ant hackers infiltrated a telecom network for over four years, using advanced techniques like web shell tunneling and data exfiltration.
Astral Foods Cyberattack: R20 Million Profit Plunge
Astral Foods suffered a cyberattack causing a R20 million profit loss and operational disruption. Swift recovery was implemented, but the incident highlights the need for ...
VanHelsing Ransomware Targets Multiple Platforms Including Windows and ESXi Systems
The new VanHelsing ransomware targets various systems, employing advanced encryption techniques and demanding ransoms up to $500,000 from its victims.
INTERPOL Operation Red Card Nets 300 Cybercrime Suspects in Africa
INTERPOL's Operation Red Card resulted in the arrest of 306 cybercrime suspects across seven African nations, seizing thousands of devices used in various scams.
Oracle Cloud Breach Compromises 6 Million Records, Threatening 140,000 Businesses
A massive Oracle Cloud breach exposed 6 million records, impacting 140,000 businesses. The attacker, "rose87168," is selling the data and demanding ransoms.
NYU Data Breach: Class Action Lawsuit Investigation Underway
NYU's March 2025 data breach exposed millions of applicants' personal data, prompting a class action lawsuit investigation. Attorneys seek to recover compensation for affected individuals.
Microsoft’s Trusted Signing Service Abused to Code-Sign Malware
Microsoft's Trusted Signing service is being abused to code-sign malware using short-lived certificates. This allows malicious software to bypass security and appear legitimate. Microsoft is ...
10 Key Benefits of Cyber Tabletop Exercises
Regular cybersecurity tabletop exercises are crucial for identifying weaknesses and strengthening your defenses. This blog explores the ten major advantages of incorporating these simulations into ...
Coinbase Targeted in GitHub Actions Breach
A major GitHub Actions breach targeted Coinbase, exploiting the tj-actions/changed-files action to steal secrets. Although Coinbase claims no damage, the attack highlights supply chain vulnerabilities.
CISA Says NAKIVO Backup Flaw is Actively Exploited in Attacks
CISA warns of a critical NAKIVO backup flaw, CVE-2024-48248, allowing unauthorized file access, urging organizations to patch systems promptly.
GitHub Supply Chain Attack Exposes Secrets in 218 Repositories
A GitHub Action supply chain attack exposed secrets from 218 repositories due to malicious code in tj-actions/changed-files, impacting popular projects and potentially causing further supply ...