Latest Articles

Gunra Ransomware Campaign Targets Critical Infrastructure Through Exploited Network Devices

Gunra Ransomware Campaign Targets Critical Infrastructure Through Exploited Network Devices

Cybersecurity authorities in the United States and South Korea have issued a warning about an active Gunra ransomware campaign targeting organizations across critical infrastructure and other...

Valve Warns European Steam Hardware Buyers After CEVA Logistics Cyberattack Exposes Customer Delivery Data

Valve Warns European Steam Hardware Buyers After CEVA Logistics Cyberattack Exposes Customer Delivery Data

Valve Corporation has begun notifying European customers who recently ordered Steam hardware that their personal delivery information was likely compromised in a cyberattack on the company’s shipping...

Levi Strauss Confirms Social Engineering Attack That Allowed Hackers to Steal Corporate Data from Employee Computers

Levi Strauss Confirms Social Engineering Attack That Allowed Hackers to Steal Corporate Data from Employee Computers

Levi Strauss & Co., the iconic American apparel company best known for its Levi's denim brand, has disclosed a cybersecurity incident in which attackers used social engineering techniques to...

Critical Metabase Zero-Day SQL Injection Flaw Actively Exploited, Exposing Customer Data at Framework and Tally

Critical Metabase Zero-Day SQL Injection Flaw Actively Exploited, Exposing Customer Data at Framework and Tally

A maximum-severity security vulnerability in Metabase, the popular open-source business intelligence and data visualization platform, was exploited as a zero-day starting around August 3, 2026. The...

Critical Unauthenticated RCE Flaw in IBM Langflow Sparks Urgent CISA Alert Amid Active Exploitation

Critical Unauthenticated RCE Flaw in IBM Langflow Sparks Urgent CISA Alert Amid Active Exploitation

Security teams worldwide are racing to secure their environments after the United States Cybersecurity and Infrastructure Security Agency added a severe vulnerability in IBM Langflow to its Known...

ChainDrop npm Worm Poisons 2,200+ Releases and Turns Valid Provenance Into Cover

ChainDrop npm Worm Poisons 2,200+ Releases and Turns Valid Provenance Into Cover

The releases were signed. The provenance was valid. The code was still malware. A self-propagating npm worm tracked as ChainDrop tore through the JavaScript ecosystem on August 4, 2026, compromising...

Actively Exploited Cisco FMC Flaw CVE-2026-20316 Exposes Sensitive Firewall Data

Actively Exploited Cisco FMC Flaw CVE-2026-20316 Exposes Sensitive Firewall Data

The credentials were already inside the firewall manager. Attackers only needed to know how to use them. Cisco has confirmed active exploitation of CVE-2026-20316, a static-credential...

Critical cPanel Flaw CVE-2026-58048 Lets Hosting Users Execute SQL as Database Root

Critical cPanel Flaw CVE-2026-58048 Lets Hosting Users Execute SQL as Database Root

A routine database-management action became a path to the most powerful identity in the database. cPanel has patched CVE-2026-58048, a critical flaw that allows an authenticated hosting customer with...

Silent Takeovers: How Pass-ta-key Attacks Let Malware Hijack Google Synced Passkeys on Windows

Silent Takeovers: How Pass-ta-key Attacks Let Malware Hijack Google Synced Passkeys on Windows

Passkeys have been widely promoted as the long-awaited successor to passwords. They promise phishing-resistant authentication through public-key cryptography, device-bound credentials, and biometric...

SonicWall SMA1000 Zero-Days Fuel INC Ransomware Attacks Against Enterprise VPN Infrastructure

SonicWall SMA1000 Zero-Days Fuel INC Ransomware Attacks Against Enterprise VPN Infrastructure

Edge appliances have become the preferred front door for ransomware operators, and SonicWall's SMA1000 platform is the latest reminder why. Security researchers have linked the INC Ransomware group...

CVE-2026-18577: N-central Authentication Bypass Gives Attackers Admin Control Over MSP Environments

CVE-2026-18577: N-central Authentication Bypass Gives Attackers Admin Control Over MSP Environments

Some vulnerabilities compromise a server. Others compromise an entire customer base. CVE-2026-18577 falls firmly into the second category. The actively exploited authentication bypass in N-able's...

Amgen Discloses Material Cybersecurity Incident Involving Patient and Proprietary Data Theft from Third-Party Cloud Environments

Amgen Discloses Material Cybersecurity Incident Involving Patient and Proprietary Data Theft from Third-Party Cloud Environments

Amgen Inc., one of the world’s leading biotechnology companies, has publicly disclosed a material cybersecurity incident that involved unauthorized access to data stored in cloud environments managed...

Russian Hackers TA488 Exploit Microsoft OWA Vulnerability for Persistent Mailbox Access

Russian Hackers TA488 Exploit Microsoft OWA Vulnerability for Persistent Mailbox Access

In a sophisticated cyber espionage campaign, the Russia aligned threat group known as TA488 has leveraged a cross site scripting vulnerability in Microsoft Outlook Web Access to achieve long term...

Critical FastJson RCE Zero-Day Under Active Exploitation: Unauthenticated Attacks Hit U.S. Organizations

Critical FastJson RCE Zero-Day Under Active Exploitation: Unauthenticated Attacks Hit U.S. Organizations

A critical remote code execution vulnerability in the widely used FastJson Java library is being actively exploited in the wild, targeting organizations across the United States. Security researchers...

Coca-Cola Confirms Data Breach Following Fairlife Ransomware Attack as Anubis Threatens Data Leak

Coca-Cola Confirms Data Breach Following Fairlife Ransomware Attack as Anubis Threatens Data Leak

What began as a production disruption has now escalated into a confirmed data breach. The Coca-Cola Company has acknowledged that cybercriminals stole data during the ransomware attack that targeted...

MCBS Data Breach Impacts 1.2 Million Patients as PEAR Ransomware Claims 3TB Data Theft

MCBS Data Breach Impacts 1.2 Million Patients as PEAR Ransomware Claims 3TB Data Theft

Healthcare organizations continue to pay the price for attacks against third-party service providers. Medical Computer Business Services (MCBS), a revenue cycle management and medical billing company...

ServiceNow Pre-Auth RCE (CVE-2026-6875) Actively Exploited as Attackers Bypass Published Techniques

ServiceNow Pre-Auth RCE (CVE-2026-6875) Actively Exploited as Attackers Bypass Published Techniques

Critical vulnerabilities rarely remain theoretical for long, and CVE-2026-6875 has already crossed that line. Days after public disclosure, threat intelligence researchers confirmed active...

Critical Facebook and Meta Account Takeover Flaws Expose Users to Rapid Compromise

Critical Facebook and Meta Account Takeover Flaws Expose Users to Rapid Compromise

Identity has become the new battleground, and the latest research targeting Meta's authentication ecosystem reinforces why. A newly disclosed chain of critical vulnerabilities demonstrates how...

Rising Sextortion Scams Exploit Massive Data Leaks from ShinyHunters Group

Rising Sextortion Scams Exploit Massive Data Leaks from ShinyHunters Group

ShinyHunters is a well-known cyber extortion collective responsible for some of the largest data leaks in recent years. The group has repeatedly targeted major corporations and organizations,...

Origin Energy Suffers Major Customer Data Breach Affecting Millions of Australians

Origin Energy Suffers Major Customer Data Breach Affecting Millions of Australians

One of Australia's largest energy retailers, Origin Energy, has confirmed a significant cybersecurity incident involving unauthorized access to customer data. The breach has raised serious concerns...