Cisco has addressed a maximum-severity vulnerability in AsyncOS, tracked as CVE-2025-20393, which has been actively exploited for at least a month. The flaw affects Secure Email Gateway (SEG) and Secure Email and Web…
Operation Escaneo is a coordinated cyberattack attributed to the MexicanMafia group, targeting critical infrastructure across Latin America, primarily Mexico. The campaign, which spanned from 2025 to 2026, utilized…
In June 2026, a new ransomware family named Spirals executed a double extortion attack against an IT services company in South Asia, completing the operation in under 24 hours. The attackers gained initial access by…
The ModHeader browser extension, used by approximately 1.6 million users across Chrome and Edge, was removed after researchers discovered a dormant data-collection capability embedded in its signed release. The…
Trendmicro's TrendAI™ Research has identified two AI-augmented threat campaigns, SHADOW-AETHER-040 and SHADOW-AETHER-064, targeting government and financial organizations in Latin America. These campaigns began in late…
Hackers are utilizing QEMU, an open-source virtual machine emulator, to create hidden Linux environments within Windows systems, effectively evading endpoint security tools. This method allows for long-term access,…
Between March 26 and 27, 2026, a phishing campaign targeted Ukrainian institutions, including government entities, healthcare providers, and educational institutions, by spoofing the Computer Emergency Response Team of…
Parrot OS 7.0, codenamed Echo, has been officially released, featuring a complete system rewrite based on Debian 13. This version introduces KDE Plasma 6, Wayland by default, and an expanded suite of penetration testing…
Cisco has reported an unpatched zero-day vulnerability (CVE-2025-20393) in its AsyncOS software, affecting Secure Email Gateway and Secure Email and Web Manager appliances. The vulnerability is being actively exploited…