RoguePlanet threat actor weaponizes Windows kernel zero-day to bypass Microsoft Defender. Critical vulnerability affects all unpatched Windows 10/11 systems. Emergency patch KB5026026 released. …
Category: Security
What is the “Best Evidence Rule” in Philippine Digital Forensics? The Core Challenge: In traditional law, the “original” document is king. But in the digital world, what is an “original”? If I email you a PDF, …
What State-Sponsored Threats Target Technology Sector? Primary Adversary: China-nexus hacking groups Target: Artificial Intelligence intellectual property Market Share: 58% of all state-sponsored intrusions against tech companies CrowdStrike’s 2026 Global Threat Landscape Report identifies Chinese state-sponsored actors …
What North Korean Hacking Groups Are Stealing Billions? Primary Group: FAMOUS CHOLLIMA (DPRK state-sponsored) Total Theft: $2.02 billion in digital assets (2025) Market Share: 47% of all state-sponsored tech intrusions North Korean state-sponsored hacking operations have …
Microsoft’s June 2026 Patch Tuesday has broken records, addressing a staggering 200 security flaws across its product ecosystem. Among these vulnerabilities are three publicly disclosed zero-day exploits and one actively exploited zero-day that was previously patched …
A critical authentication bypass vulnerability in Check Point’s VPN and firewall products is being actively exploited in the wild, with confirmed links to Qilin ransomware attacks. The flaw, tracked as CVE-2026-50751, has prompted emergency warnings from …
Google has released emergency security patches for Chrome to address a critical zero-day vulnerability actively exploited in the wild, marking the fifth Chrome zero-day of 2026. The flaw, tracked as CVE-2026-11645, affects the browser’s V8 JavaScript …
Opal Security, a San Francisco-based pioneer in AI-native identity governance, has secured $23 million in a new funding round led by Greylock and Battery Ventures, with participation from Cambium Capital. The investment brings the company’s total …
The Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity SolarWinds Serv-U Denial-of-Service (DoS) vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog following confirmed evidence of active exploitation. The directive requires Federal Civilian Executive Branch …
In what marks the most significant escalation of an ongoing supply chain campaign, the self-replicating Miasma worm compromised 73 Microsoft GitHub repositories on June 5, 2026. The attack targeted four critical organizations: Azure, Azure-Samples, Microsoft, and …
Microsoft Threat Intelligence has warned that vulnerabilities in Anthropic’s Claude Code, an AI-powered coding assistant, could allow attackers to steal credentials from GitHub, Microsoft 365, and Azure environments. The disclosure highlights a growing class of supply-chain …
A sophisticated threat actor known as PCPJack has established a large-scale covert email relay network by hijacking over 230 cloud servers across Amazon Web Services (AWS), Google Cloud, and Microsoft Azure. The operation was exposed in …
Dashlane has provided a detailed explanation of a recent security incident where attackers managed to download encrypted password vaults from a small number of user accounts. The breach, which began on May 31, 2026, highlights both …