Latest Articles

Attackers Exploit Klue Legacy OAuth Tokens to Breach Salesforce Environments at Nearly Two Dozen Organizations

Attackers Exploit Klue Legacy OAuth Tokens to Breach Salesforce Environments at Nearly Two Dozen Organizations

Attackers did not need stolen passwords or phishing pages to access these Salesforce environments. Instead, they allegedly leveraged something many organizations rarely revisit: legacy OAuth tokens...

Have I Been Pwned Adds Madison Square Garden Sports Breach Affecting 10 Million Accounts

Have I Been Pwned Adds Madison Square Garden Sports Breach Affecting 10 Million Accounts

Millions of sports fans may have unknowingly joined one of the latest major data breach disclosures. Have I Been Pwned (HIBP) has added the Madison Square Garden Sports incident to its breach...

CVE-2026-12569 Exploited in the Wild to Deploy JSP Web Shells on PTC Windchill Servers

CVE-2026-12569 Exploited in the Wild to Deploy JSP Web Shells on PTC Windchill Servers

Attackers are moving quickly against vulnerable PTC Windchill servers, and the payload of choice is a familiar one: JSP web shells that provide persistent remote access inside enterprise engineering...

CVE-2026-12957: Amazon Q Developer Flaw Lets Malicious Repositories Execute Code and Steal AWS Credentials

CVE-2026-12957: Amazon Q Developer Flaw Lets Malicious Repositories Execute Code and Steal AWS Credentials

A single Git clone could have been enough to hand an attacker active AWS credentials. Amazon has patched a high-severity vulnerability in Amazon Q Developer, tracked as CVE-2026-12957, after...

Bajaj Auto Hit by Ransomware Attack: Swift Response Contains Cyber Incident at Major Indian Two-Wheeler Giant

Bajaj Auto Hit by Ransomware Attack: Swift Response Contains Cyber Incident at Major Indian Two-Wheeler Giant

On June 23, 2026, Bajaj Auto Limited, one of India's leading manufacturers of motorcycles and three-wheelers, disclosed a significant cybersecurity incident involving a ransomware attack. The attack...

Tata Electronics Confirms Cyber Breach After Ransomware Gang Claims 630GB Leak of Apple and Tesla Data

Tata Electronics Confirms Cyber Breach After Ransomware Gang Claims 630GB Leak of Apple and Tesla Data

A cyber incident at Tata Electronics is drawing attention far beyond India’s manufacturing sector. The company, a key supplier to Apple and Tesla, has confirmed that it experienced a cybersecurity...

KerberRose Wealth Management Data Breach Exposes Sensitive Information of Over 27,000 Clients

KerberRose Wealth Management Data Breach Exposes Sensitive Information of Over 27,000 Clients

In a significant cybersecurity incident affecting the financial sector, KerberRose Wealth Management has notified approximately 27,076 clients that their personal and financial data may have been...

The Gentlemen Ransomware Group Strikes Al Khaja Holding: A Wake-Up Call for Diversified Enterprises in the UAE

The Gentlemen Ransomware Group Strikes Al Khaja Holding: A Wake-Up Call for Diversified Enterprises in the UAE

In the rapidly evolving landscape of cyber threats, few groups have scaled as aggressively as The Gentlemen, a ransomware-as-a-service operation that has claimed hundreds of victims since its...

AI Brands Become the New Phishing Lure as Threat Actors Exploit ChatGPT, Copilot, Claude, and DeepSeek Hype

AI Brands Become the New Phishing Lure as Threat Actors Exploit ChatGPT, Copilot, Claude, and DeepSeek Hype

Attackers have discovered that one of the most effective ways to exploit the AI boom isn't breaking into AI platforms—it's convincing users they already have. According to Microsoft Threat...

GentleKiller Exploits Vulnerable Drivers to Dismantle Endpoint Protection at Scale

GentleKiller Exploits Vulnerable Drivers to Dismantle Endpoint Protection at Scale

Modern ransomware operators are no longer just building better encryptors. Increasingly, they are focused on eliminating the security tools designed to stop them before encryption ever begins. New...

Massive Data Breach at Texas Parks and Wildlife Vendor Exposes Personal Information of Over 3 Million Residents

Massive Data Breach at Texas Parks and Wildlife Vendor Exposes Personal Information of Over 3 Million Residents

In a significant cybersecurity incident that has raised alarms across the Lone Star State, the Texas Parks and Wildlife Department (TPWD) disclosed that a third-party vendor responsible for its...

CISA Warns Fortinet Users to Lock Down Devices After FortiBleed Credential Leak

CISA Warns Fortinet Users to Lock Down Devices After FortiBleed Credential Leak

The risk with FortiBleed is not just that credentials leaked. It is that many of those credentials appear to unlock the perimeter itself. CISA is now urging Fortinet customers to secure affected...

CISA Orders Emergency Patch for Exploited Splunk Enterprise RCE Vulnerability CVE-2026-20253

CISA Orders Emergency Patch for Exploited Splunk Enterprise RCE Vulnerability CVE-2026-20253

A security monitoring platform becoming the target is not a theoretical risk. It is now the urgency behind CVE-2026-20253, a critical Splunk Enterprise vulnerability that moved from disclosure to...

OAuth Token Abuse Exposes Salesforce CRM Data: How Attackers Exploited Klue's Battlecards Integration

OAuth Token Abuse Exposes Salesforce CRM Data: How Attackers Exploited Klue's Battlecards Integration

In a stark reminder of the vulnerabilities inherent in third-party SaaS integrations, market intelligence firm Klue fell victim to a sophisticated OAuth token abuse incident in mid-June 2026. The...

Microsoft Confirms RoguePlanet Defender Zero-Day CVE-2026-50656, Patch Still in Development

Microsoft Confirms RoguePlanet Defender Zero-Day CVE-2026-50656, Patch Still in Development

RoguePlanet is not just another local privilege escalation bug. It targets the defensive layer many Windows environments trust by default: Microsoft Defender. Microsoft has now confirmed...

The Rise of INC Ransomware: A Prolific RaaS Operator Reshaping the 2026 Threat Landscape

The Rise of INC Ransomware: A Prolific RaaS Operator Reshaping the 2026 Threat Landscape

In the ever-evolving world of cybercrime, few groups have demonstrated such rapid growth and adaptability as INC Ransomware. Operating as a sophisticated Ransomware-as-a-Service (RaaS) platform, INC...

FortiBleed Leak Exposes Fortinet VPN Credentials for 73,000 Devices Worldwide

FortiBleed Leak Exposes Fortinet VPN Credentials for 73,000 Devices Worldwide

The FortiBleed leak is not just another credential dump. It is a map of exposed network perimeters. Security researchers say the dataset contains working Fortinet and FortiGate VPN credentials for...

CISA Adds Actively Exploited Joomla JCE RCE Flaw CVE-2026-48907 to KEV Catalog

CISA Adds Actively Exploited Joomla JCE RCE Flaw CVE-2026-48907 to KEV Catalog

A Joomla extension flaw has crossed the line from dangerous to actively weaponized. CISA’s addition of CVE-2026-48907 to the Known Exploited Vulnerabilities catalog is not just another...

Kodak Confirms Data Breach After ShinyHunters Claims Theft of 2.2 Million Records

Kodak Confirms Data Breach After ShinyHunters Claims Theft of 2.2 Million Records

Eastman Kodak Company, the iconic American imaging and technology firm, has confirmed a cybersecurity incident following claims by the notorious ShinyHunters extortion group. The hackers allege they...

Russian Tech Firm Kaluga Astral Hit by Major Cyberattack Disrupting Critical Government and Business Services

Russian Tech Firm Kaluga Astral Hit by Major Cyberattack Disrupting Critical Government and Business Services

In a significant cybersecurity incident that underscores the vulnerabilities facing critical infrastructure providers, Russian software developer Kaluga Astral confirmed it was the target of a...