Latest Articles

Crunchyroll Investigates Alleged Breach After Hacker Claims Theft of 6.8 Million User Records

Crunchyroll Investigates Alleged Breach After Hacker Claims Theft of 6.8 Million User Records

Anime streaming platform Crunchyroll is investigating a potential data breach after a threat actor claimed to have stolen personal information tied to roughly 6.8 million users, raising fresh...

HackerOne Discloses Employee Data Breach After Navia Hack Exposed SSNs and Benefits Data

HackerOne Discloses Employee Data Breach After Navia Hack Exposed SSNs and Benefits Data

Bug bounty platform HackerOne is notifying employees that their personal information was exposed following a breach at Navia, one of its U.S. benefits administrators, in an incident that highlights...

ShinyHunters Claim Data Theft from Ameriprise Financial in Latest Cybersecurity Scare

ShinyHunters Claim Data Theft from Ameriprise Financial in Latest Cybersecurity Scare

Ameriprise Financial has become the focus of a fresh cybersecurity claim issued by the notorious hacking collective ShinyHunters. The group publicly stated on underground leak forums that it had...

North Korean Hackers Exploit VS Code Auto-Run Tasks to Deploy StoatWaffle Malware

North Korean Hackers Exploit VS Code Auto-Run Tasks to Deploy StoatWaffle Malware

A North Korean-linked threat actor known as WaterPlum, also referred to as Contagious Interview, has been identified targeting developers through a sophisticated malware campaign leveraging Visual...

Mazda Discloses Data Breach Affecting Employees and Business Partners

Mazda Discloses Data Breach Affecting Employees and Business Partners

Mazda Motor Corporation has disclosed a cybersecurity incident involving unauthorized access to a warehouse management system used for handling automotive parts procured from Thailand. The breach...

Tycoon2FA Phishing Platform Rebounds Days After Global Takedown

Tycoon2FA Phishing Platform Rebounds Days After Global Takedown

The phishing-as-a-service platform Tycoon2FA has rapidly resumed operations just days after a coordinated international takedown led by Europol and Microsoft. Despite the seizure of hundreds of...

Mandiant Says Voice Phishing Is Replacing Email Phishing as Attackers Target SaaS Identities

Mandiant Says Voice Phishing Is Replacing Email Phishing as Attackers Target SaaS Identities

Voice phishing is rapidly overtaking traditional email phishing as one of the most effective initial access techniques used by attackers, according to Mandiant's newly released M-Trends 2026...

Trivy Supply Chain Attack Spreads Infostealer via Docker, Fuels CanisterWorm and Kubernetes Wiper Attacks

Trivy Supply Chain Attack Spreads Infostealer via Docker, Fuels CanisterWorm and Kubernetes Wiper Attacks

Cybersecurity researchers have uncovered a widening supply-chain attack centered on Trivy, the widely used open-source vulnerability scanner, after threat actors pushed trojanized container images to...

Microsoft Warns of IRS Tax-Season Phishing Campaign Hitting 29,000 Users With ScreenConnect, Datto, and SimpleHelp

Microsoft Warns of IRS Tax-Season Phishing Campaign Hitting 29,000 Users With ScreenConnect, Datto, and SimpleHelp

Microsoft has warned of fresh tax-season phishing campaigns that are impersonating the Internal Revenue Service (IRS), accountants, and tax professionals to steal credentials, capture two-factor...

WorldLeaks Ransomware Attack Disrupts Los Angeles Services, Data of Residents Potentially Compromised

WorldLeaks Ransomware Attack Disrupts Los Angeles Services, Data of Residents Potentially Compromised

A major cyberattack attributed to the WorldLeaks ransomware group has impacted the City of Los Angeles and its public transportation network, causing widespread service disruptions and raising...

North Korean IT Worker Scheme Exposed: U.S. Sentences Three Men in Remote Work Fraud Operation

North Korean IT Worker Scheme Exposed: U.S. Sentences Three Men in Remote Work Fraud Operation

In a striking case highlighting the intersection of cybercrime and insider threats, three American men have been sentenced for assisting North Korean operatives in securing remote IT jobs at U.S....

CISA Adds Apple, Craft CMS, and Laravel Livewire Flaws to KEV Catalog as Active Exploitation Expands

CISA Adds Apple, Craft CMS, and Laravel Livewire Flaws to KEV Catalog as Active Exploitation Expands

U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five newly confirmed, actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, raising the...

 Critical Quest KACE SMA Authentication Bypass (CVE-2025-32975, CVSS 10.0) Now Actively Exploited: Full Administrative Takeover Threatens Managed Endpoints

Critical Quest KACE SMA Authentication Bypass (CVE-2025-32975, CVSS 10.0) Now Actively Exploited: Full Administrative Takeover Threatens Managed Endpoints

The Quest KACE Systems Management Appliance remains one of the most widely deployed on-premises endpoint management platforms in education districts, municipal governments, and mid-market...

OWASP Top 10 2025 Explained: What Changed Since 2021 and Why It Matters for Modern AppSec

OWASP Top 10 2025 Explained: What Changed Since 2021 and Why It Matters for Modern AppSec

The OWASP Top 10:2025 is now the latest official OWASP list of the most critical web application security risks, and while the familiar themes remain, the ranking tells a very modern story....

The Agentic SOC: Why Security Leaders Should Invest in AI Supervisors, Not Just More Tools

The Agentic SOC: Why Security Leaders Should Invest in AI Supervisors, Not Just More Tools

The next major shift in security operations will not come from adding another dashboard, another detection feed, or another analyst console. It will come from changing the operating model of the SOC...

The Death of the SOC L1 Analyst: Why AI is the Best Thing to Happen to Your Career

The Death of the SOC L1 Analyst: Why AI is the Best Thing to Happen to Your Career

Let’s say the uncomfortable part out loud: the traditional Tier 1 SOC analyst role, at least as it has existed for years, deserves to die. Not because entry-level analysts are unimportant. Not...

The Invisible Threat: How GlassWorm's Unicode Malware is Poisoning Open-Source Ecosystems Worldwide

The Invisible Threat: How GlassWorm's Unicode Malware is Poisoning Open-Source Ecosystems Worldwide

The attackers primarily abuse Unicode variation selectors from two specific ranges: U+FE00 to U+FE0F (Variation Selectors) and U+E0100 to U+E01EF (Variation Selectors Supplement). These code points...

Invoice-Themed Phishing Campaign Targets Financial Workflows During Fiscal Year-End Activity

Invoice-Themed Phishing Campaign Targets Financial Workflows During Fiscal Year-End Activity

Cybersecurity researchers at CYFIRMA have identified a targeted phishing campaign that leverages invoice-themed lures to exploit organizations during fiscal year-end financial activities. The...

Google Introduces ‘Advanced Flow’ to Secure APK Sideloading on Android

Google Introduces ‘Advanced Flow’ to Secure APK Sideloading on Android

Google has unveiled a new security feature called “Advanced Flow” aimed at improving the safety of APK sideloading on Android devices. The update is designed to protect users from malicious...

Microsoft Azure Monitor Alerts Abused in Sophisticated Callback Phishing Attacks

Microsoft Azure Monitor Alerts Abused in Sophisticated Callback Phishing Attacks

Cybersecurity researchers have identified a new phishing technique in which attackers are abusing legitimate alerting features within Microsoft Azure Monitor to launch convincing callback phishing...