A cryptocurrency fraud operation has been found using AI coding tools to turn huge phone lists into a sharper victim-targeting system. The campaign…
Category: Cyber Security News
CISA Warns of Ray-Project Ray Code Injection Vulnerability Exploited in Attacks
CISA has added a critical Ray-Project Ray vulnerability, tracked as CVE-2025-62593, to its Known Exploited Vulnerabilities catalog after confirming…
Shadow hVNC Gives Attackers Remote Desktop Control Without Moving the Victim’s Mouse
Shadow hVNC is a remote access tool built to operate where victims cannot see it. Instead of taking over the visible desktop, it can create a separate…
10 Best Dark Web Monitoring Tools in 2026
Dark web monitoring involves tracking activities on the hidden internet, accessible only via specialized software and configurations. This shadowy realm…
VMware vCenter Attackers Drop JSP Webshell Disguised as Performance Update
A fast-moving campaign is turning a VMware vCenter flaw into a route to full control of virtual infrastructure. Attackers are abusing CVE-2026-59310, a…
Critical WordPress Plugin Vulnerability Exposes 600,000 Sites to File Upload Attacks
A critical security flaw in the Forminator Forms WordPress plugin could allow unauthenticated attackers to upload malicious PHP files, potentially…
Windows 11 File Explorer Gets Faster, Customizable Right-Click Menu With App Extension Controls
Microsoft has introduced a redesigned File Explorer context menu for Windows 11 Insiders, promising faster right-click performance, less clutter, and new…
Critical GitLab GraphQL Vulnerability Allow Attackers to Delete Public Projects
GitLab has released urgent security updates to fix a critical GraphQL vulnerability that could allow unauthenticated attackers to modify or delete public…
Top 10 Best Network Sandboxing Solutions in 2026
Network sandboxing detonates unknown files and URLs in an isolated environment to see what they actually do catching malware that has never been seen…
Claude Code Helps Ransomware Operator Steal LDAP Passwords, Backdoor VPNs and Exfiltrate SQL Databases
A new threat intelligence report from Gambit Security has documented one of the clearest real-world examples yet of artificial intelligence being…
Public Exploit Code Released for Microsoft SCCM Remote Code Execution Vulnerability
Public proof-of-concept exploit code is now available for CVE-2026-47301, a critical remote code execution vulnerability affecting Microsoft Configuration…
Pokémon Center Confirms Data Breach – Hackers Stole Customers’ Personal Data
Pokémon Center has begun notifying customers in the United Kingdom and Germany that their personal information was exposed in a third-party data breach,…
GitHub Outage Disrupts Developers Worldwide Amid Ongoing Investigation
GitHub, the world’s largest code-hosting platform, is grappling with a significant service disruption that began around 13:40 UTC on August 17, 2026,…
Top 10 Best Software-Defined Perimeter (SDP) Solutions in 2026
A software-defined perimeter makes your infrastructure invisible: resources accept no unauthenticated connections, so attackers cannot scan, probe, or…
Threema Secure Messaging Service Hit by Massive DDoS Attack
Threema, a privacy-focused secure messaging service, was hit by a series of large-scale distributed denial-of-service (DDoS attacks) that temporarily…
Microsoft SCCM Vulnerability Chained to Execute Malicious Code Remotely
Security researchers have disclosed a serious attack chain affecting Microsoft System Center Configuration Manager, commonly known as SCCM or…
Roundcube 1.6.18 and 1.7.3 Released With Fix for RCE and SSRF Vulnerabilities
Roundcube has released versions 1.6.18 and 1.7.3 to address eleven security vulnerabilities affecting its webmail platform. The updates fix a remote code…
HoneyMyte CoolClient Backdoor Uses Signed Kernel Rootkit to Hide Processes, Files and C2 Traffic
HoneyMyte has upgraded its CoolClient backdoor with a kernel-level rootkit for Windows. The change makes routine investigation much harder for defenders.…
GeoServer’s Unauthenticated SQL injection Vulnerability Enables RCE Attacks
GeoServer administrators should urgently update affected systems after researchers disclosed an unauthenticated SQL injection flaw in the…
Z.ai Unveils GLM-5.3 with Major Enhancements for Coding and Cybersecurity
Z.ai has released GLM-5.3, a new AI model built to handle complex coding, long-running agent tasks, and cybersecurity analysis. The company says the model…