AryStinger botnet infected thousands of D-Link routers worldwide
AryStinger has compromised at least 4,300 legacy routers, primarily D-Link DIR-850L and DIR-818LW devices, using vulnerabilities dating back as far as 2013. Unlike many conventional IoT botnets focused mainly on denial-…
Jun 22, 2026
Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chain
The disclosure of the USBLighter8 exploit demonstrates that even the earliest and most trusted stages of a modern device’s boot process can be undermined by a flaw built into the hardware.USBLighter8 targets Apple’s Sec…
Jun 20, 2026
Texas govt data breach exposes over 3 million driver’s licenses
The Texas Parks and Wildlife Department data breach demonstrates how a compromise at a third-party service provider can expose millions of government records without attackers necessarily breaching the government agency…
Jun 20, 2026
Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin
The active exploitation of an information-disclosure vulnerability in the Gravity SMTP WordPress plugin demonstrates how a flaw that does not directly provide code execution can still create serious security exposure.Th…
Jun 20, 2026
CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure
CISA’s warning that a critical Splunk Enterprise vulnerability is being actively exploited should be treated as an urgent security event, particularly because Splunk often occupies one of the most trusted and informatio…
Jun 19, 2026
Telegram admits it couldn't police exam-leak channels, India tells court
India’s temporary restriction of Telegram over alleged examination-leak and fraud channels highlights the difficult balance between platform accountability, public safety, examination integrity, and the rights of millio…
Jun 19, 2026
Klue OAuth breach linked to 'Icarus' Salesforce data theft attacks
The Klue OAuth breach demonstrates how third-party SaaS integrations can become a highly effective route into enterprise cloud data. Instead of compromising each affected organization individually, attackers gained acce…
Jun 19, 2026
USB worm spreads crypto-stealing malware via Windows shortcut files
The discovery of a USB-spreading malware campaign targeting cryptocurrency users demonstrates that removable media remains an effective attack channel, even in an era dominated by cloud applications, phishing emails, an…
Jun 19, 2026
F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution
F5’s disclosure of two critical vulnerabilities in NGINX Open Source highlights the security risks created when widely deployed web infrastructure handles modern HTTP protocols under unusual or attacker-controlled condi…
Jun 19, 2026
Nintendo confirms data stolen in WebMD subsidiary cyberattack
The Nintendo data breach linked to the compromise of the TinyPulse employee survey platform demonstrates how third-party services can expose an organization even when its own systems remain secure.Nintendo of America co…
Jun 19, 2026
Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline
The comment below is based on the reported 33-day intrusion into a small French automotive business, during which the attacker used in-memory malware, a keylogger, scheduled tasks, RustDesk, OpenSSH, and Tailscale to ma…
Jun 17, 2026
Kodak confirms data breach claimed by ShinyHunters extortion gang
Kodak’s confirmation of unauthorized access to company data highlights the continuing shift from traditional ransomware toward data theft and extortion. In these attacks, cybercriminals may not need to encrypt systems o…
Jun 17, 2026