loader image
Palencia Man Arrested in NoName057(16) Probe

Authorities have arrested a man in Palencia suspected of collaborating with pro-Russia hacking groups, including CARR, Z-Pentest, and NoName057(16). Investigators allege the Palencia man arrested assisted a Ukrainian hacker in fleeing to Russia. This arrest highlights the increasing scrutiny on cyber activists believed to have ties with geopolitical conflicts involving Russia and Ukraine. The man’s […]

Linux KVM Flaw Lets Guest Corrupt Host Kernel

A newly uncovered flaw, known as CVE-2026-53359 or “Januscape,” has exposed a critical vulnerability in the Linux Kernel-based Virtual Machine (KVM). This linux kvm flaw, unnoticed for 16 years, allows a malicious guest to corrupt host kernel memory by exploiting KVM’s x86 shadow memory management logic. Affecting both Intel and AMD systems, the issue lies […]

Ex-MEP Kouloglou Infected Twice by Pegasus

Ex-MEP Kouloglou was infected twice with Pegasus spyware while involved in examining its misuse within the European Parliament, according to researchers. Stelios Kouloglou, who participated in the committee probing commercial spyware abuses, experienced the breaches during his tenure. Security researchers have confirmed these infections, shedding light on the controversial application of Pegasus, developed by Israel’s […]

DHS Confirms Hackers Breached HSIN

The Department of Homeland Security confirmed hackers breached the Homeland Security Information Network (HSIN), a critical platform for information-sharing among federal, state, local, and private-sector entities. This cyberattack has triggered an investigation to assess the extent of the breach and its potential impact on sensitive data. HSIN plays a pivotal role in fostering collaboration across […]

EvilTokens Kit Fuels Complete Email Fraud

The Eviltokens kit represents a significant threat, revolutionizing the landscape of device-code phishing. This kit creates a ‘complete business email compromise (BEC) operations environment,’ according to a Talos researcher. Cybercriminals utilize this tool to exploit vulnerabilities, streamline attacks, and increase their potential reward. By focusing on device-code phishing, the kit takes advantage of a critical […]

Oracle E-Business Flaw Under Attack, 950 Exposed

A critical vulnerability in Oracle E-Business Suite, identified as CVE-2026-46817, is currently under active attack, with approximately 950 systems exposed. Defused Cyber researchers reported that this flaw, affecting Oracle Payments versions 12.2.3 through 12.2.15, allows attackers to take over systems without authentication via HTTP. Although Oracle addressed this issue in its latest Critical Patch Update, […]

CISA Adds SharePoint RCE to KEV After Exploits

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) recently added a new vulnerability affecting Microsoft SharePoint Server to its Known Exploited Vulnerabilities catalog. Identified as CVE-2026-45659, this high-severity flaw carries a CVSS score of 8.8. The issue allows remote code execution due to the deserialization of untrusted data, posing significant security risks for users. CISA […]

Adobe ColdFusion Flaws Allow Remote Code Execution

Adobe has issued a crucial security update to address significant vulnerabilities in ColdFusion 2025 and 2023. These Adobe ColdFusion flaws, rated Priority 1, pose a risk for arbitrary code execution and privilege escalation. Affected versions include ColdFusion 2025 Update 9 and earlier, and ColdFusion 2023 Update 20 and earlier. The company strongly advises users to […]

Microsoft Pulls Forward Post-Quantum to 2029

Microsoft pulls forward its post-quantum cryptography timeline, setting a new target for 2029. This acceleration stems from recent advancements in quantum computing, which pose a growing threat to traditional encryption methods. Microsoft Azure’s Chief Technology Officer, Mark Russinovich, emphasized that these developments have altered the risk landscape. The tech giant is underscoring the urgency to […]

Amazon Fined $2.25M for Withholding Records

Amazon has agreed to pay a $2.25 million civil penalty following an allegation from the U.S. Federal Trade Commission (FTC) that the company obstructed identity theft victims from accessing crucial transaction records. The settlement stems from charges that Amazon intentionally withheld this information, which could aid victims in managing the impact of fraudulent activity on […]

Apple Patches Dozens of iOS, macOS, Safari Flaws

Apple has issued crucial updates for iOS, macOS, and Safari to patch numerous vulnerabilities that could affect users of iPhone, iPad, Mac, and its web browser. The company focused on strengthening security in several key components, including WebKit, the kernel, WebRTC, and Web Extensions. These vulnerabilities posed significant risks by potentially allowing attackers to execute […]

Cisco Acquires WideField to Boost Splunk SOC

Cisco has announced its intention to acquire WideField Security, a strategic move that aims to enhance Splunk’s Agentic Security Operations Center. By obtaining WideField, Cisco seeks to bolster its threat investigation capabilities, broadening the focus to include identity, credentials, sessions, and blast radius. This acquisition aligns with Cisco’s strategy to deliver comprehensive security solutions, reinforcing […]