UNC6426 Exploits nx npm Supply-Chain Attack to Gain AWS Admin Access in 72 Hours

11/03/2026 0 Comments 0 tags

A threat actor known as UNC6426 leveraged keys stolen following the supply chain compromise of the nx npm package last year to completely breach a victim’s cloud environment within a

Five Malicious Rust Crates and AI Bot Exploit CI/CD Pipelines to Steal Developer Secrets

11/03/2026 0 Comments 0 tags

Cybersecurity researchers have discovered five malicious Rust crates that masquerade as time-related utilities to transmit .env file data to the threat actors. The Rust packages, published to crates.io, are listed

FortiGate Devices Exploited to Breach Networks and Steal Service Account Credentials

10/03/2026 0 Comments 0 tags

Cybersecurity researchers are calling attention to a new campaign where threat actors are abusing FortiGate Next-Generation Firewall (NGFW) appliances as entry points to breach victim networks.  The activity involves the

KadNap Malware Infects 14,000+ Edge Devices to Power Stealth Proxy Botnet

10/03/2026 0 Comments 0 tags

Cybersecurity researchers have discovered a new malware called KadNap that’s primarily targeting Asus routers to enlist them into a botnet for proxying malicious traffic. The malware, first detected in the

New “LeakyLooker” Flaws in Google Looker Studio Could Enable Cross-Tenant SQL Queries

10/03/2026 0 Comments 0 tags

Cybersecurity researchers have disclosed nine cross-tenant vulnerabilities in Google Looker Studio that could have permitted attackers to run arbitrary SQL queries on victims’ databases and exfiltrate sensitive data within organizations’

The Zero-Day Scramble is Avoidable: A Guide to Attack Surface Reduction

10/03/2026 0 Comments 0 tags

You can’t control when the next critical vulnerability drops. You can control how much of your environment is exposed when it does. The problem is that most teams have more

APT28 Uses BEARDSHELL and COVENANT Malware to Spy on Ukrainian Military

10/03/2026 0 Comments 0 tags

The Russian state-sponsored hacking group tracked as APT28 has been observed using a pair of implants dubbed BEARDSHELL and COVENANT to facilitate long‑term surveillance of Ukrainian military personnel. The two

How to Stop AI Data Leaks: A Webinar Guide to Auditing Modern Agentic Workflows

10/03/2026 0 Comments 0 tags

Artificial Intelligence (AI) is no longer just a tool we talk to; it is a tool that does things for us. These are called AI Agents. They can send emails,

Threat Actors Mass-Scan Salesforce Experience Cloud via Modified AuraInspector Tool

10/03/2026 0 Comments 0 tags

Salesforce has warned of an increase in threat actor activity that’s aimed at exploiting misconfigurations in publicly accessible Experience Cloud sites by making use of a customized version of an

CISA Flags SolarWinds, Ivanti, and Workspace One Vulnerabilities as Actively Exploited

10/03/2026 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added three security flaws to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerability list