German and U.S. Authorities Dismantle Global Phishing-as-a-Service Platform Kratos, Developer Arrested in Indonesia

Authorities in Germany and the United States have successfully dismantled the central infrastructure of Kratos, a sophisticated phishing-as-a-service (PhaaS) platform that operated on a global scale. In a coordinated international…

SonicWall SMA1000 Vulnerabilities Exploited in Weeks-Long Zero-Day Attacks, Custom Malware Deployed

A sophisticated threat actor, identified as UTA0533, has been actively exploiting two previously undisclosed vulnerabilities in SonicWall’s Secure Mobile Access (SMA) 1000 series appliances for weeks, a campaign that began…

Estée Lauder Confirms Data Breach Through Exploited Oracle E-Business Suite Vulnerability

Cosmetics titan Estée Lauder Companies Inc. has disclosed a significant data breach, confirming that a cybersecurity incident impacted its Oracle E-Business Suite system, which is utilized for human resources (HR)…

Hugging Face Breached by Autonomous AI Agent, Exposing Internal Datasets and Credentials

The popular open-source artificial intelligence and machine learning platform Hugging Face has suffered a significant security breach, with attackers successfully infiltrating its production infrastructure using an autonomous AI agent system.…

Microsoft Announces End of Mainstream Support for Windows Server 2022, Urges Upgrade to Latest Version

Microsoft has officially announced that Windows Server 2022 will reach the end of its mainstream support in October 2026, a crucial deadline for organizations relying on this foundational server operating…

The Global Mandate for Age Verification Spurs a Privacy Revolution in Digital Identity

The escalating global legislative landscape demanding robust age verification for online services is fundamentally reshaping how digital identities are managed and protected. As more than 30 countries and a majority…

Hackers Abuse ViPNet Software Update Mechanism to Target Russian Government and Critical Infrastructure

An advanced threat actor has been observed exploiting the legitimate update mechanism of ViPNet, a widely used Russian private networking software suite, to compromise Russian government agencies and critical infrastructure…

Microsoft Warns of Surge in ACR Stealer Attacks Targeting Enterprise Customers

Microsoft has issued a stark warning to its enterprise customers regarding a significant escalation in attacks orchestrated by the ACR Stealer malware. This sophisticated information-stealing program has been actively exploiting…

7-Zip 26.02 Released to Patch Critical Remote Code Execution Vulnerability

The popular file compression and decompression utility 7-Zip has received an urgent security update, version 26.02, addressing a critical remote code execution (RCE) vulnerability. Discovered by researcher Landon Peng of…

Critical WordPress "wp2shell" Vulnerabilities Exposed: Public Exploits Trigger Urgent Patching Mandate

The global digital landscape is on high alert following the release of publicly available exploits for critical "wp2shell" remote code execution vulnerabilities affecting WordPress Core. This development elevates the threat…