Latest Articles

Fiserv Named by Everest Ransomware on Leak Site, Raising Fintech Supply Chain Concerns

Fiserv Named by Everest Ransomware on Leak Site, Raising Fintech Supply Chain Concerns

A ransomware leak-site claim against a major fintech provider is never just another name on a victim board. On 3 May 2026, Ransomware.live listed Fiserv as a newly discovered victim claimed by the...

ZenBusiness Data Breach Added to HIBP With 5.1M Affected Accounts After ShinyHunters Leak

ZenBusiness Data Breach Added to HIBP With 5.1M Affected Accounts After ShinyHunters Leak

ZenBusiness has now moved from alleged extortion target to searchable breach record. Have I Been Pwned listed a ZenBusiness data breach on 2 May 2026, identifying 5.1 million affected accounts...

Trellix Source Code Repository Access Raises Supply-Chain Security Questions

Trellix Source Code Repository Access Raises Supply-Chain Security Questions

A source-code repository is not just a developer workspace. For a cybersecurity vendor, it is a map of product logic, assumptions, controls, and potential weak points. That is why Trellix’s...

cPanel CVE-2026-41940 Mass Exploited as “Sorry” Ransomware Hits Web Hosting Servers

cPanel CVE-2026-41940 Mass Exploited as “Sorry” Ransomware Hits Web Hosting Servers

A control panel bug has turned into a hosting-layer emergency. CVE-2026-41940 is not just another web vulnerability waiting for routine patch cycles. It is a critical authentication bypass in...

Poison in the Pipeline: How Threat Actors Hijacked PyTorch Lightning to Target the Global AI Developer Ecosystem

Poison in the Pipeline: How Threat Actors Hijacked PyTorch Lightning to Target the Global AI Developer Ecosystem

On April 30, 2026, a sophisticated supply chain attack quietly infiltrated one of the most trusted frameworks in the artificial intelligence development ecosystem. PyTorch Lightning, a widely...

30,000 Facebook Accounts Hacked via Google AppSheet Phishing Campaign: Inside the “AccountDumpling” Cybercrime Operation

30,000 Facebook Accounts Hacked via Google AppSheet Phishing Campaign: Inside the “AccountDumpling” Cybercrime Operation

A sophisticated phishing campaign dubbed “AccountDumpling” has compromised approximately 30,000 Facebook accounts worldwide, leveraging Google AppSheet as a deceptive relay platform. The...

Instructure Cyber Incident: Canvas Services Disrupted as Investigation into Threat Actor Activity Intensifies

Instructure Cyber Incident: Canvas Services Disrupted as Investigation into Threat Actor Activity Intensifies

Date: May 2026 Education technology provider Instructure has disclosed a cybersecurity incident involving a criminal threat actor, triggering widespread concern across academic institutions and...

Cordial Spider and Snarky Spider Turn Vishing and SSO Abuse Into Fast SaaS Extortion

Cordial Spider and Snarky Spider Turn Vishing and SSO Abuse Into Fast SaaS Extortion

The sharpest part of these campaigns is not the phishing page. It is what happens after the login works. Cordial Spider and Snarky Spider are showing how quickly an attacker can turn one socially...

CISA Adds Linux Kernel CVE-2026-31431 “Copy Fail” to KEV, Sets May 15 Remediation Deadline

CISA Adds Linux Kernel CVE-2026-31431 “Copy Fail” to KEV, Sets May 15 Remediation Deadline

CISA’s decision to add CVE-2026-31431 to the Known Exploited Vulnerabilities catalog changes the urgency around this Linux kernel flaw. This is no longer just a high-severity kernel bug with public...

Qilin Ransomware Group Claims Responsibility for Dual Breaches Targeting Abazia S.p.A. in Italy and Apotheca Beauty

Qilin Ransomware Group Claims Responsibility for Dual Breaches Targeting Abazia S.p.A. in Italy and Apotheca Beauty

In a concerning development that underscores the relentless nature of modern cyber threats, the notorious Qilin ransomware group has publicly claimed responsibility for successful breaches against...

EtherRAT Campaign Uses SEO Poisoning, GitHub Facades, and Ethereum C2 to Target Enterprise Admins

EtherRAT Campaign Uses SEO Poisoning, GitHub Facades, and Ethereum C2 to Target Enterprise Admins

EtherRAT is not trying to trick random users into opening a flashy lure. It is aiming at the people who already hold the keys: administrators, DevOps engineers, security analysts, and cloud operators...

Mini Shai-Hulud Supply-Chain Attack Hits SAP, Lightning, and Intercom Packages, Exposing Developer Secrets at Scale

Mini Shai-Hulud Supply-Chain Attack Hits SAP, Lightning, and Intercom Packages, Exposing Developer Secrets at Scale

The Mini Shai-Hulud campaign is a reminder that a poisoned package does not need months of persistence to create an enterprise incident. A few hours in the wrong dependency chain can be enough to...

European Commission Accuses Meta of Breaching Child Safety Rules Under Digital Services Act

European Commission Accuses Meta of Breaching Child Safety Rules Under Digital Services Act

The European Commission has issued preliminary findings accusing Meta Platforms Inc. of failing to adequately protect minors on its platforms, particularly Instagram and Facebook. The allegations...

Hackers Exploit Qinglong RCE Vulnerabilities (CVE-2026-3965 & CVE-2026-4047) to Deploy Cryptominers on Developer Servers

Hackers Exploit Qinglong RCE Vulnerabilities (CVE-2026-3965 & CVE-2026-4047) to Deploy Cryptominers on Developer Servers

A sophisticated cyberattack campaign has emerged targeting developers and DevOps environments by exploiting critical vulnerabilities in the Qinglong open-source task scheduler. Attackers leveraged...

Checkmarx KICS Supply Chain Compromise: Attackers Hijack Docker Images and VS Code Extensions to Steal Developer Secrets

Checkmarx KICS Supply Chain Compromise: Attackers Hijack Docker Images and VS Code Extensions to Steal Developer Secrets

On April 22, 2026, a sophisticated supply chain attack targeted Checkmarx's popular open source Infrastructure as Code (IaC) scanning tool KICS. Attackers gained access to official distribution...

Vimeo Data Breach via Anodot Exposes Emails and Metadata as ShinyHunters Escalates SaaS Extortion

Vimeo Data Breach via Anodot Exposes Emails and Metadata as ShinyHunters Escalates SaaS Extortion

Vimeo was not breached through a flashy exploit or a direct hit on its core video platform. The more important story is quieter: a trusted analytics integration became the path into downstream...

VECT 2.0 Ransomware: The Flawed Multi-Platform Threat That Destroys Critical Files Instead of Encrypting Them

VECT 2.0 Ransomware: The Flawed Multi-Platform Threat That Destroys Critical Files Instead of Encrypting Them

In the ever-evolving landscape of cyber threats, a new ransomware variant has emerged that challenges traditional assumptions about extortion-based attacks. VECT 2.0, a ransomware-as-a-service...

M3RX Claims Data Breach at Anvil Arts: Sensitive and Operational Information Accessed from Leading UK Performing Arts Organization

M3RX Claims Data Breach at Anvil Arts: Sensitive and Operational Information Accessed from Leading UK Performing Arts Organization

In a development that has sent ripples through the United Kingdom's cultural landscape, the hacker group known as M3RX has publicly claimed responsibility for a significant breach targeting Anvil...

GlassWorm Campaign Escalates: 73 Malicious Open VSX Sleeper Extensions Activate New Supply Chain Threats in 2026

GlassWorm Campaign Escalates: 73 Malicious Open VSX Sleeper Extensions Activate New Supply Chain Threats in 2026

April 2026 marks a significant escalation in the ongoing GlassWorm campaign, as security researchers from Socket have identified 73 malicious sleeper extensions on the Open VSX marketplace. These...

Litecoin Zero-Day Vulnerability Exploited in DoS Attack Disrupts Major Mining Pools: Technical Analysis, Impact, and Mitigation

Litecoin Zero-Day Vulnerability Exploited in DoS Attack Disrupts Major Mining Pools: Technical Analysis, Impact, and Mitigation

A critical zero-day vulnerability in the Litecoin network has recently been exploited to launch a large-scale denial-of-service (DoS) attack, temporarily disrupting operations across several major...