Latest Articles

SolarWinds Serv-U 15.5.4 Fixes Four High-Impact Privileged RCE Vulnerabilities

SolarWinds Serv-U 15.5.4 Fixes Four High-Impact Privileged RCE Vulnerabilities

SolarWinds has released Serv-U version 15.5.4 to address four critical vulnerabilities affecting Serv-U 15.5 installations. The flaws, tracked as CVE-2025-40538 through CVE-2025-40541, each carry a...

Caught in the Hook: RCE and API Token Exfiltration in Claude Code Expose New AI Supply Chain Risks

Caught in the Hook: RCE and API Token Exfiltration in Claude Code Expose New AI Supply Chain Risks

Researchers at Check Point have disclosed critical vulnerabilities in Anthropic’s Claude Code that could allow attackers to achieve remote code execution and silently exfiltrate API credentials...

Marquis Sues SonicWall Over Backup Breach That Triggered Ransomware Attack Affecting 74 Banks

Marquis Sues SonicWall Over Backup Breach That Triggered Ransomware Attack Affecting 74 Banks

Marquis Software Solutions has filed a lawsuit against cybersecurity vendor SonicWall, alleging that security failures within the vendor’s cloud backup infrastructure enabled a ransomware attack that...

The Ransomware Assault on Greater Pittsburgh Orthopedic Associates: Unpacking the 2025 Cyber Incident

The Ransomware Assault on Greater Pittsburgh Orthopedic Associates: Unpacking the 2025 Cyber Incident

In the ever-evolving landscape of digital threats, healthcare organizations remain prime targets for cybercriminals seeking to exploit sensitive patient data for profit. One such incident that has...

Machine-Speed Intrusions: LLMs Embedded into a Global Attack Pipeline

Machine-Speed Intrusions: LLMs Embedded into a Global Attack Pipeline

A new report by independent threat researcher @goyaramen outlines how a likely lone operator integrated large language models (LLMs) directly into a malicious intrusion workflow, enabling...

APT28 Targets European Organizations with Webhook-Based Macro Malware

APT28 Targets European Organizations with Webhook-Based Macro Malware

Researchers at S2 Grupo’s LAB52 have attributed a spear-phishing campaign dubbed “Operation MacroMaze” to the Russia-linked threat group APT28. Active between September 2025 and January 2026, the...

Optimizely Confirms Data Breach Following Vishing Attack

Optimizely Confirms Data Breach Following Vishing Attack

New York-based advertising technology firm Optimizely has confirmed that threat actors gained access to portions of its internal systems through a voice-phishing (vishing) attack. The company has...

The Invisible Backdoor: AI Uncovers Malicious OAuth Apps Hiding in Microsoft Entra ID

The Invisible Backdoor: AI Uncovers Malicious OAuth Apps Hiding in Microsoft Entra ID

The modern enterprise runs on integrations. From document signing platforms to collaboration tools and CRM systems, third-party applications are now deeply embedded into daily workflows. But...

US Healthcare Diagnostic Firm Reports Data Breach Impacting Nearly 140,000 Individuals

US Healthcare Diagnostic Firm Reports Data Breach Impacting Nearly 140,000 Individuals

Nearly 140,000 individuals have been affected by a data breach involving US-based diagnostic services provider Vikor Scientific, now operating under the name Vanta Diagnostics. The incident came to...

Critical Grandstream GXP1600 Flaw Enables Remote Code Execution and Call Interception

Critical Grandstream GXP1600 Flaw Enables Remote Code Execution and Call Interception

A critical vulnerability affecting Grandstream GXP1600 series IP phones could allow unauthenticated attackers to execute arbitrary code as root and potentially intercept voice calls. The flaw,...

Arkanix Stealer Emerges as Short-Lived AI-Assisted Info-Stealer Experiment

Arkanix Stealer Emerges as Short-Lived AI-Assisted Info-Stealer Experiment

Security researchers at Kaspersky have analyzed a new information-stealing malware operation known as “Arkanix Stealer,” which surfaced on dark web forums in late 2025 before abruptly disappearing...

AI-Assisted Hacker Breaches 600 Fortinet Firewalls Across 55 Countries

AI-Assisted Hacker Breaches 600 Fortinet Firewalls Across 55 Countries

Amazon has reported that a Russian-speaking threat actor leveraged generative AI services to compromise more than 600 FortiGate firewalls across 55 countries within a five-week period. The campaign...

The Keys to the Kingdom: Evaluating the Top 5 Enterprise Password Managers

The Keys to the Kingdom: Evaluating the Top 5 Enterprise Password Managers

In the current threat landscape, the single greatest vulnerability in most organizations remains the human element. Specifically, the credentials they use to access corporate resources. Despite the...

CISA Escalates Alert: Two Critical Roundcube Webmail Vulnerabilities Join the Known Exploited Catalog

CISA Escalates Alert: Two Critical Roundcube Webmail Vulnerabilities Join the Known Exploited Catalog

In a move underscoring the relentless pace of cyber threats, the U.S. Cybersecurity and Infrastructure Security Agency, commonly known as CISA, has recently expanded its Known Exploited...

PayPal Data Breach Exposed Sensitive User Data for Six Months, Raising Fresh Security Concerns

PayPal Data Breach Exposed Sensitive User Data for Six Months, Raising Fresh Security Concerns

A significant data breach at PayPal has exposed sensitive user information over a six month period, triggering renewed scrutiny of security controls across the global digital payments ecosystem. The...

Predator Spyware Hooks iOS SpringBoard to Hide Camera and Microphone Activity

Predator Spyware Hooks iOS SpringBoard to Hide Camera and Microphone Activity

A new technical analysis has revealed advanced capabilities in the Predator spyware platform, showing how the surveillance tool can manipulate iOS internals to conceal active camera and microphone...

UAE Foils AI-Powered “Terrorist” Cyber Attacks Targeting Vital Infrastructure

UAE Foils AI-Powered “Terrorist” Cyber Attacks Targeting Vital Infrastructure

The United Arab Emirates has thwarted a series of what officials described as organised cyber attacks of a terrorist nature targeting vital national sectors. The announcement was made over the...

Ransomware Onslaught: The Devastating Cyber Attack on Mississippi's Premier Medical Center

Ransomware Onslaught: The Devastating Cyber Attack on Mississippi's Premier Medical Center

In the early hours of February 19, 2026, the University of Mississippi Medical Center, commonly known as UMMC, fell victim to a sophisticated ransomware attack. This incident has sent shockwaves...

“PromptSpy” Android Malware Abuses Google Gemini AI to Evade Detection

“PromptSpy” Android Malware Abuses Google Gemini AI to Evade Detection

Security researchers have identified what is being described as the first known Android malware to actively abuse a commercial generative AI system at runtime in order to maintain persistence and...

DDoS Attacks Surge 168% as Multi-Terabit Campaigns Redefine the Threat Landscape

DDoS Attacks Surge 168% as Multi-Terabit Campaigns Redefine the Threat Landscape

Distributed Denial-of-Service attacks are escalating at a pace that security teams are struggling to match. New research from Radware’s 2026 Global Threat Analysis Report highlights what it describes...