CYBER ATTACKS

China-Linked ‘Fire Ant’ Hackers Caught Hijacking Cisco Routers to Spy and Erase Their Tracks

Incident response firm Sygnia has detailed a sophisticated espionage campaign in which a China-linked group implanted malware directly inside Cisco routers and authentication servers to intercept credentials and erase evidence of its own presence.

PaperCut Issues Second Emergency Patch After Zero-Day Flaws Exploited in the Wild

PaperCut has rushed out two rounds of emergency patches after researchers found attackers chaining two zero-day vulnerabilities to gain remote code execution on unpatched NG and MF print servers, with active exploitation confirmed since August 26.

Security News

Critical Keycloak Flaw Let Attackers Reset Any Password Without Email Access

A critical bug in Keycloak's password reset flow, tracked as CVE-2026-18963 with a CVSS score of 9.1, could have let attackers take over any account without ever accessing the victim's email.

Four-Year Study Finds Over 9,300 Exposed AWS Keys Are Still Active, Hundreds With Full Admin Rights

A four-year study by Truffle Security found more than 9,300 exposed AWS access keys remain active today, including hundreds of root and administrator-level credentials capable of handing an outsider full control of a company's cloud account.

Subscribe

* indicates required

Intuit Mailchimp

Security Standards

DNS4EU – A Whitepaper

DNS4EU is a European Union initiative aimed at strengthening digital sovereignty and cybersecurity. Unlike foreign DNS services that often lack GDPR compliance and transparency,...

Regional

CVSS is Dead. CISA Just Made It Official.

For years, vulnerability management has been reduced to a simple equation: CVSS ≥ 9 = Drop everything and patch. The problem is that attackers don't think...

Vulnerabilities

Google Patches Actively Exploited Chrome Zero-Day in V8 Engine

Google has released an emergency Chrome update to fix a zero-day vulnerability in the browser's V8 engine that attackers are already exploiting in the wild. Users should update immediately.

CISA Adds Seven Actively Exploited Flaws to KEV Catalog, Including Two Maximum-Severity Bugs

CISA added seven actively exploited vulnerabilities, including two rated maximum severity, to its Known Exploited Vulnerabilities catalog, with attackers already using them to deploy reverse shells and cryptocurrency miners.

Nearly 22,000 Exchange Servers Remain Exposed to Critical Authentication Bypass Flaw

Nearly 22,000 Microsoft Exchange servers worldwide remain unpatched against a high-severity authentication bypass flaw with public exploit code, weeks after Microsoft released a fix.

Critical JFrog Artifactory Flaw Under Active Attack Just Days After Patch Release

Attackers are actively exploiting a critical authentication bypass in JFrog Artifactory that lets them create their own admin accounts, according to researchers at watchTowr. Self-hosted customers who have not yet patched should update immediately.

PaperCut Issues Second Emergency Patch After Zero-Day Flaws Exploited in the Wild

PaperCut has rushed out two rounds of emergency patches after researchers found attackers chaining two zero-day vulnerabilities to gain remote code execution on unpatched NG and MF print servers, with active exploitation confirmed since August 26.

Data Breaches

A dark web marketplace called Nexus is selling scans of more than 153 million US and Canadian driver's licenses that researcher Brian Krebs traced to identity verification firm IDScan.net, whose clients include Hertz, Target and FedEx. The FBI has opened an investigation and class action lawsuits have followed.

LATEST ARTICLES

Most Popular

1,321FollowersFollow
61,453SubscribersSubscribe

Write to Us

Want to report a concern or publish a security incident on our channel?