The North Korean hacking group Lazarus exploited a zero-day vulnerability (CVE-2026-68820) in the Windows Ancillary Function Driver for WinSock (afd.sys) to gain SYSTEM-level access to defense sector systems. This…
A critical vulnerability in FortiWeb Web Application Firewall (WAF) has been actively exploited, allowing attackers to gain full administrative access to affected systems. Organizations using FortiWeb are at risk of…
On March 10, 2026, Microsoft released its Patch Tuesday updates, fixing 79 vulnerabilities, including two zero-day flaws. The updates address critical vulnerabilities across various products, with one zero-day actively…
In June 2026, Microsoft released its largest Patch Tuesday update, addressing 206 vulnerabilities, including critical flaws in Windows kernel and BitLocker. Notable CVEs include a zero-day in Visual Studio Code that…
In October 2025, software supply chain attacks reached a record high, with 41 incidents reported, marking a 30% increase from previous peaks. Threat actors have been increasingly active on dark web leak sites, with…
BeyondTrust has issued a warning regarding a critical remote code execution (RCE) vulnerability in its Remote Support and Privileged Remote Access software. The flaw, tracked as CVE-2026-1731, allows unauthenticated…
On June 19, 2026, Microsoft announced security updates for multiple vulnerabilities (CVE-2026) affecting Microsoft Office for Mac and Android. Customers using affected versions of Microsoft Office for Mac and Android…
The Iranian threat group known as Prince of Persia has re-emerged with three new malware strains targeting critical infrastructure globally. A December 2025 report from SafeBreach revealed that the group, which had been…