This wrap-up brings a full-on shell parade. Thirteen shiny new modules landed, starting with a buffet of RCEs. WordPress WP2Shell, Ghost CMS, Joomla …
TL;DRHudson Rock and CloudSEK confirmed the scale of the March LiteLLM PyPI hack: a 153GB archive, 433,909 files.118,829 CI runner dumps trace back t…
Some 1.6 million unique email addresses tied to RingCentral have been leaked online, alongside names, physical addresses, and phone numbers, accordin…
Researchers have verified that ExfilSquad possesses sensitive data stolen from at least 13 victims after the extortion group published leaked dataset…
France's tax authority has confirmed that an intruder accessed its systems and extracted data in June after an alleged cybercriminal advertised a pur…
The Americas carried the heaviest ransomware burden of any region on the planet in the first half of 2026. According to Cyble Research and Intelligen…
The springs at Las Vegas were essential to western travel. The Old Spanish Trail connected Santa Fe to Southern California through more than a thousa…
We have access through port 9200. We have code execution through port 5601. Reconnaissance is complete, CVEs have been exploited, and Kibana has been…
In early July, attackers used open source AI agents to autonomously hack government systems and energy companies, signaling to defenders that AI-powe…
Evooo1Bot is a newly observed botnet based on the Mirai framework but equipped with advanced features, turning edge devices into persistent proxies
Apple has expanded its threat-notification system for targets of mercenary spyware. Apple now shows a warning directly on an iPhone’s Lock Screen and…
Meta announced it’s rolling out a new feature for WhatsApp users in the fight against scammers. Scam Alert is an optional beta feature that uses an o…
It can be daunting to determine who’s responsible for showing ads on the websites we visit, or who’s harvesting data from the mobile apps we use ever…
Cryptocurrency hardware wallet maker Trezor has confirmed that a breach at one of its shipping partners exposed the personal data of more than 13,000…
Introduction CoolClient is a backdoor family attributed to the HoneyMyte APT group (also known as Mustang Panda) that has been used in their cyber-es…
Scotland's public prosecution service has warned 300 staff that their personal information may have been caught up in a cyberattack on one of its sup…
Suddenly, you’re in a room. You look around - oh, you’re surrounded by other new starters at your new job. Yes, it’s Monday, and you’re being onboard…
21 malicious npm packages targeted Google by squatting CLI binary names from scoped packages, not package names. The technique exploits a structural …