FortiGate Devices Exploited to Breach Networks and Steal Service Account Credentials

10/03/2026 0 Comments 0 tags

Cybersecurity researchers are calling attention to a new campaign where threat actors are abusing FortiGate Next-Generation Firewall (NGFW) appliances as entry points to breach victim networks.  The activity involves the

KadNap Malware Infects 14,000+ Edge Devices to Power Stealth Proxy Botnet

10/03/2026 0 Comments 0 tags

Cybersecurity researchers have discovered a new malware called KadNap that’s primarily targeting Asus routers to enlist them into a botnet for proxying malicious traffic. The malware, first detected in the

New “LeakyLooker” Flaws in Google Looker Studio Could Enable Cross-Tenant SQL Queries

10/03/2026 0 Comments 0 tags

Cybersecurity researchers have disclosed nine cross-tenant vulnerabilities in Google Looker Studio that could have permitted attackers to run arbitrary SQL queries on victims’ databases and exfiltrate sensitive data within organizations’

APT28 Uses BEARDSHELL and COVENANT Malware to Spy on Ukrainian Military

10/03/2026 0 Comments 0 tags

The Russian state-sponsored hacking group tracked as APT28 has been observed using a pair of implants dubbed BEARDSHELL and COVENANT to facilitate long‑term surveillance of Ukrainian military personnel. The two

The Zero-Day Scramble is Avoidable: A Guide to Attack Surface Reduction

10/03/2026 0 Comments 0 tags

You can’t control when the next critical vulnerability drops. You can control how much of your environment is exposed when it does. The problem is that most teams have more

How to Stop AI Data Leaks: A Webinar Guide to Auditing Modern Agentic Workflows

10/03/2026 0 Comments 0 tags

Artificial Intelligence (AI) is no longer just a tool we talk to; it is a tool that does things for us. These are called AI Agents. They can send emails,

CISA Flags SolarWinds, Ivanti, and Workspace One Vulnerabilities as Actively Exploited

10/03/2026 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added three security flaws to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerability list

Threat Actors Mass-Scan Salesforce Experience Cloud via Modified AuraInspector Tool

10/03/2026 0 Comments 0 tags

Salesforce has warned of an increase in threat actor activity that’s aimed at exploiting misconfigurations in publicly accessible Experience Cloud sites by making use of a customized version of an

Malicious npm Package Posing as OpenClaw Installer Deploys RAT, Steals macOS Credentials

09/03/2026 0 Comments 0 tags

Cybersecurity researchers have discovered a malicious npm package that masquerades as an OpenClaw installer to deploy a remote access trojan (RAT) and steal sensitive data from compromised hosts. The package,

UNC4899 Breached Crypto Firm After Developer AirDropped Trojanized File to Work Device

09/03/2026 0 Comments 0 tags

The North Korean threat actor known as UNC4899 is suspected to be behind a sophisticated cloud compromise campaign targeting a cryptocurrency organization in 2025 to steal millions of dollars in