A China-linked cybercrime group, tracked as TA4922, has significantly escalated its global operations in 2026. After years of focusing on East Asian targets, the group is now actively phishing organizations across the United Kingdom, Germany, Italy, …
Category: Security
Cisco has released critical security updates for Cisco Unified Communications Manager (Unified CM) and Unified CM Session Management Edition (SME) to address a severe server-side request forgery (SSRF) vulnerability. Tracked as CVE-2026-20230, the flaw has reached …
A critical security vulnerability, tracked as CVE-2026-3300, has been actively exploited in the Everest Forms Pro WordPress plugin. The flaw allows unauthenticated attackers to achieve complete site takeover through Remote Code Execution (RCE), posing a severe …
The U.S. Department of Justice announced a major disruption of cyber-enabled cryptocurrency fraud networks operating out of Southeast Asia, resulting in the voluntary freezing of over $3.8 million in assets. The operation, part of “Disruption Week” …
In a striking demonstration of modern cyber espionage, hackers maintained undetected access to a senior stock exchange executive’s Outlook mailbox for five consecutive months. This breach, spanning from October 2025 to March 2026, highlights critical vulnerabilities …
A sophisticated and large-scale malware campaign is actively exploiting the trust developers place in open-source software. By creating highly convincing fake websites for popular tools and manipulating Google search rankings through SEO poisoning, threat actors are …
In a landmark international cybersecurity operation, the Dutch National Police and the National Cyber Security Centre (NCSC) have successfully dismantled one of the largest botnet infrastructures ever recorded. The operation, concluded in late May 2026, disrupted …
A critical Remote Code Execution (RCE) vulnerability, designated CVE-2026-40933, has been disclosed in Flowise, a widely adopted open-source platform for building Large Language Model (LLM) workflows and AI agents. With a near-perfect CVSS score of 9.9, …
In a significant escalation of cybercriminal activity targeting telecommunications infrastructure, the notorious ShinyHunters data extortion group has leaked what it claims to be 42 million customer records from Charter Communications, one of the largest broadband providers …
In a startling display of automated aggression, a supply chain attack dubbed “Megalodon” has infected over 5,500 GitHub repositories in a single six-hour window. Discovered by cybersecurity researchers at SafeDep on May 18, 2026, this campaign …
DocketWise, a widely used immigration and legal case management platform, has confirmed a significant data breach impacting over 143,000 users. The incident, discovered in October 2025, highlights critical vulnerabilities in third-party data migration pipelines and poses …
For decades, typosquatting was seen as a “user error.” It was the digital equivalent of a wrong turn—a user mistyping a URL, landing on a phishing site, and falling for a scam. But in 2026, the …