Latest Articles

OpenAI Launches Codex Security After Scanning 1.2 Million Commits and Detecting 10,561 High-Severity Issues

OpenAI Launches Codex Security After Scanning 1.2 Million Commits and Detecting 10,561 High-Severity Issues

OpenAI has introduced Codex Security, an AI-powered security agent designed to detect, validate, and propose fixes for vulnerabilities in software codebases. The tool...

CISA Urges Immediate Patching of iOS Vulnerabilities Used in Crypto-Theft Attacks

CISA Urges Immediate Patching of iOS Vulnerabilities Used in Crypto-Theft Attacks

The CISA (Cybersecurity and Infrastructure Security Agency) has issued a warning directing U.S. federal agencies to urgently patch three actively exploited vulnerabilities affecting Apple iOS...

Fake Claude Code Install Guides Spread Amatera Infostealer in New “InstallFix” Malvertising Campaign

Fake Claude Code Install Guides Spread Amatera Infostealer in New “InstallFix” Malvertising Campaign

Cybersecurity researchers have uncovered a new malware distribution campaign in which attackers impersonate legitimate command-line installation guides for developer tools. The campaign uses a...

Murata Manufacturing Confirms Unauthorized Access to IT Systems in Major Cybersecurity Incident

Murata Manufacturing Confirms Unauthorized Access to IT Systems in Major Cybersecurity Incident

Murata Manufacturing is a very big Japanese company. It makes small electronic parts that go into phones, cars, computers, and many other things. On March 6, 2026 the company said someone got into...

APT36 Unleashes Wave of AI-Generated “Vibeware” Targeting Indian Government Networks

APT36 Unleashes Wave of AI-Generated “Vibeware” Targeting Indian Government Networks

Researchers have uncovered a new cyber campaign attributed to APT36, a Pakistan-linked threat group, that is targeting Indian government networks with large volumes of AI-generated malware. Security...

Dark Web Post Claims 23,000 Speedtest Records for Sale Amid Recent Accenture Acquisition

Dark Web Post Claims 23,000 Speedtest Records for Sale Amid Recent Accenture Acquisition

A new post circulating on a cybercrime forum is claiming that a dataset containing approximately 23,000 records linked to the Speedtest platform is available for sale. The listing appeared on a...

Cognizant’s TriZetto Breach Exposes Health Data of 3.4 Million Patients After Year-Long Intrusion

Cognizant’s TriZetto Breach Exposes Health Data of 3.4 Million Patients After Year-Long Intrusion

TriZetto Provider Solutions, a healthcare IT firm owned by Cognizant, has disclosed a major data breach affecting more than 3.4 million individuals. The incident exposed sensitive patient and...

FBI Confirms Server Breach, Investigates Possible Exposure of Sensitive Surveillance Data

FBI Confirms Server Breach, Investigates Possible Exposure of Sensitive Surveillance Data

The Federal Bureau of Investigation has confirmed that a limited number of its internal servers were compromised earlier this year after an external cyber intrusion. The breach was detected on...

Iran-Linked MuddyWater Hackers Deploy New “Dindoor” Backdoor in Campaign Targeting U.S. Networks

Iran-Linked MuddyWater Hackers Deploy New “Dindoor” Backdoor in Campaign Targeting U.S. Networks

Cybersecurity researchers have uncovered a new campaign attributed to the Iranian state-linked hacking group MuddyWater, which has embedded itself inside several U.S. organizations and deployed a...

Secret Keys Exposed: Over 900 Fortune 500 and Government TLS Certificates Found Vulnerable After Massive Key Leak

Secret Keys Exposed: Over 900 Fortune 500 and Government TLS Certificates Found Vulnerable After Massive Key Leak

A new joint study by Google and GitGuardian has uncovered a troubling weakness at the heart of internet security. Researchers found that more than 2,600 valid TLS certificates protecting major...

AI as a Weaponized Workflow: How Cybercriminals Are Embedding Artificial Intelligence Into Attack

AI as a Weaponized Workflow: How Cybercriminals Are Embedding Artificial Intelligence Into Attack

Artificial intelligence is rapidly becoming a core component of modern cybercrime operations. New research from Microsoft Threat Intelligence shows that threat actors are no longer merely...

China-Linked Cyber Espionage: UAT-9244's Assault on South American Telecom Networks

China-Linked Cyber Espionage: UAT-9244's Assault on South American Telecom Networks

In the ever-evolving landscape of global cybersecurity threats, a sophisticated campaign has emerged targeting the backbone of digital communication in South America. A China-linked advanced...

Mail2Shell: Unmasking the Zero-Click Exploit in FreeScout Mail Servers

Mail2Shell: Unmasking the Zero-Click Exploit in FreeScout Mail Servers

In the ever-evolving landscape of cybersecurity threats, a new vulnerability has emerged that poses a significant risk to organizations relying on open-source helpdesk solutions. Dubbed Mail2Shell,...

Extortion Emails Target Restaurants Using HungerRush POS After Vendor Account Compromise

Extortion Emails Target Restaurants Using HungerRush POS After Vendor Account Compromise

Restaurants using the HungerRush point-of-sale platform have been hit with a wave of extortion emails from a threat actor claiming to possess millions of customer records. The messages warned that...

Police Bust Cross-Border Laundering Ring Exploiting War-Displaced Ukrainian Women Through Online Betting

Police Bust Cross-Border Laundering Ring Exploiting War-Displaced Ukrainian Women Through Online Betting

Spanish and Ukrainian authorities have dismantled a sophisticated money laundering network that exploited war-displaced Ukrainian women to open bank accounts used to move illicit funds through online...

Cyber War Command in Tehran Targeted by Israeli Strike, but Digital Threat From Iran Persists

Cyber War Command in Tehran Targeted by Israeli Strike, but Digital Threat From Iran Persists

Israel has confirmed that it carried out a strike on a compound in Tehran believed to host key cyber warfare units tied to Iran’s Islamic Revolutionary Guard Corps and its Intelligence Directorate....

One Exposed API Key, $82,000 Gone in 48 Hours: How a Simple Mistake Triggered a Massive Cloud Bill

One Exposed API Key, $82,000 Gone in 48 Hours: How a Simple Mistake Triggered a Massive Cloud Bill

It took less than two days for a small development team to learn a painful lesson about cloud security. A single exposed API key linked to Google’s Gemini AI platform allowed attackers to rack up an...

Fake “LastPass Support” Email Threads Attempt to Steal Vault Passwords

Fake “LastPass Support” Email Threads Attempt to Steal Vault Passwords

LastPass is warning customers about an ongoing phishing campaign that impersonates the company’s support team using spoofed display names and fabricated internal email threads. The messages are...

Tycoon 2FA Phishing Platform Dismantled in Global Law Enforcement Takedown

Tycoon 2FA Phishing Platform Dismantled in Global Law Enforcement Takedown

An international law enforcement and private-sector coalition has dismantled Tycoon 2FA, a subscription-based phishing-as-a-service platform that enabled cybercriminals to bypass multi-factor...

Suspected Russian Espionage Campaign Deploys “BadPaw” Loader and “MeowMeow” Backdoor Against Ukraine

Suspected Russian Espionage Campaign Deploys “BadPaw” Loader and “MeowMeow” Backdoor Against Ukraine

Security researchers have uncovered a suspected Russian espionage campaign targeting Ukrainian entities through a carefully crafted phishing operation. The attack chain begins with a malicious email...