loader image
WinRAR ‘Zeroplayer’ Flaw Powers Spy Arsenal

A newly discovered exploit known as the WinRAR Zeroplayer flaw has emerged as a high-value tool for state-sponsored actors and cybercriminals. Tracked as CVE-2025-8088, the vulnerability affects one of the world’s most widely used file archivers, making it a prime target for espionage campaigns and covert intrusions. Security researchers recently observed a growing wave of […]

Grist Sandbox Bug Lets Spreadsheets Run Code

A critical vulnerability dubbed CVE-2026-24002 exposes a powerful attack vector through a Grist sandbox bug, according to researchers at Cyera Research Labs. The flaw in the Grist-Core platform allows malicious spreadsheet formulas to bypass sandbox protections, opening the door to remote code execution (RCE). Attackers could weaponize seemingly harmless spreadsheets to compromise entire systems. This […]

Poland Energy Grid Attack Hits 30 Sites

A sophisticated cyberattack struck the Polish power infrastructure in late December, targeting around 30 distributed energy resource sites in what officials are calling a significant poland energy grid attack. The incident disrupted systems at multiple facilities nationwide, including combined heat and power plants, as well as wind and solar energy dispatch centers. Security analysts say […]

Google Patches High-Severity Background Fetch Flaw

Google patches a high-severity vulnerability tracked as CVE-2026-1504 in the latest Chrome Stable update, issued on January 28. The new release—version 144.0.7559.109/110 for Windows and macOS, and 144.0.7559.109 for Linux—targets a flaw involving the Background Fetch API. This security issue could allow malicious actors to exploit browser behavior and potentially compromise user data. The vulnerability […]

Fortinet Blocks Exploited FortiCloud SSO Zero-Day

Fortinet blocks an exploited FortiCloud single sign-on (SSO) vulnerability as it works to develop and release a permanent fix. The company confirmed that threat actors have already taken advantage of the zero-day flaw, identified as CVE-2026-24858, which allows authentication bypass in FortiCloud SSO. In response, Fortinet has disabled SSO connections from devices running affected firmware, […]

WhatsApp Enables Lockdown for High-Risk Accounts

WhatsApp enables a lockdown feature designed to defend high-risk users from sophisticated cyber threats, according to an announcement from Meta. The new “Strict Account Settings” option empowers users to apply the most restrictive privacy controls with just a few taps. Once activated, the feature blocks attachments and silences calls from unknown contacts, limiting potential attack […]

Salt Typhoon Accused of Spying on PM Aides’ Phones

A China-linked cyberespionage group, dubbed Salt Typhoon, is accused of infiltrating mobile devices belonging to aides of UK prime ministers, according to reports. The attackers allegedly gained access to handsets used by senior government personnel, raising alarms over the potential compromise of sensitive communications. Salt Typhoon, suspected to operate under state direction, allegedly conducted the […]

WinRAR Defect Exploited for Espionage by States

Cybercriminals and advanced threat actors linked to nation-states are actively leveraging a WinRAR defect exploited for over six months to launch targeted attacks. The flaw has become a reliable entry point in espionage campaigns against military, government, and technology organizations, according to new threat intelligence reports. These malicious actors use the vulnerability to gain persistent […]

Microsoft Teams Hijacked to Steal Credentials

A newly uncovered phishing campaign has seen Microsoft Teams hijacked by cybercriminals using the platform’s native guest-invite feature to deploy malicious content under the guise of trusted Microsoft services. Attackers create fake teams with alarming financial references and invite victims via legitimate Teams email addresses, bypassing standard security checks like SPF, DKIM, and DMARC. One […]

Microsoft Patches Office Zero-Day Used in Attacks

Microsoft released a critical security update after attackers exploited a zero-day vulnerability in its Office suite. The flaw, tracked as CVE-2026-21509, allows adversaries to bypass essential security defenses, prompting Microsoft to act swiftly. With this update, Microsoft patches Office against an actively used exploit that poses a real-world risk to users. Security researchers identified the […]

EU Probes X Over Grok Sexual Images

The European Commission has opened a formal inquiry as the EU probes X over its deployment of the Grok artificial intelligence tool, which has been linked to the production of sexually explicit images. Regulators are examining whether the company adequately assessed potential risks before releasing the AI system to users. According to officials, the investigation […]

OpenAI’s ChatGPT Ads Cost 3x More Than Meta

OpenAI is rolling out promotional content directly within its ChatGPT platform, and investors are watching closely. The move highlights how OpenAI’s ChatGPT ads cost nearly three times more than Meta’s, despite relying on far less user data. The decision raises questions about targeting precision and value, as ChatGPT gathers minimal personal information compared to social […]