Threat actors are actively exploiting multiple security vulnerabilities within Fortinet FortiSandbox appliances, according to a recent advisory from cybersecurity firm Defused Cyber. The firm reported observing exploitation attempts for three specific vulnerabilities, CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089, within a 24-hour period, highlighting an urgent need for organizations using these Fortinet products…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has officially added a critical security flaw affecting the LiteSpeed cPanel Plugin to its Known Exploited Vulnerabilities (KEV) catalog. This designation mandates that Federal Civilian Executive Branch (FCEB) agencies must implement the necessary patches by June 18, 2026, to mitigate the risk…
Cisco has issued urgent security updates for a critical vulnerability affecting its Catalyst SD-WAN Manager, a widely used network management platform. This medium-severity flaw, identified as CVE-2026-20262, has been observed under active exploitation in the wild, prompting immediate action from affected organizations and government agencies. The vulnerability, which carries a…
Researchers at Obsidian Security have disclosed a critical vulnerability chain (CVSS 9.9) in LiteLLM, an open-source AI gateway, that allows a low-privilege account to achieve full server takeover and execute arbitrary code. This severe flaw, impacting how LiteLLM handles virtual API keys and custom guardrails, exposes sensitive provider keys, encrypted…
A critical vulnerability in Microsoft 365 Copilot Enterprise Search, dubbed “SearchLeak” by researchers, allowed attackers to potentially exfiltrate sensitive user data, including emails and calendar details, with a single click. This discovery highlights a new attack vector chaining together existing web vulnerabilities with an AI-specific weakness. Varonis Threat Labs researchers…
The cybersecurity landscape continues to be a battleground of innovation and exploitation, with attackers consistently finding new ways to leverage existing vulnerabilities and emerging technologies. This week’s recap highlights a series of concerning trends, from actively exploited zero-days in widely used software to the sophisticated abuse of phishing kits and…
Trending
Subscribe to Updates
Get our latest news, reports, and updates directly to your inbox.
Research & Analysis
More Articles
Researchers have demonstrated that sensitive data, including personal communications and operational details, can be intercepted from U.S. military and commercial organizations by passively scanning unencrypted satellite transmissions. The study, conducted by scientists from the University of Maryland and the University of California, San Diego, utilized approximately $600 worth of commercially…
WhatsApp has secured a permanent injunction prohibiting spyware maker NSO Group from targeting its users, a significant win for the messaging giant. However, the same court ruling dramatically reduced the punitive damages previously awarded to WhatsApp against NSO Group. Two key developments emerged from a Northern California District Court late…
Google has filed a lawsuit against a sophisticated criminal operation known as “Lighthouse,” a phishing-as-a-service platform responsible for widespread scams that have affected over one million individuals across more than 120 countries. This development highlights the increasing organization of cybercriminals and their deployment of large-scale, brand-imitating attacks to steal sensitive…
A nonprofit organization has filed a formal complaint with the Federal Trade Commission, alleging that Google’s practices concerning children and teenagers violate U.S. privacy laws and constitute unfair and deceptive business conduct. The Digital Childhood Institute’s complaint outlines several core claims against the tech giant, focusing on its operations within…
As the cybersecurity landscape evolves, organisations are wrestling with the challenges of advanced technology and the increasing human factors that contribute to security breaches. AI-driven security tools, cloud services, mobile applications, and enhanced incident response capabilities are now integral to organisational security strategies. However, the rapid adoption of new technologies…
Successor to Hacking Team linked to malware campaign, new ‘Dante’ commercial spyware uncovered
Kaspersky researchers have identified a sophisticated malware campaign, dubbed Operation ForumTroll, targeting various organizations in Russia. This campaign is linked to Memento Labs, the successor company to the notorious surveillance technology firm Hacking Team. Alongside the campaign, researchers also discovered a new commercial spyware product developed by Memento Labs. Operation…
The Python Software Foundation (PSF) has announced it will reject a $1.5 million federal grant from the National Science Foundation (NSF) due to contract stipulations regarding diversity, equity, and inclusion (DEI) initiatives. The foundation stated that the terms imposed by the administration would restrict its broader operational activities beyond the…
A sophisticated new commercial-grade spyware, dubbed “Landfall,” has been discovered targeting Samsung Galaxy phones, primarily in the Middle East. Researchers from Palo Alto Networks’ Unit 42 revealed the finding in a blog post on Friday, highlighting the exploit’s use of a previously unknown zero-day vulnerability that has since been patched…
A new whitepaper from the Electronic Privacy Information Center (EPIC) asserts that federal agencies are increasingly employing sophisticated and invasive data mining techniques, raising significant privacy concerns. The report argues that the widespread use of automated systems to analyze and connect vast amounts of data on Americans poses a substantial…
Odyssey Cybersecurity has expanded its operations in Saudi Arabia with the inauguration of new data centres in Riyadh and Dammam, alongside a state-of-the-art Security Operations Centre (SOC). This strategic expansion, powered by Odyssey’s ClearSkies™ Centric AI platform, aims to enhance the Kingdom’s cyber defence capabilities amidst a growing landscape of…
MastaStealer Exploits Windows LNK Files to Execute PowerShell Commands and Evade Defender
A newly identified cyber threat campaign is actively exploiting Windows LNK shortcut files to distribute the MastaStealer infostealer. This multifaceted attack begins with targeted spear-phishing emails that ensnare unsuspecting users with ZIP archives containing a single LNK file. Upon interaction, this malicious shortcut initiates a complex, multi-stage infection process designed…
The Nasser Centre for Science and Technology (NCST), in partnership with the National Cyber Security Centre (NCSC), has officially inaugurated a new Cybersecurity Lab at its facility in Khalifa City, Bahrain. This development is a significant step in the Kingdom’s ongoing commitment to strengthening its digital defenses and cultivating a…
