Threat actors are actively exploiting multiple security vulnerabilities within Fortinet FortiSandbox appliances, according to a recent advisory from cybersecurity firm Defused Cyber. The firm reported observing exploitation attempts for three specific vulnerabilities, CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089, within a 24-hour period, highlighting an urgent need for organizations using these Fortinet products…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has officially added a critical security flaw affecting the LiteSpeed cPanel Plugin to its Known Exploited Vulnerabilities (KEV) catalog. This designation mandates that Federal Civilian Executive Branch (FCEB) agencies must implement the necessary patches by June 18, 2026, to mitigate the risk…
Cisco has issued urgent security updates for a critical vulnerability affecting its Catalyst SD-WAN Manager, a widely used network management platform. This medium-severity flaw, identified as CVE-2026-20262, has been observed under active exploitation in the wild, prompting immediate action from affected organizations and government agencies. The vulnerability, which carries a…
Researchers at Obsidian Security have disclosed a critical vulnerability chain (CVSS 9.9) in LiteLLM, an open-source AI gateway, that allows a low-privilege account to achieve full server takeover and execute arbitrary code. This severe flaw, impacting how LiteLLM handles virtual API keys and custom guardrails, exposes sensitive provider keys, encrypted…
A critical vulnerability in Microsoft 365 Copilot Enterprise Search, dubbed “SearchLeak” by researchers, allowed attackers to potentially exfiltrate sensitive user data, including emails and calendar details, with a single click. This discovery highlights a new attack vector chaining together existing web vulnerabilities with an AI-specific weakness. Varonis Threat Labs researchers…
The cybersecurity landscape continues to be a battleground of innovation and exploitation, with attackers consistently finding new ways to leverage existing vulnerabilities and emerging technologies. This week’s recap highlights a series of concerning trends, from actively exploited zero-days in widely used software to the sophisticated abuse of phishing kits and…
Trending
Subscribe to Updates
Get our latest news, reports, and updates directly to your inbox.
Research & Analysis
More Articles
Cybercriminals are deploying a sophisticated new phishing campaign that leverages fake spam filter alerts to steal user email login credentials. This evolving threat specifically targets individuals by impersonating legitimate security notifications from their own organizations, making it a highly deceptive practice. The campaign’s ingenuity lies in its ability to bypass…
Anthropic revealed Thursday that a sophisticated, previously unknown Chinese state-sponsored hacking group utilized the company’s Claude AI generative AI product in a campaign that breached the defenses of at least 30 organizations. This marks a significant escalation in the misuse of advanced AI tools for cyberattacks. According to Anthropic’s research,…
North Korean threat actors have adopted novel tactics in their ongoing “Contagious Interview” campaign, now leveraging legitimate JSON storage services to host and distribute malicious payloads. This evolution in their methodology highlights a persistent effort to bypass security measures and compromise software developers for sensitive data exfiltration, including cryptocurrency wallet…
A sophisticated supply chain attack has been uncovered targeting the popular npm package manager, with a malicious package named “@acitons/artifact” downloaded over 206,000 times. Security researchers discovered this threat on November 7th, identifying it as a potent example of typosquatting. The attackers deliberately misspelled the name of a legitimate package,…
The evolving SmartApeSG campaign, also known as ZPHP or HANEY MANEY, is employing a sophisticated ClickFix technique to deploy the NetSupport Remote Access Trojan (RAT) on Windows systems. This shift in tactics moves away from previous methods involving fake browser updates, instead tricking users into verifying their humanity through deceptive…
Google and researchers report signs of disruption in Lighthouse text scams following lawsuit
The phishing kit known as Lighthouse, implicated in widespread text-based scams such as those demanding payment for fictitious unpaid road tolls, has reportedly been hindered shortly after Google initiated legal action against its presumed operators. Google announced on Thursday that Lighthouse’s operations have ceased, with two cybersecurity firms that monitor…
Researchers Find Serious AI Bugs Exposing Meta, Nvidia, and Microsoft Inference Frameworks
Cybersecurity researchers have uncovered critical remote code execution vulnerabilities affecting prominent AI inference engines from Meta, Nvidia, Microsoft, and open-source projects like vLLM and SGLang. The widespread flaws, identified by Oligo Security, stem from a shared insecure coding pattern dubbed “ShadowMQ,” which leverages the combination of ZeroMQ (ZMQ) and Python’s…
Security researchers have uncovered a massive, coordinated spam campaign that flooded the npm registry with over 43,000 malicious packages over nearly two years. Dubbed the “IndonesianFoods worm,” this operation highlights potential vulnerabilities in the widely used JavaScript package manager. These dormant packages, representing more than 1 percent of the entire…
Threat Actors Use JSON Storage Services for Malware Hosting and Delivery Via Trojanized Code Projects
Cybersecurity researchers have exposed a sophisticated threat campaign, dubbed “Contagious Interview,” where malicious actors are leveraging legitimate JSON storage services to host and distribute malware, specifically targeting software developers. This innovative technique allows threat actors to blend harmful code into seemingly innocuous development projects, making detection by traditional security measures…
Ransomware Landscape Fractures, Signaling Decentralized Ecosystem The ransomware landscape in Q3 2025 has reached a new peak of decentralization, with 85 active ransomware and extortion groups identified, the highest number ever recorded. This proliferation signifies a significant shift from the dominance of a few large ransomware-as-a-service (RaaS) operations to a…
A new cross-platform ransomware, dubbed Kraken, has emerged as a significant threat to enterprise environments. First observed in August 2025, this sophisticated malware developed by a Russian-speaking cybercriminal group is capable of targeting Windows, Linux, and VMware ESXi systems. This versatile attack vector marks a concerning evolution in ransomware capabilities,…
State-sponsored threat actors from China have orchestrated a highly sophisticated espionage campaign leveraging artificial intelligence (AI) technology, marking a significant escalation in the use of advanced tools for cyber attacks. In mid-September 2025, these actors employed AI capabilities developed by Anthropic, a leading AI safety company, to conduct automated cyber…
