Latest Articles

Ransomware Attack Forces Closure of Evanston Township High School: Summer Programs Canceled Amid Ongoing Investigation

Ransomware Attack Forces Closure of Evanston Township High School: Summer Programs Canceled Amid Ongoing Investigation

Evanston, Illinois - In a stark reminder of the growing vulnerability of educational institutions to cyber threats, Evanston Township High School District 202 (ETHS) was hit by a ransomware attack on...

Shadow Trades: 1 Million Lines of Chinese Crypto Trader Data Emerge for Sale on Underground Markets

Shadow Trades: 1 Million Lines of Chinese Crypto Trader Data Emerge for Sale on Underground Markets

On June 5, 2026, cybersecurity monitoring platforms reported a significant new offering in underground forums: approximately one million lines of personal information belonging to Chinese...

Pearson Ford Listed by Play Ransomware Group in Unverified Dealership Victim Claim

Pearson Ford Listed by Play Ransomware Group in Unverified Dealership Victim Claim

A ransomware listing is not the same thing as a confirmed breach. That distinction matters in the Pearson Ford case. The automotive dealership has reportedly appeared in ransomware.live tracking...

Five Eyes Warns Chinese Intelligence Is Using Fake Job Offers to Target Government and Military Personnel

Five Eyes Warns Chinese Intelligence Is Using Fake Job Offers to Target Government and Military Personnel

The job offer is the lure. The interview is the collection channel. Five Eyes intelligence agencies have warned that Chinese military intelligence services are using professional networking sites...

UNC3753 Targets US Law Firms and Financial Services in Fast-Tempo Vishing Extortion Campaign

UNC3753 Targets US Law Firms and Financial Services in Fast-Tempo Vishing Extortion Campaign

UNC3753 is not trying to win with malware first. It is winning by getting employees to do the attacker’s work for them. Mandiant has reported a fast-moving data theft and extortion campaign...

Play Ransomware Group Claims Attack on Corley Manufacturing: A Wake-Up Call for the Wood Products Industry

Play Ransomware Group Claims Attack on Corley Manufacturing: A Wake-Up Call for the Wood Products Industry

In a developing cybersecurity incident that highlights the persistent threats facing American manufacturing, the Play ransomware group has publicly claimed responsibility for an attack on Corley...

Avcon Jet Ransomware Attack: Qilin Group Exposes Sensitive Aviation Data, Heightening Supply Chain and Security Concerns

Avcon Jet Ransomware Attack: Qilin Group Exposes Sensitive Aviation Data, Heightening Supply Chain and Security Concerns

In a significant cybersecurity incident that has sent ripples through the global aviation sector, Avcon Jet, one of Europe’s leading private aviation companies, has been targeted by the notorious...

Fake E-Vite Phishing Scams Turn Party Invitations Into Credential Theft Traps

Fake E-Vite Phishing Scams Turn Party Invitations Into Credential Theft Traps

The lure is intentionally harmless: a party invite, a familiar host name, and a button to RSVP. That is what makes the latest wave of fake e-vite phishing scams effective. Instead of using fear,...

SafeBreach disclosed a Google Gemini voice assistant issue using indirect prompt injection via messaging notifications.

SafeBreach disclosed a Google Gemini voice assistant issue using indirect prompt injection via messaging notifications.

The attack did not need a malicious app, a browser exploit, or direct access to Google’s model. SafeBreach showed that a message notification could be enough. In research published on June 3,...

Cisco Unified CM CVE-2026-20230 Lets Attackers Write Files and Escalate to Root as PoC Goes Public

Cisco Unified CM CVE-2026-20230 Lets Attackers Write Files and Escalate to Root as PoC Goes Public

A Cisco voice platform bug has moved from advisory text to exploit-ready risk. Cisco has patched CVE-2026-20230, a server-side request forgery vulnerability in Unified Communications Manager and...

Massive Data Breach at World Food Programme Exposes Sensitive Information of 600,000 Gaza Households

Massive Data Breach at World Food Programme Exposes Sensitive Information of 600,000 Gaza Households

In a significant cybersecurity incident that has raised serious concerns about the protection of vulnerable populations, the United Nations World Food Programme (WFP) has confirmed a data breach...

HTTP/2 Bomb DoS Exploit Targets NGINX, Apache, IIS, Envoy, and Cloudflare Pingora

HTTP/2 Bomb DoS Exploit Targets NGINX, Apache, IIS, Envoy, and Cloudflare Pingora

HTTP/2 was built to make the web faster. HTTP/2 Bomb shows how the same efficiency features can become a memory-exhaustion weapon when servers accept compressed headers faster than they can safely...

CISA Adds Linux Kernel cgroups Container Escape Flaw CVE-2022-0492 to Exploited Vulnerabilities Catalog

CISA Adds Linux Kernel cgroups Container Escape Flaw CVE-2022-0492 to Exploited Vulnerabilities Catalog

A container escape bug from 2022 is back in the defender spotlight because CISA now says attackers are exploiting it in the wild. The issue, tracked as CVE-2022-0492, sits in the Linux kernel’s...

Redis RediShell RCE: Authenticated Users Can Trigger Lua Use-After-Free for OS Command Execution

Redis RediShell RCE: Authenticated Users Can Trigger Lua Use-After-Free for OS Command Execution

Redis is not just a cache sitting quietly behind applications. In many environments, it holds sessions, tokens, queues, transient business data, and cloud-adjacent secrets close enough to become a...

Cyber Claim Targets ACE Hospital: Ransomware Group Hits Pune Healthcare Provider

Cyber Claim Targets ACE Hospital: Ransomware Group Hits Pune Healthcare Provider

In the latest development underscoring the vulnerability of India's healthcare sector, KillSecurity, a known ransomware-as-a-service operation, has publicly claimed responsibility for breaching ACE...

Microsoft Android Apps Debug Flag Exposed Billions of Downloads to Token Theft Risk

Microsoft Android Apps Debug Flag Exposed Billions of Downloads to Token Theft Risk

One leftover debug flag is all it took to turn trusted Microsoft Android apps into a potential token exposure path. SecurityWeek reported on June 2, 2026, that researchers at Enclave found a...

Critical HP Poly VoIP Phone Vulnerability Exposes Enterprises to Root-Level RCE

Critical HP Poly VoIP Phone Vulnerability Exposes Enterprises to Root-Level RCE

Enterprise phones rarely sit at the top of the patching queue. That is exactly why this bug matters. A critical vulnerability in HP Poly VoIP phones can give an unauthenticated attacker remote...

Mini Shai-Hulud-Style Worm Compromises 32 Red Hat Cloud Services npm Packages

Mini Shai-Hulud-Style Worm Compromises 32 Red Hat Cloud Services npm Packages

A trusted package namespace is exactly where defenders least want to find a credential-stealing worm. On June 1, 2026, security researchers reported that multiple official npm packages under Red...

CISA Flags Oracle WebLogic CVE-2024-21182 as Actively Exploited: Urgent Patching Required for Enterprise Java Environments

CISA Flags Oracle WebLogic CVE-2024-21182 as Actively Exploited: Urgent Patching Required for Enterprise Java Environments

On June 1, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2024-21182, a high-severity vulnerability in Oracle WebLogic Server, to its Known Exploited Vulnerabilities...

CVE-2026-41940 Exploited to Deploy Filemanager Backdoor, Cryptominers, and Possible Ransomware Payloads

CVE-2026-41940 Exploited to Deploy Filemanager Backdoor, Cryptominers, and Possible Ransomware Payloads

CVE-2026-41940 is the kind of control-panel vulnerability defenders cannot afford to treat as “just another hosting bug.” Once attackers can bypass authentication on cPanel or WebHost Manager, the...