Latest Articles

Dissecting Qilin Ransomware’s Cross-Platform Attack Chain: Linux Payload Execution and BYOVD Abuse

Dissecting Qilin Ransomware’s Cross-Platform Attack Chain: Linux Payload Execution and BYOVD Abuse

The Qilin ransomware group, also known as Agenda or Water Galura, has unveiled a new hybrid attack method that blends a Linux-based payload with a Bring-Your-Own-Vulnerable-Driver (BYOVD) exploit....

Ransomware Attack on Mino Industry Co., Ltd. (Japan)

Ransomware Attack on Mino Industry Co., Ltd. (Japan)

Mino Industry Co., Ltd., a Japanese manufacturer specialising in screen-printing and stencil machinery, confirmed a ransomware incident in late October 2025. Open disclosures and monitoring platforms...

Dublin Airport passenger data could be compromised following cyber breach

Dublin Airport passenger data could be compromised following cyber breach

Published: October 26, 2025 Location: Dublin, Ireland Summary: A significant data breach at Dublin Airport has compromised passenger information for potentially millions of individuals who traveled...

Critical Alert: WSUS Deserialization Flaw (CVE-2025-59287) Under Active Exploitation

Critical Alert: WSUS Deserialization Flaw (CVE-2025-59287) Under Active Exploitation

Microsoft released an out-of-band security update for a critical remote code execution (RCE) in Windows Server Update Services (WSUS), tracked as CVE-2025-59287. The vulnerability is actively...

Critical ‘SessionReaper’ Exploit Hits Adobe Commerce and Magento - Urgent Patching Advised to Prevent Global E-Commerce Breaches

Critical ‘SessionReaper’ Exploit Hits Adobe Commerce and Magento - Urgent Patching Advised to Prevent Global E-Commerce Breaches

Hackers Ramp Up Attacks on Adobe Commerce with 'SessionReaper' Vulnerability Exploitation body { font-family: Arial, sans-serif; line-height: 1.6; margin: 20px; } h1 { color: #333; } h2 { color:...

Lanscope Zero-Day Exploit Sparks Urgent Security Response Across Asia-Pacific

Lanscope Zero-Day Exploit Sparks Urgent Security Response Across Asia-Pacific

A newly uncovered zero-day vulnerability in Lanscope Endpoint Manager has triggered a wave of emergency patching across enterprises in Japan and other parts of Asia. The flaw, now tracked as...

Jaguar Land Rover Cyber Attack Deepens Supply-Chain and Production Crisis

Jaguar Land Rover Cyber Attack Deepens Supply-Chain and Production Crisis

A major cyber incident that forced Jaguar Land Rover (JLR) to suspend production at multiple UK plants has left a measurable economic impact on the automotive sector and highlighted fragilities...

“ToolShell” SharePoint Flaw (CVE-2025-53770) Escalates Risk to On-Premises Environments

“ToolShell” SharePoint Flaw (CVE-2025-53770) Escalates Risk to On-Premises Environments

A critical remote-code-execution vulnerability in Microsoft SharePoint Server, tracked as CVE-2025-53770 and dubbed "ToolShell", has been exploited in the wild. Immediate patching and active hunting...

FIA Confirms Data Breach Exposed F1 Drivers' Personal Information

FIA Confirms Data Breach Exposed F1 Drivers' Personal Information

A vulnerability in the FIA’s driver-categorisation portal allowed access to passport scans, licence documents and internal correspondence of world-class drivers. The incident raises urgent questions...

Synthient Stealer Data Dump: The Hidden Cost of Compromised Credentials

Synthient Stealer Data Dump: The Hidden Cost of Compromised Credentials

The “Synthient” corpus consolidates infostealer logs (credentials, cookies, autofill data) harvested from compromised endpoints, plus combolists circulating in criminal channels. Expect...

China’s MSS Reports Foreign Cyberattack on National Time Service Center – Critical Timing Infrastructure Targeted

China’s MSS Reports Foreign Cyberattack on National Time Service Center – Critical Timing Infrastructure Targeted

Beijing, 19 October 2025 — China’s Ministry of State Security (MSS) issued a statement confirming that foreign intelligence actors attempted to infiltrate the National Time Service Center (NTSC), the...

Askul ransomware attack halts orders and shipments across B2B and consumer platforms

Askul ransomware attack halts orders and shipments across B2B and consumer platforms

Japanese e-commerce and office-supplies giant ASKUL Corporation confirmed a ransomware incident that caused widespread systems disruption, forcing a suspension of order intake and...

F5 Networks Breach Triggers CISA Emergency Directive Amid Fears of Supply-Chain Exploitation

F5 Networks Breach Triggers CISA Emergency Directive Amid Fears of Supply-Chain Exploitation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an emergency directive following a breach at F5 Networks, a major supplier of application delivery and...

“Vocus Group Cybersecurity Incident: Email Accounts and SIM Swaps Exposed in October 2025 Attack”

“Vocus Group Cybersecurity Incident: Email Accounts and SIM Swaps Exposed in October 2025 Attack”

Overview: On 19 October 2025 Vocus Group — parent company of consumer brands including Dodo and iPrimus — experienced a cybersecurity incident that resulted in unauthorised access to a number of...

Massive 100K-Node Botnet Unleashes Coordinated RDP Blitz Across US Networks

Massive 100K-Node Botnet Unleashes Coordinated RDP Blitz Across US Networks

A massive botnet comprising more than 100,000 unique IP addresses has been observed launching a coordinated wave of attacks against Remote Desktop Protocol (RDP) services in the United States....

Stop worshipping CVSS: prioritize exploitability and blast radius, not the score

Stop worshipping CVSS: prioritize exploitability and blast radius, not the score

Opinion: CVSS was never meant to decide tomorrow’s patch queue by itself. Yet many organizations still treat 8.0+ as gospel and everything else as “later.” That mindset ships toil, not risk...

Passkeys won’t save you (unless you fix identity sprawl and recovery loopholes)

Passkeys won’t save you (unless you fix identity sprawl and recovery loopholes)

Opinion: Passkeys are the best mainstream step we’ve taken against credential phishing. But enterprises rolling out “passwordless” are discovering an uncomfortable truth: you can remove passwords...

Supply-chain reality check: package-squatting + CI/OIDC abuse are the fastest routes into your cloud

Supply-chain reality check: package-squatting + CI/OIDC abuse are the fastest routes into your cloud

Package squatting / dependency confusion: Adversaries publish near-name or higher-version packages to public registries (npm/PyPI). CI/dev machines resolve to the malicious package, executing...

Search malvertising is back: signed installers + cloned brands are delivering loaders at scale

Search malvertising is back: signed installers + cloned brands are delivering loaders at scale

Malvertising/SEO-poisoning campaigns are impersonating popular software (VPNs, IDEs, archivers, wallets). The flow is consistent: paid search ad → look-alike domain → signed MSI/EXE that side-loads a...

Stop buying more EDR until you’ve fixed identity and SaaS: a pragmatic 90-day plan

Stop buying more EDR until you’ve fixed identity and SaaS: a pragmatic 90-day plan

Most incidents we triage in 2025 do not begin with a kernel exploit on an endpoints; they begin with identity and SaaS: consent grants, token theft, weak conditional access, and sprawling...