Latest Articles

North Korean State Actors Using Malicious QR Codes in Targeted Spear-Phishing Campaigns, FBI Warns

North Korean State Actors Using Malicious QR Codes in Targeted Spear-Phishing Campaigns, FBI Warns

The U.S. Federal Bureau of Investigation has issued a public advisory warning that North Korean state-sponsored threat actors are actively leveraging malicious QR codes as part of targeted...

Trend Micro Warns of Critical Apex Central RCE Vulnerability Exposing Enterprise Security Management Servers

Trend Micro Warns of Critical Apex Central RCE Vulnerability Exposing Enterprise Security Management Servers

Trend Micro has issued a critical security warning for its Apex Central management platform after researchers identified a remote code execution vulnerability that could allow attackers to take full...

Apache Tika XXE Vulnerability CVE-2025-66516 Exposes Document Parsing Pipelines to Data Theft and Service Disruption

Apache Tika XXE Vulnerability CVE-2025-66516 Exposes Document Parsing Pipelines to Data Theft and Service Disruption

A newly disclosed vulnerability in Apache Tika has drawn attention to a familiar but still dangerous class of flaws: XML External Entity injection. Tracked as CVE-2025-66516, the issue affects how...

CISA's Historic Retirement of 10 Emergency Directives: Advancing Federal Cybersecurity Resilience

CISA's Historic Retirement of 10 Emergency Directives: Advancing Federal Cybersecurity Resilience

In a landmark move that underscores the evolving landscape of federal cybersecurity, the Cybersecurity and Infrastructure Security Agency (CISA) has announced the retirement of ten Emergency...

Veeam Patches Critical Remote Code Execution Vulnerability in Backup & Replication

Veeam Patches Critical Remote Code Execution Vulnerability in Backup & Replication

In the fast-paced world of cybersecurity, vulnerabilities in essential software can pose significant risks to organizations worldwide. Recently, Veeam Software, a leading provider of data protection...

Surging Ransomware Claims: Dissecting the January 7, 2026 Disclosures

Surging Ransomware Claims: Dissecting the January 7, 2026 Disclosures

In the ever-evolving landscape of cybersecurity threats, ransomware attacks continue to pose significant risks to businesses across various sectors. On January 7, 2026, several organizations were...

China Hacks Email Systems of US Congressional Committee Staff in Major Cyber Espionage Incident

China Hacks Email Systems of US Congressional Committee Staff in Major Cyber Espionage Incident

China has reportedly compromised the email systems used by staffers on several influential committees of the United States House of Representatives, according to a Financial Times report. The...

Critical RCE Vulnerability in Legacy D-Link DSL Routers Exposes Millions of Home and Small Business Networks

Critical RCE Vulnerability in Legacy D-Link DSL Routers Exposes Millions of Home and Small Business Networks

A severe remote code execution (RCE) vulnerability has been discovered in a range of legacy D-Link DSL routers, presenting a high-risk threat to millions of end users worldwide. The flaw allows...

Ni8mare - Unauthenticated Remote Code Execution in n8n (CVE-2026-21858) Threatens Automation Workflows

Ni8mare - Unauthenticated Remote Code Execution in n8n (CVE-2026-21858) Threatens Automation Workflows

A critical vulnerability affecting the n8n workflow automation platform has been disclosed, potentially allowing unauthenticated remote code execution on exposed instances. Assigned CVE-2026-21858...

CVE-2026-21877: Max-Severity n8n Bug Turns “Low-Privilege” Access Into Full Remote Code Execution

CVE-2026-21877: Max-Severity n8n Bug Turns “Low-Privilege” Access Into Full Remote Code Execution

A newly disclosed maximum-severity vulnerability in the workflow automation platform n8n is raising alarms because it can convert ordinary authenticated access into full remote code execution on the...

Eliminating IT Blind Spots in the AI-Driven Enterprise: A CISO’s View From the Front Line

Eliminating IT Blind Spots in the AI-Driven Enterprise: A CISO’s View From the Front Line

For many CISOs, artificial intelligence is no longer an experimental technology sitting on the edge of the organisation. It is embedded in customer analytics, fraud detection, HR screening, code...

Critical jsPDF Flaw Allows Attackers to Steal Secrets Through Maliciously Generated PDFs

Critical jsPDF Flaw Allows Attackers to Steal Secrets Through Maliciously Generated PDFs

A critical security vulnerability has been disclosed in jsPDF, a widely used JavaScript library for generating PDF documents in web applications. The flaw allows attackers to craft malicious PDF...

Inside SafePay: The fast moving, centrally run ransomware crew reshaping double extortion playbooks Industry: Cybersecurity, Managed Services, Enterprise IT

Inside SafePay: The fast moving, centrally run ransomware crew reshaping double extortion playbooks Industry: Cybersecurity, Managed Services, Enterprise IT

SafePay has become one of the more closely watched ransomware names to emerge in the last 18 months, not because it invented a brand new technique, but because it operationalised familiar ones with...

Shadowy Intruders: Malicious Chrome Extensions Exposed for Stealing AI Chats

Shadowy Intruders: Malicious Chrome Extensions Exposed for Stealing AI Chats

In a startling revelation that underscores the persistent vulnerabilities in digital ecosystems, cybersecurity researchers have uncovered two rogue Chrome extensions that have been covertly...

L’Orange Bleu Data Breach Exposes Fitness Club Financial Records and Manager Personal Data

L’Orange Bleu Data Breach Exposes Fitness Club Financial Records and Manager Personal Data

L’Orange Bleu, a mid-sized fitness club chain, has confirmed a significant data breach that exposed financial information and personally identifiable data of its club managers. The incident, first...

Aarong Data Breach Exposes 3.5 Million Customer Records

Aarong Data Breach Exposes 3.5 Million Customer Records

A major data breach at Aarong, one of Bangladesh’s largest lifestyle retail brands, has resulted in the exposure of approximately 3.5 million customer records. The incident, which came to light after...

Brazilian E-Commerce Platform Mist Store Allegedly Suffers Data Breach Exposing 30,000 Orders

Brazilian E-Commerce Platform Mist Store Allegedly Suffers Data Breach Exposing 30,000 Orders

Mist Store, a popular Brazilian e-commerce platform, is reportedly the victim of a data breach that exposed information related to approximately 30,000 customer orders. The incident, disclosed by...

The Lingering Shadow of the LastPass Breach: Ongoing Cryptocurrency Thefts

The Lingering Shadow of the LastPass Breach: Ongoing Cryptocurrency Thefts

In the ever-evolving landscape of digital security, few incidents illustrate the long-term dangers of data breaches as starkly as the 2022 LastPass compromise. What began as a seemingly contained...

Sedgwick Confirms Cyberattack on Government Subsidiary Affecting Public Services

Sedgwick Confirms Cyberattack on Government Subsidiary Affecting Public Services

Sedgwick, a leading global provider of technology-enabled risk, benefits and integrated business solutions, has confirmed that one of its government-focused subsidiaries was the victim of a...

Russia-Aligned Hackers Abuse Viber to Target Ukrainian Military and Government

Russia-Aligned Hackers Abuse Viber to Target Ukrainian Military and Government

Cybersecurity analysts have uncovered a sophisticated campaign by Russia-aligned threat actors who are systematically abusing the popular messaging app Viber to deliver malware and spy on Ukrainian...