loader image
Aviation Faces Ransomware and Data Extortion

In recent years, the aviation sector has increasingly become a prime target for ransomware operators and data extortion groups. Airlines, airports, and aerospace manufacturers form a tightly connected ecosystem where an attack on one vendor can disrupt services across the board. The September 2025 incident at Collins Aerospace highlighted the potential chaos, creating widespread delays […]

Palo Alto PAN-OS Flaw Exploited Gives Root Access

A critical vulnerability in Palo Alto Networks’ PAN-OS software is actively being exploited, granting attackers root access to affected systems. The flaw, documented as CVE-2026-0300, is a buffer overflow that opens the door to potential full system compromise. Cybersecurity experts are sounding alarms about this threat, which targets Palo Alto firewalls. Organizations using these systems […]

Microsoft Edge Keeps Saved Passwords in Cleartext

Microsoft Edge exposes a major security flaw, decrypting all saved passwords into cleartext memory each time the browser launches. This discovery, unveiled by PaloAltoNtwks Norway’s researcher @L1v1ng0ffTh3L4N, reveals a significant oversight in Edge’s password handling. Unlike Google Chrome, which decrypts credentials only as needed, Microsoft Edge loads the entire vault into plaintext memory at startup, […]

LinkedIn Locks GDPR Behind Paywall, NOYB Files

European privacy advocacy group noyb has taken action against LinkedIn by filing a complaint with the Austrian data protection authority. They allege that LinkedIn locks GDPR rights behind a paywall, making it difficult for users to exercise their legal rights without obtaining a premium subscription. This act, according to noyb, could challenge the core tenets […]

Android Zero-Click Bug Lets Attackers Open Shell

The latest Android security challenge involves a critical flaw, tracked as CVE-2026-0073, that researchers have identified as an android zero click bug granting attackers remote access without user interaction. This vulnerability exists in the adbd subcomponent, part of Android’s core system, allowing remote code execution. Attackers can exploit this by being on the same local […]

Apache HTTP Server Flaw Risks RCE on Millions

The Apache Software Foundation has released a crucial update addressing an apache http server flaw that leaves millions susceptible to cyber threats. This update, for version 2.4.67 of the Apache HTTP Server, patches five vulnerabilities, including a double-free bug that could allow remote code execution (RCE). This vulnerability, labeled CVE-2026-23918, affects version 2.4.66, was uncovered […]

Data Centers Must Be Critical Infrastructure

Data centers have become integral strategic linchpins in today’s digital economy, especially with the rapid advancements in artificial intelligence. Experts in the industry stress the necessity of recognizing these hubs as critical infrastructure due to their increasing vulnerability to both physical and cyber threats. AI’s growth pushes these facilities into the spotlight not just as […]

MITRE Overhauls ATT&CK to Counter AI Attacks

MITRE overhauls ATT&CK with the release of version 19, introducing significant structural changes aimed at enhancing industrial cybersecurity. This update comes as artificial intelligence-driven threats begin to surface, demanding robust detection strategies. With the structural overhaul, organizations can expect improved visibility across industrial environments, a critical need as cyber threats grow increasingly sophisticated. The updated […]

FreeBSD DHCP Bug Lets Attackers Run Code as Root

security flaw in its default IPv4 DHCP client. Identified as CVE-2026-42511, this vulnerability could let a local network attacker execute code with root privileges. The risk stems from the way the client processes incoming data, potentially allowing unauthorized control over affected systems. The FreeBSD Project has issued a critical security advisory urging users to update […]

Bluekit Phishing Kit Packs AI, 40 Templates

The Bluekit phishing kit is a new tool under development boasting AI features and over 40 attack templates. Varonis Threat Labs discovered this kit, revealing its advanced functions like automated domain setup, spoofing, and geolocation tricks. Bluekit provides a comprehensive platform for phishing operations, targeting major services such as iCloud, Gmail, and Twitter. It centralizes […]

Jenkins Patches Plugins for RCE, XSS Flaws

The Jenkins project has issued a security advisory highlighting critical vulnerabilities within its extensive plugin ecosystem. These updates play a crucial role as Jenkins patches plugins to mitigate a range of threats, from remote code execution (RCE) to cross-site scripting (XSS) flaws. The advisory addresses several high-severity issues, ensuring developers can fortify their continuous integration […]

SAP npm Packages Compromised to Steal Credentials

The security landscape faced a significant breach as multiple official SAP npm packages were compromised. This event appears connected to a TeamPCP supply-chain attack targeting the theft of credentials and authentication tokens from developers’ systems. Cybersecurity experts believe the attackers sought access to sensitive developer information, potentially impacting a wide array of projects relying on […]