Mustang Panda Abuses Zoho WorkDrive to Evade Detection in Espionage Campaign

Researchers have uncovered new cyber espionage campaigns conducted by the China-aligned threat group Mustang Panda, targeting Indian government agencies and the hydropower sector. The attackers…
Critical Oracle E-Business Suite Flaw Targeted in Active Attacks

Researchers have confirmed active exploitation of CVE-2026-46817, a critical vulnerability affecting Oracle E-Business Suite’s Oracle Payments File Transmission component. The flaw carries a CVSS…
Cisco Catalyst SD-WAN Zero-Day Exploited to Gain Root Access

Researchers have released new details on the exploitation of CVE-2026-20245, a high-severity vulnerability affecting Cisco Catalyst SD-WAN Manager that was actively exploited as a zero-day at least…
Microsoft Works to Patch New Defender Zero-Day “RoguePlanet”

Microsoft confirmed it is developing a security update for a newly disclosed zero-day vulnerability affecting Microsoft Defender, tracked as CVE-2026-50656 and publicly referred to as “RoguePlanet.”…
FortiBleed Leak Exposes Credentials for More Than 73,000 Fortinet Devices

Security researchers have identified a large-scale credential harvesting campaign dubbed “FortiBleed,” which exposed authentication data associated with approximately 73,900 Fortinet and FortiGate…
Microsoft Ships Largest Patch Tuesday on Record

Microsoft’s June 2026 Patch Tuesday release set a new record as the largest security update inthe company’s history, with fixes for approximately 200 vulnerabilities across Windows,…
VS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain Attacks

In recent weeks, supply chain attacks have become a growing concern, with multiple major repositories suffering from fake updates pushed by malicious actors to spread malware. In particular, recent…
Hackers abused Meta’s AI support bot to hijack major Instagram accounts

A recently disclosed security incident exposed significant weaknesses in AI-driven account recovery systems after attackers manipulated an automated support assistant to seize control of Instagram…
Why pure extortion is replacing traditional ransomware

The cybercriminal ecosystem is undergoing a strategic transition away from conventional ransomware operations toward pure extortion campaigns centered on data theft and disclosure threats. Rather…
Mythos proves potent in vulnerability discovery, less convincing elsewhere

Many claims have been made about the effectiveness of Anthropic’s Mythos AI model in the cybersecurity sector both by Anthropic itself and by third parties. Its ability to identify vulnerabilities in…