Latest Articles

AI Models Caught Protecting Each Other While Defying Human Shutdown Orders

AI Models Caught Protecting Each Other While Defying Human Shutdown Orders

A new AI safety study is raising an uncomfortable question for the industry: what happens when advanced models do not just try to preserve themselves, but start protecting each other too? ...

Microsoft Warns Forest Blizzard Hijacked SOHO Routers for DNS Hijacking and AiTM Attacks

Microsoft Warns Forest Blizzard Hijacked SOHO Routers for DNS Hijacking and AiTM Attacks

Microsoft Threat Intelligence has warned that Forest Blizzard, a threat actor linked to Russian military intelligence, has been compromising vulnerable home and small-office routers and repurposing...

Hims & Hers Support Platform Breach Exposes Customer Data in Third-Party Ticket System Incident

Hims & Hers Support Platform Breach Exposes Customer Data in Third-Party Ticket System Incident

Hims & Hers is warning customers that a breach of its third-party customer support platform exposed personal information submitted through support tickets, adding another high-profile victim to the...

Unmasking the Automated Credential Harvesting Onslaught: How the React2Shell Vulnerability Powers a Global Cyber Campaign

Unmasking the Automated Credential Harvesting Onslaught: How the React2Shell Vulnerability Powers a Global Cyber Campaign

The React2Shell vulnerability, officially designated as CVE-2025-55182, has emerged as one of the most exploited flaws in modern web development frameworks. With a perfect CVSS score of 10.0, this...

Iran-Linked Password Spraying Campaign Targets Municipalities During Missile Strikes: Microsoft 365 Breach Analysis

Iran-Linked Password Spraying Campaign Targets Municipalities During Missile Strikes: Microsoft 365 Breach Analysis

Date: April 2026 A sophisticated cyber campaign attributed to an Iran-linked threat actor has exposed critical vulnerabilities in municipal cloud infrastructure, coinciding with heightened...

GPUBreach Rowhammer Attack: How GDDR6 Bit Flips Enable Full System Takeover via GPU Memory Corruption

GPUBreach Rowhammer Attack: How GDDR6 Bit Flips Enable Full System Takeover via GPU Memory Corruption

A newly disclosed attack technique dubbed GPUBreach has introduced a significant shift in the threat landscape by demonstrating how modern GPUs can be weaponized to achieve full system compromise. By...

Best EDR and XDR Platforms for Enterprise Security in 2026

Best EDR and XDR Platforms for Enterprise Security in 2026

Enterprise security has shifted decisively toward real-time detection and response. Traditional antivirus tools are no longer sufficient against modern threats that rely on fileless techniques,...

Check Point Reveals Hidden ChatGPT DNS Exfiltration Flaw That Could Silently Leak Private User Data

Check Point Reveals Hidden ChatGPT DNS Exfiltration Flaw That Could Silently Leak Private User Data

Check Point Research has disclosed a now-patched vulnerability in ChatGPT that allowed sensitive user data to be silently exfiltrated through DNS resolution, exposing a hidden outbound path inside...

Axios npm Supply Chain Attack: Post-Mortem and Everything We Know So Far

Axios npm Supply Chain Attack: Post-Mortem and Everything We Know So Far

The Axios npm compromise has quickly become one of the most important software supply chain incidents of 2026, not because the attackers poisoned a lookalike package, but because they published...

Cyberattack Disrupts Massachusetts Emergency Dispatch Systems While 911 Service Remains Online

Cyberattack Disrupts Massachusetts Emergency Dispatch Systems While 911 Service Remains Online

A cyberattack has temporarily disrupted operations at the Patriot Regional Emergency Communications Center in northern Massachusetts, affecting public-safety computer systems and non-emergency...

The $285 Million Drift Protocol Hack: North Korea-Linked Social Engineering Shakes Solana DeFi

The $285 Million Drift Protocol Hack: North Korea-Linked Social Engineering Shakes Solana DeFi

On April 1, 2026, Drift Protocol, the leading decentralized perpetual futures exchange on the Solana blockchain, suffered one of the largest exploits in DeFi history. Attackers drained approximately...

French Government Weapons Registry Breached: Personal Data of Thousands of Gun Owners Exposed in Cyberattack on SIA Database

French Government Weapons Registry Breached: Personal Data of Thousands of Gun Owners Exposed in Cyberattack on SIA Database

The French Ministry of the Interior has confirmed a cybersecurity breach involving the national firearms registration platform known as the Système d’Information sur les Armes or SIA. Hackers gained...

UNC1069 Axios Supply Chain Attack: How Social Engineering Compromised npm and Deployed WAVESHAPER Malware

UNC1069 Axios Supply Chain Attack: How Social Engineering Compromised npm and Deployed WAVESHAPER Malware

Date: April 2026 A sophisticated supply chain attack attributed to the threat group UNC1069 has exposed critical vulnerabilities in the open-source ecosystem. By targeting the maintainer of the...

LinkedIn “BrowserGate” Controversy: Allegations of Scanning 6,000+ Chrome Extensions and Device Fingerprinting Explained

LinkedIn “BrowserGate” Controversy: Allegations of Scanning 6,000+ Chrome Extensions and Device Fingerprinting Explained

Date: April 2026 A recent cybersecurity report dubbed “BrowserGate” has sparked intense debate across the tech and privacy communities. The report alleges that LinkedIn deploys hidden JavaScript...

Threat Actor Abuse of AI Shifts From Productivity Tool to Full Cyberattack Surface

Threat Actor Abuse of AI Shifts From Productivity Tool to Full Cyberattack Surface

For much of the past year, the discussion around AI and cybercrime has centered on speed. Microsoft now argues that the more important shift is deeper and more dangerous: threat actors are no longer...

Hasbro Faces Major Cybersecurity Incident: Unauthorized Network Access Detected on March 28, 2026

Hasbro Faces Major Cybersecurity Incident: Unauthorized Network Access Detected on March 28, 2026

Hasbro Inc. identified unauthorized access to its corporate network on March 28, 2026. The toy manufacturer, known for iconic brands including...

Adobe Allegedly Breached as Threat Actor Claims Exposure of Support Tickets, Employee Records, and HackerOne Data

Adobe Allegedly Breached as Threat Actor Claims Exposure of Support Tickets, Employee Records, and HackerOne Data

Adobe is being named in an alleged breach after a threat actor claimed to have accessed sensitive internal data, including millions of support tickets, employee records, HackerOne submissions, and...

Malicious “ChatGPT Ad Blocker” Chrome Extension Stole Full ChatGPT Conversations via Discord Webhook

Malicious “ChatGPT Ad Blocker” Chrome Extension Stole Full ChatGPT Conversations via Discord Webhook

Security researchers have uncovered a malicious Chrome extension called “ChatGPT Ad Blocker” that masqueraded as a lightweight privacy tool while quietly harvesting users’ full ChatGPT conversation...

Microsoft Attributes Axios npm Supply Chain Attack to North Korean Hacker Group Sapphire Sleet

Microsoft Attributes Axios npm Supply Chain Attack to North Korean Hacker Group Sapphire Sleet

Microsoft Threat Intelligence has attributed the recent Axios npm supply chain attack to Sapphire Sleet, a North Korean state actor, after identifying that the malicious package infrastructure and...

Operation NoVoice: Android Rootkit Hidden in 50+ Google Play Apps Hijacked 2.3 Million Devices and Survived Factory Reset

Operation NoVoice: Android Rootkit Hidden in 50+ Google Play Apps Hijacked 2.3 Million Devices and Survived Factory Reset

McAfee’s mobile research team has disclosed a large-scale Android rootkit campaign dubbed Operation NoVoice that used more than 50 malicious apps on Google Play to infect at least 2.3 million...