Stay informed about the latest cybersecurity threats, vulnerabilities, malware campaigns, phishing trends, supply-chain attacks, and security advisories. This section provides timely updates and practical insights to help organizations understand emerging risks and strengthen their security posture.
Counterfeit Open VSX Extensions Harvest Developer and CI/CD Environment InformationThe discovery of 77 counterfeit extensions on the Open VSX marketplace demonstrates how attackers can exploit developer trust without immediately deploying conventional malware or stealing c…
New XCSSET Variant Turns Compromised Xcode Projects into a macOS Supply-Chain AttackThe emergence of XCSSET version 40 demonstrates how attackers are increasingly targeting software developers and the trusted development environments used to build and distribute applicatio…
CISA Adds Actively Exploited N-able, Apache Tomcat and Langflow Vulnerabilities to KEV CatalogThe addition of three vulnerabilities affecting N-able N-central, Apache Tomcat and IBM Langflow to CISA’s Known Exploited Vulnerabilities Catalog demonstrates how attackers conti…
Greatness Phishing Service Exploits RingCentral Trust to Compromise Microsoft 365 AccountsA phishing campaign impersonating RingCentral demonstrates how attackers can turn an organization’s trusted-vendor configurations into a route around email security and eventually int…
Fake Adobe and Zoom Updates Show How Attackers Abuse Trusted Software to Establish Persistent Remote AccessA series of phishing campaigns using fake Adobe Reader, Zoom, Microsoft Teams and Google Meet updates demonstrates how attackers increasingly combine familiar workpla…
Keyv-Linked npm Worm Demonstrates How Developer Credentials Can Turn One Compromise into a Software Supply-Chain EpidemicThe discovery of a self-propagating npm worm linked initially to the popular Keyv package demonstrates how quickly a compromised developer account or so…
DOUBLECUP ClickFix Service Shows How Browser Caches Are Being Turned into Malware Delivery ChannelsThe newly identified DOUBLECUP loader-as-a-service demonstrates how cybercriminals are making ClickFix attacks more scalable and difficult to detect. Instead of requiring eve…
Critical cPanel Flaw Could Allow Hosting Customers to Execute SQL with Database Root PrivilegesA newly disclosed critical vulnerability in cPanel and WebHost Manager demonstrates the significant risks created when hosting control panels fail to maintain strict separation b…
Malicious npm Packages Target Alibaba Developers with a Cross-Platform Remote-Access TrojanThe discovery of 18 malicious npm packages targeting users of Alibaba developer tools demonstrates how software supply-chain attacks are becoming more targeted, modular and capable o…
Everside Health Data Breach Highlights the Risks of Healthcare Information Stored with Third-Party VendorsThe data breach affecting Everside Health demonstrates how an organization’s cybersecurity exposure extends beyond the systems it operates directly. The incident origi…
INC Ransomware Exploitation of SonicWall SMA 1000 Flaws Shows Why VPN Appliances Must Be Treated as Critical Security InfrastructureThe emergence of INC Ransomware as the dominant threat actor exploiting vulnerabilities in SonicWall SMA 1000 appliances demonstrates how qui…
ExfilSquad Leak of UK Police Personnel Data Creates Serious Phishing and Officer-Safety RisksThe reported publication of information linked to more than 100,000 UK police officers and staff demonstrates how a data breach does not need to expose classified intelligence or c…
PNLD Data Breach Exposes Police and Criminal Justice Personnel to Targeted CyberattacksThe data breach involving the Police National Legal Database demonstrates how information that may appear relatively ordinary in isolation can create serious security risks when collecte…
PNLD Data Breach Exposes Police and Criminal Justice Personnel to Targeted CyberattacksThe data breach involving the Police National Legal Database demonstrates how information that may appear relatively ordinary in isolation can create serious security risks when collecte…
Thermo Fisher DNA Software Flaw Highlights the Critical Need to Protect Forensic Data IntegrityThermo Fisher Scientific has released security updates for a vulnerability affecting several Applied Biosystems products used by forensic and human-identification laboratories. T…
N-able N-central Attacks Show How a Compromised RMM Platform Can Become a Gateway to Entire Customer NetworksThe exploitation of vulnerabilities in N-able N-central demonstrates why remote monitoring and management platforms represent some of the most powerful and sensitiv…
Atomic macOS Stealer Campaign Shows How Attackers Turn Users into the Malware InstallerA recently analysed Atomic macOS Stealer infection demonstrates how cybercriminals are bypassing traditional software-delivery protections by persuading users to copy and execute malicio…
COLDCARD Entropy Flaw Highlights the Critical Importance of Secure Random Number Generation in Hardware WalletsA serious random-number-generation weakness discovered in COLDCARD hardware-wallet firmware has raised concerns that Bitcoin wallet seeds generated by affected de…
Adobe Campaign Classic CVSS 10.0 Vulnerability Shows Why Marketing Platforms Must Be Treated as Critical InfrastructureAdobe has released an urgent security update for a maximum-severity vulnerability affecting on-premises installations of Adobe Campaign Classic. The vulne…
Adform Script Compromise Shows How Third-Party Website Code Can Become a Cryptocurrency Theft ChannelThe compromise of a JavaScript tracking library operated by online advertising company Adform demonstrates how a single trusted third-party component can expose visitors ac…