Cyber Security
3.8 Million Impacted by Unlimited Technology Systems Breach
4,407 Rockwell PLCs Exposed Online, 22 in Water Cities
Zapscape KVM Flaw Lets Privileged L1 Guest Escape to Host
TONTOU Interrupt Injection Bypasses Spectre v2 Fixes on AMD Zen 2
NatJack Attacks Hijack TCP Sessions and Spoof DNS via NAT
Claude Code and Gemini CLI Flaws Expose CI Workflow Secrets
AI-Assisted HTTP Terminator Finds Apache Traffic Server Zero-Day
TeamPCP Tied to Redis Attacks Dating Back to 2020
CryptoJS Weak RNG Behind $5.7M in Five Wallet App Drains
iCloud Private Relay WebKit Bypasses Expose Users’ Real IPs
ClickFix Campaign Pushes Go-Based macOS Crypto Drainer
China Launches Probe Into Palo Alto Networks Product Security
Attackers Compile khunt Inside Oracle to Reach Windows SYSTEM
Zbtlink Routers Ship With ENDLESSDOORS Backdoor Opening Root Shells
Ransom Cartel Creator Sentenced to 16 Years for RaaS Operation
Snowflake Hacker Pleads Guilty Over Breaches Affecting 100 Million
CISA Flags Active Exploitation of TeamCity CVE-2026-63077
Meta AI Hacked External Systems During Cybersecurity Testing
Brown Health Medical Group Breach Exposes 311,000 Records
CoreBreak Flaws Let Attackers Invoke AWS, Google, Vercel Tools
ClickFix Malware Gate Fingerprints macOS Users Before Lures
Cisco Patches Critical SD-WAN, IOS XE, and FMC Flaws
Open VSX Purges 77 Evil-Twin Extensions Stealing Developer Data
ChainDrop npm Worm Poisons 440 Packages, Steals Cloud Credentials
CISA Adds Exploited Langflow and Tomcat Flaws to KEV Catalog
QuickFox VPN Supply-Chain Attack Delivers FDMTP Backdoor
SMOKE#SCREEN Deploys ScreenConnect via Fake Adobe, Zoom Lures
Claude Mythos 5 Tried to Backdoor a Project in UK AI Security Test
Google Deletes Three ADK AI Workflows After Prompt-Injection Attack
cPanel Patches Critical Flaw Letting Customers Run SQL as Root
MITRE Highlights XSS and SQL Injection as Top Software Vulnerabilities for 2025
Cybersecurity
MITRE Highlights XSS and SQL Injection as Top Software Vulnerabilities for 2025
MITRE's latest research identifies XSS, SQL injection, and CSRF as the primary software vulnerabilities in 2025, closely followed by buffer overflow issues and improper access ...
Shadow Spreadsheets' Stealthy Role in Data Security Risks
Data Security
Shadow Spreadsheets’ Stealthy Role in Data Security Risks
Employees using unauthorised spreadsheets for daily tasks may unknowingly introduce security risks. These "shadow spreadsheets" often lack oversight, leading to data exposure, version sprawl, and ...
New Wave of Phishing Kits Target Credential Theft at Scale
News
New Wave of Phishing Kits Target Credential Theft at Scale
Cybersecurity researchers analyze four new phishing kits, each with unique capabilities aimed at large-scale credential theft. BlackForce, GhostFrame, InboxPrime AI, and Spiderman introduce advanced tactics ...
Torrent Disguised as Leonardo DiCaprio Film Evades Detection Using Subtle Malware Delivery Technique
Cybersecurity
Torrent Disguised as Leonardo DiCaprio Film Evades Detection Using Subtle Malware Delivery Technique
A fake torrent for the film 'One Battle After Another' employs a unique technique by embedding malicious PowerShell loaders in subtitle files, ultimately deploying Agent ...
Kali Linux Version 2025.4 Introduces New Hacking Tools and Improvements
Cybersecurity
Kali Linux Version 2025.4 Introduces New Hacking Tools and Improvements
Kali Linux 2025.4 marks the final update for the year, introducing new hacking tools, desktop environment improvements, and enhanced support for Wayland, alongside the preview ...
Fieldtex Ransomware Attack Akira Group Claims Responsibility
Cybersecurity
Fieldtex Ransomware Attack: Akira Group Claims Responsibility
The Akira ransomware group has claimed responsibility for the November cyberattack on Fieldtex Products, stating that 14 Gb of data was stolen. The breach potentially ...
Digital-only eVisa Scheme Faces Scrutiny Over Data Leaks and GDPR Concerns
Data Security
Digital-only eVisa Scheme Faces Scrutiny Over Data Leaks and GDPR Concerns
The UK's digital-only eVisa scheme is under fire as civil society groups call for a data protection investigation. Concerns include systemic data errors and possible ...
Gladinet CentreStack Flaw A Widespread Threat to Organizations
Cybersecurity
Gladinet CentreStack Flaw: A Widespread Threat to Organizations
Cybersecurity teams are grappling with a new wave of attacks targeting a Gladinet CentreStack vulnerability, threatening multiple organizations globally.
PyStoreRAT New JavaScript-Based RAT Distributed via GitHub
Cybersecurity
PyStoreRAT: New JavaScript-Based RAT Distributed via GitHub
Cybersecurity experts uncover a new campaign using GitHub-hosted Python repositories to deploy PyStoreRAT, a JavaScript-based Remote Access Trojan. The threat disguises itself within repositories posing ...
Pentagon Pushes for Post-Quantum Cryptography Amid Rising Tech Tensions
Cybersecurity
Pentagon Pushes for Post-Quantum Cryptography Amid Rising Tech Tensions
In a pivotal move, the Pentagon's directive to speed up the integration of post-quantum cryptography (PQC) technology comes amid heightened technical tensions. As the U.S. ...
New Cyber Threats Movie Downloads and Software Updates Under Siege
Cybersecurity
New Cyber Threats: Movie Downloads and Software Updates Under Siege
Cybersecurity incidents reveal a growing threat landscape as hackers infiltrate common online platforms, from movie downloads to browser extensions, leaving users vulnerable. Tech companies and ...
Zero-day Vulnerability in Gogs Leads to Hundreds of Compromised Servers
Cybersecurity
Zero-day Vulnerability in Gogs Leads to Hundreds of Compromised Servers
A zero-day vulnerability in Gogs, a well-known self-hosted Git service, has enabled attackers to execute remote code execution on numerous internet-facing instances, impacting hundreds of ...
Former Employee Faces Charges Over Alleged Cybersecurity Fraud DoD Compliance in Question
Cybersecurity
Former Employee Faces Charges Over Alleged Cybersecurity Fraud: DoD Compliance in Question
Danielle Hillmer, a former Accenture executive, is facing charges for allegedly misrepresenting the Department of Defense (DoD) compliance of a cloud platform used by her ...
Microsoft Expands Vulnerability Rewards Program to Third-Party Code
Cybersecurity
Microsoft Expands Vulnerability Rewards Program to Third-Party Code
Microsoft's updated program rewards security researchers for finding critical vulnerabilities in Microsoft online services, including third-party code. The initiative aims to strengthen digital defenses and ...
Stealthy Campaign Targets Developers With Malicious VSCode Extensions
Application Security
Stealthy Campaign Targets Developers With Malicious VSCode Extensions
A stealth campaign has targeted developers using VSCode with 19 malware-infested extensions since February. Threat actors exploit the flexibility of VSCode extensions to distribute malicious ...
CyberVolk's Return Unpacking the Pro-Russian Hacktivist's Ransomware Resurgence
News
CyberVolk’s Return: Unpacking the Pro-Russian Hacktivist’s Ransomware Resurgence
CyberVolk, a pro-Russian hacktivist group, resurfaces with new ransomware. Despite causing alarm, they inadvertently left a method for data recovery.
Cybercrime as a Service The New Era of Subscription-Based Attacks
Cybersecurity
Cybercrime as a Service: The New Era of Subscription-Based Attacks
Cybercriminals have adopted a subscription-based model akin to SaaS, granting low-skill hackers easy access to potent tools. Phishing kits, OTP bots, infostealer logs, and RATs ...
MITRE's 2025 ATT&CK Evaluations Reveal Company Performance on Detection Rates
News
MITRE’s 2025 ATT&CK Evaluations Reveal Company Performance on Detection Rates
The 2025 ATT&CK Enterprise evaluations by MITRE reveal detailed performance metrics of eleven cybersecurity companies, highlighting their detection capabilities. Several companies achieved a 100% detection ...
LastPass Suffers Major Setback as ICO Imposes Consequences Over 2022 Data Breach
Cybersecurity
LastPass Suffers Major Setback as ICO Imposes Consequences Over 2022 Data Breach
LastPass has been fined £1.2 million by the UK's Information Commissioner's Office due to a severe 2022 data breach. The breach exposed sensitive information from ...
Vulnerabilities in PCIe IDE Protocol Pose Risks to Local Systems
Cybersecurity
Vulnerabilities in PCIe IDE Protocol Pose Risks to Local Systems
Security flaws in the PCIe IDE protocol in Base Specification Revision 5.0 and beyond have been discovered, which could allow local attackers to exploit systems. ...
Application Security
Swiss Government SharePoint Breach Compromised 200 Accounts
Cybersecurity
UNC6671 Extortion Group Rebrands After Targeting Hedge Funds
Cybersecurity
Ransom Cartel Creator Sentenced to 16 Years for RaaS Operation

TOP CYBERSECURITY HEADLINES

This Week’s Security Spotlight

Cybersecurity
AitM Phishing Campaign Steals Microsoft 365 Finance Emails
Cybersecurity
3.8 Million Impacted by Unlimited Technology Systems Breach
Cybersecurity
Brown Health Medical Group Breach Exposes 311,000 Records
Application Security
CoreBreak Flaws Let Attackers Invoke AWS, Google, Vercel Tools
Trending

Daily Briefing Newsletter

Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Featured Videos​

  • All
  • Application Security
  • Blog
  • CVE Vulnerability Alerts
  • Cybersecurity
  • Cybersecurity Newsletter
  • Data Security
  • Endpoint Security
  • Identity and Access Management
  • Information Security
  • Network Security
  • News
  • Phishing
  • Podcasts
  • Product Reviews
  • Ransomware
  • Ransomware Victims
  • Resources
  • Security Spotlight
  • Sponsored
  • Threat Actors
  • Threat Actors
  • Threat Detection Tools
New Wave of Phishing Kits Target Credential Theft at Scale
Cybersecurity researchers analyze four new phishing kits, each with unique capabilities aimed at large-scale credential theft. BlackForce, GhostFrame, InboxPrime AI, and Spiderman introduce advanced tactics ...
Torrent Disguised as Leonardo DiCaprio Film Evades Detection Using Subtle Malware Delivery Technique
A fake torrent for the film 'One Battle After Another' employs a unique technique by embedding malicious PowerShell loaders in subtitle files, ultimately deploying Agent ...
Kali Linux Version 2025.4 Introduces New Hacking Tools and Improvements
Kali Linux 2025.4 marks the final update for the year, introducing new hacking tools, desktop environment improvements, and enhanced support for Wayland, alongside the preview ...
Fieldtex Ransomware Attack: Akira Group Claims Responsibility
The Akira ransomware group has claimed responsibility for the November cyberattack on Fieldtex Products, stating that 14 Gb of data was stolen. The breach potentially ...
Digital-only eVisa Scheme Faces Scrutiny Over Data Leaks and GDPR Concerns
The UK's digital-only eVisa scheme is under fire as civil society groups call for a data protection investigation. Concerns include systemic data errors and possible ...
Gladinet CentreStack Flaw: A Widespread Threat to Organizations
Cybersecurity teams are grappling with a new wave of attacks targeting a Gladinet CentreStack vulnerability, threatening multiple organizations globally.
PyStoreRAT: New JavaScript-Based RAT Distributed via GitHub
Cybersecurity experts uncover a new campaign using GitHub-hosted Python repositories to deploy PyStoreRAT, a JavaScript-based Remote Access Trojan. The threat disguises itself within repositories posing ...
Pentagon Pushes for Post-Quantum Cryptography Amid Rising Tech Tensions
In a pivotal move, the Pentagon's directive to speed up the integration of post-quantum cryptography (PQC) technology comes amid heightened technical tensions. As the U.S. ...
New Cyber Threats: Movie Downloads and Software Updates Under Siege
Cybersecurity incidents reveal a growing threat landscape as hackers infiltrate common online platforms, from movie downloads to browser extensions, leaving users vulnerable. Tech companies and ...
Zero-day Vulnerability in Gogs Leads to Hundreds of Compromised Servers
A zero-day vulnerability in Gogs, a well-known self-hosted Git service, has enabled attackers to execute remote code execution on numerous internet-facing instances, impacting hundreds of ...
Former Employee Faces Charges Over Alleged Cybersecurity Fraud: DoD Compliance in Question
Danielle Hillmer, a former Accenture executive, is facing charges for allegedly misrepresenting the Department of Defense (DoD) compliance of a cloud platform used by her ...
Microsoft Expands Vulnerability Rewards Program to Third-Party Code
Microsoft's updated program rewards security researchers for finding critical vulnerabilities in Microsoft online services, including third-party code. The initiative aims to strengthen digital defenses and ...
Stealthy Campaign Targets Developers With Malicious VSCode Extensions
A stealth campaign has targeted developers using VSCode with 19 malware-infested extensions since February. Threat actors exploit the flexibility of VSCode extensions to distribute malicious ...
CyberVolk’s Return: Unpacking the Pro-Russian Hacktivist’s Ransomware Resurgence
CyberVolk, a pro-Russian hacktivist group, resurfaces with new ransomware. Despite causing alarm, they inadvertently left a method for data recovery.
Cybercrime as a Service: The New Era of Subscription-Based Attacks
Cybercriminals have adopted a subscription-based model akin to SaaS, granting low-skill hackers easy access to potent tools. Phishing kits, OTP bots, infostealer logs, and RATs ...
MITRE’s 2025 ATT&CK Evaluations Reveal Company Performance on Detection Rates
The 2025 ATT&CK Enterprise evaluations by MITRE reveal detailed performance metrics of eleven cybersecurity companies, highlighting their detection capabilities. Several companies achieved a 100% detection ...
LastPass Suffers Major Setback as ICO Imposes Consequences Over 2022 Data Breach
LastPass has been fined £1.2 million by the UK's Information Commissioner's Office due to a severe 2022 data breach. The breach exposed sensitive information from ...
Vulnerabilities in PCIe IDE Protocol Pose Risks to Local Systems
Security flaws in the PCIe IDE protocol in Base Specification Revision 5.0 and beyond have been discovered, which could allow local attackers to exploit systems. ...
Google Patches Gemini Enterprise Vulnerability Exposing Corporate Data
Google has implemented security measures to patch the GeminiJack vulnerability, a zero-click exploit that exposed enterprise data to potential threats through emails and calendar invites. ...
Spiderman Phishing Kit Poses New Threat to European Banks and Crypto Holders
Spiderman phishing kit uses cloned websites to deceive European bank and crypto customers. The fraudulent sites mimic legitimate brands, posing significant risks.