Cyber Security
Sandworm Fake Job Interview Campaign Targets Ukrainian IT Workers
Kimwolf v7 Android Botnet Evades DDoS Mitigation Using HTTP/2 C2
SharePoint RCE CVE-2026-55040 First Confirmed Ransomware Exploit
Polish Power Plant Turbine Stopped After Cellular ICS Network Breach
Metabase Zero-Day SQL Injection Exploited Against Framework, Tally
Attackers Reach Managed Endpoints as N-able Ships N-central Hotfix 2
CISA Adds Exploited Kemp LoadMaster Command Injection to KEV
Atlassian Rovo One-Click Flaw Exposes Jira, Confluence Data
CSS Attacks Break Webmail Boundaries to Capture Passwords, Tokens
Head Mare Breaches TrueConf Servers, Trojanizes Client Installers
Belgian Connective eID Flaws Let Websites Forge Signatures
Solidity Pro VS Code Extensions Steal Wallets, API Keys From Devs
OpenAI Pauses Astra Work After Evaluation Flags Cyber Capabilities
AitM Phishing Campaign Steals Microsoft 365 Finance Emails
Swiss Government SharePoint Breach Compromised 200 Accounts
UNC6671 Extortion Group Rebrands After Targeting Hedge Funds
3.8 Million Impacted by Unlimited Technology Systems Breach
4,407 Rockwell PLCs Exposed Online, 22 in Water Cities
Zapscape KVM Flaw Lets Privileged L1 Guest Escape to Host
TONTOU Interrupt Injection Bypasses Spectre v2 Fixes on AMD Zen 2
NatJack Attacks Hijack TCP Sessions and Spoof DNS via NAT
Claude Code and Gemini CLI Flaws Expose CI Workflow Secrets
AI-Assisted HTTP Terminator Finds Apache Traffic Server Zero-Day
TeamPCP Tied to Redis Attacks Dating Back to 2020
CryptoJS Weak RNG Behind $5.7M in Five Wallet App Drains
iCloud Private Relay WebKit Bypasses Expose Users’ Real IPs
ClickFix Campaign Pushes Go-Based macOS Crypto Drainer
China Launches Probe Into Palo Alto Networks Product Security
Attackers Compile khunt Inside Oracle to Reach Windows SYSTEM
Zbtlink Routers Ship With ENDLESSDOORS Backdoor Opening Root Shells
Cybersecurity
Threat Actors Are Ramping Up Microsoft Teams Exploitation for Network Access
Cybercriminals are increasingly targeting Microsoft Teams in enterprise attacks, using the platform alongside legitimate tools to gain unauthorized ac...
Cybersecurity
Cybercriminals Are Bending Trust, Not Breaking Systems
Cyber attackers bypass systems without breaking them, taking advantage of trusted pathways, smartly bending trust.
Application Security
Anthropic’s Claude Desktop Unauthorized Installations Raise EU Law Compliance Concerns
Claude Desktop's unauthorized modifications may breach EU laws on clear user consent.
CVE Vulnerability Alerts
Severe Command Injection Flaw Discovered in SGLang
A critical vulnerability in SGLang could allow remote code execution. Tracked as CVE-2026-5760, this flaw scores 9.8 on CVSS.
Cybersecurity
Serial-to-IP Converter Flaws in Lantronix and Silex Products Put Critical Systems at Risk
Vulnerabilities in Lantronix and Silex products risk exploitation in OT and healthcare sectors.
News
Seiko USA Faces Ransom Threat After Website Defacement
Attackers reportedly demand ransom from Seiko USA after defacing the website and claiming to possess customer data.
Cybersecurity
Scottish Man Pleads Guilty in $8 Million Cryptocurrency Heist
A Scottish man pleads guilty in a US court to a cryptocurrency theft using phishing and SIM-swap tactics.
Cyberattacks Are Outpacing MSP and Corporate Defenses
Cybersecurity
Cyberattacks Are Outpacing MSP and Corporate Defenses
Discover cybersecurity strategies to counter evolving threats in an upcoming webinar focused on security and recovery.
Huntress Identifies Active Exploitation of Microsoft Defender Vulnerabilities
Application Security
Huntress Identifies Active Exploitation of Microsoft Defender Vulnerabilities
Huntress identifies threat actors exploiting vulnerabilities in Microsoft Defender.
Lawmakers' Concerns About AI Include Worries of Potential 'Destruction'
Cybersecurity
Lawmakers’ Concerns About AI Include Worries of Potential ‘Destruction’
Lawmakers discuss the rapid development of AI, expressing fears over its potential impact on various global aspects.
Microsoft Edge Update Introduces Bug Affecting Microsoft Teams Chats
Application Security
Microsoft Edge Update Introduces Bug Affecting Microsoft Teams Chats
A recent update in the Microsoft Edge browser has led to a bug impacting the right-click paste function in Microsoft Teams chats.
Threat Actors Repurpose Tycoon 2FA Tools in New Phishing Schemes
News
Threat Actors Repurpose Tycoon 2FA Tools in New Phishing Schemes
Cybercriminals adapt Tycoon 2FA tools for phishing, revealing new security challenges.
Attackers Exploit QEMU Virtualization to Evade Detection
CVE Vulnerability Alerts
Attackers Exploit Three Zero-Day Flaws in Microsoft Defender to Gain Elevated Access
Three zero-day flaws in Microsoft Defender, dubbed BlueHammer, RedSun, and UnDefend, are being actively exploited to gain elevated system access.
Vercel Suffers Security Breach as Threat Actors Attempt to Sell Stolen Data
Cybersecurity
Vercel Suffers Security Breach as Threat Actors Attempt to Sell Stolen Data
Vercel's recent security breach exposes unauthorized data access as threat actors intend to sell compromised information from their systems.
AI Security Challenges - Vendors' Dual Messaging Raises Questions
Cybersecurity
AI Security Challenges: Vendors’ Dual Messaging Raises Questions
AI vendors promote AI for security while denying its flaws. This raises questions about their maturity and transparency.
NIST Alters Approach to Vulnerability Assessments, Ceasing Severity Scores for Lower-Priority Issues
Cybersecurity
NIST Alters Approach to Vulnerability Assessments, Ceasing Severity Scores for Lower-Priority Issues
NIST plans to halt severity scoring for lower-priority vulnerabilities due to high submission volumes.
Phishing Scams Are Now Exploiting Apple's Trusted Email Servers
News
Phishing Scams Are Now Exploiting Apple’s Trusted Email Servers
Apple account change alerts misused for phishing, mimicking legitimate iPhone purchase notices.
Hackers Target Trucking and Logistics Firms in Organized Crime-Linked Cyber Campaign
Cybersecurity
Hackers Target Trucking and Logistics Firms in Organized Crime-Linked Cyber Campaign
Hackers linked to organized crime infiltrate logistics companies, posing rising threats of cargo theft and payment diversion.
Critical Nginx-UI Vulnerability Lets Attackers Seize Full Server Control
CVE Vulnerability Alerts
Critical Nginx-UI Vulnerability Lets Attackers Seize Full Server Control
Nginx servers vulnerable to attacks via a flaw (CVE-2026-33032) that allows authentication bypass.
Digitally Signed Adware Disables Antivirus Across Multiple Sectors
Application Security
Digitally Signed Adware Disables Antivirus Across Multiple Sectors
A system-level adware attack compromises antivirus protection on thousands of endpoints across various sectors.
Application Security
SAP Patches Zero-Day in Commerce Cloud Data Hub Adapter
Cybersecurity
Gunra Ransomware Exploits Fortinet and Schneider Flaws for MFA Bypass
Application Security
SharePoint RCE CVE-2026-55040 First Confirmed Ransomware Exploit

TOP CYBERSECURITY HEADLINES

This Week’s Security Spotlight

Trending

Daily Briefing Newsletter

Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Featured Videos​

  • All
  • Application Security
  • Blog
  • CVE Vulnerability Alerts
  • Cybersecurity
  • Cybersecurity Newsletter
  • Data Security
  • Endpoint Security
  • Identity and Access Management
  • Information Security
  • Network Security
  • News
  • Phishing
  • Podcasts
  • Product Reviews
  • Ransomware
  • Ransomware Victims
  • Resources
  • Security Spotlight
  • Sponsored
  • Threat Actors
  • Threat Actors
  • Threat Detection Tools
Severe Command Injection Flaw Discovered in SGLang
A critical vulnerability in SGLang could allow remote code execution. Tracked as CVE-2026-5760, this flaw scores 9.8 on CVSS.
Serial-to-IP Converter Flaws in Lantronix and Silex Products Put Critical Systems at Risk
Vulnerabilities in Lantronix and Silex products risk exploitation in OT and healthcare sectors.
Seiko USA Faces Ransom Threat After Website Defacement
Attackers reportedly demand ransom from Seiko USA after defacing the website and claiming to possess customer data.
Scottish Man Pleads Guilty in $8 Million Cryptocurrency Heist
A Scottish man pleads guilty in a US court to a cryptocurrency theft using phishing and SIM-swap tactics.
Cyberattacks Are Outpacing MSP and Corporate Defenses
Discover cybersecurity strategies to counter evolving threats in an upcoming webinar focused on security and recovery.
Huntress Identifies Active Exploitation of Microsoft Defender Vulnerabilities
Huntress identifies threat actors exploiting vulnerabilities in Microsoft Defender.
Lawmakers’ Concerns About AI Include Worries of Potential ‘Destruction’
Lawmakers discuss the rapid development of AI, expressing fears over its potential impact on various global aspects.
Microsoft Edge Update Introduces Bug Affecting Microsoft Teams Chats
A recent update in the Microsoft Edge browser has led to a bug impacting the right-click paste function in Microsoft Teams chats.
Threat Actors Repurpose Tycoon 2FA Tools in New Phishing Schemes
Cybercriminals adapt Tycoon 2FA tools for phishing, revealing new security challenges.
Attackers Exploit Three Zero-Day Flaws in Microsoft Defender to Gain Elevated Access
Three zero-day flaws in Microsoft Defender, dubbed BlueHammer, RedSun, and UnDefend, are being actively exploited to gain elevated system access.
Vercel Suffers Security Breach as Threat Actors Attempt to Sell Stolen Data
Vercel's recent security breach exposes unauthorized data access as threat actors intend to sell compromised information from their systems.
AI Security Challenges: Vendors’ Dual Messaging Raises Questions
AI vendors promote AI for security while denying its flaws. This raises questions about their maturity and transparency.
NIST Alters Approach to Vulnerability Assessments, Ceasing Severity Scores for Lower-Priority Issues
NIST plans to halt severity scoring for lower-priority vulnerabilities due to high submission volumes.
Phishing Scams Are Now Exploiting Apple’s Trusted Email Servers
Apple account change alerts misused for phishing, mimicking legitimate iPhone purchase notices.
Hackers Target Trucking and Logistics Firms in Organized Crime-Linked Cyber Campaign
Hackers linked to organized crime infiltrate logistics companies, posing rising threats of cargo theft and payment diversion.
Critical Nginx-UI Vulnerability Lets Attackers Seize Full Server Control
Nginx servers vulnerable to attacks via a flaw (CVE-2026-33032) that allows authentication bypass.
Digitally Signed Adware Disables Antivirus Across Multiple Sectors
A system-level adware attack compromises antivirus protection on thousands of endpoints across various sectors.
Cybercriminals Are Weaponizing n8n to Launch Phishing Attacks
Threat actors are exploiting n8n, an AI workflow platform, to launch advanced phishing attacks.
Microsoft Awards $2.3 Million to Researchers in Zero Day Quest Hacking Contest
Microsoft awarded $2.3 million to researchers during this year's Zero Day Quest for discovering vulnerabilities.
Sweden Points to Pro-Russian Group in Cyberattack on Energy Infrastructure
Swedish authorities attribute a cyberattack on a heating plant to a pro-Russian group, laying bare vulnerabilities in national energy infrastructure.