loader image
BlackSanta EDR Killer Targets HR Departments

A new cybersecurity threat, identified as the BlackSanta EDR killer, has been actively targeting human resource departments for over a year. This threat, attributed to a Russian-speaking group, utilizes sophisticated malware specifically designed to penetrate security systems commonly used by such departments. The malware’s primary function includes bypassing Endpoint Detection and Response (EDR) mechanisms, leaving […]

Ally Plugin’s SQL Flaw Threatens 400,000 Sites

A high-severity SQL Injection vulnerability has been discovered in a popular web accessibility and usability tool, leading to significant concerns. The issue within the Ally plugin’s SQL flaw jeopardizes the security of over 400,000 active WordPress sites. The flaw allows malicious actors to manipulate database queries, potentially accessing sensitive information or compromising site functionality. Experts […]

Azure Arc Flaw Lets Local Users Hijack Azure ID

A new security vulnerability, known as the Azure Arc flaw, poses a significant threat to Windows users. CVE-2026-26117 impacts Azure Arc on Windows, allowing a local privilege escalation with potentially severe consequences. Low-privileged users on any Arc-joined Windows host could exploit this flaw to gain higher access levels. Once elevated, they might abuse the Arc […]

Salesforce Sites Scanned by Custom AuraInspector

Threat actors are actively scanning Salesforce sites, particularly those utilizing Experience Cloud, using a modified AuraInspector tool. Salesforce’s Cybersecurity Operations Center warns that these adversaries aim to exploit misconfigurations and access sensitive data. AuraInspector, originally developed by Google/Mandiant, is an open-source auditing tool for Salesforce’s Aura and Experience Cloud applications. It evaluates exposure risks by […]

Lazarus Uses Fake LinkedIn to Target AllSecure CEO

Lazarus uses a fake LinkedIn profile to lure top executives in cyber-espionage schemes, with the latest target being the CEO of AllSecure. Exploiting the professional networking platform, the notorious North Korean hacking group masqueraded as a legitimate industry interviewer to deceive the executive. This audacious move highlights the growing sophistication and boldness of cyberthreats directed […]

Ericsson US Confirms Vendor Hack Exposed Data

Ericsson US confirms a data breach following a cyberattack on one of its service providers, which led to the exposure of sensitive information pertaining to employees and customers. On April 28, 2025, the service provider detected unusual activity suggesting unauthorized data access. To address the situation, they enlisted external cybersecurity experts and notified the FBI. […]

Poland Police Bust Teen DDoS Kit Sellers

Poland police busted a group of teenagers who allegedly sold software tools designed for launching distributed denial-of-service (DDoS) attacks. Authorities have accused these minors of profiting by providing resources that targeted and disrupted popular websites. The investigation revealed that these DDoS kits allowed buyers to flood specific websites with traffic, causing significant operational disruptions. Polish […]

Claude Code Lure Steals Developers’ Credentials

Cybercriminals are employing the Claude Code lure tactic to deceive developers and IT professionals. These attackers set up counterfeit download pages that imitate Claude Code, a legitimate AI coding assistant. Users, seeking official software, inadvertently download an infostealer malware. This exploit reflects a troubling trend where popular AI tools are leveraged to gain unwarranted trust. […]

Amazon’s AWS-LC Crypto Flaws Expose Cloud Risk

Cybersecurity experts have revealed critical vulnerabilities in Amazon’s AWS-LC, an open-source cryptographic library integral to Amazon’s cloud infrastructure. These amazon aws lc flaws raise significant concerns due to their potential threat to cloud-based operations. The vulnerabilities identified include CVE-2026-3338, CVE-2026-3337, CVE-2026-3336, and CVE-2026-2256, which present unauthenticated bypass risks that could compromise data security across Amazon […]

China-Linked Hackers Hit Telcos in South America

China-linked hackers hit telcos in South America with a sophisticated new malware toolkit, posing significant threats to regional telecommunications security. The APT group, identified as UAT-9244, has been active since 2024, exploiting vulnerabilities in Windows, Linux, and network-edge devices. This operation highlights the hackers’ ability to penetrate diverse system environments, which raises alarms about the […]

Iranian Hackers Weaponize IP Cameras

Iranian hackers weaponize cameras as cyber warfare takes center stage in the Middle East. According to a recent report by Check Point Research, Iranian threat actors have been manipulating IP cameras to gain a tactical advantage in regional conflicts. This digital strategy acts as a “force multiplier,” enhancing traditional military operations with real-time intelligence feed. […]

Everon OCPP Flaws Threaten EV Charging Grid

Cybersecurity experts have issued a warning about a series of vulnerabilities in Everon OCPP backends, the core system managing electric vehicle charging stations globally. These flaws threaten the stability and security of the EV charging infrastructure, raising concerns about potential disruptions. With the global push towards electric vehicles accelerating, these discoveries highlight crucial risks in […]