Microsoft Defender for Office 365 is falsely flagging legitimate Google search links as malicious. Here's what's happening, why it matters, and how to work around the glitch while Microsoft investigates.
Two GeoNetwork vulnerabilities chain into unauthenticated RCE, threatening government geoportals. Patches shipped in July 2026—here's what you need to know.
A Russian national was extradited to the U.S. for using 255 fake freelance accounts to send malware-laced Excel files to 80,000 users. Here's what this means for your online safety.
A Russian national faces charges for a phishing campaign that infected 80,000 freelancers with TVRAT and DarkVNC malware. Here's how to protect your freelance business.
Global authorities dismantled the Sality P2P botnet, one of the most resilient malware networks ever. Here's what this takedown means for your online security and privacy.
Researchers used Anthropic's Claude AI to port a pre-auth RCE exploit between WAGO PLC models, executing ARM shellcode on live hardware. Here's why this matters for industrial security.
A critical unauthenticated SQL injection flaw in Sangoma Switchvox (CVE-2026-9586, CVSS 9.3) is being actively exploited to deploy reverse shells. Here's what you need to know and how to protect your VoIP infrastructure.
The DoJ and international partners crippled the Sality P2P botnet by turning its own network against itself, cutting off new malware payloads. Here's how they did it and what it means for cybersecurity.
SonicWall warns of two actively exploited SMA1000 zero-day flaws chained for remote code execution. Learn immediate steps to protect your network before patches arrive.
Phishing actors are abusing the legitimate Faronics Deploy admin platform to gain remote control of victim PCs and install ScreenConnect. Learn how this attack works and how to defend your business.
Aesto Health's data breach exposed 9.5 million patient records. Learn what happened, how to protect yourself, and why privacy tools matter now more than ever.
Threat actors are exploiting a critical Langflow vulnerability (CVE-2026-0768) to steal OpenAI and AWS keys. Learn how to protect your AI infrastructure before it's too late.
Attackers are exploiting a critical JFrog Artifactory flaw (CVE-2026-82329) just days after disclosure, minting admin tokens for persistent access. Learn how to protect your supply chain now.
Since 2024, a threat actor called Breeze Comet has manipulated Brazilian payment systems to execute hundreds of fraudulent transfers. Here's what US businesses need to know.
A BGP hijacking attack let hackers replace legitimate Virtualizor updates with malware. Learn how this happened and what you can do to protect your VPS infrastructure.
Novocure's August cyberattack exposed data of over 1,400 U.S. cancer patients and employees. Learn what happened, why healthcare data breaches matter, and how to protect yourself from medical identity theft.
Thirteen malicious packages on Packagist are injecting spyware into streaming sites to steal crypto wallet seeds from unpatched iPhones. Here's how the attack works and how to protect yourself.
Attackers can hide behind residential proxies, VPNs, and other infrastructure that makes malicious sessions appear legitimate to existing edge security controls. Spur explains how session enrichment adds data points that help organizations identify risky sessions and make stronger enforcement decisi
An Iranian hacking group is posing as recruiters, using fake coding tests to deliver sophisticated, cross-platform malware. This new threat targets Linux and macOS systems, marking a dangerous shift in cyber-espionage tactics.
A critical, unpatched flaw in Microsoft Exchange servers leaves nearly 22,000 systems vulnerable, allowing attackers to bypass authentication and hijack every user mailbox. Immediate action is required.