loader image
Ivanti EPMM Under Single-IP RCE Siege

A critical remote code execution flaw, tracked as CVE-2026-1281, is affecting Ivanti Endpoint Manager Mobile (EPMM) and being heavily exploited, according to security data. GreyNoise reports that 83% of these attacks originate from one IP address, 193.24.123.42, registered to PROSPERO OOO, known for “bulletproof” hosting. This IP was notably absent from initial indicators of compromise […]

Joomla Framework Flaw Lets Attackers Hijack Sites

Critical security vulnerabilities have been discovered in the Joomla framework, specifically in the Novarain/Tassos Framework, exposing websites to significant threats like SQL injection and unauthorized file access. These flaws, located within multiple popular extensions such as Convert Forms and EngageBox, can lead to remote code execution if left unpatched. Security researchers identified three core weaknesses […]

287 Chrome Extensions Stole History of 37.4M

A covert campaign involving 287 Chrome extensions has compromised the browsing history of approximately 37.4 million users globally, according to new research. The scale of the breach represents nearly one percent of the Chrome user base, raising privacy concerns across the internet ecosystem. Researchers used a custom system of Docker containers and a man-in-the-middle proxy […]

Supply-Chain Attacks Fuel Cybercrime Economy

Supply-chain attacks fuel cybercrime by creating a ripple effect that links identity theft, SaaS platform compromise, and ransomware deployment, according to recent research. Analysts warn that these interconnected tactics allow threat actors to move laterally across digital ecosystems, amplifying overall damage. Once attackers gain a foothold in a software vendor or third-party provider, they can […]

Conpet Confirms Qilin Stole Data

Romania’s national oil pipeline operator, Conpet S.A., confirmed a data breach after the Qilin ransomware group launched a cyberattack on its systems last week. The confirmation comes amid growing concerns over ransomware targeting energy infrastructure across Europe, as Conpet confirms Qilin accessed and stole sensitive company information during the breach. While the company has not […]

Odido Telecom Breach Exposes 6.2 Million Accounts

A cyberattack on Odido Telecom exposed the personal data of 6.2 million customer accounts, the Dutch provider confirmed on Feb. 12. The Odido Telecom breach, discovered between Feb. 7 and 8, involved unauthorized access to the company’s customer relationship management system. Hackers downloaded sensitive information, including names, addresses, mobile numbers, email addresses, IBANs, and ID […]

Munich Report Says United States Threatens Order

The 2026 Munich Report, released by the Munich Security Conference, warns of a growing global shift toward destructive political strategies over measured reform. Rather than fostering cooperation and gradual change, governments are adopting a wrecking-ball approach that tears down institutions without offering stable alternatives. The report identifies the current U.S. administration as a leading force […]

FortiClientEMS Hit by Critical SQL Injection

A critical cybersecurity flaw has left FortiClientEMS hit by a serious SQL injection vulnerability, tracked as CVE-2026-21643. The issue affects Fortinet FortiClientEMS version 7.4.4 and allows remote attackers to execute arbitrary code without authentication by sending specially crafted HTTP requests. Security experts warn that the flaw could expose critical systems to full compromise. The vulnerability […]

Apple Fixes Dyld Zero-Day in Targeted Spy Attacks

Apple fixes a critical zero-day in the dyld component with the release of iOS and iPadOS 26.3 on Feb. 11, following reports of active exploitation in targeted attacks. The vulnerability, tracked as CVE-2026-20700, enables attackers with memory-write access to execute arbitrary code by corrupting dyld’s internal state. Google’s Threat Analysis Group identified the flaw, which […]

Russia Tries to Block WhatsApp for 100 Million

Russia tries to block WhatsApp nationwide in a move that affected over 100 million users, according to a public statement by the Meta-owned messaging platform. WhatsApp said the action is aimed at forcing users onto a Kremlin-backed alternative, which experts warn poses significant privacy risks. The disruption followed Roskomnadzor’s decision to remove WhatsApp from Russia’s […]

Morele.net Hacker Charged After 7 Years

A 29-year-old Polish man has been formally charged in a case that has lingered for years—the Morele.net hacker charged with breaching security and exposing personal details of around 2.2 million users. The incident, which occurred in 2018, compromised sensitive data including names, email addresses, phone numbers and partial credit card information. The breach targeted Morele.net, […]

Socelars Steals Facebook Ad Sessions on Windows

A stealthy malware known as Socelars steals Facebook Ad session data and other sensitive information from infected Windows systems, according to cybersecurity researchers. The spyware disguises itself as legitimate software, installs silently, and targets browser-stored session cookies—particularly from platforms like Facebook and Amazon. Once active, Socelars executes a three-stage attack. It first collects system details […]