A critical remote code execution vulnerability (CVE-2026-50522) in Microsoft SharePoint is being actively exploited. Attackers are targeting on-premise SharePoint deployments to extract IIS machine keys, allowing for…
The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding active exploitation of CVE-2009-0238, a critical remote code execution vulnerability in Microsoft Excel, first identified in…
The FBI has issued a warning regarding the Kali365 phishing kit, which is actively stealing Microsoft OAuth tokens and bypassing multi-factor authentication (MFA) protocols. First identified in April 2026, Kali365 is…
A new malware family named SharkLoader has been discovered, linked to a campaign called StrikeShark, which targets various sectors, including a diplomatic organization in Indonesia. SharkLoader acts as a loader to…
The Warlock ransomware group, also known as Water Manaul, has escalated its attack methods by exploiting unpatched Microsoft SharePoint servers and employing new tactics for persistence and lateral movement. Recent…
On April 14, 2026, the Canadian Centre for Cyber Security released its National Cyber Threat Assessment for 2025-2026, highlighting an increase in sophisticated cyber threats targeting Canada's critical infrastructure…
On July 15, 2026, Microsoft released security patches to address multiple critical vulnerabilities across its software products. The vulnerabilities include Remote Code Execution and Elevation of Privilege issues…
During the Pwn2Own Berlin 2026 event, held from May 14 to 16, security researchers exploited numerous zero-day vulnerabilities, earning over $900,000 in cash prizes. On the first day, 24 unique vulnerabilities were…
A wave of AI-driven voice phishing attacks, known as vishing, has targeted major hedge funds including Point72, Citadel, and Two Sigma. The attackers used AI-generated voices to impersonate executives and manipulate…
BeyondTrust has issued a warning regarding a critical remote code execution (RCE) vulnerability in its Remote Support and Privileged Remote Access software. The flaw, tracked as CVE-2026-1731, allows unauthenticated…