loader image
Magento Stores Face Pixel-Sized SVG Stealer

Magento stores face malware threats as hackers embark on a widespread campaign leveraging the platform. The attackers conceal credit card-stealing scripts within a minuscule, pixel-sized Scalable Vector Graphics (SVG) image. This deceptive tactic affects nearly 100 online stores, enabling hidden malicious code to operate undetected. Users remain vulnerable while conducting transactions on compromised sites employing […]

Bitcoin Depot Loses $3.6 Million in Wallet Hack

Bitcoin Depot loses millions after hackers breached its systems, stealing $3.665 million in Bitcoin from its wallets. Bitcoin Depot operates one of the largest Bitcoin ATM networks globally. The cyberattack took place last month and has drawn attention to the vulnerabilities in the cybersecurity protocols of major cryptocurrency operators. As the popularity of crypto ATMs […]

U.S. Warns Iran-Linked Hackers Target Rockwell PLCs

U.S. agencies have issued a warning that Iran-linked hackers are actively targeting internet-connected programmable logic controllers (PLCs) in critical infrastructure sectors. The FBI and CISA highlighted these cyber threats in a joint advisory. These attackers focus on Rockwell/Allen-Bradley PLCs, aiming to disrupt essential services such as water, energy, and government systems through manipulation of data […]

Iran-Linked Group Hits 300 Israeli Microsoft Firms

An Iran-linked group has launched a sophisticated password-spraying campaign targeting over 300 Microsoft 365 environments in Israel and the UAE, intensifying cybersecurity challenges amid ongoing Middle Eastern conflicts. The campaign, attributed to a threat actor with connections to Iran, executed coordinated attacks in three distinct waves on March 3, March 13, and March 23, 2026. […]

Microsoft Warns Storm-1175 Uses 0-Day for Medusa

Microsoft warns that a financially motivated threat group, Storm-1175, is exploiting zero-day flaws in internet-facing assets to launch Medusa ransomware attacks. These high-paced intrusions can incapacitate organizations within 24 hours, taking advantage of newly disclosed software vulnerabilities before they are patched. The group targets unpatched “N-day” vulnerabilities and also exploits zero-day flaws, highlighting a sophisticated […]

German Police Identify REvil, GandCrab Bosses

German police have identified key figures behind the notorious ransomware groups, REvil and GandCrab. The Federal Police in Germany (known as BKA) named two Russian nationals as masterminds behind these cybercrime operations active between 2019 and 2021. The identification marks a significant development in the global fight against cybercrime. These ransomware groups have been responsible […]

Ninja Forms Flaw Exposes 50,000 WordPress Sites

A critical ninja forms flaw in the WordPress plugin has exposed approximately 50,000 websites to potential takeover. This vulnerability, identified as CVE-2026-0740, has been assigned a severity score of 9.8, highlighting the urgent need for action from site administrators. Discovered by security researcher Sélim Lanouar, the flaw permits unauthorized file uploads, which can lead to […]

Google Plans Post-Quantum Crypto Shift by 2029

Google plans a crypto shift by setting the goal to fully transition to post-quantum cryptography by 2029. This ambitious move underscores the tech giant’s commitment to enhancing digital security. While functional quantum computers might not emerge soon, Google’s proactive approach to crypto-agility is a significant step. Adapting to future cryptographic challenges is critical for companies […]

SANS Warns Skills Gap Threatens OT

The latest 2026 report from SANS warns a skills gap is widening in the cybersecurity field, placing critical infrastructure and operational technology (OT) sectors at significant risk of breaches. The report identifies a growing disparity in the capabilities required to protect vital systems, as well as the resources available to address these gaps. As the […]

Check Point Tracks Iranian Attacks on Israel UAE

Check Point tracks a wave of Iranian cyberattacks targeting critical sectors in Israel and the UAE, with a focus on the government and energy industries. These attacks, which employ password-spraying techniques, demonstrate a growing sophistication and persistence in threatening national infrastructures. Security researchers highlight the method’s effectiveness, as attackers use numerous common passwords to gain […]

Die Linke Faces Hackers Threatening Data Leak

Die Linke faces hackers after experiencing a serious cyberattack on its IT infrastructure in late March. The German political party confirmed the breach, revealing that hackers now threaten to leak potentially sensitive data. This incident has raised concerns over the security measures in place within political entities in Germany, especially as cyber threats become more […]

DeepLoad Uses ClickFix, WMI to Steal Logins

The emerging threat landscape has introduced a new challenge as DeepLoad uses the ClickFix social engineering tactic to distribute a sophisticated and previously undocumented malware loader. According to researchers at ReliaQuest, DeepLoad employs AI-assisted obfuscation and process injection to deftly bypass static scanning, making its detection challenging. Once deployed, the malware focuses on credential theft, […]