A critical security flaw in the Forminator Forms WordPress plugin could allow unauthenticated attackers to upload malicious PHP files, potentially…
Tag: Cyber Security News
Windows 11 File Explorer Gets Faster, Customizable Right-Click Menu With App Extension Controls
Microsoft has introduced a redesigned File Explorer context menu for Windows 11 Insiders, promising faster right-click performance, less clutter, and new…
Critical GitLab GraphQL Vulnerability Allow Attackers to Delete Public Projects
GitLab has released urgent security updates to fix a critical GraphQL vulnerability that could allow unauthenticated attackers to modify or delete public…
Top 10 Best Network Sandboxing Solutions in 2026
Network sandboxing detonates unknown files and URLs in an isolated environment to see what they actually do catching malware that has never been seen…
Claude Code Helps Ransomware Operator Steal LDAP Passwords, Backdoor VPNs and Exfiltrate SQL Databases
A new threat intelligence report from Gambit Security has documented one of the clearest real-world examples yet of artificial intelligence being…
Public Exploit Code Released for Microsoft SCCM Remote Code Execution Vulnerability
Public proof-of-concept exploit code is now available for CVE-2026-47301, a critical remote code execution vulnerability affecting Microsoft Configuration…
Pokémon Center Confirms Data Breach – Hackers Stole Customers’ Personal Data
Pokémon Center has begun notifying customers in the United Kingdom and Germany that their personal information was exposed in a third-party data breach,…
GitHub Outage Disrupts Developers Worldwide Amid Ongoing Investigation
GitHub, the world’s largest code-hosting platform, is grappling with a significant service disruption that began around 13:40 UTC on August 17, 2026,…
Top 10 Best Software-Defined Perimeter (SDP) Solutions in 2026
A software-defined perimeter makes your infrastructure invisible: resources accept no unauthenticated connections, so attackers cannot scan, probe, or…
Threema Secure Messaging Service Hit by Massive DDoS Attack
Threema, a privacy-focused secure messaging service, was hit by a series of large-scale distributed denial-of-service (DDoS attacks) that temporarily…
Microsoft SCCM Vulnerability Chained to Execute Malicious Code Remotely
Security researchers have disclosed a serious attack chain affecting Microsoft System Center Configuration Manager, commonly known as SCCM or…
Roundcube 1.6.18 and 1.7.3 Released With Fix for RCE and SSRF Vulnerabilities
Roundcube has released versions 1.6.18 and 1.7.3 to address eleven security vulnerabilities affecting its webmail platform. The updates fix a remote code…
HoneyMyte CoolClient Backdoor Uses Signed Kernel Rootkit to Hide Processes, Files and C2 Traffic
HoneyMyte has upgraded its CoolClient backdoor with a kernel-level rootkit for Windows. The change makes routine investigation much harder for defenders.…
GeoServer’s Unauthenticated SQL injection Vulnerability Enables RCE Attacks
GeoServer administrators should urgently update affected systems after researchers disclosed an unauthenticated SQL injection flaw in the…
Z.ai Unveils GLM-5.3 with Major Enhancements for Coding and Cybersecurity
Z.ai has released GLM-5.3, a new AI model built to handle complex coding, long-running agent tasks, and cybersecurity analysis. The company says the model…
New MessiahGPT AI Model Fueling Automated Ransomware and Phishing Attacks
A criminal AI service called MessiahGPT is being marketed on BreachForums as an uncensored platform for creating ransomware, phishing kits, stealers,…
Evooo1Bot Linux Botnet Uses 16 DDoS Methods and SOCKS5 Proxies to Hijack Edge Devices
A newly tracked Linux botnet is turning exposed edge devices into tools for disruption, remote access, and traffic relaying. Evooo1Bot is the threat that…
ChainDrop npm Worm Poisons 444 Packages Through GitHub Actions and Trusted Publishing
ChainDrop has made an npm package compromise a warning about developer machines. The self-propagating campaign poisoned 444 packages and more than 1,300…
Fake Web3 Interview Uses Signed ClickOnce to Deploy NeedleStealer and hVNC RAT
Fake job interviews are again being used to breach cryptocurrency teams. In a documented case, a convincing Web3 recruitment process led a Windows user to…
12 KB Windows Backdoor Hides C2 Domain in desktop.ini Whitespace to Evade Detection
A newly documented Windows backdoor shows how little code an attacker needs to stay hidden. The 12 KB implant was found on one corporate workstation,…