Most SOCs measure threat intelligence the same way they measure storage: bigger is better. A feed that delivers two million indicators a month looks more impressive on a vendor scorecard than one that delivers two hundred thousand. Dashboards proudly display…
Tag: Cyber Security News
Anthropic Launches Claude Tag – AI Teammate Now Lives Inside Slack
Anthropic has unveiled Claude Tag, a new agentic AI feature that integrates directly into Slack, allowing teams to tag @Claude as a collaborative team member to delegate tasks, automate workflows, and build shared organizational context. The feature is available today…
Nearly Half of Apps Across LG and Samsung TV’S are Selling Your IP Address
New research found that 2,058 of 6,038 apps across the LG webOS and Samsung Tizen ecosystems included residential proxy SDKs, effectively turning smart TVs into exit nodes for third-party internet traffic. On screen, these apps look like harmless fish tanks,…
Five-Eye Agencies Call for “Whole-of-Organization and Whole-of-Society Response” to Stop Cyber Threats
The Five Eyes cyber security agencies have issued a joint warning urging governments, businesses, and critical infrastructure operators to adopt a “whole-of-organization and whole-of-society response” to address rapidly evolving cyber threats driven by artificial intelligence (AI). In a statement released…
DifyTap Flaws Allow Attackers to Wiretap AI Data Across Tenants – 1M+ Apps Impacted
Multiple critical vulnerabilities in Dify could expose sensitive AI data across tenants and potentially impact more than one million applications. Dify, which powers AI workflows, chatbots, and retrieval-augmented generation (RAG) pipelines, is heavily adopted across enterprises including Volvo, Maersk, Panasonic,…
LastPass Customer Data Exposed in Klue Supply Chain Attack
LastPass has disclosed a supply chain security incident involving its third-party vendor, Klue, that resulted in unauthorized access to customer data within its Salesforce environment. The company confirmed that the breach did not affect its core infrastructure or password vaults.…
8-Year-Old Samsung KNOX Vulnerability Exposes Galaxy Devices to Kernel Attacks
A critical use-after-free (UAF) vulnerability in Samsung’s proprietary KNOX security subsystem, which has been hidden for over eight years, has been discovered by security research firm LucidBit, potentially exposing hundreds of millions of Galaxy devices to kernel-level memory corruption and…
15 Best Linux Network Monitoring Tools in 2026
The “Linux network monitoring” concept describes keeping monitors on and evaluating a network’s performance, capacity, and overall health. Specialist tools and software capture, measure, and analyze data on network traffic, bandwidth utilization, latency, and connected devices. Administrators can monitor everything…
Scattered Spider Hackers Who Breached London Transport Network Plead Guilty
Two members of the Scattered Spider cybercriminal group have pleaded guilty to a cyberattack on Transport for London (TfL) that caused major service disruptions and resulted in an estimated £29 million in losses. Thalha Jubair, 20, from East London, and…
Hackers Abuse Compromised M365 Accounts to Scale CodeStorm Phishing Operations
Hackers are taking phishing to new levels by abusing legitimate Microsoft 365 accounts to supercharge an operation known as CodeStorm. Instead of building fake infrastructure from scratch, attackers are hijacking real M365 accounts and using them as trusted launching pads.…
Critical FFmpeg Vulnerability Allows Attackers to Weaponize Media Files
A critical vulnerability has been disclosed in FFmpeg’s MagicYUV decoder that allows attackers to weaponize seemingly harmless media files and, in some scenarios, achieve remote code execution (RCE). The flaw, tracked as CVE-2026-8461 and dubbed “PixelSmash,” is a heap out-of-bounds…
Critical libssh2 Vulnerability Allows Attackers to Execute Remote Code Via Malicious SSH packets
A critical security vulnerability has been identified in the widely used libssh2 library, allowing remote attackers to execute arbitrary code through specially crafted SSH packets. The flaw, tracked as CVE-2026-55200, carries a CVSS score of 9.2 and is classified under…
New Phishing Attack Abuses Outlook and Microsoft 365 Groups Features to Attack Users
Phishing attacks have grown more sophisticated, and attackers are no longer relying on clunky fake emails or obvious scam messages. A newly identified campaign shows how threat actors are turning everyday Microsoft 365 tools into weapons, hiding their attacks inside…
Tata Electronics Data Breach Exposes Confidential Apple and Tesla Documents
Indian electronics manufacturing giant Tata Electronics confirmed a “cybersecurity incident” on Monday after ransomware group World Leaks published over 200,000 files totaling more than 630 gigabytes on the dark web, allegedly containing proprietary and confidential documents belonging to Apple and…
Researcher Earns $148,337 for Google Cloud Production RCE Vulnerability
A researcher has earned a total of 148,337 USD from Google for uncovering a set of flaws in Google Cloud’s Application Integration service that escalated into remote code execution (RCE) in Google Cloud production. The core bug is now tracked…
OpenAI Releases GPT‑5.5‑Cyber With Full Automation for Vulnerability Detection and Patching
OpenAI has officially launched the full version of GPT‑5.5‑Cyber, a specialized AI model engineered for advanced vulnerability detection, patch generation, and automated remediation at machine speed. The release is part of OpenAI’s broader Daybreak initiative, which aims to democratize defensive…
Hackers Using FortigateSniffer Tool That Turns Compromised Firewalls Into Password Collectors
A financially motivated threat actor has deployed a custom Golang-based tool called FortigateSniffer across more than 430,000 FortiGate firewalls globally, silently harvesting over 110 million credentials since at least February 2026, including confirmed data exfiltration from a NATO-aligned defense contractor.…
AryStinger Botnet Hijacks 4,300+ Routers to Build Global Attack Proxy Network
A newly discovered botnet called AryStinger has quietly hijacked more than 4,300 routers across the globe, turning them into a silent army of attack proxies. The threat actors behind this campaign are exploiting decade-old vulnerabilities to build a covert reconnaissance…
Malicious GST Debit Note Attachment Deploys Remcos RAT Through Multi-Stage Loader
A sophisticated phishing campaign is actively targeting users in India by disguising malware as a routine GST debit note. The attack delivers a powerful remote access tool called Remcos RAT through a cleverly constructed multi-stage loader, giving attackers deep and…
Windows RAT Uses Encrypted HTTP C2 and Registry Persistence After npm Infection
A newly discovered malware campaign is targeting Windows systems through a deceptive package on the npm registry. Disguised as a legitimate CSS build tool, the malicious package quietly installs a full-featured Remote Access Trojan, or RAT, on developer machines. The…