Latest Articles

BridgePay Confirms Ransomware Attack After Nationwide Payment Outage

BridgePay Confirms Ransomware Attack After Nationwide Payment Outage

BridgePay Network Solutions has confirmed that a ransomware attack was responsible for a widespread outage that disrupted payment processing across the United States. The incident forced merchants,...

AI Agents’ Most Downloaded Skill Turns Malicious as Researchers Uncover Infostealer Campaign

AI Agents’ Most Downloaded Skill Turns Malicious as Researchers Uncover Infostealer Campaign

A popular skill used by AI agents has been discovered to function as an infostealer, raising fresh concerns about how rapidly expanding agent ecosystems are becoming an attractive target for...

Cyber Siege: Ransomware Attack Paralyzes La Sapienza University in Rome

Cyber Siege: Ransomware Attack Paralyzes La Sapienza University in Rome

In the heart of Rome, one of Europe's oldest and largest universities has been thrust into a digital crisis. La Sapienza University, a venerable institution founded in 1303 and home to approximately...

Malicious dYdX Packages Slip Into npm and PyPI After Maintainer Compromise, Enabling Wallet Theft and Remote Access

Malicious dYdX Packages Slip Into npm and PyPI After Maintainer Compromise, Enabling Wallet Theft and Remote Access

A sophisticated supply chain attack has struck the cryptocurrency ecosystem after malicious versions of official dYdX client libraries were published to both npm and PyPI. The compromised packages...

Winter Olympics Disrupted by Suspected Russian-Linked Cyberattack as Major European University Reports Breach

Winter Olympics Disrupted by Suspected Russian-Linked Cyberattack as Major European University Reports Breach

The Winter Olympics have become the latest high-profile target of a suspected Russian-linked cyberattack, as organizers confirmed disruptions to digital services during the event. The incident...

Phishing and OAuth Token Flaws Lead to Full Microsoft 365 Compromise

Phishing and OAuth Token Flaws Lead to Full Microsoft 365 Compromise

Modern cloud applications are often built for speed and convenience, but in doing so they can quietly introduce attack paths that are easy to overlook. A newly detailed attack chain shows how...

Potential Breach leads to Spain’s Ministry of Science IT Systems Shut Down

Potential Breach leads to Spain’s Ministry of Science IT Systems Shut Down

Spain’s Ministry of Science has temporarily shut down portions of its IT infrastructure following claims by threat actors that they breached internal systems. The move, confirmed by government...

Conduent Data Breach Escalation: A Massive Cyber Intrusion Exposing Millions

Conduent Data Breach Escalation: A Massive Cyber Intrusion Exposing Millions

In the realm of cybersecurity, few events underscore the vulnerabilities of modern digital infrastructures as starkly as the Conduent data breach. What started as an undetected intrusion in late 2024...

Hackers Compromise NGINX Servers to Silently Redirect User Traffic

Hackers Compromise NGINX Servers to Silently Redirect User Traffic

Cybersecurity researchers have uncovered an active campaign in which attackers are compromising NGINX web servers to covertly redirect user traffic to malicious or monetized destinations. The...

Al-Futtaim Confirms Data Breach Impacting Customer and Employee Information

Al-Futtaim Confirms Data Breach Impacting Customer and Employee Information

Al-Futtaim Group, one of the Middle East’s largest and most diversified conglomerates, has confirmed a data breach that resulted in unauthorized access to sensitive information belonging to customers...

Harvard and University of Pennsylvania Data Exposed in ShinyHunters Extortion Campaign

Harvard and University of Pennsylvania Data Exposed in ShinyHunters Extortion Campaign

Personal data linked to students and affiliates of Harvard University and the University of Pennsylvania has been leaked online following an extortion campaign tied to the ShinyHunters cybercrime...

Breach Wars: BreachForums Resurfaces on New Domain After HasanBroker Defacement and .bf Suspension

Breach Wars: BreachForums Resurfaces on New Domain After HasanBroker Defacement and .bf Suspension

The long running struggle for control and influence within the cybercrime underground escalated this week after BreachForums’ .bf domain was defaced by a threat actor known as HasanBroker, only to...

CVE-2025-22225 in VMware ESXi now used in active ransomware attacks

CVE-2025-22225 in VMware ESXi now used in active ransomware attacks

A critical security flaw in VMware ESXi has moved decisively from theory into practice, with ransomware groups now exploiting CVE-2025-22225 in active attacks against enterprise environments. The...

Qilin Ransomware Gang's Bold Claim: Breach at Tulsa International Airport Exposes Sensitive Data

Qilin Ransomware Gang's Bold Claim: Breach at Tulsa International Airport Exposes Sensitive Data

In a startling development that underscores the persistent threats facing critical infrastructure, the notorious Qilin ransomware gang has claimed responsibility for a significant data breach at...

Hackers Actively Exploit React Server Components Flaw to Deliver Malicious Payloads

Hackers Actively Exploit React Server Components Flaw to Deliver Malicious Payloads

Threat actors are actively exploiting a serious vulnerability in React Server Components, marking a dangerous escalation in attacks against modern web application frameworks. Security researchers...

Microsoft Begins Phasing Out NTLM as Windows Shifts Toward Kerberos Authentication

Microsoft Begins Phasing Out NTLM as Windows Shifts Toward Kerberos Authentication

Microsoft has formally begun the long anticipated phase out of New Technology LAN Manager authentication, marking a major shift in how Windows environments handle identity and access. The move...

Critical vLLM Flaw Exposes Millions of AI Servers to Remote Code Execution

Critical vLLM Flaw Exposes Millions of AI Servers to Remote Code Execution

A newly disclosed critical vulnerability in the widely adopted vLLM framework has raised urgent alarms across the artificial intelligence and cloud security communities. The flaw enables...

APT28's Rapid Assault: Exploiting Microsoft's New Office Vulnerability in Operation Neusploit

APT28's Rapid Assault: Exploiting Microsoft's New Office Vulnerability in Operation Neusploit

In the ever-evolving landscape of cyber threats, state-sponsored actors continue to demonstrate their agility in turning freshly disclosed vulnerabilities into potent weapons. The Russia-linked...

ICE Reporting Platform StopICE Hacked to Send False Alerts, Insider Access Suspected

ICE Reporting Platform StopICE Hacked to Send False Alerts, Insider Access Suspected

The StopICE reporting platform, a U.S. government service designed to allow the public to submit tips related to immigration and border enforcement, was reportedly compromised and used to send...

AT&T Breach Data Resurfaces Online, Renewing Fraud and Identity Theft Risks

AT&T Breach Data Resurfaces Online, Renewing Fraud and Identity Theft Risks

Data linked to a previously disclosed AT&T breach has resurfaced across underground forums and public sharing platforms, reigniting concerns about the long tail impact of large scale data exposure....