Latest Articles

KongTuke ClickFix Activity Fuels New Wave of Social Engineering Malware Infections

KongTuke ClickFix Activity Fuels New Wave of Social Engineering Malware Infections

Cybersecurity researchers are tracking a growing campaign known as KongTuke ClickFix, a deceptive social engineering operation that abuses fake error prompts and verification messages to trick users...

MassLogger Malware Spreads Through Malicious Email Attachments in Ongoing Credential Theft Campaign

MassLogger Malware Spreads Through Malicious Email Attachments in Ongoing Credential Theft Campaign

Cybersecurity researchers are warning of a renewed surge in MassLogger malware infections, driven primarily by malicious email attachments designed to trick recipients into executing the...

Illinois Department of Human Services Data Breach Impacts 700,000 Individuals as Notifications Continue

Illinois Department of Human Services Data Breach Impacts 700,000 Individuals as Notifications Continue

The Illinois Department of Human Services has disclosed a significant data breach affecting approximately 700,000 individuals, highlighting persistent cybersecurity challenges within government human...

Global “Lone Hacker” Campaign Breaches Data of 50 Major Companies Using Stolen Passwords

Global “Lone Hacker” Campaign Breaches Data of 50 Major Companies Using Stolen Passwords

A single threat actor operating under the aliases Zestix and Sentap has managed to compromise private files belonging to more than 50 major organizations worldwide, exposing a stark and uncomfortable...

Russian APT28 Launches Credential Harvesting Campaigns Across Europe and Central Asia

Russian APT28 Launches Credential Harvesting Campaigns Across Europe and Central Asia

Russian state sponsored threat actors linked to APT28, also known as BlueDelta, have launched a series of targeted credential harvesting campaigns against organizations across Europe and Central...

Blackshrantac Targets Schneider Prototyping India in Ransomware Attack

Blackshrantac Targets Schneider Prototyping India in Ransomware Attack

A ransomware group operating under the name Blackshrantac has claimed responsibility for a cyberattack against Schneider Prototyping India Pvt. Ltd., an industrial technology firm operating in India....

North Korean State Actors Using Malicious QR Codes in Targeted Spear-Phishing Campaigns, FBI Warns

North Korean State Actors Using Malicious QR Codes in Targeted Spear-Phishing Campaigns, FBI Warns

The U.S. Federal Bureau of Investigation has issued a public advisory warning that North Korean state-sponsored threat actors are actively leveraging malicious QR codes as part of targeted...

Trend Micro Warns of Critical Apex Central RCE Vulnerability Exposing Enterprise Security Management Servers

Trend Micro Warns of Critical Apex Central RCE Vulnerability Exposing Enterprise Security Management Servers

Trend Micro has issued a critical security warning for its Apex Central management platform after researchers identified a remote code execution vulnerability that could allow attackers to take full...

Apache Tika XXE Vulnerability CVE-2025-66516 Exposes Document Parsing Pipelines to Data Theft and Service Disruption

Apache Tika XXE Vulnerability CVE-2025-66516 Exposes Document Parsing Pipelines to Data Theft and Service Disruption

A newly disclosed vulnerability in Apache Tika has drawn attention to a familiar but still dangerous class of flaws: XML External Entity injection. Tracked as CVE-2025-66516, the issue affects how...

CISA's Historic Retirement of 10 Emergency Directives: Advancing Federal Cybersecurity Resilience

CISA's Historic Retirement of 10 Emergency Directives: Advancing Federal Cybersecurity Resilience

In a landmark move that underscores the evolving landscape of federal cybersecurity, the Cybersecurity and Infrastructure Security Agency (CISA) has announced the retirement of ten Emergency...

Veeam Patches Critical Remote Code Execution Vulnerability in Backup & Replication

Veeam Patches Critical Remote Code Execution Vulnerability in Backup & Replication

In the fast-paced world of cybersecurity, vulnerabilities in essential software can pose significant risks to organizations worldwide. Recently, Veeam Software, a leading provider of data protection...

Surging Ransomware Claims: Dissecting the January 7, 2026 Disclosures

Surging Ransomware Claims: Dissecting the January 7, 2026 Disclosures

In the ever-evolving landscape of cybersecurity threats, ransomware attacks continue to pose significant risks to businesses across various sectors. On January 7, 2026, several organizations were...

China Hacks Email Systems of US Congressional Committee Staff in Major Cyber Espionage Incident

China Hacks Email Systems of US Congressional Committee Staff in Major Cyber Espionage Incident

China has reportedly compromised the email systems used by staffers on several influential committees of the United States House of Representatives, according to a Financial Times report. The...

Critical RCE Vulnerability in Legacy D-Link DSL Routers Exposes Millions of Home and Small Business Networks

Critical RCE Vulnerability in Legacy D-Link DSL Routers Exposes Millions of Home and Small Business Networks

A severe remote code execution (RCE) vulnerability has been discovered in a range of legacy D-Link DSL routers, presenting a high-risk threat to millions of end users worldwide. The flaw allows...

Ni8mare - Unauthenticated Remote Code Execution in n8n (CVE-2026-21858) Threatens Automation Workflows

Ni8mare - Unauthenticated Remote Code Execution in n8n (CVE-2026-21858) Threatens Automation Workflows

A critical vulnerability affecting the n8n workflow automation platform has been disclosed, potentially allowing unauthenticated remote code execution on exposed instances. Assigned CVE-2026-21858...

CVE-2026-21877: Max-Severity n8n Bug Turns “Low-Privilege” Access Into Full Remote Code Execution

CVE-2026-21877: Max-Severity n8n Bug Turns “Low-Privilege” Access Into Full Remote Code Execution

A newly disclosed maximum-severity vulnerability in the workflow automation platform n8n is raising alarms because it can convert ordinary authenticated access into full remote code execution on the...

Eliminating IT Blind Spots in the AI-Driven Enterprise: A CISO’s View From the Front Line

Eliminating IT Blind Spots in the AI-Driven Enterprise: A CISO’s View From the Front Line

For many CISOs, artificial intelligence is no longer an experimental technology sitting on the edge of the organisation. It is embedded in customer analytics, fraud detection, HR screening, code...

Critical jsPDF Flaw Allows Attackers to Steal Secrets Through Maliciously Generated PDFs

Critical jsPDF Flaw Allows Attackers to Steal Secrets Through Maliciously Generated PDFs

A critical security vulnerability has been disclosed in jsPDF, a widely used JavaScript library for generating PDF documents in web applications. The flaw allows attackers to craft malicious PDF...

Inside SafePay: The fast moving, centrally run ransomware crew reshaping double extortion playbooks Industry: Cybersecurity, Managed Services, Enterprise IT

Inside SafePay: The fast moving, centrally run ransomware crew reshaping double extortion playbooks Industry: Cybersecurity, Managed Services, Enterprise IT

SafePay has become one of the more closely watched ransomware names to emerge in the last 18 months, not because it invented a brand new technique, but because it operationalised familiar ones with...

Shadowy Intruders: Malicious Chrome Extensions Exposed for Stealing AI Chats

Shadowy Intruders: Malicious Chrome Extensions Exposed for Stealing AI Chats

In a startling revelation that underscores the persistent vulnerabilities in digital ecosystems, cybersecurity researchers have uncovered two rogue Chrome extensions that have been covertly...