Latest Articles

Supply Chain Attack on Xinference PyPI Package Exposes AI Developers to Widespread Credential Theft

Supply Chain Attack on Xinference PyPI Package Exposes AI Developers to Widespread Credential Theft

p>In a concerning development for the artificial intelligence and machine learning community, three consecutive versions of the popular Xinference Python package on PyPI were compromised with...

SimpleHelp CVE-2024-57726: Critical API Key Flaw Enables Server Admin Takeover

SimpleHelp CVE-2024-57726: Critical API Key Flaw Enables Server Admin Takeover

A low-privilege technician account should not become the master key to a remote support server. In vulnerable SimpleHelp deployments, CVE-2024-57726 breaks that boundary. The flaw allows...

ShinyHunters Claims Udemy Breach, Threatens Leak of 1.4 Million User Records

ShinyHunters Claims Udemy Breach, Threatens Leak of 1.4 Million User Records

A claimed breach at Udemy is not just another “user records” headline. If ShinyHunters’ claim proves accurate, the exposed data could give attackers a useful map of learners, instructors, corporate...

ADT Data Breach: Home Security Giant Confirms Cyber Intrusion by ShinyHunters Extortion Group

ADT Data Breach: Home Security Giant Confirms Cyber Intrusion by ShinyHunters Extortion Group

On April 24, 2026, ADT Inc. confirmed that unauthorized actors accessed a limited set of customer and prospective customer data. The confirmation followed public threats from the extortion group...

Citizens Bank and Frost Bank Confirm Vendor Data Incident After Everest Ransomware Claims Millions of Records

Citizens Bank and Frost Bank Confirm Vendor Data Incident After Everest Ransomware Claims Millions of Records

Two major US banks are now dealing with the same uncomfortable question: how much customer risk can sit outside the bank, inside a vendor’s environment, before it becomes the bank’s incident...

Bluesky Hit by Sophisticated 24-Hour DDoS Attack: Pro-Iran Group 313 Team Claims Responsibility, Raising Questions on Platform Resilience

Bluesky Hit by Sophisticated 24-Hour DDoS Attack: Pro-Iran Group 313 Team Claims Responsibility, Raising Questions on Platform Resilience

Bluesky, the decentralized social media platform, faced a prolonged and sophisticated distributed denial-of-service attack that began late on April 15, 2026. The incident started around 11:40 PM...

Anthropic Investigates Vendor Breach of Claude Mythos as Discord Group Accessed Offensive Cyber AI While CISA Sits Locked Out

Anthropic Investigates Vendor Breach of Claude Mythos as Discord Group Accessed Offensive Cyber AI While CISA Sits Locked Out

The most capable offensive-security AI model Anthropic has ever built was compromised not by a novel exploit chain, but by a contractor login and an educated guess about a URL pattern. That single...

Venice Flood Control OT Breach Claim Puts Piazza San Marco Defenses Under Pressure

Venice Flood Control OT Breach Claim Puts Piazza San Marco Defenses Under Pressure

For most cities, a cyber intrusion is a data problem. For Venice, it can become a water problem. That is what makes the reported breach of the Piazza San Marco flood-control environment so...

Rituals Cosmetics Confirms Customer Data Stolen in Membership Database Breach

Rituals Cosmetics Confirms Customer Data Stolen in Membership Database Breach

Loyalty programs are breach goldmines. They aggregate exactly what attackers want — verified identities, physical addresses, purchase histories, and contact details - all in one database, all tied to...

CVE-2026-33825 BlueHammer Exploited as Defender Becomes Its Own Attack Vector

CVE-2026-33825 BlueHammer Exploited as Defender Becomes Its Own Attack Vector

All Windows endpoints running Microsoft Defender face active exploitation of three privilege escalation and defense-degradation zero-days; only one has a patch, and two remain open with no...

BravoX Ransomware Hits 1st Solution CTC in Latest Cyberattack on German Training and Auditing Firm

BravoX Ransomware Hits 1st Solution CTC in Latest Cyberattack on German Training and Auditing Firm

On April 22, 2026, the emerging ransomware group BravoX publicly listed 1st Solution CTC as a new victim on its data leak site. The claim quickly gained attention in cybersecurity monitoring...

Major Data Breach at France Titres Exposes Personal Information of Millions of Citizens

Major Data Breach at France Titres Exposes Personal Information of Millions of Citizens

In a significant blow to public trust in government systems, France Titres, the national agency responsible for issuing and managing secure identity documents, has confirmed a major cybersecurity...

Chinese APT Mustang Panda Targets Indian Banks and Korean Policy Circles With LOTUSLITE Malware

Chinese APT Mustang Panda Targets Indian Banks and Korean Policy Circles With LOTUSLITE Malware

China-linked threat actor Mustang Panda appears to be widening its playbook. New research shows the group, long associated with geopolitical espionage, has pushed a fresh LOTUSLITE campaign into...

NSW Government Rocked by Insider Data Breach: Treasury Staffer Charged for Alleged Theft of Over 5,500 Sensitive Documents

NSW Government Rocked by Insider Data Breach: Treasury Staffer Charged for Alleged Theft of Over 5,500 Sensitive Documents

NSW Police arrested a 45-year-old man identified as Jagan Ganti Venkata Satya on Monday in connection with a major internal data security incident at the New South Wales Treasury. The individual,...

Vercel Breach Tied to Context.ai OAuth Compromise Exposes Internal Systems and Non-Sensitive Secrets

Vercel Breach Tied to Context.ai OAuth Compromise Exposes Internal Systems and Non-Sensitive Secrets

Vercel has disclosed a security incident involving unauthorized access to certain internal systems, tracing the intrusion back to a compromise of Context.ai, a third-party AI tool used by a Vercel...

ShinyHunters Claims 7-Eleven Breach, Threatens to Leak 600,000 Salesforce Records

ShinyHunters Claims 7-Eleven Breach, Threatens to Leak 600,000 Salesforce Records

7-Eleven has been named on the ShinyHunters leak site in a new extortion claim that says more than 600,000 Salesforce records containing personally identifiable information and internal corporate...

The Gentlemen & SystemBC: Inside a Fast-Growing Ransomware Operation Built for Enterprise-Scale Intrusions

The Gentlemen & SystemBC: Inside a Fast-Growing Ransomware Operation Built for Enterprise-Scale Intrusions

The Gentlemen is not yet as famous as some of the older ransomware brands, but that may not last long. According to Check Point Research, the ransomware-as-a-service operation has rapidly expanded...

Defending Your Enterprise When AI Models Can Find Vulnerabilities Faster Than Ever

Defending Your Enterprise When AI Models Can Find Vulnerabilities Faster Than Ever

For years, defenders have treated vulnerability management as a race they could still partly control. A critical flaw would be disclosed, security teams would assess exposure, patch windows would be...

UAE Cyber Security Council Warns 1 in 4 Public Files Expose Sensitive Personal Data

UAE Cyber Security Council Warns 1 in 4 Public Files Expose Sensitive Personal Data

The UAE Cyber Security Council has issued a stark warning about how much sensitive data is still being exposed through everyday file-sharing habits. According to the Council, roughly 25 percent of...

Apple Account Change Emails Abused in New Phishing Campaign That Passes SPF, DKIM, and DMARC

Apple Account Change Emails Abused in New Phishing Campaign That Passes SPF, DKIM, and DMARC

Cybercriminals have found a way to turn Apple’s own account-change notification system into a phishing delivery channel, sending fake purchase alerts through Apple’s real mail infrastructure rather...