Recent Blog Posts

Lorem Ipsum has been the industry's standard dummy text.

Showing posts from April, 2026Show all
ThreatsDay Bulletin: SMS Blaster Busts, OpenEMR Flaws, 600K Roblox Hacks and 25 More Stories
New Linux 'Copy Fail' Vulnerability Enables Root Access on Major Distributions
Google Fixes CVSS 10 Gemini CLI CI RCE and Cursor Flaws Enable Code Execution
Webinar: How to Automate Exposure Validation to Match the Speed of AI Attacks
LiteLLM CVE-2026-42208 SQL Injection Exploited within 36 Hours of Disclosure
Researchers Discover Critical GitHub CVE-2026-3854 RCE Flaw Exploitable via Single Git Push
VECT 2.0 Ransomware Irreversibly Destroys Files Over 131KB on Windows, Linux, ESXi
Microsoft Patches Entra ID Role Flaw That Enabled Service Principal Takeover
Checkmarx Confirms GitHub Repository Data Posted on Dark Web After March 23 Attack
Mythos Changed the Math on Vulnerability Discovery. Most Teams Aren't Ready for the Remediation Side
Fake CAPTCHA IRSF Scam and 120 Keitaro Campaigns Drive Global SMS, Crypto Fraud
FIRESTARTER Backdoor Hit Federal Cisco Firepower Device, Survives Security Patches
NASA Employees Duped in Chinese Phishing Scheme Targeting U.S. Defense Software
Tropic Trooper Uses Trojanized SumatraPDF and GitHub to Deploy AdaptixC2
UNC6692 Impersonates IT Helpdesk via Microsoft Teams to Deploy SNOW Malware
Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign
China-Linked GopherWhisper Infects 12 Mongolian Government Systems with Go Backdoors
Malicious KICS Docker Images and VS Code Extensions Hit Checkmarx Supply Chain
Harvester Deploys Linux GoGra Backdoor in South Asia Using Microsoft Graph API
Microsoft Patches Critical ASP.NET Core CVE-2026-40372 Privilege Escalation Bug
CISA Adds 8 Exploited Flaws to KEV, Sets April-May 2026 Federal Deadlines
Anthropic MCP Design Vulnerability Enables RCE, Threatening AI Supply Chain
Researchers Detect ZionSiphon Malware Targeting Israeli Water, Desalination OT Systems
Vercel Breach Tied to Context AI Hack Exposes Limited Customer Credentials
$13.74M Hack Shuts Down Sanctioned Grinex Exchange After Intelligence Claims
Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched
Newly Discovered PowMix Botnet Hits Czech Workers Using Randomized C2 Traffic
ThreatsDay Bulletin: Defender 0-Day, SonicWall Brute-Force, 17-Year-Old Excel RCE and 15 More Stories
[Webinar] Find and Eliminate Orphaned Non-Human Identities in Your Environment
n8n Webhooks Abused Since October 2025 to Deliver Malware via Phishing Emails
Actively Exploited nginx-ui Flaw (CVE-2026-33032) Enables Full Nginx Server Takeover
Microsoft Issues Patches for SharePoint Zero-Day and 168 Other New Vulnerabilities
Google Adds Rust-Based DNS Parser into Pixel 10 Modem to Enhance Security
Analysis of 216M Security Findings Shows a 4x Increase In Critical Risk (2026 Report)
ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers
North Korea's APT37 Uses Facebook Social Engineering to Deliver RokRAT Malware
OpenAI Revokes macOS App Certificate After Malicious Axios Supply Chain Incident
CPUID Breach Distributes STX RAT via Trojanized CPU-Z and HWMonitor Downloads
Citizen Lab: Law Enforcement Used Webloc to Track 500 Million Devices via Ad Data
GlassWorm Campaign Uses Zig Dropper to Infect Multiple Developer IDEs
UAT-10362 Targets Taiwanese NGOs with LucidRook Malware in Spear-Phishing Campaigns
ThreatsDay Bulletin: Hybrid P2P Botnet, 13-Year-Old Apache RCE and 18 More Stories
The Hidden Security Risks of Shadow AI in Enterprises
Shrinking the IAM Attack Surface through Identity Visibility and Intelligence Platforms (IVIP)
Anthropic's Claude Mythos Finds Thousands of Zero-Day Flaws Across Major Systems
Iran-Linked Hackers Disrupt U.S. Critical Infrastructure by Targeting Internet-Exposed PLCs
New GPUBreach Attack Enables Full CPU Privilege Escalation via GDDR6 Bit-Flips
China-Linked Storm-1175 Exploits Zero-Days to Rapidly Deploy Medusa Ransomware
Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR Tools
BKA Identifies REvil Leaders Behind 130 German Ransomware Attacks