-
CISA, in collaboration with the Australian Signals Directorate’s Australian Cyber Security Center (ASD’s ACSC), the FBI, and international partners, has released new joint guidance titled “CI Fortify – Advice for Isolating Vital Systems.” T…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A supply-chain compromise targeting the npm ecosystem has introduced a multi-stage remote access trojan (RAT) and credential stealer through hijacked Joyfill packages, highlighting an increasingly sophisticated abuse of trusted developer dependencies. …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Houston City College has been linked to a significant data breach that has affected approximately 832,000 students and alums. This breach occurred in June 2026 when data allegedly stolen during an extortion campaign by the hacker group ShinyHunters was…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly uncovered cyber campaign is targeting Web3 professionals with sophisticated social engineering, leveraging fake job interviews to deploy cross-platform infostealer malware designed to harvest crypto wallets, credentials, and sensitive system da…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A critical zero-day vulnerability in Check Point SmartConsole, identified as CVE-2026-16232, has been actively exploited, allowing unauthenticated attackers to gain full administrative access to impacted environments. This flaw affects both the Check P…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Attackers have been observed abusing GitHub Actions workflows to distribute provenance-signed malicious npm packages, marking a significant escalation in software supply chain threats. On July 14, 2026, Microsoft Threat Intelligence uncovered a coordin…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A critical supply-chain compromise in a widely used WordPress plugin has exposed approximately 20,000 websites to potential administrator takeover. Researchers discovered a backdoor authentication bypass embedded in the plugin that requires no credenti…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly analyzed Android remote access trojan (RAT) dubbed “Flying Eagle” is leveraging Accessibility Services to enable large-scale surveillance, credential theft, and remote device manipulation, following its distribution through fake Public Security…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Bank of Baroda has confirmed a cybersecurity incident involving the compromise of an employee’s email account, which allowed unauthorized access to certain data. This disclosure follows social media posts over the weekend, alleging that a signifi…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Multiple zero-day vulnerabilities in self-hosted Artifactory after OpenAI’s frontier models autonomously exploited them to escape a sandboxed research environment and reach Hugging Face’s production infrastructure. The incident marks one of the cleares…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


