Latest Articles

Massive Data Breach at World Food Programme Exposes Sensitive Information of 600,000 Gaza Households

Massive Data Breach at World Food Programme Exposes Sensitive Information of 600,000 Gaza Households

In a significant cybersecurity incident that has raised serious concerns about the protection of vulnerable populations, the United Nations World Food Programme (WFP) has confirmed a data breach...

HTTP/2 Bomb DoS Exploit Targets NGINX, Apache, IIS, Envoy, and Cloudflare Pingora

HTTP/2 Bomb DoS Exploit Targets NGINX, Apache, IIS, Envoy, and Cloudflare Pingora

HTTP/2 was built to make the web faster. HTTP/2 Bomb shows how the same efficiency features can become a memory-exhaustion weapon when servers accept compressed headers faster than they can safely...

CISA Adds Linux Kernel cgroups Container Escape Flaw CVE-2022-0492 to Exploited Vulnerabilities Catalog

CISA Adds Linux Kernel cgroups Container Escape Flaw CVE-2022-0492 to Exploited Vulnerabilities Catalog

A container escape bug from 2022 is back in the defender spotlight because CISA now says attackers are exploiting it in the wild. The issue, tracked as CVE-2022-0492, sits in the Linux kernel’s...

Redis RediShell RCE: Authenticated Users Can Trigger Lua Use-After-Free for OS Command Execution

Redis RediShell RCE: Authenticated Users Can Trigger Lua Use-After-Free for OS Command Execution

Redis is not just a cache sitting quietly behind applications. In many environments, it holds sessions, tokens, queues, transient business data, and cloud-adjacent secrets close enough to become a...

Cyber Claim Targets ACE Hospital: Ransomware Group Hits Pune Healthcare Provider

Cyber Claim Targets ACE Hospital: Ransomware Group Hits Pune Healthcare Provider

In the latest development underscoring the vulnerability of India's healthcare sector, KillSecurity, a known ransomware-as-a-service operation, has publicly claimed responsibility for breaching ACE...

Microsoft Android Apps Debug Flag Exposed Billions of Downloads to Token Theft Risk

Microsoft Android Apps Debug Flag Exposed Billions of Downloads to Token Theft Risk

One leftover debug flag is all it took to turn trusted Microsoft Android apps into a potential token exposure path. SecurityWeek reported on June 2, 2026, that researchers at Enclave found a...

Critical HP Poly VoIP Phone Vulnerability Exposes Enterprises to Root-Level RCE

Critical HP Poly VoIP Phone Vulnerability Exposes Enterprises to Root-Level RCE

Enterprise phones rarely sit at the top of the patching queue. That is exactly why this bug matters. A critical vulnerability in HP Poly VoIP phones can give an unauthenticated attacker remote...

Mini Shai-Hulud-Style Worm Compromises 32 Red Hat Cloud Services npm Packages

Mini Shai-Hulud-Style Worm Compromises 32 Red Hat Cloud Services npm Packages

A trusted package namespace is exactly where defenders least want to find a credential-stealing worm. On June 1, 2026, security researchers reported that multiple official npm packages under Red...

CISA Flags Oracle WebLogic CVE-2024-21182 as Actively Exploited: Urgent Patching Required for Enterprise Java Environments

CISA Flags Oracle WebLogic CVE-2024-21182 as Actively Exploited: Urgent Patching Required for Enterprise Java Environments

On June 1, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2024-21182, a high-severity vulnerability in Oracle WebLogic Server, to its Known Exploited Vulnerabilities...

CVE-2026-41940 Exploited to Deploy Filemanager Backdoor, Cryptominers, and Possible Ransomware Payloads

CVE-2026-41940 Exploited to Deploy Filemanager Backdoor, Cryptominers, and Possible Ransomware Payloads

CVE-2026-41940 is the kind of control-panel vulnerability defenders cannot afford to treat as “just another hosting bug.” Once attackers can bypass authentication on cPanel or WebHost Manager, the...

Palo Alto Networks CVE-2026-0257 Exploited in the Wild: GlobalProtect Patch and Mitigation Priority

Palo Alto Networks CVE-2026-0257 Exploited in the Wild: GlobalProtect Patch and Mitigation Priority

A medium-rated VPN bug becomes a very different problem once attackers start using it against real environments. That is where Palo Alto Networks CVE-2026-0257 now sits. The issue affects...

Carnival Corporation Confirms Major Data Breach Affecting Nearly 6 Million Customers

Carnival Corporation Confirms Major Data Breach Affecting Nearly 6 Million Customers

In a significant cybersecurity event that has raised concerns across the travel industry, Carnival Corporation, the world's largest cruise operator, has officially confirmed a data breach that...

 Inside the FortiClient EMS Zero-Day: How CVE-2026-35616 Became One of 2026's Most Dangerous Enterprise Exploits

Inside the FortiClient EMS Zero-Day: How CVE-2026-35616 Became One of 2026's Most Dangerous Enterprise Exploits

In late March 2026, threat actors silently slipped into enterprise networks around the world through a flaw that Fortinet had not yet publicly acknowledged. By the time the security vendor published...

FBI Warns of Fake FIFA Portals Harvesting Credentials and Payment Data Ahead of 2026 World Cup

FBI Warns of Fake FIFA Portals Harvesting Credentials and Payment Data Ahead of 2026 World Cup

The 2026 FIFA World Cup has not kicked off yet, but the fraud economy around it is already live. The FBI has issued a public alert warning that threat actors are deploying spoofed FIFA websites to...

CISA Adds DAEMON Tools Lite Supply-Chain Compromise to KEV After Signed Installers Delivered Malware

CISA Adds DAEMON Tools Lite Supply-Chain Compromise to KEV After Signed Installers Delivered Malware

The DAEMON Tools Lite incident is a reminder that “downloaded from the official website” is not the same thing as safe. CISA has added CVE-2026-8398, tracked as the DAEMON Tools Lite Embedded...

Dutch Police and NCSC Disrupt 17 Million-Device Botnet Running Through Netherlands-Based Servers

Dutch Police and NCSC Disrupt 17 Million-Device Botnet Running Through Netherlands-Based Servers

A botnet with 17 million infected devices is not just a malware problem. It is an internet trust problem. Dutch authorities have disrupted a massive global botnet after investigators traced 200...

CrowdStrike, Google and Shadowserver Dismantle Glassworm Botnet Targeting Developers

CrowdStrike, Google and Shadowserver Dismantle Glassworm Botnet Targeting Developers

Glassworm was not just another botnet waiting on infected machines. It was built to sit inside the software supply chain. CrowdStrike says it has dismantled the developer-targeting Glassworm...

DragonForce Ransomware Hits Alliance Adjustment Group: Insurance Claims Adjuster Breached in Latest Cyber Attack

DragonForce Ransomware Hits Alliance Adjustment Group: Insurance Claims Adjuster Breached in Latest Cyber Attack

May 27, 2026 — In a developing cybersecurity incident, Alliance Adjustment Group, a prominent independent insurance claims adjusting firm, has been targeted by the DragonForce ransomware group. The...

KnowledgeDeliver Zero-Day CVE-2026-5426 Exploited via ASP.NET ViewState Deserialization

KnowledgeDeliver Zero-Day CVE-2026-5426 Exploited via ASP.NET ViewState Deserialization

This was not just a vulnerable web server. It was a trusted learning platform turned into a delivery point for malware. Mandiant has detailed exploitation of CVE-2026-5426, a KnowledgeDeliver...

Microsoft Fixes SharePoint RCE CVE-2026-45659 Affecting Server 2016, 2019, and Subscription Edition

Microsoft Fixes SharePoint RCE CVE-2026-45659 Affecting Server 2016, 2019, and Subscription Edition

SharePoint vulnerabilities rarely stay theoretical for long. When a collaboration platform sits close to sensitive files, workflows, intranet portals, and identity-connected services, even an...