Threat actors are increasingly abusing Active Directory replication to impersonate domain controllers and steal password hashes from enterprise networks.…
Category: Cyber Security News
CISA Warns of Fortinet Heap-based Buffer Overflow Flaw Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency has added a critical Fortinet vulnerability, tracked as CVE-2025-25249, to its Known Exploited…
OpenSSL 4.1.0 Alpha1 Released With DTLS 1.3 and Faster Post-Quantum Cryptography
The OpenSSL Project has released OpenSSL 4.1.0 Alpha1, an early preview of its forthcoming feature release. This update adds support for Datagram…
LiteLLM Flaws Let Attackers Execute Code as Root and Steal Cloud Credentials
LiteLLM deployments can expose far more than an organization’s AI spending. Newly disclosed weaknesses in the open-source gateway could let attackers run…
Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware
Mac users seeking AI tools face a malware trap. Attackers are using fake Claude and ChatGPT installers and sponsored search results to push MacSync, a…
Top 10 Best Endpoint Privilege Management (EPM) Tools in 2026
Local admin rights are the fuel most endpoint attacks run on: malware inherits the user’s privileges, and an admin user means an admin infection. EPM…
Top 10 Best Ransomware Protection Solutions in 2026
Bottom line up front: no single product “stops ransomware.” Modern attacks are staged intrusions initial access, credential theft, lateral movement,…
Top 10 Best Server Security Solutions in 2026
Bottom line up front: servers are not big laptops. They run Linux as often as Windows, can’t tolerate agent-induced latency, host the data ransomware…
Hackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks
Hackers have used commercial AI models to help break into government, transport and financial networks across Latin America. The activity shows how…
Top 10 Best Endpoint Encryption Software in 2026
Bottom line up front: the encryption engines are largely solved BitLocker and FileVault are strong, free, and built in. What you’re actually buying in…
Top 10 Best Device Control & USB Security Tools in 2026
USB ports remain a two-way risk: malware walks in, data walks out. Device control governs what can connect by device class, vendor ID, even serial number…
Claude AI Models Gained Unauthorized Access to Real Systems During Cybersecurity Tests
Anthropic has disclosed that four separate versions of its Claude AI models breached real-world third-party systems while running what were supposed to be…
Hackers Chain Chrome and Windows Zero-Days in New BlueMoon Exploit Kit Attacks
Multiple espionage-motivated threat actors have rapidly adopted a newly discovered exploit kit that chains Chrome browser and Microsoft Windows…
New N0va Phishkit Targets North America and EU: A Growing Identity Risk for SOCs
Recently, ANY.RUN researchers uncovered N0va, a new phishkit targeting organizations across North America and the EU, including government, technology,…
Veradigm Confirms Patient Data Exposed in Third-Party Data Breach
Healthcare technology company Veradigm Inc. disclosed that a cybersecurity incident at one of its third-party vendors exposed sensitive patient data,…
Critical ArangoDB Flaws Allow Authentication Bypass and Remote Code Execution as Root
Two critical flaws in ArangoDB can let an outsider bypass login controls, read or alter database data, and then gain root-level code execution on the…
Android Security Update September 2026 – Fix for Critical Flaws that Enable RCE Attacks
Google released the Android Security Bulletin for September 2026, addressing several critical vulnerabilities that could let attackers execute code…
CISA Warns of N-able N-central RCE Vulnerability Exploited in the Wild
The Cybersecurity and Infrastructure Security Agency has added a maximum-severity flaw in N-able’s N-central remote monitoring and management platform to…
Hackers Clone Banking Apps Into Hidden Android Work Profiles to Evade Fraud Detection
Android banking fraud is entering a deceptive phase. Attackers are using malware that copies targeted banking apps into a concealed Android work profile,…
Microsoft Teams for Android Vulnerability Exposes Sensitive Information
Microsoft has released a security update for CVE-2026-65812, a vulnerability in Microsoft Teams for Android that could allow an authorized attacker to…