Threat actors are actively exploiting multiple security vulnerabilities within Fortinet FortiSandbox appliances, according to a recent advisory from cybersecurity firm Defused Cyber. The firm reported observing exploitation attempts for three specific vulnerabilities, CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089, within a 24-hour period, highlighting an urgent need for organizations using these Fortinet products…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has officially added a critical security flaw affecting the LiteSpeed cPanel Plugin to its Known Exploited Vulnerabilities (KEV) catalog. This designation mandates that Federal Civilian Executive Branch (FCEB) agencies must implement the necessary patches by June 18, 2026, to mitigate the risk…
Cisco has issued urgent security updates for a critical vulnerability affecting its Catalyst SD-WAN Manager, a widely used network management platform. This medium-severity flaw, identified as CVE-2026-20262, has been observed under active exploitation in the wild, prompting immediate action from affected organizations and government agencies. The vulnerability, which carries a…
Researchers at Obsidian Security have disclosed a critical vulnerability chain (CVSS 9.9) in LiteLLM, an open-source AI gateway, that allows a low-privilege account to achieve full server takeover and execute arbitrary code. This severe flaw, impacting how LiteLLM handles virtual API keys and custom guardrails, exposes sensitive provider keys, encrypted…
A critical vulnerability in Microsoft 365 Copilot Enterprise Search, dubbed “SearchLeak” by researchers, allowed attackers to potentially exfiltrate sensitive user data, including emails and calendar details, with a single click. This discovery highlights a new attack vector chaining together existing web vulnerabilities with an AI-specific weakness. Varonis Threat Labs researchers…
The cybersecurity landscape continues to be a battleground of innovation and exploitation, with attackers consistently finding new ways to leverage existing vulnerabilities and emerging technologies. This week’s recap highlights a series of concerning trends, from actively exploited zero-days in widely used software to the sophisticated abuse of phishing kits and…
Trending
Subscribe to Updates
Get our latest news, reports, and updates directly to your inbox.
Research & Analysis
More Articles
A dangerous new Ethereum wallet threat has surfaced in the form of a malicious Chrome extension, “Safery: Ethereum Wallet.” Disguised as a legitimate cryptocurrency management tool, this extension, published on November 12, 2024, secretly harvests user seed phrases, granting attackers complete control over their digital assets. Security analysts from Socket.dev…
Black Box and Knürr GmbH will jointly introduce an innovative Integrated Mobile Command & Control Centre (IMCC) at Milipol Paris 2025. This new offering aims to enhance operational capabilities for security organizations requiring rapid deployment and robust command infrastructure in various challenging environments. The unveiling is scheduled to occur during…
Cybersecurity researchers are alerting organizations to a critical authentication bypass vulnerability discovered in Fortinet’s FortiWeb Web Application Firewall (WAF) that could grant attackers administrative control over compromised devices. The watchTowr cybersecurity firm has observed active exploitation of this flaw “in the wild,” indicating a significant and immediate threat to businesses…
Android photo frame app downloads malware, granting hackers device control without user interaction.
Millions of users are at risk due to newly discovered security flaws in popular Android photo frames. These smart devices, often marketed under brands like BIGASUO, WONNIE, and MaxAngel, automatically download and execute malware upon booting, thanks to a vulnerability within the Uhale application. This discovery, made by Quokka security…
A new and increasingly effective social engineering attack, dubbed ClickFix, is targeting both Windows and macOS users to deploy potent infostealer malware. This sophisticated technique deceives users into executing commands directly within their operating system’s command line, ultimately leading to the installation of malicious software designed to steal sensitive information.…
Parsons Corporation has announced the acquisition of new defence and security contracts exceeding $100 million, focusing on national security and border infrastructure within the Middle East. The company will provide critical programme management and design engineering services for government clients, enhancing border defence and operational security across the region. These…
Cybercriminals are leveraging the growing popularity of cryptocurrencies to deploy older, yet still potent, malware. Recent findings highlight the resurgence of the DarkComet Remote Access Trojan (RAT), now being disguised as legitimate Bitcoin-related applications. This tactic targets cryptocurrency enthusiasts who are lured into downloading tools from unverified sources, demonstrating how…
Bahrain and UAE Lead in Aviation Safety, Talent Development, and Next-Generation Mobility
The Middle East aviation sector is demonstrating a strong commitment to both nurturing local talent and spearheading innovation in next-generation air mobility. Bahrain and the UAE are at the forefront of these developments, with Bahrain promoting national professionals to leadership roles and the UAE advancing the certification of eVTOL aircraft.…
Tech experts are issuing stark warnings that proposed European Union legislation, often referred to as Chat Control, could fundamentally undermine privacy in the region by granting governments broad powers to scan personal devices for criminal activity. The potential passage of this measure, which could permit mass scanning of messages and…
Germany has reaffirmed its opposition to a European Union proposal that would mandate the scanning of digital devices for child sexual abuse material before encryption is applied. Federal Minister of Justice Stefanie Hubig stated that mass scanning of private messages is unacceptable in a constitutional state and that Germany will…
Voting rights groups seek court intervention to halt Trump administration’s SAVE database overhaul.
Voting rights advocacy groups have filed a lawsuit seeking to halt a Trump administration initiative that consolidates federal and state voter data into a comprehensive citizenship and voter fraud database. The coalition argues this initiative violates decades-old privacy laws. Last week, the League of Women Voters, the Electronic Privacy Information…
Cybercriminals are increasingly exploiting remote monitoring and management (RMM) tools, including popular solutions like LogMeIn and PDQ Connect, to distribute malware inconspicuously. This sophisticated attack campaign deceives users into downloading malicious payloads disguised as legitimate software updates or popular applications, granting attackers unfettered access to their systems while evading traditional…
