Cybersecurity News
Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.
How Operation BlueDash abuses RMM tools via Microsoft Teams lures
Researchers from ZeroBEC disclosed details of the phishing campaign Operation BlueDash, in which attackers use fake Microsoft Teams update pages ...
Have I Been Pwned Confirms Massive Suno Breach with Stripe Data
The Have I Been Pwned service has added to its database data stolen in the breach of Suno, a popular ...
Active Exploitation of PTC Windchill CVE-2026-12569 in Data-Theft Campaigns
The critical vulnerability CVE-2026-12569 in the PTC Windchill product is being actively exploited as part of a data-theft campaign allegedly ...
Linux kernel RefluXFS bug lets local users gain root
On July 22, the vulnerability CVE-2026-64600 (RefluXFS) in the Linux kernel was disclosed: a race condition in the XFS reflink ...
How the SourTrade browser-assembled malware targets retail crypto traders
Researchers at Confiant have disclosed details of a malvertising campaign called SourTrade, in which the victim’s browser independently assembles the ...
Fastjson 1.x CVE-2026-16723 RCE: impact, exploits, fixes
The critical remote code execution vulnerability CVE-2026-16723 in the Alibaba Fastjson 1.x library (versions 1.2.68–1.2.83) allows an attacker to execute ...
Inside BlueNoroff’s ClickFix Kit Masquerading as Zoom and Teams
Researchers at JUMPSEC have disclosed details of an active phishing platform that, according to their findings, is linked to the ...
How the AgentForger CSRF Bug Turned ChatGPT Agents into Corporate Insiders
Researchers from Zenity Labs disclosed a CSRF-class vulnerability in the OpenAI ChatGPT Agent Builder tool, which received the codename AgentForger. ...
How Bing’s image pipeline exposed critical RCE via ImageMagick delegates
Microsoft has assigned two critical CVEs — CVE-2026-32194 and CVE-2026-32191 — to vulnerabilities in Bing’s image-processing infrastructure, each with a ...
How the wp2shell Vulnerability Chain Enables RCE on Vanilla WordPress
Two critical vulnerabilities in WordPress — CVE-2026-63030 and CVE-2026-60137 — are being actively exploited by attackers in a chained exploit ...