An Unpatched Calix Flaw Lets Hackers Bypass NAT to Expose Internal Devices

A critical security vulnerability affecting a widely deployed residential router model from Calix, a prominent supplier to numerous U.S. broadband providers, has been publicly disclosed. The flaw, designated CVE-2026-75501, allows…

U.S. Reaches $400 Million Settlement with TikTok Over COPPA Violations

The United States Department of Justice has announced a significant $400 million settlement with TikTok and its parent company, ByteDance, resolving allegations of violations of the Children’s Online Privacy Protection…

CISA Mandates Urgent Patching of Actively Exploited Zimbra Vulnerability Across U.S. Government Agencies

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical directive, mandating that all U.S. federal civilian executive branch (FCEB) agencies immediately address a severe security vulnerability within the…

The Hospital for Sick Children (SickKids) Confirms Data Breach Affecting Employees and Applicants Due to Third-Party Software Vulnerability

The Hospital for Sick Children (SickKids) has announced a significant cybersecurity incident that has resulted in the unauthorized access of personal information belonging to current and former employees, as well…

Hackers Abuse FTP Server Banners to Deliver New Windows Malware

Threat actors are employing an unconventional and sophisticated tactic, leveraging the seemingly innocuous greeting messages of File Transfer Protocol (FTP) servers to embed malicious commands. This technique, discovered by security…

ToxicPanda Android Malware Evolves, Exploits VPN Permissions to Block Google Play and Steal Sensitive Data

The sophisticated Android malware known as ToxicPanda has undergone a significant evolution, emerging in its version 2.0 with a potent new arsenal of malicious functionalities. This updated threat landscape now…

Microsoft Addresses Critical Vulnerabilities Across Entra ID, Azure Arc, and Exchange Online

Microsoft has swiftly addressed a series of critical vulnerabilities impacting its core cloud services, including Entra ID (formerly Azure Active Directory), Azure Arc, and Exchange Online. These security gaps, some…

Microsoft Rolls Out Classic Outlook Theme to Enhance User Transition and Familiarity

Microsoft has commenced a phased rollout of a "Classic Outlook" theme for users accessing Outlook on the web and through the new Outlook for Windows application. This initiative aims to…

The Perils of Trust: Securing Named Pipes Against Exploitation

Named pipes, a fundamental inter-process communication (IPC) mechanism in Windows, are frequently employed for seamless data exchange between applications on the same system. Their efficiency and direct operating system support…

Android Car Head Units Hijacked by Sophisticated Proxy Botnet and Ad Fraud Scheme Linked to MoYu Threat Actor

A significant cybersecurity threat has emerged within the automotive sector, with researchers uncovering a sophisticated supply-chain attack that infects Android-based car head units with malware. This malicious software enlists compromised…