loader image
Rapid7 Alert Reveals GenAI Malware Factory

A recent alert by Rapid7 has revealed a GenAI-powered malware factory crafted by threat actors to create over 1,000 attack files. This unexpected exposure on a WebDAV server provided insights into how these actors assemble, test, and distribute malicious software. Attackers targeted Windows users with deceptive documents and phishing lures exploiting WebDAV and file explorer […]

ServiceNow Flaw Exploited Days After Disclosure

Security researchers reported swift exploitation of a newly disclosed vulnerability within the ServiceNow AI platform, known as CVE-2026-6875. This flaw can lead to remote code execution, marking a significant concern for enterprises relying on ServiceNow’s services. Cyber attackers began targeting this vulnerability mere days after its disclosure, escalating the urgency for affected organizations to implement […]

Estée Lauder Confirms Oracle EBS Data Theft

Estée Lauder confirms an Oracle EBS zero-day hack in August 2025 that led to the exfiltration of personal, financial, and health information. The attack targeted the company’s Oracle EBS instance, a software suite commonly used by large enterprises for supply chain, financial, and human resources management. The breach has raised significant concerns about data protection, […]

Coca-Cola Halts Fairlife US Production

Coca-Cola halts Fairlife production across the United States following a debilitating ransomware attack. Company officials clarified that this disruption has not compromised the integrity or safety of its products. Importantly, Fairlife’s Canadian facilities continue operations without any interruptions. The interruption underscores the increasing threat of cyberattacks on major corporations, emphasizing the urgent need for robust […]

Google Gemini Fuels Hacker’s Dental Clinic Botnet

A Russian-speaking hacker, known by the alias ‘bandcampro,’ has adopted Google’s open-source Gemini CLI artificial intelligence to bolster their cyber operations, illustrating how Google Gemini fuels botnet control. This hacker employed the AI to break passwords and manage a botnet comprising eight dental clinic computers. The activities were uncovered through analysis of 200 Gemini CLI […]

F5 Patch Warns: NGINX Bug Enables Server Takeover

F5 has released a patch, highlighting warnings for a severe vulnerability in NGINX, tracked as CVE-2026-42533. This vulnerability, scoring 9.2 on the CVSS, allows attackers to exploit heap buffer overflow via crafted HTTP requests, potentially leading to remote code execution. The flaw affects versions 0.9.6 to 1.31.2 of NGINX, both open source and NGINX Plus. […]

Microsoft Fixes Windows Bug Causing Dell Shutdowns

Microsoft fixes a Windows bug with the release of an emergency update aimed at addressing shutdowns on some Dell PCs. This quick response follows reports of adverse impacts caused by the July 2026 Windows 11 security updates. Users experienced unplanned shutdowns, leading to considerable disruptions in operations. By rolling out the KB5121767 out-of-band (OOB) update, […]

Ernst & Young Hack Exposes Client Financial Data

Hackers gained unauthorized access to sensitive data hosted by Ernst & Young, targeting a third-party management platform in a recent breach. The Ernst and Young hack compromised the personal information of individuals, including names, addresses, Social Security numbers, and credit/debit card details. Such breaches highlight vulnerabilities in data management systems and emphasize the critical need […]

OkoBot Steals Crypto Seeds via ClickFix

OkoBot, a sophisticated new malware strain, targets cryptocurrency users by deceitfully embedding itself within fake software, thereby executing its primary function: stealing vital crypto seed phrases. Security firm Kaspersky disclosed that OkoBot, employing tactics like ClickFix and hidden browser extensions, goes beyond mere data theft. This malicious software clandestinely intercepts users’ workflow by recording activities […]

OpenAI Taps GPT‑Red to Fight Prompt Injection

OpenAI taps GPT-Red to bolster the security of its latest AI model, GPT-5.6 Sol. The company unveiled GPT-Red, an internal automated red-teaming system designed to identify and address prompt injection vulnerabilities before widespread deployment. This proactive measure aims to strengthen AI models against sophisticated prompt injection attacks. OpenAI described GPT-Red as a powerful entity, noting […]

Aerdts Faces MPs Over Public Cloud Risk

Aerdts faces MPs as they pose questions in the Tweede Kamer regarding the comprehensive revision of the Dutch government’s cloud policy. The scrutiny comes amid growing concerns over the potential risks associated with the public cloud. State Secretary Aerdts for Digital Economy is being urged to clarify the implications these changes might hold for data […]

Adobe Patches ColdFusion Flaws

Adobe has taken steps to bolster cybersecurity by releasing patches for several significant vulnerabilities in its ColdFusion software. These patches target versions 25.10, 23.21, and earlier, effectively addressing critical security gaps. The vulnerabilities could potentially lead to arbitrary code execution, unauthorized privilege escalation, reading of random files, and bypassing of security measures. As of the […]