loader image
Europol Warns on Evolving Maritime Cocaine Threat

Europol warns that criminal organizations are rapidly changing their methods to smuggle cocaine into Europe through maritime routes, according to a report released Thursday. The analysis, titled “Diversification in Maritime Cocaine Trafficking Modi Operandi,” outlines how organised crime networks adapt their tactics to bypass detection and exploit weaknesses in port security across Europe. The report […]

Stanley Toolkit Fakes Chrome URLs, Sells $6,000

A newly discovered cybercrime tool known as the “Stanley” toolkit fakes Chrome browser URLs and is being sold for $6,000 on Russian-speaking hacking forums. Researchers say the toolkit disguises phishing domains by manipulating how URLs appear in Google Chrome, making it difficult for users to detect fraudulent sites. The “Stanley” toolkit operates by exploiting Chrome’s […]

Instagram Flaw Exposes Private Posts to Anyone

A newly disclosed server-side instagram flaw gave attackers the ability to access private posts and captions without authentication, security researcher Jatin Banga revealed this week. The issue exploited Instagram’s mobile web infrastructure using manipulated HTTP headers and bypassed standard privacy safeguards. By crafting a GET request with mobile user-agent headers, attackers triggered a JSON response […]

Vercel Hosting Abused to Push Remote Access Tool

A recent phishing campaign, active from November 2025 to January 2026, has seen Vercel hosting abused to distribute a remote access tool under the guise of legitimate online services. Threat actors behind the operation crafted emails with financial lures like overdue invoices and shipping documents, prompting users to click embedded links. These links led to […]

ESET Ties DynoWiper Grid Attack to Sandworm

ESET ties a DynoWiper attack on Poland’s power grid in December 2025 to Sandworm, a Russia-aligned advanced persistent threat group. Security researchers at the cybersecurity firm said the destructive malware targeted critical infrastructure, disrupting power systems in the region. ESET linked the activity to Sandworm based on malware forensics and operational tactics resembling past campaigns […]

MITRE Unveils Embedded Systems Threat Matrix

MITRE unveils a new cybersecurity framework aimed at safeguarding embedded systems powering U.S. critical infrastructure and defense technology. Developed with the Air Force’s Cyber Resiliency Office for Weapon Systems, the Embedded Systems Threat Matrix (ESTM) bridges a gap in protecting mission-critical platforms from sophisticated cyber threats. ESTM equips researchers, vendors, and security professionals with actionable […]

HPE Alletra Nimble Flaw Gives Remote Admin Access

A critical vulnerability in HPE Alletra and Nimble Storage platforms could allow remote attackers to gain full administrative access, exposing enterprise networks to serious risks. Known as CVE-2026-23594, the HPE Alletra Nimble flaw affects specific versions of Alletra 6000, 5000, and Nimble Storage Hybrid and All Flash systems. It enables privilege escalation over the network […]

Nike Hit by WorldLeaks; 481,183 Users Exposed

Global sportswear giant Nike was hit by an alleged ransomware attack claimed by WorldLeaks, a cybercriminal group focused on data extortion. The group listed Nike on its darknet leak site on Jan. 22, threatening to release stolen data by Jan. 25, 2026, at 6 p.m. GMT. The post drew more than 400 views within hours. […]

TikTok Forms U.S. Joint Venture Under Trump Order

TikTok forms a joint venture named TikTok USDS Joint Venture LLC to maintain its presence in the United States, the company said Friday. The move complies with an executive order signed in September 2025 that outlines new operating conditions for foreign-owned apps in the U.S., according to the platform. The announcement comes amid continued scrutiny […]

Under Armour Probes Breach of 72 Million Emails

Under Armour probes a data breach that exposed the email addresses and personal information of millions of customers. The Baltimore-based athletic apparel company is currently investigating the incident, which reportedly compromised data belonging to 72 million individuals. According to preliminary findings, the intrusion occurred in late 2023. Security analysts say the exposed data includes email […]

Marlink Cyber Exposes ISC BIND Flaw Threatening DNS

Marlink Cyber exposes an ISC flaw in BIND that could disrupt critical infrastructure by taking DNS services offline, potentially causing widespread outages across internet-dependent systems. The vulnerability targets BIND, the widely used Domain Name System software that underpins much of the internet’s core functionality. If exploited, the flaw could prevent DNS servers from resolving addresses, […]

Osiris Ransomware Uses Fake Malwarebytes Driver

A newly emerged threat known as the Osiris ransomware struck a major Southeast Asian food service company in November 2025, leveraging a blend of built-in system utilities and dual-use tools. Cybersecurity researchers identified the malware as unrelated to a similarly named 2016 variant, highlighting its distinct and advanced nature. The attackers combined common Windows tools […]