Cyber Security
Alleged ShinyHunters Leader ‘Rey’ Reportedly Held in Jordan
Nikkei Discloses M365 Breach, 9,000 Spoofed Emails Sent
Google Pauses Open-Source Bug Bounty Over AI Report Flood
Critical FortiMail Zero-Day Exploited With No Patch Yet
Police Dismantle KillSec Ransomware Gang, Nab Teen Leader
Kiteworks Patches Second Max-Severity Flaw in a Week
Self-Healing WordPress Backdoor Defies Standard Removal
Cisco Patches Actively Exploited Catalyst SD-WAN Flaw
MetaMask Discloses Incident, Exits Ethereum Validators
TeamViewer Patches Critical Access-Control Bypass Flaw
WatchGuard Patches Critical Root Code Execution Flaw
CISA Warns of Critical Pre-Auth Flaw in MikroTik Routers
FTC Confirms Probe Into OpenAI, Anthropic AI Agents
Teen Researcher’s AI Tool Gains Admin on Microsoft Titan
OpenSSL Patches High-Severity DTLS Memory Leak Flaw
CSuite Phishing Campaign Hijacks Microsoft 365 Sessions
Chrome, Firefox Patch Over 100 Flaws in Joint Update
Pentagon Records Agency Breach Exposes Data on 3 Million
France Tax Agency Breached Seven Weeks via Stolen Passwords
Citrix NetScaler Zero-Days Deployed WHIPSHOT, SLAPSHOT
FBI Tells ShinyHunters Members to Turn Themselves In
Russia’s Star Blizzard Targets 100+ Orgs With Fake Invites
New Spectre-v2 BTR Attack Leaks Linux Root Password Hashes
Autonomous AI Agent Breaches Cybersecurity Nonprofit DIVD
OpenAI Discloses Self-Replicating Worm-Style Prompt Injection
Fake ChatGPT Custom GPTs Push ClickFix Attacks to Drop RAT
101 Malicious npm Packages Add Developers to WhatsApp Groups
Glow Security Finds 13,000 Exposed AI Agent Screenshots
Kiteworks Patches Critical Flaw Found During Precautionary Shutdown
Ex-Air Force Members Sentenced to 189 Months for BEC Scams
Former Employee Faces Charges Over Alleged Cybersecurity Fraud DoD Compliance in Question
Cybersecurity
Former Employee Faces Charges Over Alleged Cybersecurity Fraud: DoD Compliance in Question
Danielle Hillmer, a former Accenture executive, is facing charges for allegedly misrepresenting the Department of Defense (DoD) compliance of a cloud platform used by her ...
Microsoft Expands Vulnerability Rewards Program to Third-Party Code
Cybersecurity
Microsoft Expands Vulnerability Rewards Program to Third-Party Code
Microsoft's updated program rewards security researchers for finding critical vulnerabilities in Microsoft online services, including third-party code. The initiative aims to strengthen digital defenses and ...
Stealthy Campaign Targets Developers With Malicious VSCode Extensions
Application Security
Stealthy Campaign Targets Developers With Malicious VSCode Extensions
A stealth campaign has targeted developers using VSCode with 19 malware-infested extensions since February. Threat actors exploit the flexibility of VSCode extensions to distribute malicious ...
CyberVolk's Return Unpacking the Pro-Russian Hacktivist's Ransomware Resurgence
News
CyberVolk’s Return: Unpacking the Pro-Russian Hacktivist’s Ransomware Resurgence
CyberVolk, a pro-Russian hacktivist group, resurfaces with new ransomware. Despite causing alarm, they inadvertently left a method for data recovery.
Cybercrime as a Service The New Era of Subscription-Based Attacks
Cybersecurity
Cybercrime as a Service: The New Era of Subscription-Based Attacks
Cybercriminals have adopted a subscription-based model akin to SaaS, granting low-skill hackers easy access to potent tools. Phishing kits, OTP bots, infostealer logs, and RATs ...
MITRE's 2025 ATT&CK Evaluations Reveal Company Performance on Detection Rates
News
MITRE’s 2025 ATT&CK Evaluations Reveal Company Performance on Detection Rates
The 2025 ATT&CK Enterprise evaluations by MITRE reveal detailed performance metrics of eleven cybersecurity companies, highlighting their detection capabilities. Several companies achieved a 100% detection ...
LastPass Suffers Major Setback as ICO Imposes Consequences Over 2022 Data Breach
Cybersecurity
LastPass Suffers Major Setback as ICO Imposes Consequences Over 2022 Data Breach
LastPass has been fined £1.2 million by the UK's Information Commissioner's Office due to a severe 2022 data breach. The breach exposed sensitive information from ...
Vulnerabilities in PCIe IDE Protocol Pose Risks to Local Systems
Cybersecurity
Vulnerabilities in PCIe IDE Protocol Pose Risks to Local Systems
Security flaws in the PCIe IDE protocol in Base Specification Revision 5.0 and beyond have been discovered, which could allow local attackers to exploit systems. ...
Google Patches Gemini Enterprise Vulnerability Exposing Corporate Data
Application Security
Google Patches Gemini Enterprise Vulnerability Exposing Corporate Data
Google has implemented security measures to patch the GeminiJack vulnerability, a zero-click exploit that exposed enterprise data to potential threats through emails and calendar invites. ...
Spiderman Phishing Kit Poses New Threat to European Banks and Crypto Holders
News
Spiderman Phishing Kit Poses New Threat to European Banks and Crypto Holders
Spiderman phishing kit uses cloned websites to deceive European bank and crypto customers. The fraudulent sites mimic legitimate brands, posing significant risks.
Why Insuring Keith Richards' Fingers Highlights Risk Management in Cybersecurity
Cybersecurity
Why Insuring Keith Richards’ Fingers Highlights Risk Management in Cybersecurity
Celebrities have insured body parts like Keith Richards' fingers, echoing the importance of protecting vital assets, much like prioritizing key elements in cybersecurity.
Docker Hub Data Exposure Puts Thousands of Containers at Risk
Data Security
Docker Hub Data Exposure Puts Thousands of Containers at Risk
More than 10,000 Docker Hub container images have been found to expose sensitive data, including live credentials for production systems and CI/CD databases. The exposure ...
React2Shell Exploit Continues to Deliver Undetected Malware Families
Cybersecurity
React2Shell Exploit Continues to Deliver Undetected Malware Families
React2Shell is exploiting a severe flaw in React Server Components to install cryptocurrency miners and introduce unseen malware families. The threats include a Linux backdoor, ...
Microsoft Advances Teams Security With New Suspicious Traffic Analysis Feature
Application Security
Microsoft Advances Teams Security With New Suspicious Traffic Analysis Feature
Microsoft is set to bolster Teams with a new security feature that examines suspicious traffic involving external domains. This strategic enhancement is poised to assist ...
Microsoft Faces Criticism Over Unresolved .NET Vulnerability
Application Security
Microsoft Faces Criticism Over Unresolved .NET Vulnerability
Researchers identified a .NET security flaw impacting enterprise-grade solutions, urging a fix. Despite discovering the vulnerability, Microsoft has chosen not to address the issue, leading ...
NET Framework Vulnerability SOAPwn Impact on Enterprise Applications
Application Security
.NET Framework Vulnerability SOAPwn: Impact on Enterprise Applications
A new vulnerability dubbed SOAPwn has been discovered within the .NET Framework, posing significant risks to enterprise applications by potentially enabling remote code execution. Several ...
Teen Hacker Arrested in Spain for Major Data Breach Scheme
Cybersecurity
Teen Hacker Arrested in Spain for Major Data Breach Scheme
Spanish authorities have apprehended a 19-year-old in Barcelona for allegedly stealing and attempting to sell 64 million records from nine breached companies. This significant arrest ...
Satellite Signal Interruption Causes Porsche Immobilization in Russia
Cybersecurity
Satellite Signal Interruption Causes Porsche Immobilization in Russia
Hundreds of Porsches in Russia became immobile due to satellite communication issues, sparking fears of a hack. However, Porsche asserts no breach occurred and their ...
Ivanti Urges Immediate Patch for Endpoint Manager Vulnerability
CVE Vulnerability Alerts
Ivanti Urges Immediate Patch for Endpoint Manager Vulnerability
Ivanti has issued an urgent patch for a critical vulnerability, CVE-2023-35082, in its Endpoint Manager solution. This flaw enables attackers to remotely execute code, highlighting ...
Prime Security Secures $20 Million to Advance AI-Powered Security Tools
Cybersecurity
Prime Security Secures $20 Million to Advance AI-Powered Security Tools
Prime Security has secured $20 million in funding to develop its AI-powered platform that autonomously performs security design reviews and identifies design flaws. This venture ...
Application Security
Rejetto HFS Flaw Lets Hackers Forge Admin Sessions for RCE
Cybersecurity
South Korea’s President Orders Probe Into Bank Data Breaches
Cybersecurity
Police Dismantle KillSec Ransomware Gang, Nab Teen Leader
Cybersecurity
Ransomware Attack Disrupts Keio Corporation Business Systems

TOP CYBERSECURITY HEADLINES

This Week’s Security Spotlight

Cybersecurity
South Korea’s President Orders Probe Into Bank Data Breaches
Application Security
Google Pauses Open-Source Bug Bounty Over AI Report Flood
Cybersecurity
FTC Confirms Probe Into OpenAI, Anthropic AI Agents
Cybersecurity
CSuite Phishing Campaign Hijacks Microsoft 365 Sessions
Trending

Daily Briefing Newsletter

Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Featured Videos​

  • All
  • Application Security
  • Blog
  • CVE Vulnerability Alerts
  • Cybersecurity
  • Cybersecurity Newsletter
  • Data Security
  • Endpoint Security
  • Identity and Access Management
  • Information Security
  • Network Security
  • News
  • Phishing
  • Podcasts
  • Product Reviews
  • Ransomware
  • Ransomware Victims
  • Resources
  • Security Spotlight
  • Sponsored
  • Threat Actors
  • Threat Actors
  • Threat Detection Tools
Stealthy Campaign Targets Developers With Malicious VSCode Extensions
A stealth campaign has targeted developers using VSCode with 19 malware-infested extensions since February. Threat actors exploit the flexibility of VSCode extensions to distribute malicious ...
CyberVolk’s Return: Unpacking the Pro-Russian Hacktivist’s Ransomware Resurgence
CyberVolk, a pro-Russian hacktivist group, resurfaces with new ransomware. Despite causing alarm, they inadvertently left a method for data recovery.
Cybercrime as a Service: The New Era of Subscription-Based Attacks
Cybercriminals have adopted a subscription-based model akin to SaaS, granting low-skill hackers easy access to potent tools. Phishing kits, OTP bots, infostealer logs, and RATs ...
MITRE’s 2025 ATT&CK Evaluations Reveal Company Performance on Detection Rates
The 2025 ATT&CK Enterprise evaluations by MITRE reveal detailed performance metrics of eleven cybersecurity companies, highlighting their detection capabilities. Several companies achieved a 100% detection ...
LastPass Suffers Major Setback as ICO Imposes Consequences Over 2022 Data Breach
LastPass has been fined £1.2 million by the UK's Information Commissioner's Office due to a severe 2022 data breach. The breach exposed sensitive information from ...
Vulnerabilities in PCIe IDE Protocol Pose Risks to Local Systems
Security flaws in the PCIe IDE protocol in Base Specification Revision 5.0 and beyond have been discovered, which could allow local attackers to exploit systems. ...
Google Patches Gemini Enterprise Vulnerability Exposing Corporate Data
Google has implemented security measures to patch the GeminiJack vulnerability, a zero-click exploit that exposed enterprise data to potential threats through emails and calendar invites. ...
Spiderman Phishing Kit Poses New Threat to European Banks and Crypto Holders
Spiderman phishing kit uses cloned websites to deceive European bank and crypto customers. The fraudulent sites mimic legitimate brands, posing significant risks.
Why Insuring Keith Richards’ Fingers Highlights Risk Management in Cybersecurity
Celebrities have insured body parts like Keith Richards' fingers, echoing the importance of protecting vital assets, much like prioritizing key elements in cybersecurity.
Docker Hub Data Exposure Puts Thousands of Containers at Risk
More than 10,000 Docker Hub container images have been found to expose sensitive data, including live credentials for production systems and CI/CD databases. The exposure ...
React2Shell Exploit Continues to Deliver Undetected Malware Families
React2Shell is exploiting a severe flaw in React Server Components to install cryptocurrency miners and introduce unseen malware families. The threats include a Linux backdoor, ...
Microsoft Advances Teams Security With New Suspicious Traffic Analysis Feature
Microsoft is set to bolster Teams with a new security feature that examines suspicious traffic involving external domains. This strategic enhancement is poised to assist ...
Microsoft Faces Criticism Over Unresolved .NET Vulnerability
Researchers identified a .NET security flaw impacting enterprise-grade solutions, urging a fix. Despite discovering the vulnerability, Microsoft has chosen not to address the issue, leading ...
.NET Framework Vulnerability SOAPwn: Impact on Enterprise Applications
A new vulnerability dubbed SOAPwn has been discovered within the .NET Framework, posing significant risks to enterprise applications by potentially enabling remote code execution. Several ...
Teen Hacker Arrested in Spain for Major Data Breach Scheme
Spanish authorities have apprehended a 19-year-old in Barcelona for allegedly stealing and attempting to sell 64 million records from nine breached companies. This significant arrest ...
Satellite Signal Interruption Causes Porsche Immobilization in Russia
Hundreds of Porsches in Russia became immobile due to satellite communication issues, sparking fears of a hack. However, Porsche asserts no breach occurred and their ...
Ivanti Urges Immediate Patch for Endpoint Manager Vulnerability
Ivanti has issued an urgent patch for a critical vulnerability, CVE-2023-35082, in its Endpoint Manager solution. This flaw enables attackers to remotely execute code, highlighting ...
Prime Security Secures $20 Million to Advance AI-Powered Security Tools
Prime Security has secured $20 million in funding to develop its AI-powered platform that autonomously performs security design reviews and identifies design flaws. This venture ...
Microsoft Appoints New Operating CISOs to Enhance AI-Driven Cyberdefense
Microsoft's initiative to appoint new operating CISOs reflects a strategic shift towards AI defense capabilities. Underlining the importance of operational oversight, this move aligns with ...
Fortinet Releases Fixes for Critical Vulnerabilities Affecting FortiOS and Other Products
Fortinet addresses critical vulnerabilities in FortiOS and associated products with new security updates. These weaknesses could allow attackers to bypass the FortiCloud Single Sign-On (SSO) ...