Cyber Security
Four Nation-State Groups Deploy BlueMoon Kit Within 12 Days
NSA, CISA, FBI Accuse Six Chinese AI Firms of Model Distillation
UNC3569 Exploits Sogou Input Method to Deploy GRAYRABBIT Backdoor
Attackers Use BYOD Weaknesses to Access M365 via Graph API
Surfshark VPN Breach Exposes Internal Testing and Proxy Servers
Citrix NetScaler CVE-2026-19490 Exploited Since September 3
CISA Sets September 12 Deadline for Cisco, Citrix, Fortinet Flaws
Infostealer Logs Expose Replayable AI Tokens That Bypass MFA
Google Patches Seventh Chrome Zero-Day of 2026, CVE-2026-87491
PoisonedRefresh Rootkit Injects PHP Web Shells into F5 BIG-IP Memory
September Windows Server Updates Break Remote Desktop Services
Microsoft Excel KB5002914 Update Breaks Copy and Paste Functions
cPanel Critical RCE Enables Full Server Takeover via Mail Account
SAP Patches CVSS 10.0 Kernel RCE in Extended Passport Processing
Microsoft Ships Record 974 Security Patches in September Batch
ShinyHunters Claims Breach of Florida DMV DAVID Database
Grindr Settles UK HIV Data Sharing Lawsuit for £26 Million
Liquid Network Attackers Return 3,400 Bitcoin, Keep $47 Million
OpenAI Artifactory Flaw Enabled Cross-Account Data Theft
Boston Scientific Cyberattack Damages Q3 and Full-Year Earnings
Ohio Man Sentenced to 15 Years for AI-Generated Sextortion
LG Accused of Privacy Violations Over Smart TV Data Collection
Microsoft Adds Age-Awareness APIs to Windows 11
EU Cyber Resilience Act 24-Hour Vulnerability Deadline Arrives
UK Lawmakers Question Cyber Bill’s Executive Liability Exemption
Welsh Regulator Exposes 2,000 Staff Diversity Records via FoI Error
OpenAI Agent Swarm Logs Reveal Emergent Deception and Coordination
PEEP Toolkit Turns Chrome and Edge Into Post-Exploitation Backdoors
Magento StyleSmuggler Zero-Day Deploys Linux Backdoors on Stores
Mathspace Breach Exposes Data of Over 1 Million Students and Staff
GoodSmile Data Breach: Customers Report Credit Card Theft After Security Compromise
News
GoodSmile Data Breach: Customers Report Credit Card Theft After Security Compromise
Good Smile Company's US store suffered a data breach, resulting in customer credit card theft. The company remains silent, prompting concern and calls for immediate ...
Andrew Tate's Real World Hacked: 800,000 Users Exposed in Andrew Tate leaks
News
Andrew Tate’s Real World Hacked: 800,000 Users Exposed in Data Breach
Andrew Tate's Real World, formerly Hustler's University, suffered a major data breach exposing nearly 800,000 users. Learn about the hack, the leaked data, and how ...
RansomHub Cyberattack: Coppell, Texas, and Minneapolis Agency Targeted
News
RansomHub Cyberattack: Coppell, Texas, and Minneapolis Agency Targeted
RansomHub's ransomware attacks crippled Coppell, Texas, and the Minneapolis Park and Recreation Board, causing widespread system outages and potential data breaches.
Starbucks Cyberattack Leaves Workers Facing Pay Issues and Frustration
News
Starbucks Cyberattack Leaves Workers Facing Pay Issues and Frustration
A ransomware attack on a Starbucks software vendor has caused widespread payroll problems for Starbucks employees, leaving many baristas struggling with delayed and potentially inaccurate ...
LifeLabs Data Breach Report Finally Public After Four-Year Legal Battle
Cybersecurity
LifeLabs Data Breach Report Finally Public After Four-Year Legal Battle
After a four-year legal battle, the report on the 2019 LifeLabs data breach, affecting millions of Canadians, has been released, detailing security failures and the ...
Microsoft 365 Outage: Service Disruption Impacts Exchange Online, Teams, and SharePoint
News
Microsoft 365 Outage: Service Disruption Impacts Exchange Online, Teams, and SharePoint
Microsoft 365 outage severely impacted Exchange Online, Teams, and SharePoint, causing widespread disruption for users globally. Microsoft acknowledged the issue and deployed a fix, but ...
Starbucks and Other Retailers Face Widespread Disruption After Ransomware Attack on Tech Provider
News
Starbucks and Other Retailers Face Widespread Disruption After Ransomware Attack on Tech Provider
A ransomware attack targeting a tech provider crippled Starbucks and other retailers, causing widespread operational disruptions and highlighting cybersecurity vulnerabilities.
Blue Yonder Ransomware Attack Cripples Grocery Store Supply Chains
News
Blue Yonder Ransomware Attack Cripples Grocery Store Supply Chains
Blue Yonder ransomware attack disrupts grocery store supply chains across the UK, impacting major retailers and highlighting vulnerabilities in critical infrastructure.
BianLian Ransomware Updated Advisory: CISA and Australian Agencies Detail Evolving Tactics and Techniques
News
BianLian Ransomware Updated Advisory: CISA and Australian Agencies Detail Evolving Tactics and Techniques
US and Australian cybersecurity agencies have issued an updated advisory on the BianLian ransomware group, detailing new tactics, techniques, and indicators of compromise (IoCs) following ...
Thala Recovers $25.5 Million After Security Breach
Cybersecurity
Thala Recovers $25.5 Million After Security Breach
DeFi protocol Thala recouped $25.5 million stolen in a security breach by negotiating a $300,000 bounty with the attacker, showcasing effective crisis management in the ...
Bojangles' Restaurant Data Breach Exposes Sensitive Customer Information
News
Bojangles’ Restaurant Data Breach Exposes Sensitive Customer Information
Bojangles' Restaurants suffered a significant data breach between February and March 2024, exposing the personal information of tens of thousands of customers. The Murphy Law ...
Columbus Data Leak Has Exposed Half a Million Residents;City Offers Limited Protection
News
Columbus Data Leak Has Exposed Half a Million Residents City Offers Limited Protection
Columbus data leak has compromised the personal information of an estimated 500,000 residents. The city's response has been criticized for offering credit monitoring to only ...
BianLian Ransomware Shifts Focus Exclusively to Data Theft, CISA Warns
News
BianLian Ransomware Shifts Focus Exclusively to Data Theft, CISA Warns
Chinese state-sponsored hackers are using a new Linux backdoor called WolfsBane, a sophisticated malware tool that includes a dropper, launcher, and backdoor, alongside a modified ...
WolfsBane Linux Malware Unleashed by Chinese Hackers
Cybersecurity
WolfsBane Linux Malware Unleashed by Chinese Hackers
Chinese state-sponsored hackers are using a new Linux backdoor called WolfsBane, a sophisticated malware tool that includes a dropper, launcher, and backdoor, alongside a modified ...
This Week In Cybersecurity: 18th to 22nd November
Cybersecurity
This Week In Cybersecurity: 18th to 22nd November
This Week In Cybersecurity: 18th to 22nd November
HeptaX Cyberattack: A Deep Dive into the Multi-Stage RDP Exploitation Targeting Enterprises
Application Security
HeptaX Cyberattack: A Deep Dive into the Multi-Stage RDP Exploitation Targeting Enterprises
The HeptaX cyberattack represents a sophisticated, multi-stage threat targeting enterprises, particularly in healthcare. This in-depth analysis details the attack chain, technical analysis, and crucial mitigation ...
Finastra Data Breach: 400GB of Sensitive Financial Data Compromised
News
Finastra Data Breach: 400GB of Sensitive Financial Data Compromised
Finastra, serving 45 of the world's top 50 banks, is investigating a potential data breach involving its secure file transfer platform. A threat actor claimed ...
Stop and Shop Cyberattack Leaves Shelves Empty Ahead of Thanksgiving
News
Stop and Shop Cyberattack Leaves Shelves Empty Ahead of Thanksgiving
A cyberattack on Stop & Shop and Hannaford, owned by Ahold Delhaize, has caused empty shelves just a week before Thanksgiving, impacting holiday shopping.
French Hospital Cyberattack Exposes Sensitive Data of 750,000 Patients
News
French Hospital Cyberattack Exposes Sensitive Data of 750,000 Patients
A major hospital data breach in France exposed the medical records of 750,000 patients. The French hospital cyberattack highlights the vulnerability of healthcare systems and ...
23andMe's Data Breach Settlement: Are you Eligible for $10,000?
News
23andMe’s Data Breach Settlement: Are you Eligible for $10,000?
Millions of 23andMe users were affected by a data breach, leading to a $30 million settlement offering payouts up to $10,000 for those who experienced ...
Cybersecurity
Russian Actor Uses AI to Exploit PaperCut, Hits 440+ Organizations
Cybersecurity
ShinyHunters Claims Breach of Florida DMV DAVID Database
Application Security
GoldFactory and Mantax Otax Target Indonesian Android Bank Users
CVE Vulnerability Alerts
Aurora Ransomware Operators Use Cursor AI to Execute Network Attacks

TOP CYBERSECURITY HEADLINES

This Week’s Security Spotlight

Cybersecurity
Russian Actor Uses AI to Exploit PaperCut, Hits 440+ Organizations
Cybersecurity
LG Accused of Privacy Violations Over Smart TV Data Collection
Application Security
OpenAI Agents Made 18,000 Unauthorized Edits to German Wiki
Application Security
Judge Rules Pentagon Actions Against Anthropic Unlawful
Trending

Daily Briefing Newsletter

Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Featured Videos​

Podcasts

Sorry, we couldn't find any posts. Please try a different search.

  • All
  • Application Security
  • Blog
  • CVE Vulnerability Alerts
  • Cybersecurity
  • Cybersecurity Newsletter
  • Data Security
  • Endpoint Security
  • Identity and Access Management
  • Information Security
  • Network Security
  • News
  • Phishing
  • Podcasts
  • Product Reviews
  • Ransomware
  • Ransomware Victims
  • Resources
  • Security Spotlight
  • Sponsored
  • Threat Actors
  • Threat Actors
  • Threat Detection Tools
WinRAR Vulnerability Bypasses Windows Mark of the Web Security
WinRAR vulnerability (CVE-2025-31334) bypasses Windows Mark of the Web security, enabling silent malicious code execution. Update to version 7.11 immediately.
Port of Seattle Ransomware Attack Impacts 90,000 Individuals
A ransomware attack on the Port of Seattle exposed the personal data of 90,000 individuals. The Rhysida ransomware group was responsible, and the Port refused ...
E-ZPass Phishing Scam Targets E-ZPass
A massive wave of phishing texts impersonating E-ZPass is stealing personal and financial data. Scammers use urgency and encrypted messaging to bypass security measures.
CISA Warns of Fast Flux DNS Evasion Used by Cybercrime Gangs
CISA warns of Fast Flux DNS evasion, a technique used by cybercrime gangs to mask malicious activity by rapidly changing DNS records, making detection and ...
COBIT 2019 vs. COBIT 5: What’s New and Why It Matters
The IT world is constantly changing, and so are the frameworks that govern it. This blog post delves into the significant differences between COBIT 5 ...
Texas State Bar Data Breach: INC Ransomware Gang Claims Responsibility
The Texas State Bar suffered a data breach between January 28 and February 9, 2025, with the INC ransomware gang claiming responsibility and leaking stolen ...
GitHub Supply Chain Attack Traced to Leaked SpotBugs Token
A devastating GitHub supply chain attack, targeting Coinbase, stemmed from a leaked SpotBugs token, exposing secrets in 218 repositories and highlighting critical vulnerabilities in open-source ...
Oracle Cloud Breach Confirmed, Data Theft Impacts Legacy Systems
Oracle confirms a data breach impacting its legacy Oracle Cloud Classic system, resulting in the theft of client credentials. Investigations are underway, but the company's ...
Hunters International Shifts to Data Extortion and Rebrands as World Leaks
Hunters International, a notorious ransomware operation, has rebranded as World Leaks, shifting its focus to data extortion.
$500,000 Lost in Australian Superannuation Fund Data Breach
Major Australian superannuation funds experienced a data breach, resulting in $500,000 in losses and impacting thousands of members via a credential stuffing attack.
KillSec: Hacktivists Turned RaaS Syndicate
KillSec, a Russia-linked RaaS group, targets healthcare and finance, leveraging OSINT and affiliates for extortion, showing a preference for Asian victims over Western ones.
CVE Vulnerability Alerts – 18th March, 2025
This post summarizes various vulnerabilities from recent CVE alerts that could potentially be exploited by malicious actors. Each entry includes brief information on the vulnerability, ...
The Soaring Cost of Data Breaches for Enterprise Businesses in 2024
The cost of data breach is skyrocketing. This in-depth analysis reveals the staggering financial impact and strategies for mitigation. Learn more.
ChatGPT is Down Worldwide Impacting Millions
Global ChatGPT outage caused widespread disruption, displaying a "Something went wrong" error. OpenAI acknowledged the problem and implemented a fix.
Royal Mail Data Breach: No Operational Impact Reported
Royal Mail investigates a data breach involving third-party supplier Spectos GmbH. Over 144GB of data, including customer PII, was leaked; however, Royal Mail operations remain ...
Triada Malware Preloaded on Counterfeit Android Devices
Counterfeit Android phones are infecting users with Triada malware pre-installed in the firmware, stealing data and cryptocurrency. This supply chain attack highlights the risks of ...
Urgent Security Alert: Exploited CSLU Backdoor Threatens Cisco Systems
Exploited Cisco CSLU backdoor admin account enables unauthorized access and control. Immediate patching is critical to prevent attacks.
SimonMed Imaging Confirms Cybersecurity Breach in January 2025
SimonMed Imaging confirmed a cybersecurity breach in January 2025, exposing patient data through a vendor, prompting investigations, security upgrades, and at least one class-action lawsuit. ...
173,000 Patients Affected by Chord Specialty Dental Partners Email Data Breach
Chord Specialty Dental Partners reports a data breach impacting 173,000 patients, exposing personal and health data, and offering free credit monitoring services to affected individuals. ...
openSNP to Shut Down: Genetic Data Privacy Concerns Lead to Platform Closure
openSNP, a genetic data sharing platform, will close and delete all data on April 30th due to escalating privacy concerns and the risk of government ...