A swarm of AI agents attributed by researchers to OpenAI flooded RubyGems with more than 2,000 packages in May 2026, abused RubyDoc.info’s documentation…
Category: Cyber Security News
CISA Warns of GitLab Path Traversal Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab vulnerability, tracked as CVE-2026-85706, to its Known…
New KATARU IoT Malware Packs Linux Privilege Escalation Exploits and Mirai-Style DDoS Attacks
KATARU is a newly observed IoT malware strain that can turn poorly secured devices into DDoS attack nodes. The sample was captured after an attacker used…
Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments
A large email fraud campaign used fake CEO messages and invoices to push employees toward payments of nearly $50,000. The operation did not rely on a…
Russia-Aligned Hackers Use GuardBreaker Prompt Injection to Disrupt AI Malware Analysis
Russia-aligned operators are testing a new way to make artificial intelligence overlook malicious code. The technique, called GuardBreaker, hides a…
Windows 11 Security Update KB5124008 Breaks Always-On VPN Connections
Microsoft’s September 2026 security update KB5124008 is knocking some Windows 11 enterprise clients off Always On VPN after the Patch Tuesday package…
cPanel ConfigServer Security & Firewall Vulnerability Allows Remote Attacker to Execute Arbitrary Commands
A critical vulnerability in ConfigServer Security & Firewall (CSF), used on cPanel and WHM servers, could allow an unauthenticated remote attacker to…
Ubuntu 24.04.5 LTS Released With Linux 7.0 Kernel and Latest Security Updates
Canonical has officially rolled out Ubuntu 24.04.5 LTS, the fifth maintenance update to the “Noble Numbat” long-term support release, delivering a fresh…
Conti Ransomware Hacker Sentenced After Group Attacked Over 1,000 Victims Worldwide
A Ukrainian national has been sentenced to four years in U.S. prison for his role in the Conti ransomware operation, which compromised more than 1,000…
New Android Ransomware Records Screens, Steals OTPs and Secretly Takes Photos of Victims
A newly uncovered Android threat combines ransomware with spying, creating a trap for people who install apps from untrusted links. Called Mantax Otax,…
IDScan Confirms Data Breach Following 153 Million Driver’s Licenses Leaked on the Dark Web
IDScan.net, a Louisiana-based identity verification firm whose technology underpins age and identity checks for retailers, bars, and other Fortune 500…
Okta Fixes Auth0 and Access Gateway Flaws Enabling XSS, Auth Bypass, and SQL Injection
Okta has released security fixes for three vulnerabilities affecting the Auth0 AD/LDAP Connector and Okta Access Gateway. The flaws could enable stored…
GitLab Patches Critical Flaws Enabling Arbitrary File Read, Credential Theft and Remote Code Execution
GitLab has released security updates for Community Edition and Enterprise Edition to fix multiple vulnerabilities, including two critical flaws that could…
JFrog Artifactory Vulnerabilities Actively Exploited in the Wild to Gain Administrative Control
An active exploitation of three JFrog Artifactory vulnerabilities that attackers are using to bypass authentication, elevate privileges, and take…
Top 10 Best Cloud Security Posture Management (CSPM) Tools in 2026
CSPM finds the cloud misconfigurations that cause most cloud breaches public buckets, permissive IAM, exposed databases continuously, across accounts and…
Top 10 Best Enterprise Browsers in 2026
The enterprise browser puts security inside the thing people actually work in: policy, data loss prevention (DLP), and visibility in the browser itself,…
Top 10 Best Browser Isolation Solutions in 2026
Remote browser isolation executes web content on a remote machine and sends only a safe representation to the user so whatever the page tries to run, it…
Top 10 Best Cloud Workload Protection (CWPP) Solutions in 2026
CWPP protects the workloads themselves VMs, containers, Kubernetes, serverless at runtime: detecting compromise, blocking malicious behaviour, and feeding…
Top 10 Best CNAPP (Cloud-Native Application Protection) Platforms in 2026
Bottom line up front: CNAPP is the umbrella — it bundles CSPM (posture), CWPP (runtime), CIEM (entitlements), and increasingly DSPM (data) into one…
Microsoft Investigating Microsoft 365 Copilot Access Issues Under Incident CP1470554
Microsoft is investigating a Microsoft 365 Copilot disruption in which users may be unable to open the assistant or encounter errors while using it. The…