The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
A new malware campaign has affected users globally, stealing sensitive data. Identified as PXA stealer,…PXA Python Malware Targets Thousands Of Victims Globall…
Microsoft recently announced the launch of Project Ire – a dedicated AI agent for malware…Project Ire – Microsoft Launches AI Agent For Automated Malware Class…
The threat actor known as EncryptHub is continuing to exploit a now-patched security flaw impacting Microsoft Windows to deliver malicious payloads.Trustwave S…
A Chinese-speaking advanced persistent threat (APT) actor has been observed targeting web infrastructure entities in Taiwan using customized versions of open-s…
The U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) on Thursday renewed sanctions against Russian cryptocurrency exchange platform Ga…
Multiple HTTP/2 implementations have been found susceptible to a new attack technique called MadeYouReset that could be explored to conduct powerful denial-of-…
Ever wonder how a seemingly minor bug in memory management can crack open a door for attackers to slip through? Meet the use-after-free (UAF) vulnerability''an…
Cybersecurity researchers have disclosed a new Android trojan called PhantomCard that abuses near-field communication (NFC) to conduct relay attacks for facili…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added two security flaws impacting N-able N-central to its Known Exploited Vulner…
In 2025, the CISO’s job isn’t just about stopping breaches—it’s about enabling business without compromising security. Whether it’s remote access to Linux serv…
Over the past few years, ransomware has evolved into a highly advanced type of malicious software, targeting individual systems and entire enterprises with inc…
Cybersecurity researchers have discovered a new malvertising campaign that's designed to infect victims with a multi-stage malware framework called PS1Bot."PS1…
Maintaining PCI DSS compliance has gone from a sprint to a year-round marathon. Verizon's 2022 Payment Security Report found only 43.4% of organizations were f…
Zoom and Xerox have addressed critical security flaws in Zoom Clients for Windows and FreeFlow Core that could allow privilege escalation and remote code execu…
Fortinet is alerting customers of a critical security flaw in FortiSIEM for which it said there exists an exploit in the wild.The vulnerability, tracked as CVE…
Security operations have never been a 9-to-5 job. For SOC analysts, the day often starts and ends deep in a queue of alerts, chasing down what turns out to be …
The popular file archiving tool WinRAR had a serious zero-day vulnerability threatening systems with code…WinRAR Fixed A Zero-Day Flaw Exploited By RomCom on L…
The AI revolution isn’t coming. It’s already here. From copilots that write our emails to autonomous agents that can take action without us lifting a finger, A…
Recently, Cloudflare and Perplexity came at odds recently as the former alleged Perplexity of stealth…Cloudflare Blames Perplexity Of Stealth Data Scraping – P…
A new Linux malware has recently caught the attention of security researchers. Identified as “Plague,”…Newly Discovered Plague Linux Backdoor Malware Remained …
Cybersecurity researchers have discovered a new campaign that employs a previously undocumented ransomware family called Charon to target the Middle East's pub…
DEFCON isn't your average tech conference. It's not about launching flashy products or corporate handshakes''it's about putting reality under a microscope and …
Let's talk about CVE-2025-38236 . If you've been following the Linux kernel's security track record, you already know how hard developers work to keep it solid…
Let's address what's happening head-on: Microsoft's third-party UEFI Certificate Authority (CA) key''responsible for signing shim bootloaders so Linux distribu…