MuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting 9 Countries

26/05/2026 0 Comments 0 tags

The Iranian hacking group known as MuddyWater has been linked to a new campaign affecting at least nine organizations across nine countries on four continents in the first quarter of

Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions

26/05/2026 0 Comments 0 tags

Microsoft has rolled out updates to fix a remote code execution vulnerability impacting SharePoint that could be exploited by bad actors in attacks without requiring any specialized conditions to be

New AI DDoS Attacks Are Smarter. Learn How to Fight Back in This Webinar

26/05/2026 0 Comments 0 tags

Every single day, hackers are finding new ways to crash websites and steal data. But right now, something has changed. Hackers are no longer working alone. They are now using

MFA Prompt Bombing: Why Your Second Factor Isn’t Saving You

26/05/2026 0 Comments 0 tags

Multi-factor authentication (MFA) was supposed to close a critical gap in identity security. It meant that, even if an attacker possessed the account credentials, they couldn’t log in without the

CERT-In Mandates 12-Hour Patching for Internet-Facing Flaws Amid AI-Assisted Attacks

26/05/2026 0 Comments 0 tags

The Indian Computer Emergency Response Team (CERT-In) has issued new guidelines requiring organizations to patch critical security vulnerabilities in internet-exposed systems within 12 hours of being flagged where “feasible” to

Iranian Hackers Deploy MiniFast and MiniJunk V2 via Phishing and SEO Poisoning

26/05/2026 0 Comments 0 tags

The Iranian state-sponsored threat actor known as Nimbus Manticore (aka Screening Serpens and UNC1549) has been attributed to a fresh campaign using lures impersonating organizations in the aviation and software

KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt Strike

26/05/2026 0 Comments 0 tags

A now-patched high-severity security flaw affecting Digital Knowledge KnowledgeDeliver, a Learning Management System (LMS) popular in Japan, was exploited as a zero-day to deliver the Godzilla web shell and ultimately

⚡ Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaos

25/05/2026 0 Comments 0 tags

Monday recap. Same mess, new week. A sketchy dev tool got people pwned, old bugs came back from the dead, and security products somehow needed protecting from themselves. A bunch

The Alert Firehose Finally Meets Its Match

25/05/2026 0 Comments 0 tags

Ask a cybersecurity pro about Network Detection and Response (NDR) and you might still hear “Noisy,” “Too much data.” But ask the teams running NDR that includes agentic AI capabilities

Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks

25/05/2026 0 Comments 0 tags

Threat actors are exploiting a recently disclosed critical security flaw in Ghost CMS to inject malicious JavaScript code with an aim to fuel ClickFix attacks. According to QiAnXin XLab, the