North Korean hacking groups have stolen approximately $577 million in cryptocurrency through just two attacks in 2026—accounting for a staggering 76% of all crypto hack losses year-to-date, according to a new analysis from TRM Labs. The …
Category: Security
Two American cybersecurity professionals have been sentenced to prison for abandoning their defensive roles to assist a notorious ransomware gang, marking a disturbing case of insider betrayal in the security industry. Sentencing Details Ryan Goldberg of …
This week’s cybersecurity news roundup covers major developments ranging from international sanctions and hacker arrests to critical vulnerabilities affecting industrial networks and developer tools. OFAC Sanctions Iranian Central Bank Crypto Reserves The U.S. Office of Foreign …
A newly discovered phishing kit called Bluekit is raising concerns in the cybersecurity community due to its advanced features, including an integrated AI assistant that helps attackers craft phishing campaigns. What Is Bluekit? Bluekit is a …
Microsoft Security Blog has disclosed CVE-2026-31431, nicknamed “Copy Fail,” a high-severity local privilege escalation vulnerability in the Linux kernel that affects major distributions including Red Hat, SUSE, Ubuntu, and AWS Linux—potentially impacting millions of cloud workloads …
Hosting providers and website owners using cPanel are facing a catastrophic ransomware campaign that has already encrypted thousands of Linux servers worldwide. The attackers behind the “Sorry” ransomware family have weaponized a critical zero-day vulnerability (CVE-2026-41940) …
A critical authentication bypass vulnerability in cPanel and WHM is being actively exploited in the wild, granting attackers full root-level access to vulnerable servers. The flaw, tracked as CVE-2026-41940, carries a CVSS score of 9.8 and …
What Happened On April 29, 2026, Aftermath Finance—a leading decentralized exchange on the Sui Network—suffered a security exploit that drained approximately $1.14 million in USDC from its Perpetual Futures (PERP) trading vaults. The attacker executed 11 …
A critical remote code execution vulnerability discovered in GitHub’s infrastructure has put millions of repositories at risk of unauthorized access and manipulation. The flaw, tracked as CVE-2026-3854, allows any authenticated GitHub user to execute arbitrary commands …
In what has become the most controversial blockchain security incident of April 2026, the Kelp DAO LayerZero bridge was exploited for $292 million in rsETH tokens. The attack didn’t target a smart contract bug—it deceived the …
Elon Musk’s xAI is facing mounting legal pressure after Switzerland’s finance minister filed a lawsuit against the company over Grok’s generation of sexually explicit deepfake images. The scandal has triggered investigations across Europe and the United …
Bitwarden CLI Compromised in Supply Chain Attack In a shocking supply chain incident, the official Bitwarden command-line interface package (@bitwarden/cli) was hijacked for approximately 90 minutes, exposing users who installed or updated during the window to …