Latest Articles

Palo Alto Networks CVE-2026-0257 Exploited in the Wild: GlobalProtect Patch and Mitigation Priority

Palo Alto Networks CVE-2026-0257 Exploited in the Wild: GlobalProtect Patch and Mitigation Priority

A medium-rated VPN bug becomes a very different problem once attackers start using it against real environments. That is where Palo Alto Networks CVE-2026-0257 now sits. The issue affects...

Carnival Corporation Confirms Major Data Breach Affecting Nearly 6 Million Customers

Carnival Corporation Confirms Major Data Breach Affecting Nearly 6 Million Customers

In a significant cybersecurity event that has raised concerns across the travel industry, Carnival Corporation, the world's largest cruise operator, has officially confirmed a data breach that...

 Inside the FortiClient EMS Zero-Day: How CVE-2026-35616 Became One of 2026's Most Dangerous Enterprise Exploits

Inside the FortiClient EMS Zero-Day: How CVE-2026-35616 Became One of 2026's Most Dangerous Enterprise Exploits

In late March 2026, threat actors silently slipped into enterprise networks around the world through a flaw that Fortinet had not yet publicly acknowledged. By the time the security vendor published...

FBI Warns of Fake FIFA Portals Harvesting Credentials and Payment Data Ahead of 2026 World Cup

FBI Warns of Fake FIFA Portals Harvesting Credentials and Payment Data Ahead of 2026 World Cup

The 2026 FIFA World Cup has not kicked off yet, but the fraud economy around it is already live. The FBI has issued a public alert warning that threat actors are deploying spoofed FIFA websites to...

CISA Adds DAEMON Tools Lite Supply-Chain Compromise to KEV After Signed Installers Delivered Malware

CISA Adds DAEMON Tools Lite Supply-Chain Compromise to KEV After Signed Installers Delivered Malware

The DAEMON Tools Lite incident is a reminder that “downloaded from the official website” is not the same thing as safe. CISA has added CVE-2026-8398, tracked as the DAEMON Tools Lite Embedded...

Dutch Police and NCSC Disrupt 17 Million-Device Botnet Running Through Netherlands-Based Servers

Dutch Police and NCSC Disrupt 17 Million-Device Botnet Running Through Netherlands-Based Servers

A botnet with 17 million infected devices is not just a malware problem. It is an internet trust problem. Dutch authorities have disrupted a massive global botnet after investigators traced 200...

CrowdStrike, Google and Shadowserver Dismantle Glassworm Botnet Targeting Developers

CrowdStrike, Google and Shadowserver Dismantle Glassworm Botnet Targeting Developers

Glassworm was not just another botnet waiting on infected machines. It was built to sit inside the software supply chain. CrowdStrike says it has dismantled the developer-targeting Glassworm...

DragonForce Ransomware Hits Alliance Adjustment Group: Insurance Claims Adjuster Breached in Latest Cyber Attack

DragonForce Ransomware Hits Alliance Adjustment Group: Insurance Claims Adjuster Breached in Latest Cyber Attack

May 27, 2026 — In a developing cybersecurity incident, Alliance Adjustment Group, a prominent independent insurance claims adjusting firm, has been targeted by the DragonForce ransomware group. The...

KnowledgeDeliver Zero-Day CVE-2026-5426 Exploited via ASP.NET ViewState Deserialization

KnowledgeDeliver Zero-Day CVE-2026-5426 Exploited via ASP.NET ViewState Deserialization

This was not just a vulnerable web server. It was a trusted learning platform turned into a delivery point for malware. Mandiant has detailed exploitation of CVE-2026-5426, a KnowledgeDeliver...

Microsoft Fixes SharePoint RCE CVE-2026-45659 Affecting Server 2016, 2019, and Subscription Edition

Microsoft Fixes SharePoint RCE CVE-2026-45659 Affecting Server 2016, 2019, and Subscription Edition

SharePoint vulnerabilities rarely stay theoretical for long. When a collaboration platform sits close to sensitive files, workflows, intranet portals, and identity-connected services, even an...

TrapDoor Campaign: Sophisticated Cross-Ecosystem Supply Chain Attack Targets Developers Across npm, PyPI, and Crates.io

TrapDoor Campaign: Sophisticated Cross-Ecosystem Supply Chain Attack Targets Developers Across npm, PyPI, and Crates.io

In a striking demonstration of the evolving threats in the open source ecosystem, security researchers have uncovered a coordinated supply chain attack dubbed TrapDoor. This campaign has deployed...

Ghost CMS SQL Injection Exploited to Poison 700+ Sites in ClickFix Campaign

Ghost CMS SQL Injection Exploited to Poison 700+ Sites in ClickFix Campaign

The danger in this campaign is not just that Ghost CMS sites are vulnerable. It is that compromised publishing sites are being turned into malware delivery infrastructure for everyone who trusts...

HIBP Adds 7-Eleven Breach Affecting 185,300 Accounts After April 2026 ShinyHunters Extortion Leak

HIBP Adds 7-Eleven Breach Affecting 185,300 Accounts After April 2026 ShinyHunters Extortion Leak

The risk in the 7-Eleven breach is not only the number of exposed accounts. It is the type of people and records involved: franchise applicants, business-linked identities, and personal data that can...

LiteSpeed cPanel Plugin CVE-2026-48172 Exploited for Root-Level Server Compromise

LiteSpeed cPanel Plugin CVE-2026-48172 Exploited for Root-Level Server Compromise

A cPanel account should not be a straight path to root. CVE-2026-48172 makes that boundary fail in exactly the place hosting providers least want it to fail: inside a user-facing control panel plugin...

Megalodon GitHub Attack Hits 5,561 Repositories with Malicious CI/CD Workflows

Megalodon GitHub Attack Hits 5,561 Repositories with Malicious CI/CD Workflows

Megalodon did not need to poison application code to create supply-chain risk. It went after the machinery that builds, tests, signs, and ships that code. Security researchers have disclosed a...

Nimbus Manticore Deploys MiniFast Backdoor During Iranian Conflict Using SEO Poisoning and Zoom Installer Abuse

Nimbus Manticore Deploys MiniFast Backdoor During Iranian Conflict Using SEO Poisoning and Zoom Installer Abuse

Nimbus Manticore did not just return during the Iranian conflict. It adapted under pressure. Check Point Research’s latest investigation shows an Iranian, IRGC-affiliated threat actor shifting...

TrendAI Patches Apex One Zero-Day CVE-2026-34926 After In-the-Wild Exploitation

TrendAI Patches Apex One Zero-Day CVE-2026-34926 After In-the-Wild Exploitation

A medium-severity vulnerability rarely deserves routine treatment once exploitation starts in the wild. CVE-2026-34926 is a reminder that attacker requirements do not always equal business risk: when...

Singapore Logistics Firm A-Sonic Hit by Payload Ransomware: 1GB of Sensitive Data at Risk

Singapore Logistics Firm A-Sonic Hit by Payload Ransomware: 1GB of Sensitive Data at Risk

May 22, 2026 — In a significant cybersecurity incident affecting the Asia-Pacific supply chain sector, Singapore-based A-Sonic Logistics has become the latest victim of the emerging Payload...

GitHub Internal Repo Breach Linked to Malicious Nx Console Extension and TanStack npm Supply-Chain Attack

GitHub Internal Repo Breach Linked to Malicious Nx Console Extension and TanStack npm Supply-Chain Attack

A supply-chain attack does not need months of persistence to do damage. In this case, a poisoned developer extension was reportedly live for minutes, yet it became the entry point into thousands of...

Microsoft Defender Zero-Days Patched as CISA Adds CVE-2026-45498 to KEV Catalog

Microsoft Defender Zero-Days Patched as CISA Adds CVE-2026-45498 to KEV Catalog

Microsoft Defender is supposed to be the control plane that helps stop intrusions from getting worse. That is what makes the latest Defender zero-day activity uncomfortable: attackers have been...