Cyber Security
Application Security
Insecure Deployments of Moltbot Pose Risks in Enterprise Settings
Gabby Lee
January 29, 2026
Insecure deployments of Moltbot, an AI assistant, in enterprise environments raise severe risks of leaking sensitive data such as API keys, OAuth tokens, and conversation ...
Cybersecurity
FBI Successfully Seizes RAMP Cybercrime Forum Disrupting Ransomware Operations
Andrew Doyle
January 29, 2026
The FBI has effectively dismantled RAMP, a prominent cybercriminal forum. Known for its bold promotion of ransomware activities, RAMP's seizure marks a significant law enforcement ...
Cybersecurity
Chinese Hackers Breach Phones of UK Officials in Long-term Cyber Espionage
Mitchell Langley
January 29, 2026
Chinese hackers, linked to state-sponsored activities, reportedly penetrated the smartphones of UK officials, accessing sensitive communications for several years. The invasion probes the sophistication of ...
Application Security
Microsoft Office and Linux Kernel Among Newly Cataloged Vulnerabilities
Gabby Lee
January 29, 2026
The U.S. Cybersecurity and Infrastructure Security Agency updated its Known Exploited Vulnerabilities catalog with newly identified security flaws, including those in Microsoft Office and the ...
Cybersecurity
Meta Implements Enhanced Security Measures on WhatsApp
Andrew Doyle
January 29, 2026
WhatsApp rolls out Strict Account Settings to secure high-risk users against advanced, targeted cyber threats. Meta's focus is on enhancing user safety amid increasing cyber ...
CVE Vulnerability Alerts
Exploitations of WinRAR Vulnerability CVE-2025-8088 Emerge as a Major Threat
Andrew Doyle
January 28, 2026
Cyber attackers leverage the CVE-2025-8088 high-severity WinRAR vulnerability. This security loophole is targeted for initial access and malware delivery, affecting numerous organizations globally.
Application Security
Meta Introduces Enhanced WhatsApp Security for High-Risk Users
Mitchell Langley
January 28, 2026
Meta's initiative to enhance the security of high-risk individuals on WhatsApp involves a trade-off between functionality and security, providing an extra layer of defense through ...
Application Security
ShinyHunters Allegedly Breach Panera Bread and Other Companies via Microsoft Entra SSO
Gabby Lee
January 28, 2026
ShinyHunters, an extortionist gang, claims to have accessed data from Panera Bread, CarMax, and Edmunds, using Microsoft Entra Single Sign-On (SSO). Understanding the technical breach ...
Cybersecurity
Memcyco Secures $37 Million to Expand Anti-Impersonation Technology Globally
Andrew Doyle
January 28, 2026
Memcyco has successfully raised $37 million to expand its cutting-edge anti-impersonation technology worldwide, with a focus on Latin America. This significant investment will accelerate the ...
CVE Vulnerability Alerts
Major Security Flaw Found in vm2 Node.js Sandbox Tool
Andrew Doyle
January 28, 2026
A serious vulnerability in the vm2 Node.js sandbox library, identified as CVE-2026-22709, could jeopardize system security by enabling the execution of arbitrary code outside the ...
News
Nebraska Grand Jury Indicts Additional Members in Tren de Aragua ATM Scheme
Mitchell Langley
January 28, 2026
Nebraska federal authorities charge 31 more individuals linked to a Venezuelan crime syndicate for their part in a widespread ATM fraud operation. This development brings ...
Cybersecurity
Crunchbase Data Breach Raises Security Concerns After ShinyHunters Attack
Gabby Lee
January 28, 2026
Cybercriminal group ShinyHunters reportedly compromised Crunchbase, stealing over 2 million personal records. The breach involved a 402 MB data file being leaked, prompting concerns about ...
Cybersecurity
NPM Security Measures Post-‘Shai-Hulud’ Attacks Show Vulnerabilities
Mitchell Langley
January 28, 2026
Despite enhanced defense mechanisms by NPM following the 'Shai-Hulud' supply-chain attacks, Git dependencies reveal key vulnerabilities that threat actors could exploit, casting doubt over the ...
Cybersecurity
Phishing Attacks Target Indian Users with a Multi-Stage Backdoor
Mitchell Langley
January 28, 2026
Cybersecurity researchers from eSentire uncovered an ongoing campaign targeting Indian users using a multi-stage backdoor. Phishing emails mimic the Income Tax Department to deceive victims.
Cybersecurity
Upwind Secures $250 Million to Expand Its Cloud Security Solutions
Andrew Doyle
January 28, 2026
Upwind, a cloud-native application protection platform (CNAPP) provider, has attracted $250 million in fresh investment. This funding elevates the company’s valuation to $1.5 billion and ...
Cybersecurity
Microsoft Releases Emergency Patch to Mitigate Office Zero-Day Vulnerability
Gabby Lee
January 28, 2026
Microsoft has released urgent updates to address an actively exploited security flaw, CVE-2026-21509, impacting several Office versions. This vulnerability allows attackers to bypass security features, ...
Cybersecurity
Vulnerabilities in Dormakaba Systems Expose Security Flaws
Andrew Doyle
January 28, 2026
Dormakaba's access control systems exhibited significant vulnerabilities, leading to security risks at major European firms. Over 20 flaws, including six critical ones, allowed unauthorized access ...
Cybersecurity
EU Investigates AI Risk Management: Scrutiny Over Grok AI’s Content Generation
Gabby Lee
January 28, 2026
The European Commission launches an investigation into X's Grok AI, questioning the company's risk assessment process following its controversial use in generating explicit imagery. This ...
Cybersecurity
Cloudflare Analyzes the Impact of a Recent BGP Route Leak
Mitchell Langley
January 28, 2026
Cloudflare recently detailed a BGP route leak lasting 25 minutes. The incident resulted in noticeable network disruptions, with packet loss and roughly 12 Gbps of ...
Application Security
Microsoft’s Out-of-Band Updates Resolve Microsoft Outlook Issue With Cloud-Hosted PST Files
Gabby Lee
January 28, 2026
Microsoft has issued crucial out-of-band updates for Windows 10, Windows 11, and Windows Server to address a specific problem affecting Microsoft Outlook. This issue resulted ...
Application Security
SAP Patches Zero-Day in Commerce Cloud Data Hub Adapter
Gabby Lee
August 12, 2026
Application Security
CISA Adds Metabase SQL Injection Zero-Day to KEV With Aug 14 Deadline
Gabby Lee
August 12, 2026
Cybersecurity
Gunra Ransomware Exploits Fortinet and Schneider Flaws for MFA Bypass
Gabby Lee
August 12, 2026
Application Security
SharePoint RCE CVE-2026-55040 First Confirmed Ransomware Exploit
Mitchell Langley
August 12, 2026
TOP CYBERSECURITY HEADLINES
This Week’s Security Spotlight
Cybersecurity
OpenAI Pauses Astra Work After Evaluation Flags Cyber Capabilities
Andrew Doyle
August 11, 2026
Trending
Daily Briefing Newsletter
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.
Featured Videos
Podcasts
Cyber Security News
- All
- Application Security
- Blog
- CVE Vulnerability Alerts
- Cybersecurity
- Cybersecurity Newsletter
- Data Security
- Endpoint Security
- Identity and Access Management
- Information Security
- Network Security
- News
- Phishing
- Podcasts
- Product Reviews
- Ransomware
- Ransomware Victims
- Resources
- Security Spotlight
- Sponsored
- Threat Actors
- Threat Actors
- Threat Detection Tools
Microsoft Office and Linux Kernel Among Newly Cataloged Vulnerabilities
January 29, 2026
The U.S. Cybersecurity and Infrastructure Security Agency updated its Known Exploited Vulnerabilities catalog with newly identified security flaws, including those in Microsoft Office and the ...
Meta Implements Enhanced Security Measures on WhatsApp
January 29, 2026
WhatsApp rolls out Strict Account Settings to secure high-risk users against advanced, targeted cyber threats. Meta's focus is on enhancing user safety amid increasing cyber ...
Exploitations of WinRAR Vulnerability CVE-2025-8088 Emerge as a Major Threat
January 28, 2026
Cyber attackers leverage the CVE-2025-8088 high-severity WinRAR vulnerability. This security loophole is targeted for initial access and malware delivery, affecting numerous organizations globally.
Meta Introduces Enhanced WhatsApp Security for High-Risk Users
January 28, 2026
Meta's initiative to enhance the security of high-risk individuals on WhatsApp involves a trade-off between functionality and security, providing an extra layer of defense through ...
ShinyHunters Allegedly Breach Panera Bread and Other Companies via Microsoft Entra SSO
January 28, 2026
ShinyHunters, an extortionist gang, claims to have accessed data from Panera Bread, CarMax, and Edmunds, using Microsoft Entra Single Sign-On (SSO). Understanding the technical breach ...
Memcyco Secures $37 Million to Expand Anti-Impersonation Technology Globally
January 28, 2026
Memcyco has successfully raised $37 million to expand its cutting-edge anti-impersonation technology worldwide, with a focus on Latin America. This significant investment will accelerate the ...
Major Security Flaw Found in vm2 Node.js Sandbox Tool
January 28, 2026
A serious vulnerability in the vm2 Node.js sandbox library, identified as CVE-2026-22709, could jeopardize system security by enabling the execution of arbitrary code outside the ...
Nebraska Grand Jury Indicts Additional Members in Tren de Aragua ATM Scheme
January 28, 2026
Nebraska federal authorities charge 31 more individuals linked to a Venezuelan crime syndicate for their part in a widespread ATM fraud operation. This development brings ...
Crunchbase Data Breach Raises Security Concerns After ShinyHunters Attack
January 28, 2026
Cybercriminal group ShinyHunters reportedly compromised Crunchbase, stealing over 2 million personal records. The breach involved a 402 MB data file being leaked, prompting concerns about ...
NPM Security Measures Post-‘Shai-Hulud’ Attacks Show Vulnerabilities
January 28, 2026
Despite enhanced defense mechanisms by NPM following the 'Shai-Hulud' supply-chain attacks, Git dependencies reveal key vulnerabilities that threat actors could exploit, casting doubt over the ...
Phishing Attacks Target Indian Users with a Multi-Stage Backdoor
January 28, 2026
Cybersecurity researchers from eSentire uncovered an ongoing campaign targeting Indian users using a multi-stage backdoor. Phishing emails mimic the Income Tax Department to deceive victims.
Upwind Secures $250 Million to Expand Its Cloud Security Solutions
January 28, 2026
Upwind, a cloud-native application protection platform (CNAPP) provider, has attracted $250 million in fresh investment. This funding elevates the company’s valuation to $1.5 billion and ...
Microsoft Releases Emergency Patch to Mitigate Office Zero-Day Vulnerability
January 28, 2026
Microsoft has released urgent updates to address an actively exploited security flaw, CVE-2026-21509, impacting several Office versions. This vulnerability allows attackers to bypass security features, ...
Vulnerabilities in Dormakaba Systems Expose Security Flaws
January 28, 2026
Dormakaba's access control systems exhibited significant vulnerabilities, leading to security risks at major European firms. Over 20 flaws, including six critical ones, allowed unauthorized access ...
EU Investigates AI Risk Management: Scrutiny Over Grok AI’s Content Generation
January 28, 2026
The European Commission launches an investigation into X's Grok AI, questioning the company's risk assessment process following its controversial use in generating explicit imagery. This ...
Cloudflare Analyzes the Impact of a Recent BGP Route Leak
January 28, 2026
Cloudflare recently detailed a BGP route leak lasting 25 minutes. The incident resulted in noticeable network disruptions, with packet loss and roughly 12 Gbps of ...
Microsoft’s Out-of-Band Updates Resolve Microsoft Outlook Issue With Cloud-Hosted PST Files
January 28, 2026
Microsoft has issued crucial out-of-band updates for Windows 10, Windows 11, and Windows Server to address a specific problem affecting Microsoft Outlook. This issue resulted ...
The ShinyHunters and Their Voice Phishing Tactics Target Okta, Microsoft, and Google
January 28, 2026
ShinyHunters are deploying voice phishing to breach SSO accounts and access corporate data in platforms like Okta, Microsoft, and Google. This tactic aids in stealing ...
Windows 11 Boot Failures After Patch Tuesday Updates
January 28, 2026
Recent updates from January 2026 rendered some Windows 11 devices unusable, throwing an “UNMOUNTABLE_BOOT_VOLUME” error. Microsoft is actively examining these issues and working on a ...
US Cybersecurity Agency Opts Out of RSA Conference While Jen Easterly Plans Attendance
January 28, 2026
The US Cybersecurity and Infrastructure Security Agency (CISA) confirmed it will not be attending the upcoming RSA Conference in March. However, new RSA CEO and ...





































