CrowdStrike says The Com-affiliated threat groups are using voice phishing and fake SSO pages to break into SaaS environments and steal data fast for extortion. The post Two new extortion crews...
A new phishing kit named Bluekit offers more than 40 templates targeting popular services and includes basic AI features for generating campaign drafts. [...]
Cybersecurity researchers have disclosed details of a Linux local privilege escalation (LPE) flaw that could allow an unprivileged local user to obtain root. The high-severity vulnerability...
Vect ransomware, a new group that emerged in January 2026, has recently begun attracting attention in the cybersecurity space for its strategic partnerships, which are helping it expand. One...
GitLab security advisory (AV26-406)
Cloudflare IPsec now has generally available support for post-quantum encryption via hybrid ML-KEM. We’ve confirmed interoperability with Cisco and Fortinet.
A Romanian national who led an online swatting ring that targeted more than 75 public officials, multiple journalists, and four religious institutions was sentenced to 4 years in federal prison. [...]
Turns out the real problem is not AI but staff still clicking on dodgy emails from 'IT support'
When AI meets CI/CD: permission bypasses, prompt injection, and what to do about it.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and government partners have released a new guide to accelerate... The post New CISA guidance outlines zero trust roadmap for OT...
Healthcare organizations recorded 120 ransomware attacks in the first quarter of this year, marking a 14% decline compared... The post Comparitech assesses healthcare ransomware decline in volume...
New research from RunSafe Security highlights growing operational and clinical impact of cyber threats targeting connected healthcare technology.... The post RunSafe Index reports that healthcare...
Just in time for the Trump-Xi summit
Claroty’s threat research team, Team82, uncovered two vulnerabilities in EnOcean’s SmartServer IoT platform affecting version 4.60.009 and earlier.... The post Research finds EnOcean SmartServer...
Google has addressed a maximum severity security flaw in Gemini CLI -- the "@google/gemini-cli" npm package and the "google-github-actions/run-gemini-cli" GitHub Actions workflow -- that could...
The U.S. Federal Bureau of Investigation (FBI) warned the transportation and logistics industry of a sharp rise in cyber-enabled cargo theft, with estimated losses in the United States and Canada...
Emergency patches out now for those managing the millions of domains assumed to be affected
Northwood University has been designated as a National Center of Academic Excellence in Cybersecurity by the National Security... The post Northwood University earns NSA Cybersecurity Excellence...
Cross-site Scripting vulnerability (CVE-2026-1493) has been found in LEX Baza Dokumentów software.
A flaw in the Linux kernel present since 2017 allows a local user to gain root access on virtually every major Linux distribution. A public exploit is available and reported to work reliably.Key...
Turns out the real problem is not AI but staff still clicking on dodgy emails from 'IT support' Nearly half of UK businesses are still getting breached, and in many cases, the attacker's big...
The April 2026 KB5083769 security update breaks third-party backup applications from multiple vendors on systems running Windows 11 24H2 and 25H2. [...]
Just in time for the Trump-Xi summit Exclusive A novel China-linked threat group infiltrated more than a dozen critical networks in Poland, Asian countries, and possibly beyond, beginning in...
Researchers have reverse-engineered a piece of malware named Fast16. It’s almost certainly state-sponsored, probably US in origin, and was deployed against Iran years before Stuxnet: “…the Fast16...
Emergency patches out now for those managing the millions of domains assumed to be affected Emergency patches are available for a critical vulnerability in cPanel and WHM that allows attackers to...
This quarter, Australia and New Zealand ranked first in terms of the growth in the percentage of ICS computers on which web miners were blocked.
When a new asset goes live, attackers start scanning within minutes. Sprocket Security shows how automated attacks move from discovery to compromise in under 24 hours. [...]
Great idea, guys. Let's keep all of the data in an Excel file with weak password protection
Extremely sensitive personal data from a European celebrity that appears to have been compiled using spyware was publicly accessible until a researcher flagged the exposure.
Part 4 of 6: Aligning co-marketing for conversion