FortiGuard Labs analyzes Evooo1Bot, a modular Linux botnet targeting internet-facing devices with DDoS, SSH attacks, CVE exploits, and SOCKS relays
GitLab 19.2.2 Patches 13 Security Flaws, Including High-Severity XSS and CI/CD Authorization Flaws
GitLab has released security updates for Community Edition and Enterprise Edition, addressing 13 vulnerabilities affecting analytics dashboards, CI/CD…
Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection
Project CAV3RN targets Israel with Google Apps Script C2 relays and DNS-based routing. Modular .NET NativeAOT framework blends C2 traffic with legitimate…
Keep Your Tech FLAME Alive: Trailblazer Suzanne Wheeler
In this Akamai FLAME Trailblazer blog post, Suzanne Wheeler describes her journey into cybersecurity and gives advice to women who are finding their own…
RingCentral – 1,596,490 breached accounts
In July 2026, the cloud-based business communications platform RingCentral was the target of a ShinyHunters “pay or leak” extortion campaign . The group…
Kimwolf v7: An Evolution of the Kimwolf Botnet
Discover how Kimwolf v7 targets Android IoT devices with HTTP/2 DDoS fingerprinting, Ethereum ENS C2 resolution and Tor backup routing.
US Court Gives Go-Ahead To Thousands Of Social Media Cases
Thousands of addiction lawsuits against social media giants to proceed in California federal court after legal challenge dismissed
RingCentral breach: 1.6M accounts exposed
Cloud-based business communications provider RingCentral suffered a data breach in July 2026 after falling victim to an extortion campaign by the…
Levi Strauss & Co. Confirms Hackers Stole Corporate Data in Cyberattack
Levi Strauss & Co. (Levi’s) has announced a cybersecurity incident involving an unauthorized third party who used social engineering to access the…
Attackers exploit critical SharePoint flaw after PoC goes public (CVE-2026-55040)
Threat actors have begun exploiting a critical Microsoft SharePoint flaw following the release of proof-of-concept (PoC) exploit code by Rapid7. About…
Microsoft’s August Patch Tuesday: 400+ Bugs Fixed, One Zero-Day Already Under Attack
Microsoft’s August Patch Tuesday fixes about 400 security flaws, including an actively exploited Windows zero-day and multiple 9.8-rated RCE bugs.
CISA Warns of Windows Ancillary Function 0-Day Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency has added a Microsoft Windows vulnerability to its Known Exploited Vulnerabilities Catalog,…
SharePoint CVE-2026-55040 Under Active Exploit
A critical authentication bypass vulnerability in Microsoft SharePoint Server Subscription Edition is under active exploitation following the public…
Hackers Leveraging GoogleWorkspace Accounts to Send Phishing and Scam Emails
Hackers are turning compromised Google Workspace accounts into tools for phishing and scam emails. The messages can look ordinary because they come from…
CBTS launches continuous penetration testing service
CBTS has launched a new Penetration Testing as a Service (PTaaS) offering that provides continuous security assessment capabilities for enterprise…
Jewelbug APT Hijacks Browsers to Steal Cookies and Spy on Government Networks
Jewelbug has turned ordinary web browsing into an entry point for espionage. The China-based group compromised government webmail systems, stole browser…
Cisco sees network refresh surge from AI vulnerability disco
Cisco is experiencing a surge in network equipment sales as customers rush to replace unsupported devices following the emergence of Anthropic’s Mythos AI…
Armored Likho Still Toolkit Steals Telegram Sessions and Records Victims’ Conversations
A cyber-espionage operation linked to Armored Likho is using a convincing donation app to reach people and organizations in Russia. Once opened, the fake…
Twitch AI training opt-out enabled by default
Twitch has rolled out a new privacy control that allows streamers to prevent their channel content from being used to train Amazon’s generative AI models,…
The Model Is the Malware | What Four Agentic Intrusions Tell Defenders
OpenAI, Anthropic and Meta disclosed agents reaching external systems. The tools didn’t matter, and that changes the playbook for investigating intrusions.
Microsoft Exchange Server Vulnerabilities Allow DoS, Privilege Escalation, and RCE
Microsoft has released security updates that address six vulnerabilities in Exchange Server. These vulnerabilities include flaws that could allow remote…
WordPress 7.0.4 Patches Remote Code Execution Vulnerability
Attackers with Author-level user or higher permissions could exploit the flaw via malicious Postscript files.
Senior Police Detective Probed Over AI Use
Senior police detective in Derbyshire investigated by IOPC over alleged gross misconduct related to AI use
Ransomware Didn’t Slow Down in Q2 2026. It Just Spread Out.
Ransomware kept its grip on organizations through the second quarter of 2026, and the headline number barely moved. What changed underneath that number is…