-
Google’s Threat Intelligence Group has announced that its Agentic Vulnerability Discovery Harness (AVDH) identified over 100 critical true-positive vulnerabilities in stolen corporate source code repositories within just two days. This result hig…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Microsoft has issued a 60-day reminder that the Windows 11 version 24H2 Home and Pro editions will reach the end of updates on October 13, 2026. This date also marks the end of servicing for Windows 10 Enterprise LTSB 2016. As a result, both organizati…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Mexico’s banking sector is facing a more industrialized fraud threat as the Balonx Sistema phishing-as-a-service (PhaaS) operation combines real-time OTP theft, Android malware, and AI-generated vishing calls. Balonx is not a conventional credential-ha…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A data leak published on a cybercrime data-trading forum has exposed live Stripe API credentials for 659 merchant accounts, along with approximately 35 GB of customer- and payment-related data. The exposure affects an estimated 688,363 customer records…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A recently disclosed security issue in Cursor IDE exposed a serious Windows binary-planting vulnerability that could allow malicious code to execute simply by opening an untrusted repository. This flaw, tracked as CVE-2026-63093, relates to Cursor’s ex…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
BeyondTrust has revealed two high-severity vulnerabilities in its Endpoint Privilege Management (EPM) Windows Deployment product, which could lead to local privilege escalation and bypasses of anti-tamper protections on affected devices. These vulnerab…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Oracle has released 943 security patches as part of its August 2026 Critical Security Patch Update (CSPU), addressing newly disclosed vulnerabilities across its enterprise software portfolio. This update affects Oracle products under both Premier Suppo…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A threat actor calling itself “Ransom Busters” is targeting ransomware victims with a deceptive recovery offer, claiming it can restore encrypted files and delete stolen data from ransomware infrastructure. GuidePoint Security’s Research and Intelligen…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
More than 30 domains tied to MacSync Stealer, exposing a rotating macOS-focused infrastructure that supports payload delivery, command-and-control, credential theft, staging, and chunked data exfiltration. The investigation shows why defenders should p…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
D-Link has disclosed and patched 15 Common Vulnerabilities and Exposures (CVEs) affecting its DWR-M961 4G/LTE router, specifically hardware revision C1. This follows the discovery of multiple command injection and buffer overflow vulnerabilities in the…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


