In a significant blow to the ransomware ecosystem, Microsoft has successfully dismantled “Fox Tempest,” a sophisticated malware-signing-as-a-service (MSaaS) operation that has been fueling cybercriminal activity since at least May 2025. The takedown, codenamed “OpFauxSign,” marks a …
Category: Security
A critical security flaw has emerged in Drupal Core, potentially allowing unauthenticated attackers to execute arbitrary code on servers using PostgreSQL databases. Tracked as CVE-2026-9082, the vulnerability is a high-severity SQL injection within Drupal’s database abstraction …
NVIDIA has confirmed a data breach affecting GFN.AM, a regional Alliance partner operating GeForce NOW cloud gaming services in Armenia and surrounding territories. The breach, which occurred between March 20-26, 2026, was detected on May 2, …
The gaming industry is currently weathering a storm of high-profile security breaches, with one of the most notorious threat actors, ShinyHunters, leading a coordinated “pay or leak” extortion campaign. Among the primary targets is Rockstar Games, …
cPanel and WHM have released critical security updates addressing three vulnerabilities that could enable privilege escalation, arbitrary code execution, and denial-of-service attacks. System administrators are urged to patch immediately. The Vulnerabilities Three distinct vulnerabilities have been …
The hardest part of cybersecurity isn’t the technology—it’s the people. Every major breach you’ve read about lately usually starts the same way: one employee, one clever email, and one “Patient Zero” infection. In 2026, hackers are …
Cybersecurity researchers have discovered three packages on the Python Package Index (PyPI) repository that are designed to stealthily deliver a previously unknown malware family called ZiChatBot on Windows and Linux systems. “While these wheel packages do …
A vulnerability in the Claude extension for Chrome could allow attackers to take over the AI agent and abuse it for information theft, cybersecurity firm LayerX reports. The flaw, dubbed ClaudeBleed, is a combination of lax …
Ivanti is warning that a new security flaw impacting Endpoint Manager Mobile (EPMM) has been explored in limited attacks in the wild. The high-severity vulnerability, CVE-2026-6973 (CVSS score: 7.2), is a case of improper input validation …
Cybersecurity researchers have disclosed details of a new credential theft framework dubbed PCPJack that targets exposed cloud infrastructure and ousts any artifacts linked to TeamPCP from the environments. “The toolset harvests credentials from cloud, container, developer, …
Details have emerged about a new, unpatched local privilege escalation (LPE) vulnerability impacting the Linux kernel. Dubbed Dirty Frag, it has been described as a successor to Copy Fail (CVE-2026-31431), a recently disclosed LPE flaw that …
Cybersecurity researchers have exposed a new Mirai-derived botnet that self-identifies as xlabs_v1. This operation specifically targets internet-exposed devices running the Android Debug Bridge (ADB) to enlist them in a massive network designed for high-powered distributed denial-of-service …