Russian state-backed hackers from APT28 are actively exploiting a high-severity stored cross-site scripting vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite (ZCS) to target Ukrainian government entities.…
Russian hackers have deployed a new remote access toolkit named 'CTRL' to hijack Remote Desktop Protocol (RDP) sessions. This toolkit utilizes FRP-based reverse tunnels to gain stealthy access to compromised Windows…
Azerbaijan has created a National Cybersecurity Agency (NCA) to combat increasing cyber threats from Russia and Iran. This decision follows a significant cyberattack in February 2025 attributed to the Russian group…
The Chinese APT group known as GopherWhisper has been identified as targeting the Mongolian government using multiple cloud-based tools for espionage. Active since November 2023, the group has backdoored at least 12…
Microsoft has announced the timeline for the shutdown of Exchange Web Services (EWS) in Microsoft 365 and Exchange Online. EWS will be disabled by default on October 1, 2026, with a complete shutdown scheduled for April…
Google's Threat Intelligence Group, in collaboration with industry partners, has disrupted the IPIDEA proxy network, which hijacked consumer devices such as smartphones and desktop computers. This network was used to…
Microsoft has announced that starting in March 2026, it will block Exchange Web Services (EWS) access for users without the appropriate license rights. Affected users include those with only Microsoft 365 or Office 365…