Iranian cyber espionage disguised as a Chaos Ransomware attack

1 month ago

Iran-linked APT MuddyWater used ransomware-style tactics to mask espionage, combining phishing, credential theft, data exfiltration, and extortion without encryption. A…

Apache fixes critical HTTP/2 double-free flaw CVE-2026-23918 enabling RCE

1 month ago

Apache fixed several flaws in HTTP Server, including CVE-2026-23918 (CVSS score of 8.8), a double-free bug in HTTP/2 that could…

Palo Alto Networks PAN-OS flaw exploited for remote code execution

1 month ago

Palo Alto Networks warns of a critical PAN-OS flaw (CVE-2026-0300) that is under active attack, allowing unauthenticated remote code execution.…

Malicious PyTorch Lightning update hits AI supply chain security

1 month ago

A malicious PyTorch Lightning update (v2.6.3) on PyPI spread briefly, stealing credentials and raising major concerns about AI supply chain…

U.S. court sentences Karakurt ransomware negotiator to 8.5 years

1 month ago

Deniss Zolotarjovs was sentenced to 8.5 years in the U.S. after pleading guilty to money laundering and fraud tied to…

Vimeo confirms breach via third-party vendor impacts 119K users

1 month ago

Hackers stole data of 119,000 Vimeo users in April. The breach, linked to a third‑party vendor, exposed personal details. Vimeo…

Critical Android vulnerability CVE-2026-0073 fixed by Google<gwmw style="display:none;"></gwmw><gwmw style="display:none;"></gwmw>

1 month ago

Google patched a critical Android flaw (CVE‑2026‑0073) that lets attackers run code remotely without user action. Google released a security…

Microsoft warns of global campaign stealing auth tokens from 35K users

1 month ago

Microsoft revealed a phishing campaign hitting 35,000 users in 26 countries, stealing login tokens via fake code-of-conduct emails and legit…

Educational tech firm Instructure data breach may have impacted 9,000 schools

1 month ago

Instructure, maker of the Canvas learning platform, is investigating a cyber incident that exposed users’ personal data. Instructure is a U.S.-based…

MOVEit automation flaws could enable full system compromise

1 month ago

Progress fixes critical MOVEit Automation flaws, including an authentication bypass bug that could let attackers gain unauthorized access to systems.…

This website uses cookies.