Latest Articles

Hidden AI Access: Thousands of Exposed Google Cloud API Keys Quietly Gained Gemini Privileges

Hidden AI Access: Thousands of Exposed Google Cloud API Keys Quietly Gained Gemini Privileges

Thousands of publicly exposed Google Cloud API keys may have silently gained access to Gemini AI services after organizations enabled the Generative Language API, according to new security research....

University of Hawaiʻi Cancer Center Data Breach Exposes Sensitive Information of Over a Million Individuals

University of Hawaiʻi Cancer Center Data Breach Exposes Sensitive Information of Over a Million Individuals

In a significant cybersecurity incident, the University of Hawaiʻi Cancer Center fell victim to a ransomware attack that compromised sensitive personal information belonging to potentially over a...

APT37 Hackers Deploy New Malware to Breach Air-Gapped Networks

APT37 Hackers Deploy New Malware to Breach Air-Gapped Networks

Security researchers have identified a new malware campaign attributed to APT37, a North Korean state-linked threat actor, targeting air-gapped environments. The operation demonstrates increasingly...

Pentagon Designates Anthropic a Supply Chain Risk Amid Escalating AI–Military Policy Dispute

Pentagon Designates Anthropic a Supply Chain Risk Amid Escalating AI–Military Policy Dispute

The U.S. Department of Defense (DoD) has reportedly designated AI developer Anthropic as a “supply chain risk,” a move that signals heightened scrutiny in federal procurement processes and...

Meta Escalates Legal Fight Against Scam Networks Targeting Celebrities and Consumers

Meta Escalates Legal Fight Against Scam Networks Targeting Celebrities and Consumers

Meta has launched a new wave of legal action against scam advertisers operating across multiple continents, signaling a more aggressive stance against fraud networks abusing its advertising...

Claude Code Security and the Identity Reckoning: Why the Real Risk in the AI Era Isn’t Code

Claude Code Security and the Identity Reckoning: Why the Real Risk in the AI Era Isn’t Code

When Anthropic unveiled Claude Code Security, markets reacted instantly. A tool capable of scanning full codebases, identifying vulnerabilities, and proposing fixes directly inside developer...

Juniper PTX Routers Hit by Critical Junos OS Evolved Flaw Allowing Unauthenticated Root RCE

Juniper PTX Routers Hit by Critical Junos OS Evolved Flaw Allowing Unauthenticated Root RCE

Juniper Networks has issued an out-of-band security update for Junos OS Evolved on PTX series routers after identifying a critical vulnerability that can hand an attacker root-level code execution...

Darktrace Detects 32 Million Phishing Emails in 2025 Amid Surge in Identity Attacks

Darktrace Detects 32 Million Phishing Emails in 2025 Amid Surge in Identity Attacks

Darktrace reported detecting more than 32 million high-confidence phishing emails in 2025, highlighting a significant rise in automated, identity-driven cyberattacks. The findings indicate that...

Unveiling the Critical Zero-Day: CVE-2026-20127 in Cisco SD-WAN Systems and Its Global Ramifications

Unveiling the Critical Zero-Day: CVE-2026-20127 in Cisco SD-WAN Systems and Its Global Ramifications

In the ever-evolving landscape of cybersecurity threats, a new vulnerability has emerged as a stark reminder of the vulnerabilities inherent in even the most robust network infrastructures. On...

VMware Aria Operations Flaws Patched, Including Critical RCE (CVE-2026-22719)

VMware Aria Operations Flaws Patched, Including Critical RCE (CVE-2026-22719)

Broadcom has released security updates addressing multiple vulnerabilities in VMware Aria Operations, including a critical command injection flaw that could allow remote code execution (RCE) by...

CarGurus Data Breach Exposes 12.4 Million Accounts

CarGurus Data Breach Exposes 12.4 Million Accounts

The ShinyHunters extortion group has published a 6.1GB archive allegedly containing data from 12.4 million CarGurus user accounts. The dataset includes a broad range of personal and account-related...

Microsoft Expands Copilot Data Controls Across All Storage Locations

Microsoft Expands Copilot Data Controls Across All Storage Locations

Microsoft is strengthening data protection controls for Microsoft 365 Copilot by expanding Microsoft Purview Data Loss Prevention (DLP) enforcement across all storage locations. The update ensures...

North Korean Lazarus Group Adopts Medusa Ransomware for Extortion Campaigns

North Korean Lazarus Group Adopts Medusa Ransomware for Extortion Campaigns

In a significant development within the cybersecurity landscape, the notorious North Korean state-sponsored hacking collective known as the Lazarus Group has been linked to the deployment of Medusa...

Exposing the Undercurrent: Google and Mandiant Disrupt GRIDTIDE, a Cloud API Powered Espionage Campaign Spanning 42 Countries

Exposing the Undercurrent: Google and Mandiant Disrupt GRIDTIDE, a Cloud API Powered Espionage Campaign Spanning 42 Countries

When defenders talk about “living off the cloud,” this is what they mean. Last week, Google Threat Intelligence Group (GTIG), Mandiant, and partners moved to disrupt a long-running espionage...

SolarWinds Serv-U 15.5.4 Fixes Four High-Impact Privileged RCE Vulnerabilities

SolarWinds Serv-U 15.5.4 Fixes Four High-Impact Privileged RCE Vulnerabilities

SolarWinds has released Serv-U version 15.5.4 to address four critical vulnerabilities affecting Serv-U 15.5 installations. The flaws, tracked as CVE-2025-40538 through CVE-2025-40541, each carry a...

Caught in the Hook: RCE and API Token Exfiltration in Claude Code Expose New AI Supply Chain Risks

Caught in the Hook: RCE and API Token Exfiltration in Claude Code Expose New AI Supply Chain Risks

Researchers at Check Point have disclosed critical vulnerabilities in Anthropic’s Claude Code that could allow attackers to achieve remote code execution and silently exfiltrate API credentials...

Marquis Sues SonicWall Over Backup Breach That Triggered Ransomware Attack Affecting 74 Banks

Marquis Sues SonicWall Over Backup Breach That Triggered Ransomware Attack Affecting 74 Banks

Marquis Software Solutions has filed a lawsuit against cybersecurity vendor SonicWall, alleging that security failures within the vendor’s cloud backup infrastructure enabled a ransomware attack that...

The Ransomware Assault on Greater Pittsburgh Orthopedic Associates: Unpacking the 2025 Cyber Incident

The Ransomware Assault on Greater Pittsburgh Orthopedic Associates: Unpacking the 2025 Cyber Incident

In the ever-evolving landscape of digital threats, healthcare organizations remain prime targets for cybercriminals seeking to exploit sensitive patient data for profit. One such incident that has...

Machine-Speed Intrusions: LLMs Embedded into a Global Attack Pipeline

Machine-Speed Intrusions: LLMs Embedded into a Global Attack Pipeline

A new report by independent threat researcher @goyaramen outlines how a likely lone operator integrated large language models (LLMs) directly into a malicious intrusion workflow, enabling...

APT28 Targets European Organizations with Webhook-Based Macro Malware

APT28 Targets European Organizations with Webhook-Based Macro Malware

Researchers at S2 Grupo’s LAB52 have attributed a spear-phishing campaign dubbed “Operation MacroMaze” to the Russia-linked threat group APT28. Active between September 2025 and January 2026, the...