A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild. The…
Tag: EN
Shein Sees $99m Loss Ahead Of Hong Kong IPO
China-founded e-commerce company sees US market contract, falls to loss in first quarter as it prepares to list in Hong Kong
Houston City College – 831,642 breached accounts
In June 2026, Houston City College was the target of a ShinyHunters “pay or leak” extortion campaign . Data allegedly obtained from the college was later…
Should You Use AI for a Task? Here’s a Simple Way to Decide
This essay originally appeared in The Guardian . I teach public policy at the Harvard Kennedy School and the Munk School at the University of Toronto. And…
OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia
Our experts discovered OctLurk and SilkLurk, backdoors operating primarily in memory, targeting Central Asia. They inject plugins to launch shells, scan…
Hugging Face Has a Deepfake Nudes Problem
Researchers tested top image editing models on Hugging Face and found they could easily create explicit deepfakes—and 1,000 image editing prompts show how…
Semiconductor Firm Analog Devices Discloses Data Breach
Hackers were detected on Analog Devices systems in June, and an investigation found that they stole files.
Attackers are using Microsoft’s legitimate login system to camouflage phishing attacks
Attackers are moving away from fake Microsoft login pages in favor of abusing Microsoft’s own authentication system, letting phishing campaigns slip past…
Linux XMRig Botnet Abuses PAM for Fileless Monero Mining and Persistent Access
A covert Monero (XMR) cryptomining campaign uncovered in May 2026 is abusing Linux Pluggable Authentication Modules (PAM) to evade detection, maintain…
How Heimdal grew from a bold idea into a global cybersecurity platform
Heimdal did not start as a traditional cybersecurity company. It started with two Danish cybersecurity researchers, a piece of innovative technology and a…
Fake Flash Player Installer Uses Microsoft-Themed Certificate to Deploy AtlasRAT
AtlasRAT is being delivered through a fake Flash Player installer that looks harmless but can give attackers remote control of a Windows computer. The…
Introducing the Industry’s First AI Network Firewall
AI has introduced a new class of network traffic. Prompts, file uploads, model calls, and agent actions carrying sensitive business context now traverse…
OpenAI’s Hacking Debacle Was a Human Mistake
If the generative AI giant had followed well-known security best practices, it’s likely that its AI agent would never have escaped to the open internet…
Fake Claude Install Guide Delivers Six-Stage macOS Stealer and RAT, Huntress Finds
Security researchers at Huntress have reverse-engineered a previously undocumented macOS malware family, dubbed MacSync, after tracing an intrusion back…
Cisco FMC static credentials exploited by attackers (CVE-2026-20316)
A static credentials vulnerability (CVE-2026-20316) in Cisco Secure Firewall Management Center (FMC), a platform for centrally managing multiple Cisco…
FCC Restricts New Foreign Robots and Inverters Over Security Risks
The FCC added foreign robots and power inverters to its Covered List, while allowing security updates for existing authorized devices until 2029. The FCC…
SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT
The Chinese cybercrime group known as Silver Fox has been observed using new drivers as part of bring your own vulnerable driver (BYOVD) attacks targeting…
MediaArena malvertising: why a quarantine isn’t the end of the incident
If Microsoft Defender quarantines BrowserModifier:Win32/MediaArena on one of your endpoints, the alert reads like a win. Our SOC data says treat it as a…
Dropzone AI turns threat hunting into a routine SOC operation
Dropzone AI has announced the general availability of AI Threat Hunter, its proactive threat hunting agent. The tool enables security teams to run…
Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts
South Korean authorities and four security firms have disclosed a state-sponsored campaign that compromised trusted domestic websites. The attackers used…