Latest Articles

Major Data Breach at France Titres Exposes Personal Information of Millions of Citizens

Major Data Breach at France Titres Exposes Personal Information of Millions of Citizens

In a significant blow to public trust in government systems, France Titres, the national agency responsible for issuing and managing secure identity documents, has confirmed a major cybersecurity...

Chinese APT Mustang Panda Targets Indian Banks and Korean Policy Circles With LOTUSLITE Malware

Chinese APT Mustang Panda Targets Indian Banks and Korean Policy Circles With LOTUSLITE Malware

China-linked threat actor Mustang Panda appears to be widening its playbook. New research shows the group, long associated with geopolitical espionage, has pushed a fresh LOTUSLITE campaign into...

NSW Government Rocked by Insider Data Breach: Treasury Staffer Charged for Alleged Theft of Over 5,500 Sensitive Documents

NSW Government Rocked by Insider Data Breach: Treasury Staffer Charged for Alleged Theft of Over 5,500 Sensitive Documents

NSW Police arrested a 45-year-old man identified as Jagan Ganti Venkata Satya on Monday in connection with a major internal data security incident at the New South Wales Treasury. The individual,...

Vercel Breach Tied to Context.ai OAuth Compromise Exposes Internal Systems and Non-Sensitive Secrets

Vercel Breach Tied to Context.ai OAuth Compromise Exposes Internal Systems and Non-Sensitive Secrets

Vercel has disclosed a security incident involving unauthorized access to certain internal systems, tracing the intrusion back to a compromise of Context.ai, a third-party AI tool used by a Vercel...

ShinyHunters Claims 7-Eleven Breach, Threatens to Leak 600,000 Salesforce Records

ShinyHunters Claims 7-Eleven Breach, Threatens to Leak 600,000 Salesforce Records

7-Eleven has been named on the ShinyHunters leak site in a new extortion claim that says more than 600,000 Salesforce records containing personally identifiable information and internal corporate...

The Gentlemen & SystemBC: Inside a Fast-Growing Ransomware Operation Built for Enterprise-Scale Intrusions

The Gentlemen & SystemBC: Inside a Fast-Growing Ransomware Operation Built for Enterprise-Scale Intrusions

The Gentlemen is not yet as famous as some of the older ransomware brands, but that may not last long. According to Check Point Research, the ransomware-as-a-service operation has rapidly expanded...

Defending Your Enterprise When AI Models Can Find Vulnerabilities Faster Than Ever

Defending Your Enterprise When AI Models Can Find Vulnerabilities Faster Than Ever

For years, defenders have treated vulnerability management as a race they could still partly control. A critical flaw would be disclosed, security teams would assess exposure, patch windows would be...

UAE Cyber Security Council Warns 1 in 4 Public Files Expose Sensitive Personal Data

UAE Cyber Security Council Warns 1 in 4 Public Files Expose Sensitive Personal Data

The UAE Cyber Security Council has issued a stark warning about how much sensitive data is still being exposed through everyday file-sharing habits. According to the Council, roughly 25 percent of...

Apple Account Change Emails Abused in New Phishing Campaign That Passes SPF, DKIM, and DMARC

Apple Account Change Emails Abused in New Phishing Campaign That Passes SPF, DKIM, and DMARC

Cybercriminals have found a way to turn Apple’s own account-change notification system into a phishing delivery channel, sending fake purchase alerts through Apple’s real mail infrastructure rather...

SafePay Ransomware Targets BBA Law Group: Houston Immigration Law Firm Faces Double-Extortion Threat in Latest Cyber Attack

SafePay Ransomware Targets BBA Law Group: Houston Immigration Law Firm Faces Double-Extortion Threat in Latest Cyber Attack

BBA Law Group, operating as BBA Immigration, has become the latest victim listed by the SafePay ransomware group. The incident was publicly claimed on April 17, 2026, with the domain bbalawgroup.com...

Google Blocked 602 Million Scam Ads With Gemini as AI Turns Ad Safety Into a Real-Time Cyber Fight

Google Blocked 602 Million Scam Ads With Gemini as AI Turns Ad Safety Into a Real-Time Cyber Fight

Google says it is using its Gemini models around the clock to identify and block scam ads in real time, marking one of the clearest examples yet of how large platforms are turning generative AI into...

Zerion Loses $100,000 in DPRK-Linked Social Engineering Attack as UNC1069 Targets Crypto Firms

Zerion Loses $100,000 in DPRK-Linked Social Engineering Attack as UNC1069 Targets Crypto Firms

Zerion has disclosed that roughly $100,000 was stolen from its internal hot wallets after a team member was hit in what the company linked to a sophisticated, AI-enabled social engineering campaign...

CISA Flags Actively Exploited Apache ActiveMQ Jolokia Flaw Found With AI After 13 Years

CISA Flags Actively Exploited Apache ActiveMQ Jolokia Flaw Found With AI After 13 Years

A high-severity Apache ActiveMQ vulnerability that appears to have been sitting quietly in the codebase since roughly 2013 is now at the center of an urgent patching push after CISA confirmed active...

U.S. Nationals Jailed Over DPRK IT Worker Laptop Farm Scheme That Hit 100+ Companies

U.S. Nationals Jailed Over DPRK IT Worker Laptop Farm Scheme That Hit 100+ Companies

Two U.S. nationals have been sentenced to prison for helping North Korean IT workers pose as American remote employees, in a case that shows just how effective the DPRK’s fake-worker playbook has...

Qilin Ransomware Assault on Die Linke: Cyberattack Exposes Vulnerabilities in German Political Cybersecurity

Qilin Ransomware Assault on Die Linke: Cyberattack Exposes Vulnerabilities in German Political Cybersecurity

The German democratic socialist political party Die Linke fell victim to a significant ransomware operation carried out by the Qilin group in late March 2026. The attack led to a temporary outage of...

CoinbaseCartel Targets Astreya: Inside the Latest Data Extortion Attack Shaking the IT Services Sector

CoinbaseCartel Targets Astreya: Inside the Latest Data Extortion Attack Shaking the IT Services Sector

Astreya is a prominent player in the managed IT services and consulting industry, offering comprehensive solutions that help enterprises streamline their technology operations. Headquartered in...

NIST Limits CVE Enrichment Amid Surge in Vulnerability Submissions: What It Means for Cybersecurity

NIST Limits CVE Enrichment Amid Surge in Vulnerability Submissions: What It Means for Cybersecurity

The National Institute of Standards and Technology (NIST) has announced a major shift in how it manages and enriches Common Vulnerabilities and Exposures (CVE) records, citing an unprecedented surge...

n8n Webhook Abuse Since October 2025: How Threat Actors Weaponized Cloud Workflows for Phishing and Malware Delivery

n8n Webhook Abuse Since October 2025: How Threat Actors Weaponized Cloud Workflows for Phishing and Malware Delivery

Since October 2025, cybersecurity researchers have observed a sharp increase in the abuse of cloud-based workflow automation platforms, particularly n8n, by threat actors. These attackers ...

ICS Patch Tuesday: Siemens, Schneider, Rockwell and Others Fix Industrial Flaws as Iran-Linked PLC Threats Escalate

ICS Patch Tuesday: Siemens, Schneider, Rockwell and Others Fix Industrial Flaws as Iran-Linked PLC Threats Escalate

Industrial operators got two warnings at once this week, and together they tell a bigger story than either one alone. On one side, eight major OT and industrial automation vendors published fresh...

Microsoft April 2026 Patch Tuesday Addresses 169 Vulnerabilities Including Actively Exploited SharePoint Zero-Day

Microsoft April 2026 Patch Tuesday Addresses 169 Vulnerabilities Including Actively Exploited SharePoint Zero-Day

Microsoft released security updates in April 2026 that address a total of 169 vulnerabilities across its extensive product portfolio. This large volume includes eight vulnerabilities rated as...