Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsStudyTraining
ProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Study
Training
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

1310+ Articles
157+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
All tags
126 articles

#BleepingComputer

All CosmicBytez Labs articles tagged #BleepingComputer, across news, security advisories, how-to guides, and projects.

  • NewsJun 2, 2026

    AI-Built Ransomware Toolkit Automates EDR Evasion and AD Discovery

    A threat actor has deployed an AI-generated ransomware attack toolkit that automates Active Directory discovery and helps evade endpoint detection and response solutions, marking a new escalation in AI-assisted cybercrime.

  • NewsJun 2, 2026

    Google Fixes One Actively Exploited Android Zero-Day, 124 Flaws in June 2026 Update

    Google's June 2026 Android security update patches 124 vulnerabilities including one zero-day flaw that has been actively exploited in targeted attacks against Android devices.

  • NewsJun 2, 2026

    Microsoft's Coreutils Project Brings Linux Commands to Windows

    Microsoft announced Coreutils for Windows at Build 2026, bringing widely used Linux command-line utilities — ls, grep, cat, awk, and more — to Windows as native applications without requiring WSL or third-party tools.

  • NewsJun 1, 2026

    Critical Windows Netlogon RCE Flaw Now Exploited in Attacks

    Belgium's national cybersecurity authority (CCB) has issued an urgent warning that threat actors are actively exploiting a recently patched critical Windows Netlogon Remote Protocol vulnerability that allows unauthenticated remote code execution on domain controllers.

  • NewsMay 31, 2026

    ChatGPT Share Links Abused to Host Fake Outage Pages Delivering Malware

    Threat actors are exploiting ChatGPT's content-sharing feature to publish fake OpenAI outage pages that trick users into downloading trojanized ChatGPT desktop applications bundled with infostealer malware.

  • NewsMay 31, 2026

    From $5 Attacks to Botnet-Powered Platforms: Inside the DDoS-as-a-Service Market

    DDoS attacks are increasingly sold as subscription services with pricing tiers, reseller programs, and customer support. Flare's analysis reveals how the DDoS-as-a-Service market has matured from scattered tools into polished criminal attack platforms.

  • NewsMay 31, 2026

    WP Maps Pro Bug Exploited to Create Admin Accounts on WordPress Sites

    Hackers are actively exploiting a critical vulnerability in the WP Maps Pro WordPress plugin that allows unauthenticated attackers to create rogue administrator accounts, granting full site control without any login.

  • NewsMay 29, 2026

    Charter Communications Data Breach Affects 4.9 Million Accounts

    ShinyHunters stole personal information from 4.9 million Charter Communications accounts in an April 2026 hack, confirmed via Have I Been Pwned.

  • NewsMay 29, 2026

    Dutch Govt Disrupts Malware Botnet with 17 Million Infected Devices

    Dutch authorities took offline a massive botnet of 17 million infected devices and seized more than 200 servers from a local hosting provider that...

  • NewsMay 29, 2026

    Man Sent to Prison for Selling Data of 7 Million Elderly Americans

    A North Carolina man was sentenced to more than 10 years in federal prison for selling the personal information of over 7 million elderly Americans to...

  • NewsMay 29, 2026

    US Charges Google Security Engineer with Polymarket Insider Trading

    A Google security engineer was charged with insider trading after winning $1.2 million by placing bets on cryptocurrency-based Polymarket using...

  • NewsMay 28, 2026

    Carnival Cruise Confirms Data Breach Affecting Nearly 6 Million People

    Carnival Corporation, the world's largest cruise operator, confirms a breach affecting nearly 6M people after ShinyHunters' April 2026 extortion claim.

  • NewsMay 28, 2026

    New Gogs Zero-Day Flaw Lets Hackers Get Remote Code Execution

    An unpatched Gogs zero-day lets attackers gain RCE on internet-facing instances of the self-hosted Git service — no patch is currently available.

  • NewsMay 26, 2026

    KnowledgeDeliver Flaw Exploited as Zero-Day to Install Web

    Attackers exploited a critical zero-day vulnerability in KnowledgeDeliver LMS servers to deploy the Godzilla web shell, giving persistent backdoor access to.

  • NewsMay 23, 2026

    Drupal: Critical SQL Injection Flaw Now Targeted in Attacks

    Drupal is warning that hackers are actively attempting to exploit a 'highly critical' SQL injection vulnerability, CVE-2026-9082, announced earlier this...

  • NewsMay 23, 2026

    Former US Execs Plead Guilty to Aiding Tech Support Scammers

    Two former executives of a call-tracking and analytics company have pleaded guilty to concealing a years-long tech support fraud scheme that victimized...

  • NewsMay 23, 2026

    Italy Disrupts CINEMAGOAL Piracy App That Stole Streaming

    Italian authorities have dismantled the CINEMAGOAL piracy ecosystem after the app was found to have been stealing authentication codes from streaming...

  • NewsMay 23, 2026

    Netherlands Seizes 800 Servers of Hosting Firm Enabling

    Dutch financial crime investigators (FIOD) arrested two men and seized 800 servers from a hosting company that provided bulletproof infrastructure...

  • NewsMay 22, 2026

    Trend Micro Warns of Apex One Zero-Day Exploited in the Wild

    Trend Micro has patched an Apex One zero-day vulnerability actively exploited in attacks targeting Windows systems. The flaw, discovered in the company's...

  • NewsMay 22, 2026

    US and Canada Arrest and Charge Suspected Kimwolf Botnet

    U.S. and Canadian authorities arrested and charged a Canadian man with operating the Kimwolf DDoS botnet, which infected nearly two million devices...

  • NewsMay 21, 2026

    Apple Blocked Over $11 Billion in App Store Fraud in 6 Years

    Apple has revealed it blocked more than $11 billion in fraudulent App Store transactions over the past six years, including $2.2 billion in 2025 alone,...

  • NewsMay 21, 2026

    GitHub Links Repo Breach to TanStack npm Supply-Chain Attack

    GitHub has confirmed that hackers who stole 3,800 internal repositories gained access through a malicious version of the Nx Console VS Code extension...

  • NewsMay 21, 2026

    Google Accidentally Exposed Details of Unfixed Chromium Flaw

    Google accidentally leaked information about an unpatched Chromium vulnerability that allows JavaScript to continue running in the background even after...

  • NewsMay 19, 2026

    7-Eleven Confirms Data Breach Claimed by the ShinyHunters

    Convenience store giant 7-Eleven has confirmed a data breach after the ShinyHunters extortion group publicly claimed responsibility for the attack. The...

  • NewsMay 19, 2026

    Cybercrime Service Disrupted for Abusing Microsoft Platform

    Microsoft has disrupted a malware-signing-as-a-service operation that exploited the company's Artifact Signing service to produce fraudulent code-signing...

  • NewsMay 18, 2026

    5 Steps to Managing Shadow AI Tools Without Slowing Down

    80% of employees currently use unapproved AI tools at work, yet only 12% of companies have formal AI governance policies. Adaptive Security outlines a...

  • NewsMay 15, 2026

    Popular node-ipc npm Package Compromised to Steal

    Hackers have injected credential-stealing malware into newly published versions of node-ipc, a popular inter-process communication npm package, in a new...

  • NewsMay 9, 2026

    Fake OpenAI Repository on Hugging Face Pushes Infostealer

    A malicious repository impersonating OpenAI's "Privacy Filter" project climbed to Hugging Face's trending list and delivered information-stealing malware...

  • NewsMay 9, 2026

    JDownloader Site Hacked to Replace Installers with Python

    The official website for JDownloader, one of the most widely-used open-source download managers, was compromised to distribute malicious Windows and Linux...

  • NewsMay 9, 2026

    Zara Data Breach Exposed Personal Information of 197,000

    Hackers gained access to Zara's customer databases and stole personal information belonging to more than 197,000 individuals, with the breach surfacing...

  • NewsMay 8, 2026

    NVIDIA Confirms GeForce NOW Data Breach Affecting Armenian

    NVIDIA has confirmed that GeForce NOW user data was exposed in a data breach, with the incident specifically affecting users in Armenia. The company...

  • NewsMay 8, 2026

    Trellix Source Code Breach Claimed by RansomHouse Hackers

    The RansomHouse threat group has claimed responsibility for the Trellix source code repository breach disclosed last week, leaking a set of proof images...

  • NewsMay 1, 2026

    US Ransomware Negotiators Get 4 Years in Prison Over

    Two former cybersecurity incident responders from Sygnia and DigitalMint were each sentenced to four years in federal prison for leveraging their trusted...

  • NewsApr 29, 2026

    European Police Dismantles €50 Million Crypto Investment

    Austrian and Albanian law enforcement jointly dismantled a large-scale cryptocurrency investment fraud operation estimated to have caused over €50 million...

  • NewsApr 29, 2026

    GitHub Fixes RCE Flaw That Gave Access to Millions of

    GitHub has patched CVE-2026-3854, a critical remote code execution vulnerability exploitable via a single HTTP request that could have granted attackers...

  • NewsApr 29, 2026

    Hackers Exploit RCE Flaws in Qinglong Task Scheduler for

    Threat actors are actively exploiting two authentication bypass vulnerabilities in the Qinglong open-source task scheduling tool to deploy cryptomining...

  • NewsApr 29, 2026

    Learning from the Vercel Breach: Shadow AI and OAuth Sprawl

    The Vercel breach, traced to a compromised third-party AI tool with OAuth access, illustrates how Shadow AI adoption and unchecked OAuth integrations are...

  • NewsApr 28, 2026

    Broken VECT 2.0 Ransomware Acts as a Data Wiper for Large

    Researchers have found that VECT 2.0 ransomware contains a critical flaw in its nonce handling that causes encryption to permanently destroy large files...

  • NewsApr 28, 2026

    Hackers Are Exploiting a Critical LiteLLM Pre-Auth SQLi Flaw

    Threat actors are actively exploiting CVE-2026-42208, a critical pre-authentication SQL injection vulnerability in the LiteLLM open-source LLM gateway,...

  • NewsApr 28, 2026

    Video Service Vimeo Confirms Anodot Breach Exposed User Data

    Vimeo has confirmed that customer and user data was accessed without authorization following a security breach at Anodot, a data anomaly detection...

  • NewsApr 26, 2026

    Microsoft Now Lets Admins Uninstall Copilot on Enterprise

    Following the April 2026 Patch Tuesday, Microsoft has made broadly available a new MDM policy setting that enables IT administrators to fully uninstall...

  • NewsApr 26, 2026

    New 'Pack2TheRoot' Flaw Gives Hackers Root Linux Access

    A newly disclosed vulnerability in the PackageKit daemon, dubbed Pack2TheRoot, allows local Linux users to escalate privileges to root by abusing the...

  • NewsApr 26, 2026

    Over 10,000 Zimbra Servers Vulnerable to Ongoing XSS Attacks

    CISA has confirmed that a cross-site scripting vulnerability in Zimbra Collaboration Suite is being actively exploited in the wild, with over 10,000...

  • NewsApr 25, 2026

    DORA and Operational Resilience: Credential Management as a

    Article 9 of DORA makes authentication and access control a legal obligation for EU financial entities. With stolen credentials now the single largest...

  • NewsApr 25, 2026

    Microsoft to Roll Out Entra Passkeys on Windows in Late

    Microsoft is rolling out passkey support for phishing-resistant passwordless authentication to Microsoft Entra-protected resources from Windows devices...

  • NewsApr 24, 2026

    ADT Confirms Data Breach After ShinyHunters Leak Threat

    Home security giant ADT has confirmed a data breach after the ShinyHunters extortion group threatened to publish stolen data unless a ransom is paid,...

  • NewsApr 24, 2026

    Firestarter Malware Survives Cisco Firewall Updates and

    US and UK cybersecurity agencies are warning about Firestarter, a custom implant that persists on Cisco Firepower and Secure Firewall devices running ASA...

  • NewsApr 24, 2026

    Windows Update Gets New Controls to Reduce Forced Restarts

    Microsoft is rolling out Windows Update improvements that give users more control over how updates are installed while reducing disruption from frequent...

  • NewsApr 23, 2026

    Hackers Actively Exploiting Breeze Cache File Upload Bug in

    Threat actors are mass-exploiting a critical unauthenticated file upload vulnerability in the Breeze Cache WordPress plugin, uploading PHP webshells to...

  • NewsApr 23, 2026

    Trigona Ransomware Deploys Custom CLI Exfiltration Tool in

    Recently observed Trigona ransomware attacks are using a bespoke command-line exfiltration tool to steal data from compromised environments faster and...

  • NewsApr 22, 2026

    Former Ransomware Negotiator Pleads Guilty to BlackCat

    Angelo Martino, 41, a former employee of cybersecurity incident response firm DigitalMint, has pleaded guilty to targeting U.S. companies with BlackCat...

  • NewsApr 22, 2026

    France Titres Confirms Data Breach as Hacker Offers Stolen

    France Titres, the French government agency responsible for issuing and managing administrative documents, has confirmed a cyberattack after a threat...

  • NewsApr 22, 2026

    Kyber Ransomware Gang Uses Post-Quantum Encryption to

    A new ransomware operation called Kyber is targeting Windows systems and VMware ESXi endpoints, with one variant implementing Kyber1024 post-quantum...

  • NewsApr 22, 2026

    Microsoft Teams to Get Efficiency Mode for Low-Resource PCs

    Microsoft is rolling out a new Efficiency Mode for Microsoft Teams that automatically throttles CPU and memory usage on hardware-constrained devices,...

  • NewsApr 22, 2026

    New Mirai Campaign Exploits RCE Flaw in End-of-Life D-Link

    A new Mirai-based malware campaign is actively exploiting CVE-2025-29635, a high-severity command-injection vulnerability in end-of-life D-Link DIR-823X...

  • NewsApr 22, 2026

    New npm Supply Chain Attack Self-Spreads to Steal Developer

    A newly discovered supply chain attack targeting the npm ecosystem steals developer authentication tokens and uses compromised accounts to publish...

  • NewsApr 22, 2026

    Over 1,300 Microsoft SharePoint Servers Vulnerable to

    More than 1,300 internet-facing Microsoft SharePoint servers remain unpatched against a spoofing vulnerability exploited as a zero-day, with active...

  • NewsApr 22, 2026

    Spain Dismantles Major $4.7M Manga Piracy Platform, Arrests

    Spanish police have shut down the largest Spanish-language manga piracy platform, which had operated since 2014 and served millions of monthly users...

  • NewsApr 21, 2026

    Actively Exploited Apache ActiveMQ Flaw Impacts 6,400

    Shadowserver found over 6,400 Apache ActiveMQ servers exposed online and vulnerable to ongoing attacks exploiting a high-severity code injection...

  • NewsApr 21, 2026

    French Government Agency France Titres Confirms Data Breach

    France Titres, the French government agency responsible for issuing administrative identity documents, has confirmed a data breach after a threat actor...

  • NewsApr 20, 2026

    KelpDAO Suffers $290 Million Heist Tied to Lazarus Hackers

    North Korean state-sponsored hackers from the Lazarus Group are behind a $290 million cryptocurrency theft from DeFi platform KelpDAO, marking one of the...

  • NewsApr 20, 2026

    Microsoft Releases Emergency Updates to Fix Windows Server

    Microsoft released out-of-band updates to address critical issues affecting Windows Server systems that emerged after the installation of April 2026 Patch...

  • NewsApr 20, 2026

    The Backup Myth That Is Putting Businesses at Risk

    Backups protect your data, but they don't keep your business running during downtime. Understanding the difference between backup and BCDR is critical as...

  • NewsApr 20, 2026

    The Gentlemen Ransomware Now Uses SystemBC for Bot-Powered

    Researchers have discovered a SystemBC proxy botnet of over 1,570 compromised hosts linked to Gentlemen ransomware operations. The gang's affiliate is...

  • NewsApr 19, 2026

    Apple Account Change Alerts Abused to Send Phishing Emails

    Threat actors are exploiting Apple's legitimate account change notification system to embed fake iPhone purchase scams inside genuine Apple emails,...

  • NewsApr 19, 2026

    NIST to Stop Rating Non-Priority Flaws Due to Volume

    The National Institute of Standards and Technology will stop assigning CVSS severity scores to lower-priority vulnerabilities in the NVD as CVE submission...

  • NewsApr 19, 2026

    Vercel Confirms Breach as Hackers Claim to Be Selling

    Cloud development platform Vercel has confirmed a security incident after threat actors claimed to have stolen internal databases, API keys, tokens, and...

  • NewsApr 18, 2026

    Critical Flaw in protobuf.js Library Enables JavaScript

    A critical remote code execution vulnerability in protobuf.js, the widely used JavaScript implementation of Google's Protocol Buffers, has been disclosed...

  • NewsApr 18, 2026

    Microsoft Teams Right-Click Paste Broken by Edge Update Bug

    Microsoft has acknowledged that a recent Microsoft Edge browser update introduced a regression that breaks right-click paste functionality in the...

  • NewsApr 17, 2026

    Recently Leaked Windows Zero-Days Now Exploited in Active

    Threat actors are actively exploiting three recently disclosed Windows security vulnerabilities that allow attackers to gain SYSTEM or elevated...

  • NewsApr 10, 2026

    1 Billion CISA KEV Records Reveal Human-Scale Security Has

    A Qualys analysis of over one billion CISA Known Exploited Vulnerabilities remediation records shows that most critical flaws are being actively exploited...

  • NewsApr 9, 2026

    Eurail Says December Data Breach Impacts 300,000 Individuals

    Eurail B.V. has confirmed that a December 26, 2025 breach exposed the personal data of 308,777 individuals — including passport copies, IBAN bank details,...

  • NewsApr 9, 2026

    Hackers Exploiting Acrobat Reader Zero-Day Flaw Since

    Attackers have been silently exploiting an unpatched zero-day vulnerability in Adobe Acrobat Reader since at least November 2025, using malicious PDFs to...

  • NewsApr 9, 2026

    Hackers Steal $3.6 Million from Crypto ATM Giant Bitcoin

    Bitcoin Depot, operator of one of the largest Bitcoin ATM networks in North America, disclosed that attackers stole $3.665 million in Bitcoin from its hot...

  • NewsApr 9, 2026

    Healthcare IT Provider ChipSoft Hit by Ransomware Attack

    Dutch healthcare software vendor ChipSoft has been struck by a ransomware attack, forcing the company to take its website and digital patient services...

  • NewsApr 9, 2026

    Microsoft Suspends Dev Accounts for High-Profile Open

    Microsoft has suspended developer accounts used to maintain several prominent open-source projects without prior notice or a quick reinstatement path,...

  • NewsApr 8, 2026

    Hackers Use Pixel-Large SVG Trick to Hide Credit Card

    A massive campaign targeting nearly 100 Magento e-commerce stores embeds credit card-stealing JavaScript inside a pixel-sized SVG image, bypassing visual...

  • NewsApr 8, 2026

    Snowflake Customers Hit in Data Theft Attacks After SaaS

    Over a dozen companies have suffered data theft attacks after a SaaS integration provider was breached and authentication tokens stolen, enabling...

  • NewsApr 7, 2026

    Authorities Disrupt APT28 Router DNS Hijacks Targeting

    An international law enforcement operation has dismantled FrostArmada, an APT28 campaign that hijacked DNS on compromised MikroTik and TP-Link routers to...

  • NewsApr 7, 2026

    Drift $280M Crypto Theft Linked to 6-Month In-Person DPRK

    Drift Protocol has revealed that the $280 million hack it suffered was the culmination of a six-month long operation in which North Korean-linked threat...

  • NewsApr 7, 2026

    FBI: Americans Lost a Record $21 Billion to Cybercrime Last

    The FBI's Internet Crime Complaint Center reports that U.S. victims lost nearly $21 billion to cyber-enabled crimes in 2025 — an all-time record — driven...

  • NewsApr 7, 2026

    Hackers Exploit Critical Flaw in Ninja Forms WordPress

    Attackers are actively exploiting a critical unauthenticated arbitrary file upload vulnerability in the Ninja Forms File Uploads premium add-on for...

  • NewsApr 6, 2026

    Disgruntled Researcher Leaks BlueHammer Windows Zero-Day

    A security researcher operating under the aliases 'Chaotic Eclipse' and 'Nightmare-Eclipse' has publicly released exploit code for an unpatched Windows...

  • NewsApr 6, 2026

    German Authorities Identify REvil and GandCrab Ransomware

    Germany's Federal Police have publicly named two Russian nationals as the leaders of the GandCrab and REvil ransomware operations, linking them to at...

  • NewsApr 6, 2026

    Microsoft Links Storm-1175 to Medusa Ransomware Zero-Day

    Microsoft has formally attributed Medusa ransomware zero-day attacks to Storm-1175, a China-based financially motivated cybercriminal group that has...

  • NewsApr 6, 2026

    GPUBreach: New Rowhammer Attack on GPU GDDR6 Memory Enables

    Researchers from the University of Toronto have demonstrated GPUBreach, a novel attack that induces Rowhammer bit-flips in GPU GDDR6 memory to bypass...

  • NewsApr 6, 2026

    Why Simple Breach Monitoring Is No Longer Enough

    Infostealers are harvesting credentials and session cookies at scale, quietly bypassing MFA and traditional defenses. Here's why organizations need...

  • NewsApr 5, 2026

    Hackers Exploit React2Shell in Automated Credential Theft

    Threat actors are running a large-scale, automated campaign exploiting React2Shell (CVE-2025-55182) in vulnerable Next.js applications to steal...

  • NewsApr 5, 2026

    Traffic Violation Scams Switch to QR Codes in New Phishing

    Scammers are sending fake "Notice of Default" traffic violation SMS messages impersonating state courts across the U.S., pressuring recipients to scan a...

  • NewsApr 4, 2026

    Device Code Phishing Attacks Surge 37x as New Kits Spread

    Device code phishing attacks abusing the OAuth 2.0 Device Authorization Grant flow have exploded 37-fold in 2026 as ready-made phishing kits proliferate...

  • NewsApr 4, 2026

    Evolution of Ransomware: Multi-Extortion Ransomware Attacks

    Modern ransomware has evolved far beyond simple file encryption. Multi-extortion tactics — combining encryption, data theft, and public leak threats —...

  • NewsApr 4, 2026

    Hims & Hers Warns of Data Breach After Zendesk Support

    Telehealth giant Hims & Hers Health is warning customers of a data breach after support tickets were stolen from a third-party customer service platform,...

  • NewsApr 3, 2026

    CERT-EU: European Commission Hack Exposes Data of 30 EU

    CERT-EU has attributed the European Commission cloud account compromise to the TeamPCP threat group, revealing the breach exposed sensitive data from at...

  • NewsApr 3, 2026

    Die Linke German Political Party Confirms Data Stolen by

    The Qilin ransomware group has claimed responsibility for an attack against German political party Die Linke, forcing an IT systems outage and threatening...

  • NewsApr 3, 2026

    Microsoft Now Force-Upgrades Unmanaged Windows 11 24H2 PCs

    Microsoft has begun automatically upgrading unmanaged Windows 11 Home and Pro devices from 24H2 to 25H2, removing user choice from the update process for...

  • NewsApr 2, 2026

    Adversaries Exploit Vacant Homes to Intercept Mail in

    Threat actors are weaponizing vacant properties as drop addresses for mail interception, blending physical access with digital fraud. A Flare threat...

  • NewsApr 2, 2026

    Claude Code Leak Used to Push Infostealer Malware on GitHub

    Threat actors are capitalising on the Claude Code source code leak by creating fake GitHub repositories that impersonate the leaked source to deliver...

  • NewsApr 2, 2026

    Drift Loses $280 Million as Hackers Seize Security Council

    The Drift Protocol DeFi platform lost at least $280 million after a sophisticated threat actor executed a planned governance attack, seizing control of...

  • NewsApr 2, 2026

    New Progress ShareFile Flaws Can Be Chained in Pre-Auth RCE

    Two newly disclosed vulnerabilities in Progress ShareFile can be chained together to enable unauthenticated remote code execution and file exfiltration,...

  • NewsApr 2, 2026

    Over 14,000 F5 BIG-IP APM Instances Still Exposed to RCE

    Internet security watchdog Shadowserver has found over 14,000 BIG-IP APM instances exposed online amid ongoing attacks exploiting a critical-severity...

  • NewsApr 1, 2026

    Apple Expands iOS 18 Updates to More iPhones to Block

    Apple has extended security update eligibility to additional iPhone models still running iOS 18, enabling more devices to receive protections against the...

  • NewsApr 1, 2026

    Google Fixes Fourth Chrome Zero-Day Exploited in Attacks in

    Google has patched the fourth Chrome zero-day vulnerability actively exploited in attacks this year, a use-after-free flaw in the Dawn graphics engine...

  • NewsApr 1, 2026

    Hackers Exploit TrueConf Zero-Day to Push Malicious

    Threat actors have weaponized an unpatched zero-day in TrueConf conference server software to execute arbitrary files on all connected endpoints,...

  • NewsApr 1, 2026

    ''NoVoice'' Android Malware on Google Play Infected 2.3

    A new Android malware named NoVoice was discovered hiding in over 50 apps on the Google Play Store, with a combined download count of at least 2.3...

  • NewsMar 30, 2026

    Healthcare Tech Firm CareCloud Says Hackers Stole Patient

    Healthcare IT company CareCloud has disclosed a cyberattack that resulted in the theft of sensitive patient data and caused an eight-hour network outage,...

  • NewsMar 29, 2026

    File Read Flaw in Smart Slider Plugin Impacts 500K

    A vulnerability in the Smart Slider 3 WordPress plugin, active on more than 800,000 websites, allows subscriber-level users to read arbitrary files on the...

  • NewsMar 28, 2026

    Anti-Piracy Coalition Takes Down AnimePlay App with 5

    The Alliance for Creativity and Entertainment has announced the shutdown of AnimePlay, a major unauthorized anime streaming platform serving over 5...

  • NewsMar 28, 2026

    Backdoored Telnyx PyPI Package Pushes Malware Hidden in WAV

    Threat actors known as TeamPCP compromised the Telnyx Python package on PyPI, uploading malicious versions that conceal credential-stealing malware inside...

  • NewsMar 28, 2026

    New Infinity Stealer Malware Grabs macOS Data via ClickFix

    A new info-stealing malware named Infinity Stealer is targeting macOS systems with a Python payload packaged as an executable using the open-source Nuitka...

  • NewsMar 27, 2026

    European Commission Investigating Breach After Amazon Cloud

    The European Commission is investigating a security breach after a threat actor gained unauthorized access to its Amazon Web Services cloud environment...

  • NewsMar 26, 2026

    PolyShell Attacks Target 56% of All Vulnerable Magento

    Mass exploitation is underway against Magento 2 and Adobe Commerce installations using the 'PolyShell' polyglot file upload vulnerability, with attackers...

  • NewsMar 25, 2026

    Citrix Urges Admins to Patch NetScaler Flaws as Soon as

    Citrix has patched two NetScaler ADC and Gateway vulnerabilities — including a critical CVSS 9.3 out-of-bounds read flaw eerily similar to the previously...

  • NewsMar 25, 2026

    Manager of Botnet Used in Ransomware Attacks Gets 2 Years

    Ilya Angelov, co-leader of the TA551/Mario Kart cybercrime group, was sentenced to two years in prison for operating a phishing botnet that sent 700,000...

  • NewsMar 25, 2026

    Paid AI Accounts Are Now a Hot Underground Commodity

    New research from Flare Systems reveals that premium AI platform access — including ChatGPT Plus, Claude Pro, and raw API keys — has been systematically...

  • NewsMar 25, 2026

    PTC Warns of Imminent Threat from Critical Windchill

    PTC is warning customers of an imminent exploit threat against a critical deserialization vulnerability in Windchill and FlexPLM — CVE-2026-4681, CVSS...

  • NewsMar 23, 2026

    Crunchyroll Probes Breach After Hacker Claims to Steal 6.8M

    Popular anime streaming platform Crunchyroll is investigating a breach after hackers claimed to have stolen personal information for approximately 6.8...

  • NewsMar 23, 2026

    Mazda Discloses Security Breach Exposing Employee and

    Mazda Motor Corporation has disclosed a security incident detected in December 2025 in which unauthorized access to a warehouse management system exposed...

  • NewsMar 22, 2026

    Trivy Vulnerability Scanner Breached to Push Infostealer

    The Trivy open-source vulnerability scanner was compromised in a supply chain attack by the threat group TeamPCP, which hijacked 75 release tags and...

  • NewsMar 22, 2026

    VoidStealer Malware Steals Chrome Master Key via Debugger

    A new infostealer named VoidStealer bypasses Chrome's Application-Bound Encryption by attaching a remote debugger to the browser process and using the...

  • NewsMar 20, 2026

    Navia Discloses Data Breach Impacting 2.7 Million People

    Navia Benefit Solutions has notified nearly 2.7 million individuals of a data breach that exposed sensitive personal and health-related information to...

  • NewsMar 20, 2026

    Oracle Pushes Emergency Fix for Critical Identity Manager

    Oracle has released an out-of-band security update to fix a critical unauthenticated remote code execution vulnerability in Oracle Identity Manager and...

  • NewsMar 16, 2026

    CISA Adds Wing FTP Server Flaw to KEV as RCE Chain Exploits

    CISA added CVE-2025-47813 to its Known Exploited Vulnerabilities catalog on March 16, warning that the medium-severity path disclosure flaw is being...

  • NewsMar 14, 2026

    AppsFlyer Web SDK Supply Chain Attack Spread

    Attackers hijacked AppsFlyer's CDN domain via a registrar incident, serving a sophisticated 170 KB crypto-stealing JavaScript payload to every site...

  • NewsMar 13, 2026

    Telus Digital Confirms Massive Breach After ShinyHunters

    Canadian telecom giant Telus Digital has confirmed a security incident after the ShinyHunters hacking group claimed to have stolen nearly 1 petabyte of...

  • NewsFeb 8, 2026

    Tirith: New Open-Source Tool Blocks Homoglyph Attacks

    A new cross-platform tool called Tirith hooks into terminal shells to detect and block Unicode homoglyph attacks, pipe-to-shell exploits, and supply chain...

  • NewsFeb 7, 2026

    Shadow Campaigns: State-Backed Espionage Group Breaches 70+

    Palo Alto Unit 42 reveals a state-aligned group designated TGR-STA-1030 compromised government and critical infrastructure targets in 37 countries using...