Nuxt has released security patches for versions 4.5.1 and 3.21.10, addressing multiple vulnerabilities including a high-severity server-side remote code execution (RCE) risk. The RCE vulnerability occurs when the Vue…
Manufacturing organizations are increasingly targeted by cyberattacks, with a focus on identity-driven methods. Attackers exploit credential leaks and social engineering tactics such as vishing and impersonation to…
Recent research revealed that over 5,000 vibe-coded applications, created using platforms like Lovable and Base44, exposed sensitive corporate and personal data. The cybersecurity firm RedAccess found that approximately…
A Vietnamese-linked cyber operation, codenamed AccountDumpling, has compromised around 30,000 Facebook accounts through a sophisticated phishing campaign. The attackers exploited Google AppSheet to send fully…
A targeted campaign exploiting GitHub Actions' pull_request_target trigger was identified, allowing attackers to execute malicious code with elevated privileges. This vulnerability has been documented since 2021 but…
A phishing campaign has emerged, impersonating over 30 well-known brands, including Adidas, Netflix, and Coca-Cola, to steal Google account credentials from marketing professionals. The attackers use fake job offers and…
CTM360's research reveals a significant evolution in phishing tactics targeting insurance sectors, where attackers now employ real-time account hijacking methods. In a simulation involving 13.9 million phishing…
Infostealer malware is increasingly exposing enterprise identity credentials, with 16% of infections involving Single Sign-On or identity provider details, according to Flare's analysis of 18.7 million logs from 2025. A…
Foxveil is a newly identified malware loader first detected in August 2025. It utilizes legitimate platforms such as Discord, Cloudflare, and Netlify to stage Donut-generated shellcode, employing techniques like…
Cybercriminals have increasingly adopted the browser-in-the-browser (BitB) phishing technique to deceive users into providing their login credentials. This method, which creates a fake browser window mimicking…