Identity has become the primary battleground of enterprise cybersecurity. Attackers increasingly bypass traditional defenses by stealing credentials, hijacking sessions, abusing privileged accounts, and exploiting misconfigurations across Active Directory, cloud platforms, SaaS applications, and non-human identities. Microsoft reported more than 7,000…
Category: Cyber Security News
CISA Warns of Microsoft SharePoint Code Execution Vulnerability Exploited in Attacks
CISA has added a critical Microsoft SharePoint vulnerability, tracked as CVE-2026-58644, to its Known Exploited Vulnerabilities (KEV) catalog. This addition comes with a warning that attackers are actively exploiting the flaw in real-world attacks. The vulnerability stems from a weakness…
New ClickLock macOS Stealer Kills Every App to Force Password Entry
A newly discovered macOS malware dubbed ClickLock is raising alarms in the cybersecurity community for its aggressive and deceptive credential-harvesting techniques. According to researchers at Group-IB, the stealer employs a highly disruptive tactic that forcibly terminates running applications, effectively locking…
CISA Warns of Fortinet FortiSandbox OS Injection Vulnerabilities Exploited in Attacks
CISA has added two critical Fortinet FortiSandbox vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, warning that attackers are actively exploiting the flaws in real-world attacks. The vulnerabilities, identified as CVE-2026-39808 and CVE-2026-25089, allow unauthenticated attackers to execute unauthorized operating…
Two Hackers Jailed for Hacking 148 TfL Systems, Forcing Password Reset for 27,000 Staff
Two young members of the Scattered Spider cybercrime group have been jailed for a 2024 attack that knocked out 148 Transport for London (TfL) systems, forced all 27,000 staff to reset passwords in person, and cost the organization about £29…
7-Zip Vulnerability Exposes Millions of Users to Remote Code Execution Risk
A newly disclosed vulnerability in 7-Zip, one of the most widely used open-source file archiving tools, could allow remote attackers to execute arbitrary code on affected systems. Tracked as CVE-2026-14266, the flaw stems from improper handling of XZ chunked data…
Two Hackers Jailed for Hacking 148 TfL Systems, Forcing Password Reset for 27,000 staffs
Two young members of the Scattered Spider cybercrime group have been jailed for a 2024 attack that knocked out 148 Transport for London (TfL) systems, forced all 27,000 staff to reset passwords in person, and cost the organization about £29…
Next.js Launches Monthly Security Release Program as First Update Patches 9 Vulnerabilities
Next.js has launched a monthly security release program, with the first update scheduled for July 20, 2026. This update will address nine vulnerabilities across supported versions of the framework. The initial release will provide patch updates for Next.js versions 16.2…
Top 10 Best Firewall as a Service (FWaaS) Providers – 2026
The firewall is leaving the rack: firewall-as-a-service delivers inspection, intrusion prevention, and policy from the cloud, so every user, branch, and cloud workload gets identical protection without appliances to size, patch, or refresh. Zscaler is our top FWaaS pick for 2026 on the strength…
AnyDesk 0-Day Vulnerability Lets Attackers Trigger Denial-of-Service
A newly disclosed zero-day flaw in AnyDesk, tracked as CVE-2026-15682, allows local attackers to crash affected installations by abusing a core support feature, raising fresh concerns for organizations relying on the remote desktop tool for IT support and access management.…
Linus Torvalds Told Kernel Developers that Linux is Not Against AI projects
Linux creator Linus Torvalds has told kernel developers that the Linux project is not anti-AI, arguing that artificial intelligence and large language models should be judged on whether they provide practical technical value. He emphasized that developers will not be…
Dutch Police Disrupt €100 Million Investment Fraud Network Operating 20 Call Centers
Dutch police have moved against a large investment-fraud operation that allegedly used a network of call centers to reach victims at scale. The case shows how organized fraud can borrow the speed, scripts, and customer-service appearance of a legitimate business…
AI Penetration Testing Expands to Retrieval Poisoning, Memory Attacks, and Sensor Manipulation
AI systems are moving from chat windows into security operations, business workflows, and physical environments. That shift is changing what penetration testing must look for. An attacker may no longer need to breach a server or steal credentials to cause…
Hackers Actively Exploiting SonicWall SMA1000 0-Day Vulnerability in the Wild
SonicWall disclosed two vulnerabilities affecting its SMA1000 Series remote access appliances, and threat actors were already exploiting one of them before the advisory even went public. The flaws include a critical server-side request forgery (SSRF) bug, CVE-2026-15409, scoring a perfect…
Specter Turns Your Flipper Zero Into a Pocket Skimmer Detector
A new Flipper Zero app called Specter aims to turn the handheld device into a passive counter-surveillance tool for finding active 13.56 MHz NFC readers, including potentially suspicious readers hidden near payment terminals, access-control panels, desks, or other equipment. Unlike…
JetBrains Patched 6 Vulnerabilities Across TeamCity, YouTrack and IntelliJ IDEA
JetBrains has addressed six security vulnerabilities in its software development and project management products. The affected applications include IntelliJ IDEA, TeamCity, and YouTrack. The most critical vulnerability, tracked as CVE-2026-59792, is an improper path handling (CWE-23) flaw that could allow…
WhatsApp GhostPairing Lets Scammers Hijack Accounts Without Stealing Passwords
WhatsApp users are being targeted by a social-engineering technique called GhostPairing that can give scammers access to an account without requiring a password or one-time verification code. Instead of breaking into the service directly, the scam abuses WhatsApp’s legitimate device-linking…
Hackers Don’t Crack Telegram 2FA—They Copy Your Already Logged-In Session
A macOS information-stealing malware is turning stolen Telegram desktop data into immediate account access. Instead of guessing passwords or breaking two-factor authentication, it copies the local files that prove a user has already logged in. When those files are restored…
Kratos PhaaS Attacking Microsoft 365 Users Across the US, Europe to Steal Credentials
Kratos is a phishing-as-a-service operation built to steal Microsoft 365 credentials. It is targeting organizations across the United States, Europe, and other regions by using believable document, invoice, and file-sharing lures that lead victims to fake login pages. The campaign…
GPT-Red – A Red Teamer to Find Prompt Injection Vulnerabilities in GPT 5.6 Sol
OpenAI has introduced GPT-Red, an internal automated red-teaming model designed to identify and remediate prompt injection vulnerabilities in GPT-5.6. This approach aims to tackle a growing safety challenge. While human red-team exercises are valuable, they cannot generate adversarial test cases…
