Latest Articles

React2Shell And Next.js RCE: How A Flight Protocol Flaw Put Modern Web Apps At Risk

React2Shell And Next.js RCE: How A Flight Protocol Flaw Put Modern Web Apps At Risk

A critical remote code execution vulnerability in React Server Components and the Next.js framework has sent a shockwave through the modern web ecosystem. At the heart of the issue is a flaw in...

NCFE Forced to Shut Down All IT Systems After Serious Cyber Incident Disrupts UK Vocational Education

NCFE Forced to Shut Down All IT Systems After Serious Cyber Incident Disrupts UK Vocational Education

4 December 2025 • In-depth Report NCFE, the 175-year-old awarding body responsible for millions of vocational and technical qualifications across the UK, has taken the drastic and unprecedented step...

SeedSnatcher Android Malware Uncovered - Crypto Wallet Seed Phrases Targeted via WebView Overlays

SeedSnatcher Android Malware Uncovered - Crypto Wallet Seed Phrases Targeted via WebView Overlays

Security analysts have uncovered a sophisticated new Android malware campaign dubbed “SeedSnatcher.” The malware is designed to steal cryptocurrency wallet seed phrases by abusing WebView overlays,...

University of Phoenix Data Breach Sends Shockwaves Through U.S. Education Sector

University of Phoenix Data Breach Sends Shockwaves Through U.S. Education Sector

Date: December 3, 2025 Overview: The University of Phoenix has disclosed a significant cybersecurity incident after discovering unauthorized access to its enterprise systems. The breach—linked to...

Fintech Firm Marquis Confirms Ransomware Linked Data Breach Affecting Sensitive Client Information

Fintech Firm Marquis Confirms Ransomware Linked Data Breach Affecting Sensitive Client Information

Fintech services provider Marquis has confirmed a ransomware driven data breach that exposed sensitive customer and partner information. The incident has sent ripples across the financial services...

Global Surge in Sophisticated Phishing Campaigns Raises Alarm Across Digital Ecosystems

Global Surge in Sophisticated Phishing Campaigns Raises Alarm Across Digital Ecosystems

Phishing campaigns continue to escalate in volume and complexity, with attackers deploying increasingly advanced social engineering tactics designed to bypass traditional security controls. The...

Massive Dark Web Leak Exposes 413,000 CVV Records in Alarming Data Breach

Massive Dark Web Leak Exposes 413,000 CVV Records in Alarming Data Breach

In a stark reminder of the persistent vulnerabilities in digital payment systems, a significant data leak has surfaced on the dark web, compromising the security of 413,000 CVV records. This...

MuddyWater Hackers Exploit Fake Emails and VPN Vulnerabilities in Latest Intrusion Campaign

MuddyWater Hackers Exploit Fake Emails and VPN Vulnerabilities in Latest Intrusion Campaign

A newly analysed cyber espionage campaign linked to the group known as MuddyWater has revealed how attackers combined convincing fraudulent emails with exploits targeting unpatched VPN appliances to...

Critical OpenPLC and ScadaBR Vulnerabilities Expose Industrial Systems to Remote Exploitation

Critical OpenPLC and ScadaBR Vulnerabilities Expose Industrial Systems to Remote Exploitation

Security researchers have disclosed a series of high impact vulnerabilities affecting OpenPLC and ScadaBR, two widely used open source platforms that help industrial operators manage programmable...

Akira ransomware group claims data theft at 11 North American organisations

Akira ransomware group claims data theft at 11 North American organisations

The Akira leak site presents stolen corporate data through a retro style command line interface on the dark web. The Akira ransomware group has listed 11 new organisations on its data leak...

Ransomware Assault on bpost: Belgium's Postal Giant Paralyzed Amid Escalating Cyber Threats

Ransomware Assault on bpost: Belgium's Postal Giant Paralyzed Amid Escalating Cyber Threats

In the heart of Europe's bustling logistics network, a digital storm has struck without warning. On December 2, 2025, bpost, Belgium's national postal service and one of the continent's largest...

Microsoft Defender XDR - Widespread Outage Reported Globally

Microsoft Defender XDR - Widespread Outage Reported Globally

Incident Overview Today, December 2, 2025, multiple users worldwide reported that Microsoft Defender XDR became inaccessible or exhibited serious performance issues. Aggregated data from...

SmartTube Compromise Raises Security Concerns Across the Streaming Ecosystem

SmartTube Compromise Raises Security Concerns Across the Streaming Ecosystem

The popular open-source Android TV client SmartTube experienced a significant security compromise that has raised concerns throughout the streaming and open-source software communities. Known for...

Google Issues Major Security Update Patching 107 Vulnerabilities

Google Issues Major Security Update Patching 107 Vulnerabilities

Google has released a major security update addressing 107 distinct vulnerabilities affecting the Android ecosystem. This latest security bulletin - part of the regular monthly patch cycle —...

Mercedes-Benz USA legal data breach claim and what it means for customers

Mercedes-Benz USA legal data breach claim and what it means for customers

Mercedes-Benz USA (MBUSA) is facing serious questions after a threat actor using the alias “zestix” claimed to have stolen a large cache of confidential legal documents and customer information...

Devman Ransomware Group Claims Full Breach of Major Adult Entertainment Platform cacd.com

Devman Ransomware Group Claims Full Breach of Major Adult Entertainment Platform cacd.com

December 1, 2025 – 18:40 UTC In what is shaping up to be one of the most damaging ransomware incidents ever to strike the adult entertainment sector, the Devman ransomware operation has claimed...

CISA Adds Actively Exploited XSS Bug CVE-2021-26829 in OpenPLC ScadaBR to KEV

CISA Adds Actively Exploited XSS Bug CVE-2021-26829 in OpenPLC ScadaBR to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns of critical risk to Industrial Control Systems (ICS) by adding an old vulnerability to its list of Known Exploited...

Qilin Ransomware Hits US Manufacturer Chenango Valley Technologies

Qilin Ransomware Hits US Manufacturer Chenango Valley Technologies

On November 29, 2025 the ransomware-as-a-service group Qilin claimed responsibility for an attack on Chenango Valley Technologies, a U.S. manufacturing and technology-services firm. In a public leak...

Microsoft Teams Cross-Tenant Bypass Vulnerability Reveals Critical Security Gaps in Enterprise Collaboration Platforms

Microsoft Teams Cross-Tenant Bypass Vulnerability Reveals Critical Security Gaps in Enterprise Collaboration Platforms

The Microsoft Teams cross-tenant bypass vulnerability represents a fundamental architectural limitation within the platform's guest access functionality. When an external user is granted guest access...

Qilin Ransomware Strikes U.S. Grocery Retailer CJW — Expanding Scope of Global Retail Attacks

Qilin Ransomware Strikes U.S. Grocery Retailer CJW — Expanding Scope of Global Retail Attacks

On November 29, 2025, the ransomware group Qilin publicly claimed responsibility for a cyberattack against CJW, a U.S.-based grocery retail chain. The group posted an extortion notice threatening to...