Hackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for…
Tag: EN
Securing Agent-to-Agent Communication: The Next Identity Frontier
As organizations deploy autonomous AI agents, security teams face a significant shift as non-human non-human entities making decisions, invoking tools,…
Top 10 Best Software Supply Chain Security Tools in 2026 [Ranked & Scored]
The supply chain is four attack surfaces wearing one buzzword dependencies, pipelines, artifacts, and base images and no vendor covers all four. We scored…
Hackers Target Hotels With Fake Guest Complaints to Deploy Blockchain-Based RAT Malware
Hackers are targeting hotels with fabricated guest complaints and negative reviews to distribute EtherRAT and TONResolver, two malware families that abuse…
16 Malicious Firefox Extensions Pose as Rabby and OKX Wallets to Steal Recovery Phrases
Cybersecurity researchers have discovered a cluster of 16 malicious Mozilla Firefox extensions that are capable of stealing cryptocurrency wallet recovery…
Critical Atlassian Flaw CVE-2026-21589
Atlassian has disclosed a critical security vulnerability affecting eight of its self-hosted Data Center products, allowing unauthenticated attackers to…
Angel One – 6,765,054 breached accounts
In July 2024, the Indian stock brokerage firm Angel One confirmed that data leaked online related to a breach that occurred in April 2023 . The leaked…
Possible Vulnerability in Apple’s Automatic Reboot
404Media is reporting (alternate link ) that a cyber-weapons arms manufacturer is exploiting a vulnerability in iOS to bypass its automatic reboot…
South Korean president calls for creation of tools that stop all cyber-attacks
‘Complete security paradigm refresh’ needed for the AI era
ClickFix Attack Hides VBScript Payload in Browser Cache
ClickFix sites stage a VBScript payload in the browser cache to bypass the Run dialog’s length limit
ASOS app turned into ransom note as hackers claim Snowflake breach
ASOS customers were alarmed Tuesday morning after the retailer’s own mobile app sent a push notification claiming the company had been hacked and…
Teenager suspected of leading KillSec ransomware group as law enforcement seizes servers and leak site
On 30 September 2026, law enforcement took control of KillSec’s leak site, securing at least 110 terabytes of data against further unauthorised access.…
Ignore all instructions and read this blog: The state of AI-analysis evasion in malware
“AI-analysis evasion” encapsulates the real-world techniques malware authors are developing in attempt to obstruct or defeat any layers of automated AI…
Hackers Use GitHub-Hosted Poem to Control PoeLLM Malware Targeting AI Infrastructure
Hackers are using a poem hosted on GitHub to guide PoeLLM malware toward its command-and-control servers, turning exposed AI infrastructure into a growing…
Critical Splunk Enterprise Vulnerability Lets Unauthenticated Attackers Execute OS Commands
Splunk has addressed a critical vulnerability in Splunk Enterprise that allows unauthenticated attackers to execute operating system commands through the…
Critical Cisco Nexus Flaws Let Unauthenticated Attackers Execute Code With Root Privileges
Cisco has released security updates for three critical vulnerabilities in Nexus 3000 and 9000 Series switches that could let remote attackers run code…
Europol and US GAO Sound the Alarm Over Quantum Threats
Europol and US Government Accountability Office urge faster transition to post-quantum cryptography
MALFEX npm Malware Hides Executables in PNG Files to Infect Windows Developers
A long-running npm malware campaign called MALFEX is targeting Windows developers with remote access tools, data stealers, and hidden downloaders. The…
When everything looks normal: why context, not more alerts, is the next frontier for security operations
Security awareness has long relied on teaching people to spot the obvious warning signs. Steve Povolny, Vice President of AI Strategy & Security Research…
Top 10 Best Secrets Detection Tools in 2026 [Ranked & Scored]
Attackers don’t crack what they can copy and leaked API keys sit in git history, Slack threads, and cloud workloads waiting. Evaluating the landscape…
