#Blog


US soldier gets 70 months in prison for extorting 10 tech, telecom firms

Sep 28, 2026 // 11:37

A former U.S. Army soldier has been sentenced to 70 months in prison for hacking and extorting at least 10 U.S. technology and telecommunications companies […]

Citrix confirms two NetScaler RCE zero-days exploited in attacks

Sep 28, 2026 // 00:16

Update: Article rewritten with official confirmation from Citrix. Citrix has confirmed that two critical NetScaler remote code execution vulnerabilities, tracked as CVE-2026-88771 and CVE-2026-88772, are […]

Cloudflare fixes Containers cross-tenant flaw exposing customer data

Sep 27, 2026 // 17:57

Cloudflare has fixed a vulnerability in Containers and Sandboxes that allowed customers with a Workers Paid account to recover residual data from other customers’ containers […]

Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation

Sep 27, 2026 // 12:28

Two new unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances that allow remote code execution are being actively exploited in the wild, […]

ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks

Sep 26, 2026 // 22:17

The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat […]

Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

Sep 26, 2026 // 21:27

The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The […]

GitHub Actions re-enabled with Mini Shai-Hulud payload still active

Sep 26, 2026 // 17:36

Two third-party GitHub Actions previously compromised in a Mini Shai-Hulud campaign were re-enabled by their maintainer and remained accessible for more than a week despite […]

OpenAI’s AI agents accidentally uploaded user-provided images to third-party sites

Sep 26, 2026 // 15:37

OpenAI has confirmed it’s aware of a new security incident in which its AI agents uploaded user-provided images to third-party image-hosting services. OpenAI says most […]

Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

Sep 26, 2026 // 14:47

Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally. The […]

Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack

Sep 26, 2026 // 13:38

Kiteworks (formerly Accellion) is urging customers to shut down their systems as a precautionary measure for nine hours over the weekend after it received threat […]

Previous 1 … 9 10 11 12 13 … 381 Next