New Data Extortion Group “Pink” Goes Big Game Hunting With Evasive Phi...
New Data Extortion Group “Pink” Goes Big Game Hunting With Evasive Phishing Kits Pink Data Extortion Group is emerging as one of the latest examples of how voice phishing and data extortion continue t...
Electronic Warfare, Drones, and Cyber: Inside Modern Hybrid Warfare
Electronic Warfare, Drones, and Cyber: Inside Modern Hybrid Warfare Electronic warfare, drone warfare, and cyber operations all depend on the same foundation, the electromagnetic spectrum and the digi...
Dark Web Profile: Tengu Ransomware (Shisa)
Dark Web Profile: Tengu Ransomware (Shisa) Despite a measured public persona, Tengu Ransomware operates as a financially motivated, well-organized threat. First observed in late 2025, the group emerge...
ServiceNow Breach: Customer Data Exposed Through Unauthenticated API A...
ServiceNow Breach: Customer Data Exposed Through Unauthenticated API Access In early June 2026, ServiceNow notified impacted customers about malicious activity involving unauthorized access to custome...
Ivanti Sentry’s CVE-2026-10520 Enables Root RCE
Ivanti Sentry’s CVE-2026-10520 Enables Root RCE CVE-2026-10520 is a critical OS command injection vulnerability in Ivanti Sentry that can allow a remote, unauthenticated attacker to execute commands a...
June 2026 Patch Tuesday: 206 Vulnerabilities, Three Zero-Days Includin...
June 2026 Patch Tuesday: 206 Vulnerabilities, Three Zero-Days Including HTTP/2 Bomb Flaw (CVE-2026-49160) Microsoft released its June 2026 Patch Tuesday security updates, resolving a total of 206 vuln...
SAP Security Patch Day June 2026: Critical CVE-2026-44748 SAML Flaw Co...
SAP Security Patch Day June 2026: Critical CVE-2026-44748 SAML Flaw Could Allow Full Authentication Bypass On June 9, 2026, SAP released its monthly security updates, which included 15 new Security No...
What Do You Need to Know About Claude Fable 5?
What Do You Need to Know About Claude Fable 5? On June 9, 2026, Anthropic released Claude Fable 5, calling it the most capable model it has ever made available to the general public. For security team...
CVE-2026-11645: Exploited Chrome V8 Bug Enables In-Browser Code Execut...
CVE-2026-11645: Exploited Chrome V8 Bug Enables In-Browser Code Execution CVE-2026-11645 is a high-severity Google Chrome zero-day in the V8 JavaScript/WebAssembly engine caused by an out-of-bounds (O...
CISA KEV Highlights LiteLLM RCE (CVE-2026-42271) & Check Point VPN Aut...
CISA KEV Highlights LiteLLM RCE (CVE-2026-42271) & Check Point VPN Auth Bypass (CVE-2026-50751) CISA added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on June 8, 2026:...
Shai-Hulud Hades PyPI Campaign: 19 Packages Trojanized via Wheel Start...
Shai-Hulud Hades PyPI Campaign: 19 Packages Trojanized via Wheel Startup Hooks A PyPI supply-chain campaign in the Shai-Hulud / Mini Shai-Hulud / Miasma lineage compromised 19 Python packages by shipp...
Handala Claims It Disrupted Israeli Radar Systems: Here's What We Actu...
Handala Claims It Disrupted Israeli Radar Systems: Here’s What We Actually Know On the same day that Iran and Israel traded missile strikes in their most serious exchange since the April ceasefire, an...
2026 FIFA World Cup Threat Landscape: The Kickoff for Cybercriminals
2026 FIFA World Cup Threat Landscape: The Kickoff for Cybercriminals The fraud and threat ecosystem targeting the 2026 FIFA World Cup is already live, with thousands of phishing domains, active creden...
CVE-2026-20230: Cisco Unified CM WebDialer SSRF Can Lead to Root-Level...
CVE-2026-20230: Cisco Unified CM WebDialer SSRF Can Lead to Root-Level Compromise [Update] July 3, 2026: Cisco Confirms Active Exploitation of CVE-2026-20230 Cisco has released fixes for CVE-2026-2023...
Dark Web Profile: Vect Ransomware
Dark Web Profile: Vect Ransomware Most new ransomware operations spend their first months in the shadows, courting affiliates one at a time on closed forums. Vect did the opposite. Within four months ...
HTTP/2 Bomb: How Default Configurations Open a New DoS Vector
HTTP/2 Bomb: How Default Configurations Open a New DoS Vector A newly disclosed Denial-of-Service (DoS) technique dubbed HTTP/2 Bomb can crash or stall servers that run default HTTP/2 configurations a...
CVE-2025-48595: June 2026 Android Security Update Fixes Framework Zero...
CVE-2025-48595: June 2026 Android Security Update Fixes Framework Zero-Day Google’s June 2026 Android Security Bulletin includes a fix for an Android Framework elevation of privilege zero-day tracked ...
Top 10 Cyber Threat Actors Targeting Brazil
Top 10 Cyber Threat Actors Targeting Brazil Brazil enters the second half of 2026 as Latin America’s undisputed top cybercrime target. With a general election approaching in October 2026 and a booming...
Top 10 Dark Web Search Engines
Top 10 Dark Web Search Engines This guide compares the top Dark Web search engines active in 2026 for safer, privacy-focused research and secure access to hidden services. The Dark Web search engines ...
Top Supply Chain Risks in 2026 and Management Strategies
Top Supply Chain Risks in 2026 and Management Strategies Supply chains in 2026 are more connected, digital, and exposed than ever. Organizations now depend on software vendors, SaaS platforms, cloud p...
