Cybersecurity News
Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.
Exploited PAN-OS User-ID Portal RCE (CVE-2026-0300) Guidance
Palo Alto Networks PAN-OS contains a critical vulnerability CVE-2026-0300 in the User-ID Authentication Portal service that is already being exploited ...
MetInfo CMS 7.9–8.1 under active attack via CVE-2026-29014 RCE
The critical remote code execution vulnerability CVE-2026-29014 (CVSS 9.8) in MetInfo CMS versions 7.9, 8.0, and 8.1 is already being ...
Inside PCPJack: Cloud Credential Theft Targeting Open Services
PCPJack is a new credential theft framework targeting exposed cloud services (Docker, Kubernetes, Redis, MongoDB, RayML, vulnerable web applications). It ...
How Dirty Frag Breaks Linux Kernel Security for Local Attackers
Dirty Frag is a new, currently unpatched local privilege escalation vulnerability in the Linux kernel that allows any local user ...
How Google’s Binary Transparency Changes Android Trust
Google has announced the extension of its Binary Transparency mechanism to the Android ecosystem, introducing a public cryptographic log of ...
ZiChatBot malware hides in PyPI packages, abusing Zulip C2
Three packages have been discovered on Python Package Index (PyPI) that, in addition to their advertised functionality, silently deliver the ...
Targeted and Mass Attacks Using cPanel CVE-2026-41940
The critical CVE-2026-41940 vulnerability in cPanel/WHM is already being used not only by mass botnets and ransomware operators, but also ...
ScarCruft targets sqgame[.]net users with BirdCall spyware
The North Korea–linked group ScarCruft carried out a targeted supply-chain attack against the gaming platform sqgame[.]net, popular among ethnic Koreans ...
How a Multi‑Stage AiTM Phishing Campaign Bypasses MFA and Targets 35,000 Users
In mid‑April 2026, a multi‑stage phishing campaign was identified that targeted more than 35,000 users across 13,000 organizations. It used ...