459 articles
Check Point Research found a DeepSeek-generated sample using Chrome's File System Access API to encrypt Android photo directories — no native payload or exploit required.
CVE-2026-45408 (CVSS 9.0) in Dokku <0.38.2 lets authenticated users inject shell commands via crafted app names in git push operations. No public exploit yet.
Chinese-speaking threat group CL-STA-1062 compromised at least 10 Southeast Asian government and energy entities in 2025 using web shells, tunneling tools, and a new TinyRCT...
Mexico's 2025–2030 National Cybersecurity Plan targets ransomware and organized crime, facing a critical test during the 2026 FIFA World Cup amid a history of high-profile...
Indian auto giant Bajaj Auto disclosed a ransomware incident on June 24, 2026, impacting operations and its tech subsidiary.
Kaspersky uncovers StrikeShark, a global campaign using SharkLoader malware to deploy Cobalt Strike Beacon across 10+ countries via exploits for ProxyLogon, Openfire, and...
Kaspersky details an active global campaign distributing VBS files via WhatsApp that installs UEMS RMM software, enabling persistent remote access across 12 countries including...
CVE-2019-25763 (CVSS 9.8) allows unauthenticated attackers to hijack admin sessions in WordPress Ultimate Addons for Beaver Builder 1.2.4.1 via a crafted POST request to...
CISA warns of active exploitation of CVE-2026-48907, a CVSS 10.0 improper access control flaw in Widget Factory Joomla Content Editor (JCE) allowing unauthenticated PHP code...
Maine shut its public data breach portal after fake notices for VRChat (2.4M alleged victims) and Discord were posted.
Great Marlow School in Buckinghamshire sent 1,428 pupils home for a second day after a cybersecurity incident; only GCSE and A-Level exam takers attended.
Mackay Sugar, Australia's second-largest sugar producer, shut down Farleigh and Racecourse mills after a cyberattack halted harvesting in Queensland's Mackay region during crush...