Stay informed about the latest cybersecurity threats, vulnerabilities, malware campaigns, phishing trends, supply-chain attacks, and security advisories. This section provides timely updates and practical insights to help organizations understand emerging risks and strengthen their security posture.
The Novo Nordisk security breach highlights how cyberattacks on the healthcare and pharmaceutical sector are no longer limited to disrupting operations. They now directly target sensitive research, clinical trial data, patient-related information, and intellectual property. Ac…
The compromise of over 400 Arch Linux AUR packages is another reminder that the software supply chain has become one of the easiest ways for attackers to enter trusted environments. In this case, malicious packages were reportedly used to deliver an infostealer with rootkit ca…
DentaQuest Breach Highlights the Risk of Healthcare Data ExposureThe DentaQuest data breach reportedly exposed information linked to 2.6 million accounts after the extortion group ShinyHunters claimed to have stolen more than 234 GB of data. DentaQuest, a major dental b…
CISA Adds Exploited SolarWinds Serv-U Flaw to KEV CatalogCISA has added a SolarWinds Serv-U vulnerability, tracked as CVE-2026-28318, to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. The flaw affects SolarWinds Serv-U multi-protocol …
AI Finds 21 Zero-Days in FFmpeg: The Security Game Has ChangedAn AI agent has reportedly uncovered 21 previously unknown vulnerabilities in FFmpeg, one of the most widely used open-source multimedia frameworks. FFmpeg is embedded across browsers, media players, video pl…
Miasma Worm Hits Microsoft GitHub Repositories: A New Warning for AI-Assisted DevelopmentThe Miasma self-replicating worm has reportedly impacted 73 Microsoft GitHub repositories across Azure, Azure-Samples, Microsoft, and MicrosoftDocs. GitHub disabled access to the af…
Exposed Tank Gauge Systems Show Why OT Security Cannot Be an AfterthoughtMore than 900 automatic tank gauge systems in the United States were reportedly found exposed online, leaving fuel and chemical storage monitoring systems vulnerable to attack. These systems are us…
OP-512 Targets Microsoft IIS Servers with Custom Web Shell FrameworkA newly reported threat cluster called OP-512 has been observed targeting Microsoft IIS servers using a custom web shell framework. The activity is linked to China-aligned cyber espionage operations and…
Suspicious Polyfill Login Prompts on Toshiba and MUJI Websites: A Supply Chain Warning Without a Full Breach## What happenedVisitors to some Toshiba and MUJI websites recently saw unexpected browser login prompts generated through the external `polyfill.io` service.…
Comment: Hola Browser Compromise Shows Why Software Trust Must Be Earned ContinuouslyThe compromise of Hola Browser for Windows is a useful reminder that software supply chain risk is not limited to developer tools, npm packages, or enterprise servers. Even a consumer b…
Cisco SD-WAN Zero-Day Attacks Show the Risk of Compromised Network Control PlanesCisco has warned that a critical Catalyst SD-WAN vulnerability, tracked as CVE-2026-20182, has been exploited in zero-day attacks. The flaw affects Cisco Catalyst SD-WAN Controller, formerl…
Everest Forms Pro Flaw Exploited to Take Over WordPress SitesAttackers are actively exploiting a critical vulnerability in the Everest Forms Pro WordPress plugin, tracked as CVE-2026-3300. The flaw has a CVSS score of 9.8 and affects all versions up to and including 1.9…
FIFA World Cup 2026 Scams Are Already LiveCybercriminals have already started exploiting the excitement around the FIFA World Cup 2026 through fake websites, phishing pages, fraudulent ticket offers, counterfeit merchandise, fake streaming apps, and stolen login campaig…
Google Fixes Actively Exploited Android Zero-Day and 124 Security FlawsGoogle has released the June 2026 Android security updates, fixing 124 vulnerabilities, including one actively exploited zero-day tracked as CVE-2025-48595. The flaw affects the Android Framework and…
CISA Orders Federal Agencies to Patch Exploited Oracle WebLogic FlawCISA has added an Oracle WebLogic Server vulnerability, tracked as CVE-2024-21182, to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. The flaw was originally patched b…
WeedHack Malware Campaign Targets Minecraft Players at ScaleA large-scale malware campaign called WeedHack has reportedly infected more than 116,000 Minecraft systems since January 2026. According to BleepingComputer, the malware is being distributed through Minecraft-r…
Critical Kirki Flaw Exploited to Hijack WordPress Admin AccountsHackers are actively exploiting a critical privilege escalation vulnerability in the Kirki plugin for WordPress, tracked as CVE-2026-8206. The flaw affects Kirki versions 6.0.0 through 6.0.6 and allows unau…
HTTP/2 Bomb Vulnerability: Small Requests, Big Denial-of-Service ImpactSecurity researchers have disclosed a new remote denial-of-service technique called HTTP/2 Bomb, affecting major web servers and infrastructure components including NGINX, Apache HTTPD, Microsoft IIS…
Unpatched Windows Search URI Issue Can Leak NTLMv2 HashesSecurity researchers have disclosed an unpatched Windows Search URI issue that could allow attackers to steal a user’s NTLMv2 hash. According to The Hacker News, the issue affects the `search:` URI handler and can…
Acer Wave 7 Router Zero-Days: When the Network Gateway Becomes the Weak LinkAcer has warned about two maximum-severity vulnerabilities affecting its Wave 7 routers running firmware version T7c_GBL_1.01.000055 or earlier. Both flaws received a critical severity score of …