Attack volumes are back to pre-disruption levels, and the adversary tactics have remained unchanged.
Hi, what are you looking for?
Attack volumes are back to pre-disruption levels, and the adversary tactics have remained unchanged.
CVE-2026-21992 can be used without authentication for remote code execution and it may have been exploited in the wild.
The vulnerability is tracked as CVE-2025-32975 and it may have been exploited in attacks against the education sector.
Other noteworthy stories that might have slipped under the radar: vulnerabilities found in KVM devices, Claudy Day Claude vulnerabilities, The Gentlemen ransomware group.
The men violated U.S. export controls laws by scheming to divert massive quantities of the high-performance servers assembled in the United States to China.
The company will use the investment to expand its platform’s capabilities and grow channel partnerships.
The US has seized several domains used by Handala in cyber-enabled psychological operations.
Cape offers a privacy-focused mobile virtual network operator (MVNO) service for consumers, enterprises, and governments.
Between late December 2025 and mid-January 2026, hackers stole personal and health plan information from Navia’s environment.
The attacks started on February 27 and have targeted e-commerce platforms, global brands, and government services.
The company will invest in expanding its digital brand protection platform and in scaling its go-to-market efforts.
Because attacker-supplied flow data is used in public flows, the bug leads to unauthenticated remote code execution.
The lesser-known JackSkid and Mossad botnets have also been targeted in the operation.
The company will invest in R&D, product expansion across AI frameworks, and in scaling go-to-market and sales efforts.
The company’s endpoint security platform monitors behavior and verifies user intent to stop cyberattacks in real time.
Latest ScreenConnect version adds encrypted storage and management to prevent unauthorized access to machine keys.
Cloaked plans to introduce AI agents designed to act on behalf of users to monitor, manage, and enforce privacy preferences and security postures.
Analysis reveals a six-month buildup of Iran-linked cyber infrastructure, including US-based shell companies, designed to weather kinetic strikes and ensure the resilience of its global hacking operations.
It was previously estimated that more than 1.6 million people may be affected by the Marquis data breach.
The information was stolen from a marketing tool after an employee fell victim to a targeted phone phishing attack.