Fake IT support calls on Microsoft Teams push EtherRAT malware
The fake IT-support campaign abusing Microsoft Teams shows how attackers are shifting from email phishing to direct social engineering through trusted collaboration platforms.Threat actors impersonate corporate IT suppo…
Jul 07, 2026
Medtronic notifies customers impacted by ShinyHunters data breach
The Medtronic data breach highlights the serious and long-lasting consequences of exposing personal and health-related information.The incident involved unauthorized access to certain corporate IT systems and may have e…
Jul 03, 2026
SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation
CISA’s addition of CVE-2026-45659 to its Known Exploited Vulnerabilities catalogue confirms that attackers are actively exploiting the Microsoft SharePoint flaw in real environments.
The vulnerability affects on-prem…
Jul 03, 2026
CISA: Microsoft SharePoint RCE flaw now actively exploited
The active exploitation of CVE-2026-45659 highlights the continuing risk posed by vulnerabilities in on-premises Microsoft SharePoint environments.The flaw results from unsafe deserialization and can allow an attacker w…
Jul 03, 2026
Cisco finally confirms attackers exploiting Unified CM flaw
Cisco’s confirmation that attackers are actively exploiting CVE-2026-20230 makes patching affected Unified Communications Manager systems an immediate priority.The vulnerability affects Cisco Unified CM and Unified CM S…
Jul 03, 2026
ST Engineering iDirect iQ-Series Terminals
CISA’s advisory on ST Engineering iDirect iQ-Series satellite terminals highlights the operational risk created when device-management interfaces expose sensitive information or permit unauthorized actions.The vulnerabi…
Jul 03, 2026
ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API
The Umbrij malware linked to the ToddyCat threat group demonstrates how attackers can abuse legitimate OAuth authorization processes to gain persistent access to corporate Gmail accounts.Umbrij takes control of an activ…
Jul 03, 2026
What the Numbers Say About FIFA 2026 Cyber Risk
The cyber activity surrounding the FIFA World Cup 2026 shows how attackers prepare fraud infrastructure months before a major global event begins.More than one-third of official tournament partners were reportedly unabl…
Jul 01, 2026
Malicious PyPI packages give hackers control of Telegram bot servers
The discovery of malicious PyPI packages targeting Telegram bot developers highlights the growing risk of installing unofficial forks of popular open-source libraries.The campaign, known as Operation Navy Ghost, used at…
Jul 01, 2026
Adobe patches seven max severity ColdFusion, Campaign flaws
Adobe’s release of emergency security updates for ColdFusion and Campaign Classic highlights the risk posed by critical vulnerabilities in internet-facing application and marketing platforms.Six ColdFusion vulnerabiliti…
Jul 01, 2026
Citrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-Service
Citrix’s disclosure of six vulnerabilities in NetScaler ADC and NetScaler Gateway highlights the continuing security risks associated with internet-facing application delivery and remote-access appliances.The flaws incl…
Jul 01, 2026
Azure CLI Password Spray Hits at Least 78 Microsoft Accounts in 81M+ Attempts
The large-scale Azure CLI password-spraying campaign demonstrates how incomplete multifactor authentication and Conditional Access policies can leave cloud accounts exposed despite appearing secure.Between June 12 and J…
Jul 01, 2026