loader image
Russian State Hackers Exploit Microsoft Flaw

Russian state hackers began exploiting a newly disclosed Microsoft Office vulnerability to target systems in Ukraine and the European Union, according to Ukraine’s cybersecurity agency. The country’s Computer Emergency Response Team, CERT-UA, reported that attackers moved quickly after Microsoft revealed the flaw, tracked as CVE-2026-21509, in early January. The vulnerability affects how Microsoft Office applications […]

Poland Detains Defense Official in Russia Spy Case

Poland detains a defense official on allegations of spying for Russia, authorities said, in a move that intensifies tensions between Warsaw and Moscow. The suspect, a 60-year-old Polish citizen, worked in the Ministry of National Defense’s strategy and planning department. He was involved in military modernization projects, according to government officials. Authorities arrested the man […]

Hikvision AP Flaw Lets Users Run Commands

A newly disclosed vulnerability in multiple Hikvision wireless access point models poses a high-severity risk to enterprise networks. The Hikvision AP flaw, tracked as CVE-2026-0709, allows attackers with valid credentials to execute arbitrary commands due to weak input validation within the WAP firmware. The vulnerability carries a CVSS v3.1 base score of 7.2. This flaw […]

Russian Legion Targets Danish Energy, Health Sites

A newly formed hacker coalition known as the Russian Legion has launched a coordinated cyberattack campaign against Denmark, targeting key sectors and government websites. The group, comprising Cardinal, The White Pulse, Russian Partizan, and Inteid, announced its formation on Jan. 27, 2026. Within 24 hours, it issued an ultimatum demanding that Denmark cancel a 1.5 […]

Google Play App With 50K Installs Deploys Anatsa

A malicious Google Play app disguised as a document reader has infected over 50,000 Android devices with a powerful banking trojan known as Anatsa. Security researchers at Zscaler ThreatLabz uncovered the app, which initially appeared legitimate but functioned as an installer for the malware. Once downloaded, Anatsa gained elevated permissions and deployed its full payload, […]

APT28 Exploits Microsoft Office Zero-Day

Russian-backed hackers from APT28 are exploiting a newly discovered Microsoft Office zero-day vulnerability, according to Ukraine’s CERT. The agency warned that APT28 exploits Microsoft Office through this flaw, moving from public disclosure to active use within days. The speed of the exploitation underscores the growing efficiency of targeted cyber threats. Security researchers say attackers are […]

Two AI Assistants Secretly Send Code to China

A newly surfaced report raises alarm over two AI assistants widely used by software developers, revealing they quietly transmit all processed code to China. These coding tools, employed by approximately 1.5 million developers globally, may compromise sensitive data by sending it outside user control without consent or transparency. The covert transfer of proprietary or confidential […]

Google Says ShinyHunters Widens Cloud Extortion

Google says the ShinyHunters threat group has significantly expanded its operations, using new tactics to extract sensitive cloud-based information from multiple organizations. The attackers now deploy voice phishing and fake websites that mimic corporate login portals to steal credentials and bypass multi-factor authentication. They often impersonate IT staff over the phone to trick employees into […]

Notepad++ Updates Hijacked Through Host Compromise

Nation-state hackers hijacked Notepad++ updates by exploiting infrastructure at the app’s hosting provider, redirecting update traffic to attacker-controlled servers, according to the project’s maintainers. The incident, first detected in June 2025, did not stem from any vulnerability in Notepad++ itself but from unauthorized access at the server level hosting the updates. Security experts found that […]

MongoDB Servers Wiped, Ransom Notes Left

Hackers are launching automated attacks that have left thousands of MongoDB servers wiped after discovering them exposed on the public internet without authentication. Using simple scanning tools, threat actors identify databases running on port 27017, delete stored information, and leave behind ransom notes demanding payments of $500 to $600 in Bitcoin. Recent analyses reveal that […]

CERT Polska: Attacks Fail to Halt Power, Heat

Cybersecurity experts at CERT Polska revealed a wave of targeted cyberattacks on a Polish manufacturing firm and energy sector sites, noting the cert polska attacks fail to impact power generation or heat distribution systems. Although the attacks were sophisticated and aimed at critical infrastructure, response teams contained the threats before they could cause physical damage […]

SolarWinds Fixes Four Unauthenticated RCE Bugs

SolarWinds fixes a series of high-impact flaws in its Web Help Desk platform, releasing a security update that patches six vulnerabilities—four of which attackers could exploit without authentication. These critical issues, identified by researchers from watchTowr and Horizon3.ai, include remote code execution (RCE) risks and authentication bypasses. Among the flaws, CVE-2025-40552 and CVE-2025-40554 allow access […]