Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
The Cl0p-linked targeting of internet-exposed PTC Windchill and FlexPLM systems highlights the growing risk around enterprise product lifecycle management platforms.PTC Windchill and FlexPLM are not ordinary web applica…
Jul 26, 2026
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
The active exploitation of the Fastjson 1.x remote code execution vulnerability highlights the serious risk created when widely used application libraries process untrusted data unsafely.Fastjson is Alibaba’s JSON libra…
Jul 26, 2026
ShinyHunters data leaks fuel $2,000 sextortion email scam
The ShinyHunters-linked sextortion scam shows how stolen breach data can be reused long after the original incident to frighten victims into paying criminals.In this campaign, scammers are sending sextortion emails that…
Jul 26, 2026
Malicious sites use JavaScript to build malware in browser memory
The campaign using JavaScript to build malware in browser memory highlights a dangerous shift in web-based malware delivery.Traditionally, many malware campaigns worked in a simple way: lure the user to a fake website, …
Jul 26, 2026
Chick-fil-A data breach affects more than 13,000 customers
The Chick-fil-A data breach is another reminder that credential stuffing remains one of the most common and effective ways attackers compromise customer accounts.The incident involved automated login attempts against Ch…
Jul 25, 2026
Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
The Certighost exploit highlights one of the most dangerous areas in enterprise identity security: Active Directory Certificate Services.Active Directory is already the control plane for most Windows enterprise environm…
Jul 25, 2026
OnTrac notifies customers of data breach after network hack
The OnTrac data breach highlights the growing risk around logistics and delivery companies, where customer data can become highly valuable for fraud, phishing, and targeted social engineering.OnTrac is a major U.S. parc…
Jul 25, 2026
Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts
The hotel Wi-Fi DNS hijacking campaign highlights a serious risk for business travelers: the network you connect to can become part of the phishing attack.Attackers are reportedly compromising Wi-Fi infrastructure at ho…
Jul 25, 2026
Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files
The Claude Cowork flaw highlights a serious and growing security issue around AI agents: once an agent can execute code, access files, connect to tools, and work across environments, its sandbox becomes a security bound…
Jul 24, 2026
Hackers abuse Notepad++ plugins to stealthily install malware
The abuse of Notepad++ plugins to install malware highlights how attackers are increasingly hiding inside trusted software workflows instead of relying only on obvious malicious executables.Notepad++ is a widely used te…
Jul 24, 2026
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
The Russian espionage campaign exploiting a Zimbra zero-day highlights how dangerous email-platform vulnerabilities can become when they are used for intelligence collection.The flaw, tracked as CVE-2025-66376, affected…
Jul 24, 2026
Fake Claude app promoted by Bing ads pushes SectopRAT malware
The fake Claude app campaign promoted through Bing ads highlights how attackers are abusing trust in both popular AI brands and search-engine advertising.Victims searching for a Claude desktop app were shown sponsored s…
Jul 24, 2026