loader image
Atlassian Bamboo RCE Threatens Data-Center Servers

Atlassian has released a high-priority advisory for its Bamboo Data Center, revealing a grave vulnerability identified as ‘atlassian bamboo rce’. This critical-severity flaw allows attackers to execute arbitrary OS commands, potentially taking full control of compromised servers. The vulnerability, designated CVE-2026-21571, is just one of several reported security risks, including CVE-2026-40372, CVE-2026-39813, CVE-2026-39808, CVE-2026-22679, and […]

Anthropic Mythos Breached via Vendor Access

Anthropic’s Mythos cybersecurity tool has been breached by an unauthorized group through a third-party vendor environment. This breach occurred on the very day the Claude Mythos Preview model was announced. Despite strict access controls and limited release to elite tech companies like Apple and Amazon, the group exploited contractor accounts. They discovered the tool’s online […]

Vercel OAuth Breach Ties to Context.ai

The Vercel OAuth breach ties to a clever exploitation involving the compromise of Context.ai, serving as a stark reminder of the vulnerability inherent in trust chains. At the center of this incident lies a sophisticated MITRE T1199 trust-chain attack, which enabled unauthorized access by exploiting the trust relationships between connected applications. Organizations leveraging Google Workspace […]

Microsoft SharePoint: 1,300 Servers Under Attack

Over 1,300 Microsoft SharePoint servers currently face significant security risks as they remain unpatched against a major spoofing vulnerability. This flaw, initially exploited as a zero-day vulnerability, continues to be targeted in ongoing attacks, leaving these servers exposed to cyber threats. Despite the known risks, system administrators have yet to address this issue comprehensively, allowing […]

CISA Warns of Supply-Chain Hack in Axios Npm

CISA warns organizations of a significant supply chain compromise impacting the Axios npm package. The compromised package reportedly delivers a remote access trojan, raising major cybersecurity concerns. This development highlights the increasing threats within software supply chains, where seemingly benign updates might harbor malicious code. Organizations relying on the Axios npm package should scrutinize their […]

Darktrace Finds ZionSiphon Targeting Israeli Water

Darktrace finds the ZionSiphon malware, explicitly designed to disrupt operational technology systems in Israel’s water sector, according to recent research by the firm. This malware targets critical infrastructure, specifically desalination and water treatment facilities, raising concerns about potential impacts on public utilities. The ZionSiphon malware aims to infiltrate these systems, potentially manipulating processes essential for […]

Vect, BreachForums, TeamPCP Form Ransomware Pact

Vect has cemented its collaboration with BreachForums and TeamPCP, aiming to enhance its model for industrialized ransomware while expanding its Ransomware-as-a-Service (RaaS) operations. The alliance underscores a growing trend of cybercriminal entities seeking to professionalize and industrialize their illicit activities. This strategic move could significantly amplify the scale and impact of their ransomware attacks, posing […]

Bluesky Hit by 24-Hour DDoS; 313 Team Claims

Bluesky, a decentralized, open-source microblogging platform akin to X (formerly Twitter), suffered a 24-hour service disruption due to a sophisticated DDoS attack that began on April 15. A pro-Iran hacker group named 313 Team claimed responsibility, amplifying concerns about cybersecurity threats against social media platforms. The attack resulted in interrupted feeds, notifications, threads, and search […]

Adaptavist Breach Sparks Ransomware Boast

Adaptavist breach sparks ransomware concerns as cyber attackers reportedly gain access to a significant cache of data. The group is already exploiting the breach by sending fraudulent emails, posing as Adaptavist associates. Recipients should exercise caution, as these emails may appear credible at first glance. The attackers, who have claimed responsibility, boast about the size […]

NGate Hides in HandyPay to Steal Card Data

The NGate malware is hiding within a counterfeit version of HandyPay, a trusted mobile payment app, to target Android users. This fraudulent variant takes advantage of Near-Field Communication (NFC) technology to steal credit card information from unsuspecting users. The trojanized application appears legitimate, which helps it bypass many security protocols and evade immediate detection. Cybersecurity […]

GitHub Comments Hijack Claude, Gemini, Copilot

A new cybersecurity threat, known as “Comment and Control,” has emerged as a critical vulnerability, jeopardizing systems through GitHub comments. This threat exploits AI coding agents such as Claude Code, Google’s Gemini CLI, and GitHub Copilot, showcasing severe security gaps. These vulnerabilities allow attackers to hijack AI agents directly within GitHub, executing harmful commands that […]

SideWinder Phish Steals South Asian Webmail Logins

SideWinder, a notorious advanced persistent threat group, has intensified its operations in South Asia with a sophisticated phishing campaign. The group employs a fake Chrome PDF viewer and a replica of the Zimbra email portal to steal government webmail credentials—a tactic known as the SideWinder phish. This campaign has seen relentless targeting since February 2026, […]