Cisco has released security updates for an actively exploited zero-day vulnerability in Cisco Secure Firewall Management Center (FMC) Software. This…
Category: Cyber Security News
TA488 May Have Exploited Outlook Web Access 0-Day Flaw Before Microsoft’s Emergency Patch
TA488 has been linked to a new campaign that turns a routine Outlook Web Access email into a gateway for mailbox compromise. The operation abused a…
North Korean Hackers Turn Trusted npm Packages Into a Gateway for Supply-Chain Attacks
North Korean-linked hackers are turning trusted npm packages into an entry point for widespread software supply-chain attacks. By compromising the…
Microsoft Word Copilot Vulnerability Turns Hidden Prompts Into Self‑Propagating AI Worms
A new vulnerability in Microsoft Copilot for Word shows how hidden prompts inside documents can transform routine editing into a self‑propagating “AI…
Critical Rails Flaw Lets Attackers Read Arbitrary Files and Execute Malicious Code Remotely
A severe security vulnerability in Ruby on Rails Active Storage tracked as CVE-2026-66066 can let unauthenticated attackers read sensitive files from a…
AI-Generated Phishing No Longer Needs Malware: It Can Steal Your Session Inside the Browser
AI-generated phishing campaigns are rapidly evolving beyond traditional malware delivery, shifting the battleground directly into the web browser where…
Revolut Alleged Data Breach – Hackers Claiming to Access Over 75 Million Users’ Records
Revolut is currently under scrutiny after hackers claimed to be selling a database containing records of more than 75 million users. However, the company…
Hackers Can Hijack Tor Browser Users Through a Single Malicious Web Page
A single malicious webpage is enough to compromise Tor Browser users running an unpatched build, following newly disclosed research into CVE-2026-10702.…
Russian Intelligence Hackers Phish Signal Backup Keys to Hijack Accounts and Messages
Russian intelligence-linked hackers are trying to seize Signal accounts by posing as support staff and asking targets for backup recovery keys. The…
macOS ClickFix Attack Deploys Atomic Stealer to Steal Passwords and Crypto Wallets
Mac users are being targeted by a ClickFix campaign that turns a fake verification prompt into a path for malware installation. Victims are persuaded to…
Critical Ruflo MCP Bridge Flaw Lets Attackers Execute Commands and Hijack AI Agents
A critical security flaw in the open-source AI orchestration platform Ruflo has been disclosed, allowing unauthenticated attackers to execute arbitrary…
NVIDIA BlueField Vulnerability Enables Code Execution Attacks
NVIDIA has disclosed a serious vulnerability affecting its BlueField DPUs and ConnectX networking platforms that could allow attackers to execute code on…
Hijacked Joyfill npm Packages Deploy Worm-Like RAT and Steal Developer Credentials
A fresh supply chain scare hit software teams after attackers slipped malware into trusted open source libraries. On July 28, 2026, malicious beta builds…
Houston City College Data Breach Exposes 832k Unique Student Email Addresses
Houston City College has experienced a serious data breach that exposed sensitive personal information of approximately 832,000 unique students and alums.…
Russia Charges Telegram CEO Pavel Durov With Aiding Terrorism, Issues Arrest Warrant
Russia’s Federal Security Service (FSB) has formally charged Telegram founder and CEO Pavel Durov with aiding terrorism and issued a warrant for his…
Fake Recruiters Target Web3 Developers Through Trusted Bitbucket and npm Workflows
A new wave of job scams is hitting Web3 developers who are simply looking for their next role. Attackers pose as recruiters, start friendly chats about…
JFrog Artifactory Zero-Day Exploited by OpenAI Models to Escape Sandbox
Artificial intelligence models have now demonstrated how quickly a security test can become a real infrastructure risk. In an isolated evaluation, OpenAI…
Android Malware Scanners Are Flagging Legitimate Apps and Missing Threats Without Context
Android malware scanners are increasingly misaligning with real-world risk by over-flagging legitimate, high-permission applications while quietly missing…
20-Year-Old Vulnerability Enables Takeover of Thousands of Data Centers in Minutes
A two-decade-old vulnerability in the Intelligent Platform Management Interface (IPMI) protocol could allow attackers to gain control of thousands of…
Check Point SmartConsole 0-Day Exploited to Gain Full Administrator Access – PoC Released
A critical authentication bypass in SmartConsole that was actively exploited as a zero-day before patches were available. Tracked as CVE-2026-16232, the…
