Latest Articles

Princeton University Confirms Data Breach Affecting Alumni, Donor and Student Records

Princeton University Confirms Data Breach Affecting Alumni, Donor and Student Records

Princeton University has confirmed that one of its databases managed by the advancement office was compromised by external actors on November 10. The breach lasted less than 24 hours and exposed...

Security in the Era of AI Assistants and Autonomous Agents

Security in the Era of AI Assistants and Autonomous Agents

The rapid advancement of Artificial Intelligence (AI) has ushered in a new era of digital interaction and automation. From intelligent virtual assistants helping with daily tasks to sophisticated...

DanaBot Trojan Resurfaces After Hiatus With Version 669, Rebuilt Infrastructure

DanaBot Trojan Resurfaces After Hiatus With Version 669, Rebuilt Infrastructure

Date: November 14, 2025 Overview: The DanaBot banking trojan, long considered disrupted following a global law enforcement operation earlier this year, has reemerged in a new, upgraded form....

Microsoft Urgently Issues Patches for 63 Vulnerabilities in Critical Security Update

Microsoft Urgently Issues Patches for 63 Vulnerabilities in Critical Security Update

Date: November 13, 2025 Overview: Microsoft has released a sweeping security update addressing a total of 63 vulnerabilities across multiple Windows and enterprise products. The update—deemed a...

Critical RCE Vulnerabilities in Major AI Inference Engines

Critical RCE Vulnerabilities in Major AI Inference Engines

Unprecedented Remote Code Execution Flaws Expose Global AI Infrastructure to Full System Compromise Published: November 15, 2025 ...

Logitech Confirms Data Breach After Zero-Day Exploit in Third-Party Vendor

Logitech Confirms Data Breach After Zero-Day Exploit in Third-Party Vendor

Logitech International S.A., the Swiss-based consumer electronics giant, has disclosed a cybersecurity incident involving the unauthorized access and data exfiltration from its internal IT systems....

Akira Ransomware Targets Nutanix AHV Hypervisors in New Wave of Virtual Infrastructure Attacks

Akira Ransomware Targets Nutanix AHV Hypervisors in New Wave of Virtual Infrastructure Attacks

The Akira ransomware group has expanded its operations by targeting Nutanix AHV hypervisors, marking a significant escalation in attacks on virtualized infrastructure. The campaign focuses on...

Unauthenticated Authentication Bypass in Fortinet FortiWeb (CVE-2025-64446) Exploited in the Wild

Unauthenticated Authentication Bypass in Fortinet FortiWeb (CVE-2025-64446) Exploited in the Wild

A critical flaw in Fortinet’s FortiWeb Web Application Firewall, tracked as CVE-2025-64446, is now being actively exploited in the wild. The vulnerability enables unauthenticated attackers to bypass...

WatchGuard Fireware Critical Vulnerability

WatchGuard Fireware Critical Vulnerability

CVE-2025-9242 CVSS 9.3 Actively Exploited Added to CISA Known Exploited Vulnerabilities Catalog – November 13, 2025 This vulnerability is under active exploitation in...

Anthropic Foils First Fully AI Orchestrated Cyber Espionage Campaign

Anthropic Foils First Fully AI Orchestrated Cyber Espionage Campaign

Anthropic has disclosed that it disrupted a highly sophisticated cyber espionage operation in which a state sponsored threat group used its Claude Code tool to automate large parts of an intrusion...

RansomHouse Ransomware Attack on Fulgar

RansomHouse Ransomware Attack on Fulgar

Italian knitwear giant hit by ransomware — 500 GB of sensitive data at risk November 13, 2025 In a bold and calculated cyber assault,...

Proactive Hunting Against Ransomware-as-a-Service Campaigns: From Watch-List to Takedown

Proactive Hunting Against Ransomware-as-a-Service Campaigns: From Watch-List to Takedown

Date: November 13 2025 Overview: As ransomware-as-a-service (RaaS) platforms continue to proliferate, shifting the threatscape from isolated attacks to industrial-scale extortion operations, more...

Amazon Uncovers APT Targeting Cisco and Citrix Zero Day Vulnerabilities

Amazon Uncovers APT Targeting Cisco and Citrix Zero Day Vulnerabilities

Amazon’s threat intelligence team has identified an advanced persistent threat actor actively exploiting zero day vulnerabilities in Cisco Identity Services Engine and Citrix NetScaler systems. The...

Maverick And Coyote: Twin Brazilian Banking Trojans Riding The WhatsApp Threat Wave

Maverick And Coyote: Twin Brazilian Banking Trojans Riding The WhatsApp Threat Wave

Brazilian banking customers are facing a new generation of focused financial malware. Two closely related families, known as Maverick and Coyote, blend social engineering, fileless infection...

Oncology Company Data Breach Disclosure

Oncology Company Data Breach Disclosure

Sensitive Patient and Research Data Potentially Exposed November 12, 2025 A prominent oncology company has disclosed a significant data breach that may have...

Google Files Lawsuit Against China-Based “Lighthouse” Smishing Network in Landmark Cybercrime Action

Google Files Lawsuit Against China-Based “Lighthouse” Smishing Network in Landmark Cybercrime Action

Date: November 12, 2025 In a major legal escalation in the fight against global cyber-fraud, Google LLC has filed a civil lawsuit in the U.S. District Court for the Southern District of New York...

North Korea-linked APT abuses Google Find Hub for device wiping and spying

North Korea-linked APT abuses Google Find Hub for device wiping and spying

A state-sponsored threat actor affiliated with APT37 (and the KONNI activity cluster) has been observed abusing Google Find Hub to geolocate Android devices and perform remote wipes after credential...

Attack on Polish Loan Platform SuperGrosz Data Breach

Attack on Polish Loan Platform SuperGrosz Data Breach

SuperGrosz, a Poland-based online loan platform run by AIQLABS, disclosed a major security incident that exposed sensitive personal and financial data for thousands of customers. National authorities...

Gladinet Triofox Unauthenticated RCE CVE-2025-12480: Active Exploitation and Immediate Response

Gladinet Triofox Unauthenticated RCE CVE-2025-12480: Active Exploitation and Immediate Response

Summary: A critical improper access control vulnerability in Gladinet Triofox, tracked as CVE-2025-12480, has been exploited in the wild to bypass authentication, upload arbitrary payloads, and...

Microsoft patches Windows Kernel zero-day CVE-2025-62215

Microsoft patches Windows Kernel zero-day CVE-2025-62215

Microsoft’s November security update closes a locally exploitable Windows Kernel elevation of privilege vulnerability that was observed in the wild. Administrators must prioritize deployment to...