AI-Powered Cyber Espionage: Inside the GTG-1002 Campaign
AI-Powered Cyber Espionage: Inside the GTG-1002 Campaign The cybersecurity world is facing a new kind of threat, AI-powered cyber espionage. The GTG-1002 campaign, uncovered between 2022 and 2025, mar...
OpenAI Notifies Users of Mixpanel Security Incident
OpenAI Notifies Users of Mixpanel Security Incident A recent security incident involving Mixpanel, a third-party analytics provider that OpenAI used to track frontend web interactions on its API platf...
Shai Hulud’s “The Second Coming": New npm Campaign Hits Zapier, ENS, P...
Shai Hulud’s “The Second Coming”: New npm Campaign Hits Zapier, ENS, Postman Security teams face yet another npm supply chain emergency. A new wave of Shai Hulud: The Second Coming. The worm has troja...
CVE-2025-61757: Oracle Identity Manager Auth Bypass Flaw Added to CISA...
CVE-2025-61757: Oracle Identity Manager Auth Bypass Flaw Added to CISA’s KEV CISA recently added CVE-2025-61757 to its Known Exploited Vulnerabilities (KEV) Catalog after confirming active exploitatio...
CVE-2025-40601: SonicOS SSLVPN Buffer Overflow Leads to Firewall Crash...
CVE-2025-40601: SonicOS SSLVPN Buffer Overflow Leads to Firewall Crash Risk, Patch Available SonicWall has disclosed a severe flaw affecting specific Gen7 and Gen8 firewalls. Identified as CVE-2025-40...
Scattered LAPSUS Hunters Escalate With New Channel and Gainsight Breac...
Scattered LAPSUS Hunters Escalate With New Channel and Gainsight Breach Scattered LAPSUS$ Hunters (SLH) has returned to the spotlight with new claims, alleged leaks, and a new Telegram channel, signal...
Cl0p’s Oracle EBS Zero-Day Campaign: What We Know So Far
Cl0p’s Oracle EBS Zero-Day Campaign: What We Know So Far The Cl0p ransomware group has returned to the spotlight with a new wave of attacks that target Oracle EBS (E-Business Suite) zero-day vulnerabi...
October 2025: Oracle Exploitation, Red Hat Incident, PhantomCaptcha, a...
October 2025: Oracle Exploitation, Red Hat Incident, PhantomCaptcha, and Major Breaches October 2025 brought forward a mix of high-impact data breaches, targeted intrusion campaigns, and continued act...
3.5 Billion WhatsApp Accounts Identified Through Enumeration
3.5 Billion WhatsApp Accounts Identified Through Enumeration A recent study by IT-security researchers at the University of Vienna and SBA Research examines the ease of identifying WhatsApp users and ...
Chrome V8 Zero-Day CVE-2025-13223 – Active Exploit Confirmed, Google I...
Chrome V8 Zero-Day CVE-2025-13223 – Active Exploit Confirmed, Google Issues Security Fix A fresh security update from Google has put Chrome users on alert. The company has patched two high-severity vu...
CVE-2025-58034: New FortiWeb Zero-Day Exploited, Enables OS Command In...
CVE-2025-58034: New FortiWeb Zero-Day Exploited, Enables OS Command Injection [Update] FortiWeb’s CVE-2025-58034 Enters CISA’s Known Exploited Vulnerabilities Fortinet has issued a new advisory confir...
IndonesianFoods Spam Campaign: What Security Teams Need To Know
IndonesianFoods Spam Campaign: What Security Teams Need To Know A large-scale campaign known as IndonesianFoods has recently gained attention for its unusual impact on the npm ecosystem. For nearly 2 ...
DDoSia Targets Denmark: Weekly DDoS Threat Intelligence
DDoSia Targets Denmark: Weekly DDoS Threat Intelligence Between November 4 and November 13, 2025, Denmark was included in a focused campaign by the pro-Russian hacktivist groups. The group published t...
Eurofiber Breach Exposes Critical Infrastructure Data Across Europe – ...
Eurofiber Breach Exposes Critical Infrastructure Data Across Europe – What You Need to Know A major supply chain breach has surfaced at Eurofiber, a core digital infrastructure provider serving thousa...
FortiWeb Path Traversal Exploit Actively Targeted: What You Need to Kn...
FortiWeb Path Traversal Exploit Actively Targeted: What You Need to Know A recent surge in attacks against Fortinet FortiWeb appliances has revealed an undocumented path traversal flaw, now formally t...
The Deepfake Threat: Chollima APT Group Uses AI Filters to Infiltrate ...
The Deepfake Threat: Chollima APT Group Uses AI Filters to Infiltrate Crypto and Web3 Companies The rapid expansion of remote work and hiring has exposed companies, particularly in high-value sectors ...
How Private AI Compute Is Redefining the Future of Secure Intelligent ...
How Private AI Compute Is Redefining the Future of Secure Intelligent Computing AI systems are becoming more capable, more personal, and more deeply integrated into daily workflows. Yet as these model...
November 2025 Patch Tuesday: Microsoft Fixes 63 Vulnerabilities, Inclu...
November 2025 Patch Tuesday: Microsoft Fixes 63 Vulnerabilities, Including Windows Kernel Zero-Day (CVE-2025-62215) Microsoft has released the November 2025 Patch Tuesday updates, resolving 63 securit...
CVE-2025-21042: Samsung Galaxy Zero-Day Exploited in LANDFALL Spyware ...
CVE-2025-21042: Samsung Galaxy Zero-Day Exploited in LANDFALL Spyware Campaign A critical security vulnerability affecting Samsung Galaxy devices, tracked as CVE-2025-21042, has been confirmed as acti...
Severe QNAP NAS Zero-Day Flaws Patched After Pwn2Own 2025: What You Sh...
Severe QNAP NAS Zero-Day Flaws Patched After Pwn2Own 2025: What You Should Know QNAP has released security updates addressing seven zero-day vulnerabilities discovered and demonstrated during Pwn2Own ...