Latest Articles

AI Side-Channel Attack on LLMs Exposes Sensitive Model Outputs - The “Whisper Leak”

AI Side-Channel Attack on LLMs Exposes Sensitive Model Outputs - The “Whisper Leak”

Date: November 15, 2025 Summary: Security researchers have disclosed a newly identified class of side-channel attack against large language models (LLMs) deployed in multi-tenant cloud and...

The Top 10 XDR Platforms Empowering Enterprise Cybersecurity in 2025

The Top 10 XDR Platforms Empowering Enterprise Cybersecurity in 2025

The Definitive 2025 Guide to Autonomous, AI-Powered Extended Detection and Response In 2025, XDR is no...

SilentButDeadly: The Network Communication Blocker Neutralizing EDR/AV

SilentButDeadly: The Network Communication Blocker Neutralizing EDR/AV

In the ever-escalating cat-and-mouse game between red teamers and blue team defenders, new tools and techniques constantly emerge to test the limits of security solutions. One such tool that has...

RondoDox Botnet Expands to Enterprise: Critical XWiki Flaw Now Under Active Attack

RondoDox Botnet Expands to Enterprise: Critical XWiki Flaw Now Under Active Attack

A dangerous, multi-purpose botnet known as RondoDox has significantly escalated its operations by adding a critical, unauthenticated remote code execution vulnerability in the XWiki enterprise...

Princeton University Confirms Data Breach Affecting Alumni, Donor and Student Records

Princeton University Confirms Data Breach Affecting Alumni, Donor and Student Records

Princeton University has confirmed that one of its databases managed by the advancement office was compromised by external actors on November 10. The breach lasted less than 24 hours and exposed...

Security in the Era of AI Assistants and Autonomous Agents

Security in the Era of AI Assistants and Autonomous Agents

The rapid advancement of Artificial Intelligence (AI) has ushered in a new era of digital interaction and automation. From intelligent virtual assistants helping with daily tasks to sophisticated...

DanaBot Trojan Resurfaces After Hiatus With Version 669, Rebuilt Infrastructure

DanaBot Trojan Resurfaces After Hiatus With Version 669, Rebuilt Infrastructure

Date: November 14, 2025 Overview: The DanaBot banking trojan, long considered disrupted following a global law enforcement operation earlier this year, has reemerged in a new, upgraded form....

Microsoft Urgently Issues Patches for 63 Vulnerabilities in Critical Security Update

Microsoft Urgently Issues Patches for 63 Vulnerabilities in Critical Security Update

Date: November 13, 2025 Overview: Microsoft has released a sweeping security update addressing a total of 63 vulnerabilities across multiple Windows and enterprise products. The update—deemed a...

Critical RCE Vulnerabilities in Major AI Inference Engines

Critical RCE Vulnerabilities in Major AI Inference Engines

Unprecedented Remote Code Execution Flaws Expose Global AI Infrastructure to Full System Compromise Published: November 15, 2025 ...

Logitech Confirms Data Breach After Zero-Day Exploit in Third-Party Vendor

Logitech Confirms Data Breach After Zero-Day Exploit in Third-Party Vendor

Logitech International S.A., the Swiss-based consumer electronics giant, has disclosed a cybersecurity incident involving the unauthorized access and data exfiltration from its internal IT systems....

Akira Ransomware Targets Nutanix AHV Hypervisors in New Wave of Virtual Infrastructure Attacks

Akira Ransomware Targets Nutanix AHV Hypervisors in New Wave of Virtual Infrastructure Attacks

The Akira ransomware group has expanded its operations by targeting Nutanix AHV hypervisors, marking a significant escalation in attacks on virtualized infrastructure. The campaign focuses on...

Unauthenticated Authentication Bypass in Fortinet FortiWeb (CVE-2025-64446) Exploited in the Wild

Unauthenticated Authentication Bypass in Fortinet FortiWeb (CVE-2025-64446) Exploited in the Wild

A critical flaw in Fortinet’s FortiWeb Web Application Firewall, tracked as CVE-2025-64446, is now being actively exploited in the wild. The vulnerability enables unauthenticated attackers to bypass...

WatchGuard Fireware Critical Vulnerability

WatchGuard Fireware Critical Vulnerability

CVE-2025-9242 CVSS 9.3 Actively Exploited Added to CISA Known Exploited Vulnerabilities Catalog – November 13, 2025 This vulnerability is under active exploitation in...

Anthropic Foils First Fully AI Orchestrated Cyber Espionage Campaign

Anthropic Foils First Fully AI Orchestrated Cyber Espionage Campaign

Anthropic has disclosed that it disrupted a highly sophisticated cyber espionage operation in which a state sponsored threat group used its Claude Code tool to automate large parts of an intrusion...

RansomHouse Ransomware Attack on Fulgar

RansomHouse Ransomware Attack on Fulgar

Italian knitwear giant hit by ransomware — 500 GB of sensitive data at risk November 13, 2025 In a bold and calculated cyber assault,...

Proactive Hunting Against Ransomware-as-a-Service Campaigns: From Watch-List to Takedown

Proactive Hunting Against Ransomware-as-a-Service Campaigns: From Watch-List to Takedown

Date: November 13 2025 Overview: As ransomware-as-a-service (RaaS) platforms continue to proliferate, shifting the threatscape from isolated attacks to industrial-scale extortion operations, more...

Amazon Uncovers APT Targeting Cisco and Citrix Zero Day Vulnerabilities

Amazon Uncovers APT Targeting Cisco and Citrix Zero Day Vulnerabilities

Amazon’s threat intelligence team has identified an advanced persistent threat actor actively exploiting zero day vulnerabilities in Cisco Identity Services Engine and Citrix NetScaler systems. The...

Maverick And Coyote: Twin Brazilian Banking Trojans Riding The WhatsApp Threat Wave

Maverick And Coyote: Twin Brazilian Banking Trojans Riding The WhatsApp Threat Wave

Brazilian banking customers are facing a new generation of focused financial malware. Two closely related families, known as Maverick and Coyote, blend social engineering, fileless infection...

Oncology Company Data Breach Disclosure

Oncology Company Data Breach Disclosure

Sensitive Patient and Research Data Potentially Exposed November 12, 2025 A prominent oncology company has disclosed a significant data breach that may have...

Google Files Lawsuit Against China-Based “Lighthouse” Smishing Network in Landmark Cybercrime Action

Google Files Lawsuit Against China-Based “Lighthouse” Smishing Network in Landmark Cybercrime Action

Date: November 12, 2025 In a major legal escalation in the fight against global cyber-fraud, Google LLC has filed a civil lawsuit in the U.S. District Court for the Southern District of New York...