Cyber Security
Four Nation-State Groups Deploy BlueMoon Kit Within 12 Days
NSA, CISA, FBI Accuse Six Chinese AI Firms of Model Distillation
UNC3569 Exploits Sogou Input Method to Deploy GRAYRABBIT Backdoor
Attackers Use BYOD Weaknesses to Access M365 via Graph API
Surfshark VPN Breach Exposes Internal Testing and Proxy Servers
Citrix NetScaler CVE-2026-19490 Exploited Since September 3
CISA Sets September 12 Deadline for Cisco, Citrix, Fortinet Flaws
Infostealer Logs Expose Replayable AI Tokens That Bypass MFA
Google Patches Seventh Chrome Zero-Day of 2026, CVE-2026-87491
PoisonedRefresh Rootkit Injects PHP Web Shells into F5 BIG-IP Memory
September Windows Server Updates Break Remote Desktop Services
Microsoft Excel KB5002914 Update Breaks Copy and Paste Functions
cPanel Critical RCE Enables Full Server Takeover via Mail Account
SAP Patches CVSS 10.0 Kernel RCE in Extended Passport Processing
Microsoft Ships Record 974 Security Patches in September Batch
ShinyHunters Claims Breach of Florida DMV DAVID Database
Grindr Settles UK HIV Data Sharing Lawsuit for £26 Million
Liquid Network Attackers Return 3,400 Bitcoin, Keep $47 Million
OpenAI Artifactory Flaw Enabled Cross-Account Data Theft
Boston Scientific Cyberattack Damages Q3 and Full-Year Earnings
Ohio Man Sentenced to 15 Years for AI-Generated Sextortion
LG Accused of Privacy Violations Over Smart TV Data Collection
Microsoft Adds Age-Awareness APIs to Windows 11
EU Cyber Resilience Act 24-Hour Vulnerability Deadline Arrives
UK Lawmakers Question Cyber Bill’s Executive Liability Exemption
Welsh Regulator Exposes 2,000 Staff Diversity Records via FoI Error
OpenAI Agent Swarm Logs Reveal Emergent Deception and Coordination
PEEP Toolkit Turns Chrome and Edge Into Post-Exploitation Backdoors
Magento StyleSmuggler Zero-Day Deploys Linux Backdoors on Stores
Mathspace Breach Exposes Data of Over 1 Million Students and Staff
Cisco Confirms Data Breach: Public-Facing DevHub Targeted by Hackers
News
Cisco Confirms Data Breach: Public-Facing DevHub Targeted by Hackers
Cisco confirms a breach of its public-facing DevHub, exposing source code, credentials, and API tokens, raising concerns about future attacks despite no internal system compromise.
Internet Archive Breached Again: Stolen Access Tokens Expose Millions of Support Tickets
News
Internet Archive Breached Again: Stolen Access Tokens Expose Millions of Support Tickets
The Internet Archive suffered a second breach due to exposed GitLab tokens, granting access to 800,000+ Zendesk support tickets and potentially sensitive user data.
Cyberattack Targets Critical Sectors in Cyprus
News
Cyberattack Targets Critical Sectors in Cyprus
A major cyberattack targeted critical sectors in Cyprus, causing significant concerns about national security and economic stability. The incident highlights the urgent need for enhanced ...
Cyprus Successfully Defends Against Wave of DDoS Cyberattacks
News
Cyprus Successfully Defends Against Wave of DDoS Cyberattacks
Cyprus successfully repelled a wave of cyberattacks targeting government and private sector institutions, including a DDoS attack on the gov.cy portal. Authorities responded swiftly, preventing ...
This Week In Cybersecurity: 14th October to 18th October
Cybersecurity
This Week In Cybersecurity: 14th October to 18th October
Live Nation Faces Class Action Lawsuit Following Ticketmaster Data Breach In April 2024, Ticketmaster experienced a significant data breach, exposing ...
Omni Family Health Data Breach: Thousands Affected
News
Omni Family Health Data Breach: Thousands Affected
The Omni Family Health data breach exposed sensitive information of thousands. Levi & Korsinsky, LLP is investigating potential compensation for affected individuals.
Brazil Apprehends Hacker Responsible for FBI InfraGard and Massive National Public Data Breach
News
Brazil Apprehends Hacker Responsible for FBI InfraGard and Massive National Public Data Breach
Brazilian police arrested USDoD, the hacker behind the FBI's InfraGard breach and the massive National Public Data breach, exposing the details of billions.
DPS Data Breach Exposes Sensitive Information of Over 115,000 Texans
News
DPS Data Breach Exposes Sensitive Information of Over 115,000 Texans
DPS data breach exposed the personal information of over 115,000 Texans, including Social Security and driver's license numbers. The DPS has yet to notify victims.
Clorox 2023 Cyberattack: A Setback for Clorox's Sustainability Goals
News
Clorox 2023 Cyberattack: A Setback for Clorox’s Sustainability Goals
The Clorox 2023 cyberattack significantly impacted its 2030 sustainability goals, causing operational disruptions and delaying progress on reducing plastic waste.
Alliance Laundry Systems Data Breach: Sensitive Customer Data Compromised
News
Alliance Laundry Systems Data Breach: Sensitive Customer Data Compromised
Alliance Laundry Systems suffered a data breach, exposing customer names, Social Security numbers, financial information, and driver's license numbers. Data breach notification letters are being ...
Live Nation Faces Class Action Lawsuit Following Ticketmaster Data Breach
News
Live Nation Faces Class Action Lawsuit Following Ticketmaster Data Breach
Live Nation faces a class-action lawsuit after a Ticketmaster data breach exposed the personal information of up to 560 million users, highlighting inadequate security measures. ...
Cisco Investigates Data Breach Following Alleged Sale of Stolen Data on Hacking Forum
News
Cisco Investigates Data Breach Following Alleged Sale of Stolen Data on Hacking Forum
Cisco investigates a potential data breach after a threat actor allegedly sold stolen data, including source code and customer information, on a hacking forum.
Axis Health System Suffers Rhysida Ransomware Attack
News
Axis Health System Suffers Rhysida Ransomware Attack
Axis Health System, a Colorado healthcare provider, suffered a Rhysida ransomware attack, temporarily shutting down its patient portal and raising concerns about patient data.
Calgary Public Library Cyberattack Limits Essential Services
News
Calgary Public Library Cyberattack Limits Essential Services
A cyberattack on the Calgary Public Library has limited services, shutting down computer access, Wi-Fi, and the digital library. The library remains open, but with ...
7 Best Patch Management Tools for Streamlining Enterprise Security
Application Security
7 Best Patch Management Tools for Streamlining Enterprise Security
Robust patch management is critical. This comprehensive guide explores the leading patch management tools, helping enterprise businesses choose the best solution for their needs. We ...
Star Health Insurance Data Breach Exposes Millions of Customer Records
News
Star Health Insurance Data Breach Exposes Millions of Customer Records
Star Health Insurance data breach exposed personal data of 3.1 crore customers and 5.8 million claims, highlighting vulnerabilities in data security.
Marriott Agrees $52m Settlement for Data Breach: A Deep Dive into Cybersecurity Failures and Legal Ramifications
News
Marriott Agrees $52m Settlement for Data Breach: A Deep Dive into Cybersecurity Failures and Legal Ramifications
Marriott's $52 million settlement resolves a massive data breach impacting 339 million records, highlighting critical cybersecurity failures and legal ramifications.
Pokemon Data Breach Reveals Secrets of Unannounced Games and Nintendo Switch 2 Codename
News
Pokemon Data Breach Reveals Secrets of Unannounced Games and Nintendo Switch 2 Codename
A massive Pokemon data breach reveals unreleased game details, the Nintendo Switch 2 codename, and even a canceled Detective Pikachu sequel. The Pokemon data leak ...
This Week In Cybersecurity: 7th October to 11th October
Cybersecurity
This Week In Cybersecurity: 7th October to 11th October
MoneyGram Cyberattack: No Ransomware Evidence Found, Social Engineering Suspected In September 2024, MoneyGram experienced a cyberattack leading to a five-day ...
Internet Archive Breach Exposes Data of 31 Million Users
News
Internet Archive Breach Exposes Data of 31 Million Users
The internet archive breach exposed data of 31 million users. The attack involved the theft of a user authentication database containing sensitive information like email ...
Cybersecurity
Russian Actor Uses AI to Exploit PaperCut, Hits 440+ Organizations
Cybersecurity
ShinyHunters Claims Breach of Florida DMV DAVID Database
Application Security
GoldFactory and Mantax Otax Target Indonesian Android Bank Users
CVE Vulnerability Alerts
Aurora Ransomware Operators Use Cursor AI to Execute Network Attacks

TOP CYBERSECURITY HEADLINES

This Week’s Security Spotlight

Cybersecurity
Russian Actor Uses AI to Exploit PaperCut, Hits 440+ Organizations
Cybersecurity
LG Accused of Privacy Violations Over Smart TV Data Collection
Application Security
OpenAI Agents Made 18,000 Unauthorized Edits to German Wiki
Application Security
Judge Rules Pentagon Actions Against Anthropic Unlawful
Trending

Daily Briefing Newsletter

Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Featured Videos​

Podcasts

Sorry, we couldn't find any posts. Please try a different search.

  • All
  • Application Security
  • Blog
  • CVE Vulnerability Alerts
  • Cybersecurity
  • Cybersecurity Newsletter
  • Data Security
  • Endpoint Security
  • Identity and Access Management
  • Information Security
  • Network Security
  • News
  • Phishing
  • Podcasts
  • Product Reviews
  • Ransomware
  • Ransomware Victims
  • Resources
  • Security Spotlight
  • Sponsored
  • Threat Actors
  • Threat Actors
  • Threat Detection Tools
Brute-Force on Autopilot: Black Basta’s ‘BRUTED’ VPN Tool for Ransomware Expansion
Black Basta, one of the most notorious ransomware gangs, has taken brute-force attacks to the next level with BRUTED—an automated framework designed to breach VPNs, ...
GitHub Action Hijacked: The Supply Chain Attack That Exposed 23,000 Repositories
In this episode, we unpack a major supply chain attack that compromised the widely used GitHub Action ‘tj-actions/changed-files’, affecting over 23,000 repositories. Attackers injected malicious ...
Brave Browser Review 🎯 How Safe is This Web Browser? (2025)
BlackBasta Ransomware Uses Automated Tool ‘BRUTED’ to Brute-Force VPNs
The BlackBasta ransomware group uses an automated tool, BRUTED, to brute-force VPNs and firewalls, highlighting the need for robust multi-factor authentication.
JD.com Data Breach: Babuk Ransomware Cartel Claims Massive Data Theft
JD.com, a major Chinese retailer, faces a massive data breach after the Babuk ransomware cartel claims to have stolen customer passwords and other sensitive information. ...
UDMI Radiology Firm Suffers Major Data Breach: Fog Ransomware Claims Responsibility
Fog ransomware group claims responsibility for a major data breach at UDMI, a radiology firm, impacting over 138,000 individuals. The incident underscores the critical need ...
FBI Issues Warning Against Medusa Ransomware for Gmail, Outlook, and VPN Users
The FBI warns of escalating Medusa ransomware attacks targeting Gmail, Outlook, and VPN users, urging immediate security enhancements to mitigate the threat.
LockBit Ransomware Developer Extradited to the United States
A key LockBit ransomware developer, Rostislav Panev, has been extradited to the US to face charges for his role in the group's global attacks.
Compliance Isn’t Security: Why a Checklist Alone Won’t Stop Cyberattacks
This blog delves into the critical gap between meeting compliance standards and achieving true cybersecurity resilience. Learn why simply checking boxes isn't enough and how ...
Bridging the Gap: Developers vs. Security in the Cloud
In this episode of The Deep Dive, we explore the ongoing tension between development and security teams in cloud environments. While developers prioritize speed and ...
This Week In Cybersecurity: 11th March to 14th March
This week in cybersecurity highlights major incidents, including a $5 million theft from 1inch, a DDoS attack on X, and a significant data breach at ...
Insider Attack and Extortion at Stram Center, SSK Plastic Surgery and Grove at Valhalla Rehabilitation
Three healthcare providers suffered data breaches from insider attacks, extortion, and third-party vulnerabilities, highlighting the need for robust cybersecurity measures.
CISA Reports Medusa Ransomware Attacks Over 300 Critical Infrastructure Organizations
A joint advisory from CISA, FBI, and MS-ISAC reveals Medusa ransomware impacted over 300 US critical infrastructure organizations by February 2025. The advisory details mitigation ...
Critical FreeType Vulnerability Exploited in Attacks: Urgent Update Required
Facebook disclosed a critical FreeType vulnerability (CVE-2025-27363), allowing arbitrary code execution. All versions up to 2.13 are affected; immediate updates are crucial.
Lazarus Group North Korean Hackers Infect Hundreds via Malicious npm Packages
The Lazarus Group, a North Korean hacking collective, deployed six malicious npm packages, infecting hundreds of developers. The packages steal credentials and deploy backdoors.
Sunflower Medical Group Data Breach: Rhysida Ransomware Attack Exposes 220,968 Records
Kansas' Sunflower Medical Group suffered a data breach impacting 220,968 individuals. The Rhysida ransomware group claimed responsibility for the incident in January.
Infostealer Malware Infects 26 Million Devices, Steals Bank Card Data and Passwords
A devastating Infostealer malware campaign has compromised 26 million devices, stealing bank card details and passwords. Kaspersky's report highlights the scale of the threat.
Ransomware Victims on Dark Web – 13th March, 2025
This report summarizes recent ransomware attacks across various sectors, detailing the victims, threat actors, and available information on the incidents. Due to the nature of ...
LockBit Linked SuperBlack Ransomware Exploits Fortinet Authentication Bypass Flaws
New SuperBlack ransomware leverages Fortinet authentication bypass flaws (CVE-2024-55591 and CVE-2025-24472), showing strong ties to LockBit. Immediate patching is crucial.
ClickFix Phishing Campaign Targets Booking.com Using Infostealers and RATs
A sophisticated ClickFix phishing campaign uses fake Booking.com emails to deliver infostealers and RATs, targeting hospitality businesses. Strong security measures are crucial.