News Archive
All Categories
Cybersecurity Breach
Defence Tech
Cyber Threat
Malware Alert
Security Update
AI Security
23 August 2026
security bypass
Defender’s Own Driver Can Kill Security
Researchers weaponized Microsoft Defender’s trusted boot driver to delete security software before Windows defenses
Read More →
data privacy
TikTok Agrees to $400 Million Privacy Settlement
TikTok will pay $400 million to settle U.S. allegations that it illegally collected children's personal data and violated
Read More →
software supply chain attack
Trojanized npm Packages Deploy AI-Powered Backdoor
Fourteen malicious npm packages secretly install RedC2 4.0, giving attackers advanced Linux control and AI-assisted
Read More →
21 August 2026
AI prompt injection
Encrypted Prompts Can Steal Grok Chat Data
Cryptographic Context Injection hides malicious instructions inside encrypted content, bypassing AI filters and triggering
Read More →
threat roundup
Gogs RCE Tops Weekly Cyber Threats
ThreatsDay highlights critical Gogs and n8n flaws alongside malware, supply-chain, cloud, and AI security risks.
Read More →
AI-enabled ICS attack
AI-Generated Exploits Target Industrial PLCs
Attackers use AI-generated scripts to exploit exposed Siemens PLCs across U.S. critical infrastructure.
Read More →
19 August 2026
data exposure
One Attacker Scrapes Salesforce and ServiceNow
City Forum campaign exploits overly permissive guest access to extract records from public-facing enterprise
Read More →
AI prompt injection
AI Mind Viruses Spread Between Agents
Researchers show hidden prompt injections can propagate across connected AI agents and persist through shared
Read More →
ransomware extortion
Ransom Busters Extorts Ransomware Victims Twice
Suspected ransomware affiliate claims to hack criminal servers, then charges existing victims up to $60,000 to
Read More →
18 August 2026
botnet malware
Evooo1Bot Turns Edge Devices Into Proxies
Mirai-based Linux botnet exploits known vulnerabilities to hijack routers, cameras, and other edge devices as SOCKS5
Read More →
AI security
MCP Servers Put Enterprise Secrets at Risk
Poorly secured MCP servers can expose API keys, credentials, and sensitive enterprise access through weak
Read More →
mobile vulnerability
VoLTE Call Exploit Gains Android Kernel Access
Unisoc modem flaws can turn a malicious VoLTE video call into full Android kernel compromise.
Read More →
16 August 2026
domain abuse
Hackers Spend $7 Million Buying Trust
Threat actors buy expired domains to inherit reputation and traffic, then redirect users to scams, gambling, and...
Read More →
remote code execution vulnerability
SAP Commerce Cloud Flaw Enables RCE
Critical vulnerability could allow unauthenticated attackers to execute arbitrary code on vulnerable SAP Commerce...
Read More →
privacy vulnerability
macOS Screen Sharing Exposes Sensitive Data
Apple Screen Sharing flaw can expose protected information during remote sessions despite macOS privacy...
Read More →
15 August 2026
information stealer
AmnesiaStealer Hijacks Live Browser Sessions
macOS malware steals credentials and gives attackers interactive control of authenticated Chromium browser
Read More →
cyber espionage
Mustang Panda Adds Signed Windows Rootkit
China-linked hackers enhance the CoolClient backdoor with a signed kernel rootkit that hides malicious activity from...
Read More →
session hijacking
Chrome DevTools Enables Silent Session Hijacking
Attackers abuse Chrome DevTools capabilities to control authenticated browser sessions without stealing..
Read More →
14 August 2026
mobile payment fraud
WindRelay Turns Phones Into Payment Proxies
Android malware relays live NFC card data to fraudsters for unauthorized contactless payments and cash withdrawals.
Read More →
cyber espionage
PATCHCORD Targets Indian Critical Infrastructure
Pakistan-aligned hackers deploy new backdoors against Afghan telecom providers and Indian government, defense,
Read More →
information stealer
AmnesiaStealer Hijacks Chromium Browsers
New information stealer targets Chromium browser data to capture credentials, cookies, and other sensitive
Read More →
13 August 2026
critical vulnerability
Adobe Fixes Three CVSS 10.0 Flaws
Critical ColdFusion and Campaign Classic vulnerabilities could enable arbitrary code execution on vulnerable
Read More →
zero-day exploitation
Lazarus Exploits Windows Zero-Day
North Korean hackers exploit a Windows privilege-escalation zero-day to gain SYSTEM access and deploy
Read More →
AI data exposure
AI API Flaw Exposes Hidden Reasoning
Weaknesses in encrypted reasoning objects allowed weaker AI models to recover hidden reasoning and sensitive
Read More →
12 August 2026
privilege escalation
USB Auto-Install Grants Windows SYSTEM Access
Researchers weaponized Windows Plug and Play to turn emulated USB devices into SYSTEM-level privilege
Read More →
AI cybersecurity
OpenAI Launches GPT-5.6 Cyber
New cybersecurity-focused AI model strengthens defensive analysis while introducing additional safeguards against
Read More →
mobile security vulnerability
Malicious SIM Cards Can Hijack Smartphones
Researchers show a modified SIM can abuse trusted cellular interfaces to execute attacker-controlled actions on...
Read More →
11 August 2026
active exploitation
LoadMaster Flaw Faces 792 Exploit Attempts
Attackers actively exploit a critical Progress Kemp LoadMaster command-injection flaw to execute commands
Read More →
ransomware activity
China-Linked Hackers Deploy StormEncryptor
Storm-1175 shifts from Medusa to new ransomware, likely exploiting N-central authentication bypass flaws for initial
Read More →
AI-enabled cyber espionage
Kimsuky Builds Private AI Hacking Stack
North Korean hackers are running AI locally to improve phishing, analyze data, and automate parts of malware
Read More →
10 August 2026
information stealer
ClickFix Malware Drains Mac Crypto Wallets
Social engineering tricks macOS users into running a stealer that targets credentials and cryptocurrency wallets.
Read More →
AI prompt injection
Rovo Prompt Injection Leaks Enterprise Data
Malicious instructions can trick Atlassian Rovo into exfiltrating accessible Jira and Confluence data to attacker...
Read More →
active exploitation
LoadMaster Flaw Added to CISA Exploited List
Attackers are actively exploiting a critical command-injection vulnerability affecting Progress Kemp LoadMaster
Read More →
09 August 2026
active exploitation
N-central Attackers Reach Managed Systems
Attackers exploit N-central authentication bypass flaws to gain administrator access and establish persistence on..
Read More →
webmail vulnerability
CSS Attacks Break Webmail Security Boundaries
New CSS techniques can escape email content boundaries to steal passwords, authentication tokens, and sensitive
Read More →
zero-day exploitation
Metabase Zero-Day Grants Admin Access
Actively exploited CVSS 10.0 flaw lets unauthenticated attackers gain administrator access through SQL injection.
Read More →
07 August 2026
critical infrastructure
Thousands of Rockwell PLCs Exposed Online
More than 4,400 internet-facing Rockwell PLCs increase the risk of attacks against industrial control systems.
Read More →
network security update
Cisco Fixes 12 Critical Network Flaws
Security updates address high-severity vulnerabilities in Cisco SD-WAN and IOS XE networking platforms.
Read More →
hardware vulnerability
Interrupt Injection Bypasses Spectre Defenses
CPU attack bypasses Spectre v2 protections, allowing local attackers to leak sensitive data.
Read More →
06 August 2026
phishing-as-a-service
Kali365 Phishing Kit Targets Microsoft 365
New phishing platform abuses Microsoft's device authentication flow to bypass MFA and hijack enterprise
Read More →
supply compromise
Trojanized npm Packages Hide C2 in Unicode
Malicious npm packages decode hidden command-and-control addresses from Unicode characters to evade
Read More →
privilege escalation
OvsWrap Flaw Grants Linux Root Access
New Linux kernel vulnerability allows local attackers to gain root privileges through Open vSwitch.
Read More →
05 August 2026
ransomware activity
INC Ransomware Becomes Top Threat
INC ransomware rapidly expands operations, surpassing other groups through aggressive double-extortion
Read More →
web hosting vulnerability
cPanel Flaw Enables Server Compromise
Critical vulnerability could let attackers gain unauthorized control over vulnerable cPanel hosting servers.
Read More →
supply compromise
Malicious npm Packages Deploy Cross-Platform Malware
Eighteen rogue npm packages spread malware that targets Windows, Linux, and macOS developers.
Read More →
04 August 2026
malware evasion
Chinese Hackers Abuse Leaked Shellter Tool
China-linked attackers use a leaked commercial red-team framework to deploy stealthy malware and evade EDR.
Read More →
password manager
Google Password Manager Passkeys Face Malware Risk
New attacks let Windows malware silently hijack passkey-protected accounts without user approval.
Read More →
ransomware activity
INC Ransomware Becomes Top Threat
INC ransomware rapidly expands operations, surpassing other groups through aggressive double-extortion
Read More →
02 August 2026
hardware security
Coldcard Wallet Flaw Exposes Seed Phrases
Researchers linked a hardware flaw to fault-injection attacks capable of extracting cryptocurrency wallet seed
Read More →
cyber espionage
Chinese Hackers Target Financial Firms
Suspected Chinese-speaking attackers exploit trusted software and stealth techniques to infiltrate financial
Read More →
remote code execution vulnerability
Adobe Fixes Critical Campaign Classic Flaw
CVSS 10.0 vulnerability could allow attackers to fully compromise Adobe Campaign Classic servers.
Read More →
01 August 2026
browser security
Chrome Fixes 1,442 Security Flaws
Three recent Chrome releases patched a record number of vulnerabilities, most discovered through Google's internal
Read More →
malware loader
HollowFrame Loader Delivers Matryoshka Malware
New malware loader uses layered evasion techniques to deploy Matryoshka payloads while avoiding security
Read More →
supply chain compromise
Fake Android TV Boxes Spy on Users
Low-cost Android TV boxes masquerade as phones to install hidden apps, display ads, and steal user data.
Read More →
31 July 2026
targeted phishing
Silver Fox Targets Japanese Manufacturer
China-linked attackers use tax-themed phishing to deploy stealthy malware against Japanese manufacturing
Read More →
cloud vulnerability
CosmosEscape Exposes Azure Database Secrets
Critical Azure Cosmos DB flaw exposed platform-wide keys, risking cross-tenant database compromise.
Read More →
watering-hole attack
AnySign4PC Exploited Through Trusted Websites
Hackers weaponize compromised Korean websites to silently install backdoors via vulnerable AnySign4PC
Read More →
30 July 2026
critical infrastructure
Coordinated Cyberattack Hits Water Utilities
Attackers targeted over 30 water systems, disrupting operational technology and critical infrastructure services.
Read More →
AI vulnerabilities
Ruflo MCP Flaw Enables Remote Code Execution
Unauthenticated MCP endpoints let attackers execute commands and poison AI agent memory.
Read More →
virtualization vulnerability
VMware Flaws Threaten Virtual Infrastructure
Three critical vulnerabilities enable authentication bypass, remote code execution, and virtual machine escape.
Read More →
28 July 2026
malware evasion
Cruciferra Hides Malware From EDR
Advanced crypter uses BYOVD and Process Ghosting to bypass Windows security and deploy malware.
Read More →
sandbox escape
n8n Sandbox Escape Enables Host Access
Critical sandbox flaw lets workflow creators execute system commands beyond intended execution boundaries.
Read More →
remote intrusion
BlueDash Deploys Level RMM Malware
Operation BlueDash abuses trusted remote management tools to gain persistent enterprise access.
Read More →
27 July 2026
privilege escalation
Certighost Enables Full Domain Takeover
Public exploit lets low-privileged users impersonate domain controllers through Active Directory Certificate Services.
Read More →
malvertising campaign
SourTrade Rebuilds Malware Inside Browsers
Malvertising campaign makes browsers assemble malware, bypassing traditional download-based security detection.
Read More →
ransomware activity
DevMan Streamlines Ransomware Operations
Centralized affiliate portal automates payload creation, victim management, and ransomware profit sharing.
Read More →
26 July 2026
ransomware activity
Cl0p Targets Exposed PTC Platforms
Cl0p affiliates exploit internet-facing Windchill and FlexPLM flaws for data theft and extortion.
Read More →
zero-day exploitation
Fastjson Zero-Day Faces Active Exploitation
Attackers exploit critical Fastjson 1.x RCE flaw while affected applications remain without an official patch.
Read More →
remote exploitation
GitLab RCE PoC Raises Attack Risk
Public exploit code increases the likelihood of real-world attacks against unpatched GitLab servers.
Read More →
25 July 2026
identity protection
Aadhaar Copies Increase Identity Theft Risk
Kolkata Police warns hotel guests against sharing unmasked Aadhaar copies during check-ins.
Read More →
AI vulnerabilities
AgentForger Creates Hidden AI Insiders
Patched ChatGPT flaw allowed phishing attacks to silently deploy attacker-controlled Workspace AI agents.
Read More →
targeted phishing
BlueNoroff Profiles Victims Before Zoom Attacks
North Korean hackers use fake Zoom meetings and victim profiling to deploy targeted malware.
Read More →
24 July 2026
ransomware activity
Chaos Ransomware Hides Behind MSRAT
Attackers route ransomware through MSRAT tunnels to evade detection and maintain covert access.
Read More →
threat roundup
Android Spyware Tops Weekly Threats
Weekly roundup highlights Android spyware, PLC attacks, ransomware, and emerging enterprise cyber threats.
Read More →
AI vulnerability
Claude Cowork Sandbox Escape Discovered
Sandbox flaw could let AI agents access host files beyond intended virtual machine boundaries.
Read More →
23 July 2026
software vulnerability
7-Zip XZ Flaw Enables Code Execution
Crafted XZ archives can trigger remote code execution when opened in vulnerable 7-Zip versions.
Read More →
cyber espionage
Russian Hackers Hijack NATO Security Cameras
Russian intelligence exploits exposed IP cameras to monitor NATO logistics and Ukrainian military movements.
Read More →
exposure management
Exposure Window Drives Modern Cyber Risk
AI speeds vulnerability discovery, but slow remediation leaves organizations exposed to real attacks.
Read More →
19 July 2026
regulatory compliance
EU Forces Android Voice Access
EU mandates broader microphone access to boost competition among voice assistants.
Read More →
malware delivery
ClickFix Captchas Spread LAMEHUG Malware
UAC-0145 abuses fake CAPTCHA pages to infect Windows systems with LAMEHUG malware.
Read More →
zero-day exploitation
SonicWall Zero-Days Under Active Attack
Attackers exploit SonicWall SMA zero-days to gain unauthorized access and compromise enterprise networks.
Read More →
18 July 2026
supply compromise
Malicious Vite Packages Target Developers
Rogue npm packages steal credentials through fake Vite plugins and hidden malicious code.
Read More →
web vulnerability
WP2Shell Exposes WordPress Core
Critical flaw enables remote code execution through vulnerable WordPress core installations.
Read More →
denial-of-service vulnerability
HollowByte Silently Weakens OpenSSL Servers
Tiny TLS requests trigger persistent memory exhaustion without authentication or exploit code.
Read More →
17 July 2026
cyber espionage
GoldenEyeDog Linked to New Espionage Campaign
China-linked subgroup uses stealthy malware and compromised infrastructure for targeted intelligence
Read More →
supply chain attack
Fake Coding Tests Hide OtterCookie Malware
North Korean hackers conceal multi-stage malware inside SVG flag images in trojanized coding projects.
Read More →
botnet malware
NadMesh Hunts Exposed AI Services
Botnet steals cloud keys, Kubernetes tokens, and credentials from misconfigured AI infrastructure.
Read More →
16 July 2026
software vulnerability
n8n OAuth Flaw Risks Account Takeover
Token exchange vulnerability could let attackers hijack authenticated n8n workflow sessions.
Read More →
cybercrime prosecution
Scattered Spider Members Sentenced
Two cybercriminals received prison terms for ransomware attacks and large-scale fraud.
Read More →
threat roundup
Game Cheats Fuel New Cyber Threats
Weekly roundup highlights spyware, rapid ransomware, AI abuse, and supply-chain attacks.
Read More →
15 July 2026
supply compromise
AsyncAPI npm Packages Backdoored
Compromised packages stole developer credentials and threatened software supply-chain security.
Read More →
crypto malware
OkoBot Targets Crypto Wallet Recovery
Malware injects fake recovery phrases to hijack cryptocurrency wallets and steal digital assets.
Read More →
security updates
Major Vendors Rush Critical Security Fixes
Firefox, Chrome, Adobe, and VMware release urgent patches for high-risk vulnerabilities.
Read More →
14 July 2026
enterprise vulnerability
SAP Patches Critical NetWeaver Flaw
High-severity vulnerability could allow attackers to gain unauthorized access to SAP systems.
Read More →
remote access trojan
Fake NVIDIA Tool Delivers LabubuRAT
Malware disguised as an NVIDIA utility installs a stealthy remote access trojan.
Read More →
software vulnerability
RabbitMQ Flaws Expose OAuth Secrets
Critical vulnerabilities could leak OAuth credentials and compromise enterprise messaging systems.
Read More →
13 July 2026
AI malware
AI-Generated Malware Evades Detection
Suspected AI-generated malware uses advanced obfuscation to bypass security tools and analysts.
Read More →
fileless malware
MemGhost Hides Malware in Memory
New attack maintains persistent fileless access by storing malware directly in system memory.
Read More →
AI security
Meta Seeks AI Fraud Detection Patent
New patent describes AI capable of identifying and preventing online fraud in real time.
Read More →
12 July 2026
hardware security
Laser Attack Targets Crypto Wallets
Researchers reset hardware wallets using laser fault injection to bypass security protections.
Read More →
supply compromise
Compromised npm Package Steals Secrets
Malicious Jscrambler release harvested developer credentials through a trusted package update.
Read More →
malware delivery
Police Website Used to Spread Malware
Attackers weaponized a government website to distribute malware through trusted downloads.
Read More →
11 July 2026
firmware vulnerability
U-Boot Flaws Threaten Embedded Devices
Six vulnerabilities enable attackers to bypass Secure Boot and compromise embedded systems.
Read More →
email vulnerability
Critical Zimbra Flaw Enables Account Hijacking
Crafted emails can trigger remote code execution and compromise vulnerable Zimbra servers.
Read More →
supply compromise
GitHub Breach Delivers Crypto Wallet Malware
Compromised Injective Labs repository pushed malicious updates targeting developer cryptocurrency wallets.
Read More →
10 July 2026
account takeover
WhatsApp Flaw Enabled Account Takeover
Vulnerability chained WhatsApp and Microsoft 365 to compromise enterprise cloud accounts.
Read More →
remote access trojan
ModBeaCon RAT Hides in gRPC Traffic
New remote access trojan uses gRPC streaming for stealthy command-and-control communications.
Read More →
software vulnerability
xRing Flaw Enables Remote Code Execution
Unpatched XQUIC vulnerability allows attackers to execute code through crafted QUIC traffic.
Read More →
09 July 2026
privilege escalation
Microsoft Fixes Defender Privilege Flaw
RoguePlanet vulnerability allowed attackers to gain SYSTEM privileges through Microsoft Defender.
Read More →
threat roundup
Cloud Hijacking Dominates Weekly Threats
Threat roundup highlights cloud bucket abuse, AI attacks, ransomware, and supply-chain risks.
Read More →
ransomware
GodDamn Ransomware Abuses Signed Driver
Attackers use PoisonX driver to disable defenses before encrypting enterprise systems.
Read More →
07 July 2026
cybercrime investigation
Windows Device ID Helped Track Hacker
Court documents reveal Microsoft telemetry helped identify an alleged Scattered Spider member.
Read More →
AI vulnerability
Rogue Agent Flaw Exposed GitHub Repositories
Critical GitHub Copilot flaw allowed MCP servers to access private repository data.
Read More →
AI vulnerability
GitHub Issue Trick Targets Developers
Public GitHub issues can manipulate AI coding assistants into executing malicious instructions.
Read More →
06 July 2026
software vulnerability
Gitea Docker Flaw Faces Active Probing
Attackers are scanning for vulnerable Gitea Docker instances to gain remote access.
Read More →
cyber espionage
Fake File Converters Spread Espionage Malware
China-linked hackers use counterfeit converter websites to infect targeted Windows systems.
Read More →
data exfiltration
rojPix Breaches Air-Gapped Networks
Image-based malware covertly steals data from isolated systems without network connectivity.
Read More →
05 July 2026
supply compromise
Fake npm Packages Target Developers
North Korean packages impersonate Rollup tools to steal credentials and enable remote access.
Read More →
linux vulnerability
Bad Epoll Flaw Grants Linux Root
New Linux kernel vulnerability enables local users to gain root privileges.
Read More →
malware framework
Avalon Malware Framework Targets Enterprises
Modular malware framework enables stealthy persistence, credential theft, and remote command execution.
Read More →
04 July 2026
cyber extortion
U.S. Paid Million-Dollar Extortion Demand
Government entity paid attackers to prevent publication of stolen sensitive data.
Read More →
supply compromise
North Korea Expands Supply Chain Attacks
Malicious packages and extensions target developers across multiple software ecosystems.
Read More →
embedded vulnerability
Embedded Filesystem Bugs Threaten Millions
Unpatched FatFs flaws expose embedded devices to memory corruption and code execution.
Read More →
03 July 2026
MacOS malware
PamStealer Targets Apple Silicon Macs
Fake Maccy sites deliver stealthy infostealer validating stolen passwords before data theft.
Read More →
Cyber espionage
Armored Likho Targets Government Networks
Advanced malware campaign strengthens persistence and espionage against government organizations.
Read More →
Cyber espionage
Pegasus Spyware Hits EU Investigator
European lawmaker probing spyware abuses became a Pegasus surveillance target.
Read More →
02 July 2026
Threat roundup
AI Compute Hijacking Leads Weekly Threats
Weekly bulletin highlights AI abuse, Apple flaw, ransomware, and emerging attack techniques.
Read More →
Cyber espionage
Gmail OAuth Attack Evades Authentication
ToddyCat malware abuses OAuth to silently hijack Gmail accounts through trusted browser sessions.
Read More →
AI exploitation
AI Agent Exploits Langflow Automatically
Autonomous agent chained Langflow flaw into full server compromise without human intervention.
Read More →
01 July 2026
AI vulnerability
Cursor Flaws Enable Prompt Injection Attacks
Critical vulnerabilities let prompt injections execute malicious actions and expose developer environments.
Read More →
Banking malware
Ousaban Targets Iberian Banking Users
Brazilian banking trojan uses stealthy phishing and geofencing to hijack financial accounts.
Read More →
Software update
Adobe Fixes Critical Commerce Flaws
Seven maximum-severity vulnerabilities could enable remote code execution on Commerce servers.
Read More →
30 June 2026
AI security
Hundreds Of iOS Apps Leak AI Keys
Researchers found widespread LLM credential exposure across AI-powered iOS applications.
Read More →
Crypto malware
Langflow Flaw Powers Crypto Mining
Attackers exploit Langflow vulnerability to deploy Monero miners on exposed AI servers.
Read More →
Crypto malware
Fake CAPTCHA Spreads Crypto Clipper
Silent Swap campaign hijacks clipboard wallets through deceptive verification pages.
Read More →
29 June 2026
Scam infrastructure
Scam Network Exploits Uni-App Framework
Over 236,000 fraudulent sites abused a legitimate framework to power global scams.
Read More →
Cyber espionage
Gamaredon Expands Ukraine Cyber Campaigns
Russian APT enhances malware, phishing, and cloud abuse against Ukrainian government targets.
Read More →
malware loader
SharkLoader Deploys Cobalt Strike
New loader exploits public flaws to compromise governments and enterprise networks.
Read More →
28 June 2026
AI vulnerability
Amazon Q Flaw Exposes Cloud Credentials
Malicious repositories executed code and stole developer credentials through AI workspace configuration.
Read More →
cyber espionage
Russian Smishing Campaign Targets Officials
Fake support messages steal messaging credentials from government and military personnel.
Read More →
malware loader
SharkLoader Deploys Cobalt Strike
New loader exploits public flaws to compromise governments and enterprise networks.
Read More →
27 June 2026
Software vulnerability
CISA Flags Exploited PTC Flaw
Active attacks prompted urgent patching of critical Windchill remote code execution vulnerability.
Read More →
AI regulation
OpenAI Restricts GPT-5.6 Rollout
Government-requested limits delay public access to advanced AI cybersecurity capabilities.
Read More →
Cyber espionage
FBI Warns Signal Backup Keys Targeted
Russian hackers steal Signal recovery keys to hijack encrypted messaging accounts.
Read More →
26 June 2026
Cyber espionage
Chinese APT Unleashes New Backdoor
New malware maintains stealthy persistence across compromised enterprise and government networks.
Read More →
Linux vulnerability
Linux Kernel Flaw Grants Root Access
New Pedit COW exploit enables local privilege escalation through cached binary poisoning.
Read More →
Network vulnerability
Cisco Zero-Day Granted Root Access
Attackers chained Cisco SD-WAN vulnerabilities to obtain persistent root-level access.
Read More →
25 June 2026
Supply compromise
Popular Ad Blocker Turned Malicious
Compromised Chrome extension secretly hijacked browsers and redirected millions of user requests.
Read More →
Ransomware access
Stealthy Backdoor Aids Ransomware Access
Mistic backdoor strengthens initial access for ransomware groups through stealthy enterprise intrusions.
Read More →
AI malware
AI-Evading Malware Targets macOS
Gaslight malware uses prompt injection to disrupt AI-assisted malware analysis and detection.
Read More →
24 June 2026
Network compromise
FortiBleed Exposes Thousands Of Firewalls
Massive campaign leaked working FortiGate credentials, enabling global firewall compromise risks.
Read More →
Cybercrime disruption
DoJ Strikes Major Cybercrime Marketplace
U.S. seized Huione infrastructure used to launder billions from scams and cybercrime.
Read More →
Supply vulnerability
CI/CD Flaws Expose Hundreds Of Repositories
Cordyceps vulnerabilities allow attackers to hijack workflows and compromise software supply chains.
Read More →
23 June 2026
Malware delivery
Fake Office Files Spread Malware
WhatsApp campaign delivers VBScript malware through deceptive Office document attachments.
Read More →
Supply security
GitHub Blocks Workflow Supply Attacks
Updated Actions checkout mitigates malicious branch and workflow manipulation techniques.
Read More →
AI exploitation
Autonomous AI Removes Human Bottlenecks
Agentic AI enables attacks with minimal human input, accelerating cyber operations.
Read More →
22 June 2026
IoT malware
Legacy Routers Become Stealth Recon Nodes
AryStinger malware hijacks old routers for scanning, proxying, and attacker concealment.
Read More →
Malware delivery
Malicious SVG Files Deliver OxLoader
New OxLoader campaign abuses SVG images to deploy malware and evade detection.
Read More →
Mobile security
Google Tightens Android App Trust
Unverified developers face installation blocks across millions of Android devices.
Read More →
21 June 2026
software update
Apple Fixes Wireless Eavesdropping Risk
Beats Studio Buds flaw enabled nearby attackers to access audio streams and pairing.
Read More →
Software vulnerability
F5 Fixes Critical NGINX Flaws
Severe vulnerabilities expose NGINX environments to denial-of-service and memory corruption risks.
Read More →
hardware vulnerability
USB Exploit Bypasses Modern Defenses
Unpatchable USB attack breaks isolation protections and enables stealthy hardware compromise.
Read More →
20 June 2026
Supply compromise
North Korea Hits AI Supply Chain
Sapphire Sleet compromised Mastra packages to steal developer secrets and crypto wallets.
Read More →
Software vulnerability
WordPress SMTP Flaw Under Attack
Active exploitation exposes email credentials and sensitive configuration data on websites.
Read More →
Supply compromise
Klue Breach Hits Security Firms
Supply-chain compromise exposed customer data from cybersecurity companies using Klue platforms.
Read More →
19 June 2026
AI security
Agentic AI Reshapes Cyber Operations
Autonomous AI links intelligence, validation, and response into continuous security workflows.
Read More →
Network vulnerability
CISA Urges Fortinet Emergency Patching
Active exploitation forces immediate action against critical Fortinet vulnerabilities affecting enterprises.
Read More →
Malware disruption
Operation Endgame Hits Malware Networks
Global operation disrupted SocGholish infrastructure and weakened major cybercrime ecosystems.
Read More →
18 June 2026
AI security
Hidden AI Agents Create Access Risks
Orphaned AI agents retain privileges, exposing sensitive systems and data to misuse.
Read More →
threat roundup
Trusted Platforms Become Attack Vectors
AI chats, npm packages, and phishing campaigns abused legitimate services for attacks.
Read More →
crypto malware
Clipboard Malware Steals Crypto Funds
Windows Clipper malware hijacks copied wallet addresses to redirect cryptocurrency payments.
Read More →
17 June 2026
Software vulnerability
Joomla Flaw Under Active Attack
CISA warns attackers are exploiting critical Joomla JCE vulnerability enabling remote code execution.
Read More →
Supply compromise
Malicious JetBrains Plugins Steal AI Keys
Fake AI coding plugins exfiltrate developer API keys from trusted IDE environments.
Read More →
supply compromise
144 NPM Packages Backdoored
Supply-chain attack compromised AI framework packages, exposing developers and production environments.
Read More →
16 June 2026
Mobile malware
New Android Malware Targets Banking Data
RokaRolla steals credentials, financial information, and device data from Android users.
Read More →
Threat intelligence
Hidden Infrastructure Powers Most Attacks
Survey found anonymized infrastructure enables attackers while defenders remain largely reactive.
Read More →
Network vulnerability
Fortinet Flaws Fuel Active Attacks
Attackers exploit multiple Fortinet vulnerabilities to gain access and compromise networks.
Read More →
15 June 2026
Software vulnerability
Decade-Old phpBB Flaw Fixed
Authentication bypass vulnerability remained hidden for years, exposing forum accounts to compromise.
Read More →
Phishing scam
Fake Facebook Offers Fuel Scams
Fraudsters impersonate trusted entities to steal credentials from MENA region users.
Read More →
Network vulnerability
Palo Alto Flaw Under Active Attack
Exploited PAN-OS vulnerability allows unauthorized VPN access to enterprise networks.
Read More →
14 June 2026
Phishing disruption
FBI Disrupts Massive AI Phishing Network
Authorities dismantled AI-powered phishing infrastructure linked to over one million malicious URLs.
Read More →
insider threat
Insider Hacker Sentenced To Prison
Former employee jailed after cyberattacks disrupted school district systems and operations.
Read More →
privacy concern
Meta Expands Biometric Tracking Ambitions
Meta explores facial recognition capabilities, raising privacy and surveillance concerns globally.
Read More →
13 June 2026
AI regulation
U.S. Halts Access To Advanced AI
Government ordered Anthropic to suspend powerful AI models for foreign nationals worldwide.
Read More →
software vulnerability
Splunk Flaw Enables Code Execution
Low-privileged users can gain remote code execution through vulnerable Splunk components.
Read More →
supply compromise
Arch Repository Hit By Massive Supply Chain Attack
Over 400 AUR packages distributed malware stealing credentials and compromising Linux systems.
Read More →
12 June 2026
phishing disruption
INTERPOL Dismantles Major Phishing Platform
Global operation shut down SniperDz infrastructure and arrested its alleged developer.
Read More →
AI security
AgentJacking Turns AI Into Attackers
New attack hijacks coding agents into executing malicious commands through trusted error reports.
Read More →
security strategy
MDR Evolves For AI-Powered Threats
Security providers shift MDR beyond detection toward prevention, automation, and resilience.
Read More →
11 June 2026
supply security
GitHub Blocks Risky NPM Script Execution
npm will require explicit approval before running install scripts commonly abused in attacks.
Read More →
ransomware activity
Ransomware Gang Claims Hundreds Victims
The Gentlemen ransomware operation reported widespread attacks across multiple industries worldwide.
Read More →
cyber espionage
OceanLotus Targets Vietnamese Investors
State-linked hackers deployed malware through investment-themed lures targeting financial communities.
Read More →
10 June 2026
cyber espionage
Chinese Botnet Expands Military Targeting
JDY botnet grew rapidly, focusing reconnaissance against military and critical infrastructure networks.
Read More →
software update
Critical Enterprise Flaws Patched
Ivanti, Fortinet, and SAP released fixes for high-risk vulnerabilities affecting enterprises.
Read More →
AI vulnerability
Langflow Flaw Enables Full Takeover
Unpatched vulnerability allows remote code execution and complete compromise of AI workflows.
Read More →
09 June 2026
cyber espionage
WinRAR Flaw Fuels Russian Espionage
Russia-aligned groups exploit patched WinRAR vulnerability to deploy malware against Ukrainian targets.
Read More →
backup vulnerability
Veeam Backup Servers Face Critical RCE
Authenticated domain users can execute code on vulnerable backup infrastructure.
Read More →
supply compromise
Microsoft Supply Chain Breach Hits AI Developers
Compromised repositories delivered credential-stealing malware through trusted Microsoft developer tools.
Read More →
08 June 2026
cyber espionage
Linux Malware Expands Beyond Linux
Chinese-linked hackers deployed BSD malware variant to broaden stealthy cross-platform espionage operations.
Read More →
cyber extortion
Hackers Blend Vishing With Physical Intrusions
UNC3753 used fake IT support calls and onsite visits for rapid data theft.
Read More →
network vulnerability
Check Point VPN Flaw Under Attack
Attackers actively exploit critical VPN vulnerability to gain unauthorized network access.
Read More →
07 June 2026
account security
Instagram Flaw Exposed Account Recovery
AI-assisted recovery weakness enabled unauthorized password reset and account takeover attempts.
Read More →
mobile spyware
Android Spyware Targets Arabic Communities
Asin spyware spreads through fake apps targeting journalists and researchers in Arabic regions.
Read More →
AI security
ChatGPT Adds High-Security Lockdown Mode
New mode limits risky features to reduce prompt injection and data theft.
Read More →
06 June 2026
security tooling
OWASP Launches Developer Security Scanner
CVE Lite CLI helps developers detect and remediate dependency vulnerabilities before deployment.
Read More →
AI security
AI Agent Finds 21 Zero-Days
Autonomous AI uncovered 21 vulnerabilities across widely used open-source software projects.
Read More →
software vulnerability
CISA Flags Exploited SolarWinds Flaw
Active attacks prompted CISA to prioritize immediate patching of critical SolarWinds vulnerabilities.
Read More →
05 June 2026
software vulnerability
Laravel Email Validation Flaw Disclosed
CRLF injection bug enables outbound email manipulation and potential mail relay abuse.
Read More →
linux vulnerability
Linux CIFSwitch Flaw Grants Root
Kernel vulnerability enables local users to escalate privileges and obtain root access.
Read More →
AI development
Google Challenges AI Coding Leaders
Antigravity 2.0 introduces autonomous coding agents competing directly with Claude and Codex.
Read More →
04 June 2026
AI security
Agentic AI Reshapes Cyber Defense
Autonomous AI boosts security operations but introduces governance, trust, and control risks.
Read More →
vulnerability management
Cisco Accelerates Vulnerability Disclosures
AI-driven bug discovery forces faster disclosures and proactive security response strategies.
Read More →
AI regulation
U.S. Advances AI Regulation Effort
Lawmakers proposed framework governing AI safety, transparency, accountability, and national security.
Read More →
03 June 2026
malware delivery
Google Domain Abused For Malware Delivery
Attackers leveraged DoubleClick redirects to evade detection and deploy remote access malware.
Read More →
AI security
AI Unearths Hidden RCE Flaw
Autonomous AI discovered a two-year-old remote code execution vulnerability missed by researchers.
Read More →
windows vulnerability
Windows Flaw Leaks Authentication Hashes
Unpatched Windows Search URI bug exposes NTLMv2 hashes through malicious link interactions.
Read More →
02 June 2026
security strategy
EDR Alone Is No Longer Enough
Organizations combine hardening and MDR to improve resilience against AI-powered attacks.
Read More →
AI exploitation
AI Shrinks Exploitation Timelines Dramatically
AI accelerates vulnerability weaponization, reducing defenders’ remediation windows from days to hours.
Read More →
cyber espionage
SideCopy Expands Regional Espionage Campaign
Pakistan-linked hackers targeted Afghan finance entities using phishing and Xeno RAT malware.
Read More →
01 June 2026
cybersecurity recap
Cyber Threats Escalate Across Platforms
Linux flaws, PAN-OS exploits, AI attacks, and phishing campaigns intensified globally.
Read More →
cyber espionage
China-Linked Cyberattacks Intensify Globally
Chinese-aligned groups expanded espionage campaigns targeting governments, infrastructure, and strategic
Read More →
security business
MSP Security Market Expands Rapidly
Rising cyber threats drive MSP adoption, identity security growth, and AI-powered protection.
Read More →