Cybersecurity News
Stay informed about the latest cybersecurity incidents, vulnerabilities, and threat landscape changes. We cover data breaches, ransomware campaigns, critical CVEs, and regulatory updates – with context on what it means for you and how to protect yourself.
VerdantBamboo campaign abuses pfSense, NAS and Egnyte devices
Researchers at Volexity have published a report on a cyber-espionage campaign in which a group believed to be linked to ...
Why VS Code Now Delays Automatic Extension Updates by Two Hours
Starting with VS Code 1.123, Microsoft is introducing a two-hour delay for automatic extension updates — a simple but effective ...
Exploited SolarWinds Serv-U DoS Vulnerability CVE-2026-28318: Analysis
On June 5, 2026, CISA added vulnerability CVE-2026-28318 (CVSS 7.5) to the Known Exploited Vulnerabilities catalog, confirming that it is ...
Miasma Supply Chain Attack Compromises 73 Microsoft GitHub Repos
The self-replicating Miasma supply chain attack has impacted Microsoft repositories on GitHub — according to researchers, 73 repositories in four ...
Active Exploitation of Cisco Catalyst SD-WAN Manager CVE-2026-20245
Cisco has confirmed active exploitation of the CVE-2026-20245 (CVSS 7.8) vulnerability in Cisco Catalyst SD-WAN Manager, which allows an authenticated ...
Asin Android spyware campaign targets Arabic-speaking OSINT users
Researchers from the Slovak company ESET have documented a new family of Android spyware codenamed Asin, targeting Arabic-speaking users. The ...
ReliaQuest Uncovers OP-512, a Stealthy IIS Espionage Framework
ReliaQuest has disclosed a previously unknown threat cluster designated OP-512, targeting Microsoft Internet Information Services (IIS) servers. The group uses ...
Critical Everest Forms Pro RCE and Emerging Stripe-Based Skimming Campaigns
The critical remote code execution vulnerability CVE-2026-3300 (CVSS 9.8) in the Everest Forms Pro plugin for WordPress is being actively ...
PCPJack’s Cloud SMTP Proxy Network Targets Linux Servers
The PCPJack group, according to researchers at Hunt.io, compromised about 230 cloud servers on Amazon Web Services, Google Cloud, and ...
How CVE-2026-20230 Puts Cisco Unified CM at Risk
Cisco has released a fix for critical vulnerability CVE-2026-20230 in Cisco Unified Communications Manager (Unified CM) and its Session Management ...