loader image
Google Patches 10 Chrome Flaws, 3 Critical

Google has promptly released a crucial update for the Chrome Stable channel, addressing multiple security vulnerabilities. Notably, the update resolves 10 vulnerabilities, with three deemed critical and seven classified as high-risk. This proactive move by Google patches Chrome flaws that could potentially compromise user data and browser stability. Users should prioritize updating Chrome to secure […]

Russian Coruna iOS Exploit Powers Global Attacks

Recent analysis from Google and iVerify has unveiled a potent threat in the form of the Russian Coruna iOS exploit. Initially utilized by Russian state actors, this sophisticated exploit kit is now being repurposed across expansive criminal operations worldwide. Experts have highlighted the Coruna kit’s role in breaching robust iOS security measures, signaling a significant […]

Europol Dismantles Tycoon 2FA Phishing Kit

Europol dismantles Tycoon 2FA, a notorious phishing-as-a-service operation that facilitated large-scale credential harvesting attacks. This collaborative effort, involving law enforcement agencies and cybersecurity firms, has effectively curtailed a major tool of cybercriminals. Emerging in August 2023, Tycoon 2FA allowed attackers to execute adversary-in-the-middle (AitM) phishing attacks, duping users into revealing sensitive information. Described by Europol […]

Silver Dragon Uses Google Drive as Command Channel

The Silver Dragon group, linked to China, uses Google Drive to orchestrate covert communication targeting Europe and Asia. As part of the APT41 umbrella, Silver Dragon exploits vulnerabilities in public internet servers and uses phishing emails with malicious attachments to infiltrate systems. After gaining access, the group utilizes the commercial tool Cobalt Strike for maintaining […]

Microsoft AzCopy Abused to Exfiltrate Data

The cybersecurity landscape is facing a new threat as ransomware operators have started using Microsoft’s AzCopy, a trusted command-line tool, to facilitate data exfiltration during attacks. This utility, designed for transferring data to Azure Storage, helps attackers extract sensitive information undetected by exploiting its seamless integration with business operations. Researchers at Varonis Threat Labs discovered […]

Google Cloud Hosts Phishing Redirects

A sophisticated phishing campaign exploits Google Cloud by using its storage services to host malicious redirects, making fraudulent emails more convincing. This approach allows attackers to evade standard email security measures by leveraging Google’s trusted domain. Initially detected in March 2026, the campaign employs over 25 distinct phishing emails targeting a single user. These emails […]

Iranian APTs Target Global Infrastructure

In the wake of rising geopolitical tensions, Iranian APTs are intensifying cyber threats against critical infrastructure, expanding the conflict beyond traditional battlefields. Following Operation Lion’s Roar by the U.S. and Israeli forces targeting Iran, cyberspace has become a focal arena for retaliation. Iranian state-affiliated groups, known for sophisticated advanced persistent threat capabilities, are aggressively targeting […]

Amazon Data Centers Hit in Iranian Strikes

Iranian forces have executed drone strikes targeting Amazon data centers in the United Arab Emirates and Bahrain, raising alarm over the tech industry’s exposure to physical threats. The assault directly hit two AWS facilities in the UAE and impacted an additional center in Bahrain when a drone crashed nearby. This incident underscores the critical need […]

AVideo Flaws Let SQL Injection Lead to RCE

Security researchers have discovered critical AVideo flaws in the widely-used open-source video streaming platform, which content creators and businesses utilize to host and monetize video content. The identified vulnerabilities include a SQL injection flaw and a remote code execution risk, posing significant security threats. Exploiting these vulnerabilities could allow attackers unauthorized access to sensitive data […]

Facebook Hit by Global Outage

Facebook was hit by a global outage starting at 4:15 PM ET, preventing users worldwide from accessing their accounts. Many reported encountering the message, “Account Temporarily Unavailable,” indicating a site issue that the company aims to resolve quickly. According to Meta’s status page, other services such as Ads Manager, Instagram Boost, and WhatsApp Business API […]

WordPress Plugin Opens Admin Takeover

A critical vulnerability in a widely-used WordPress plugin opens the door to admin takeover for over 60,000 websites. The flaw resides in the User Registration & Membership plugin, a favored tool for managing tiered subscription plans and custom login features. This security gap could allow malicious actors to escalate privileges, potentially gaining complete administrative control. […]

OpenStack Vitrage Faces Critical RCE Flaw

OpenStack Vitrage faces an RCE vulnerability, as security researcher Khalil Lemtaffah from Nokia has uncovered a significant remote code execution flaw in the platform’s Root Cause Analysis service. This vulnerability presents a considerable security threat, particularly given OpenStack’s extensive use in private and public cloud environments. The identified vulnerabilities, CVE-2026-2256 and CVE-2026-28370, highlight systemic risks […]