The cybersecurity landscape continues to be a battleground of innovation and exploitation, with attackers consistently finding new ways to leverage existing vulnerabilities and emerging technologies. This week’s recap highlights a series of concerning trends, from actively exploited zero-days in widely used software to the sophisticated abuse of phishing kits and…
Palo Alto Networks VPN vulnerability, identified as CVE-2026-0257, is being actively exploited by an unknown threat actor to gain unauthorized access to GlobalProtect portals. The critical authentication bypass flaw, which affects the portal and gateway components of PAN-OS software, carries a CVSS score of 7.8 and allows malicious actors to…
Splunk has issued critical security updates to address CVE-2026-20253, a severe vulnerability in Splunk Enterprise that allows unauthenticated users to perform arbitrary file operations and potentially achieve remote code execution. Rated 9.8 on the CVSS scoring system, the flaw presents a significant risk to enterprise environments utilizing the affected software.…
U.S. law enforcement agencies, in collaboration with international partners, have seized multiple internet domains alleged to have hosted nonconsensual AI-generated pornography. The operation targeted websites that specialized in creating and distributing digitally altered images and videos of women without their consent. The domains, CFAKE.com and SOCFAKE.com, are accused of publishing…
Cybersecurity researchers have unveiled a novel attack technique, dubbed “Agentjacking,” that subverts artificial intelligence (AI) coding agents, compelling them to execute arbitrary code on developer workstations. This groundbreaking vulnerability exploits a fundamental architectural weakness at the intersection of error tracking platforms and AI agents, potentially granting attackers unfettered access to…
The cybercriminal group ShinyHunters has been actively exploiting a critical vulnerability in Oracle PeopleSoft, a widely used enterprise resource planning (ERP) system. This zero-day exploit, identified as CVE-2026-35273, allows attackers to gain unauthorized access, exfiltrate sensitive data, and then demand ransom payments to prevent its public release. The campaign has…
Trending
Subscribe to Updates
Get our latest news, reports, and updates directly to your inbox.
Research & Analysis
More Articles
A new report reveals that data sovereignty has become a paramount concern for global business leaders, with every surveyed executive re-evaluating their data strategies. The shift is driven primarily by escalating geopolitical risks and the potential for significant reputational damage, indicating a move beyond mere compliance. The qualitative survey, conducted…
Dashcams, lauded as vigilant digital co-pilots for drivers, are facing a stark new security revelation. Researchers have demonstrated that these seemingly secure devices can be hijacked by hackers in seconds, transforming them into potent surveillance tools capable of gathering sensitive data. This alarming discovery, unveiled at the Security Analyst Summit…
Cybercriminals are increasingly leveraging AI tools to launch sophisticated attacks against WhatsApp Web users, a trend highlighted by the emerging “Water Saci” campaign. This campaign, primarily targeting Brazilian users, utilizes compromised WhatsApp accounts to distribute banking trojans and illicitly obtain sensitive financial information. By sending malicious attachments through trusted contacts,…
Hackers exploit Evilginx to bypass multi-factor authentication by impersonating legitimate SSO sites.
Hackers are increasingly employing a sophisticated adversary-in-the-middle tool known as Evilginx to bypass multi-factor authentication (MFA) and compromise cloud accounts. This advanced toolkit effectively mimics legitimate single sign-on (SSO) portals, presenting a deceptive interface to users and allowing attackers to steal session cookies and tokens. Infoblox security analysts have observed…
Ukraine-linked hackers are escalating their cyberattacks against Russian aerospace and defense companies, employing newly developed custom malware to exfiltrate sensitive design blueprints, production schedules, and internal communications. This intensified cyber campaign, detailed by security analysts, targets the entirety of Russia’s war industry, from major contractors to smaller specialized suppliers, aiming…
Nisos Discloses Prior Indicators of Insider Threat Detection Through Authentication and Access Controls
Insider threats continue to be a significant cybersecurity challenge, often evading detection by blending into normal operations. These insidious attacks don’t typically present obvious warning signs, instead revealing themselves through subtle, anomalous activities within legitimate user accounts. Nisos, a cybersecurity firm, has detailed earlier signs of insider detection specifically through…
Candiru, an Israeli-based spyware vendor, is actively deploying a sophisticated malware infrastructure across multiple countries, targeting high-value individuals including politicians, journalists, and business leaders with its DevilsTongue spyware. This advanced threat to Windows users has established eight distinct operational clusters in nations such as Hungary, Saudi Arabia, Indonesia, and Azerbaijan,…
A new malware family, dubbed Arkanix Stealer, is actively targeting home users and small businesses by exploiting their reliance on VPN clients and Wi-Fi networks. This sophisticated information-stealing malware aims to pilfer sensitive data including VPN account credentials, saved Wi-Fi profiles, browser login information, and even desktop screenshots, providing attackers…
The popular third-party YouTube client, SmartTube, has been compromised due to exposed developer signing keys, leading to the malicious embedding of code within official releases. Google has responded by forcibly disabling the application on affected Android TV devices, marking a significant security crisis for the community. This incident highlights the…
Hackers Utilize Telegram, WinSCP, Google Chrome, and Microsoft Teams for ValleyRat Deployment
A sophisticated malware campaign is actively distributing trojanized installers for popular applications like Telegram, WinSCP, Google Chrome, and Microsoft Teams to deploy ValleyRat, a potent remote access trojan. This campaign has been attributed to Silver Fox, a China-aligned advanced persistent threat (APT) group observed to be active since at least…
The Glassworm malware campaign has resurfaced, deploying 24 malicious extensions across Microsoft Visual Studio Marketplace and OpenVSX marketplaces over the past week. This significant escalation highlights the ongoing threat posed by supply chain attacks targeting developer tools, impacting platforms essential for software development. These malicious extensions meticulously clone legitimate packages…
A sophisticated cybercrime group known as ShadyPanda has been implicated in a massive malware campaign that has compromised an estimated 4.3 million users of Google Chrome and Microsoft Edge browsers. For seven years, the threat actors operated undetected, leveraging malicious browser extensions that gained official approval from both Google and…
