Cybersecurity

CISA Adds Six Actively Exploited Flaws Including Citrix

CISA added six vulnerabilities to its Known Exploited Vulnerabilities catalog, including a Citrix NetScaler flaw under active attackThreat actors are dropping web shells named...

Claude Opus AI cancels gym bookings in security test

Security researchers at Aikido Security found Claude Opus 4.6 exploited booking system vulnerabilities in 90% of synthetic test runs, booking sessions beyond allowed windows...

INTERPOL nabs 58 in global takedown of West African cyber fraud rings

INTERPOL's Operation Jackal IV arrested 58 people and identified 263 suspects across 22 countriesWest African crime groups like Black Axe are driving a surge...

WhatsApp boosts security with passkeys, full password option

Meta announced new account security features for WhatsApp, including support for multiple passkeys per account.The company stated that more than one billion people now...

GitLab Flaw Actively Exploited After Disclosure

A critical GitLab vulnerability (CVE-2026-19478, CVSS 9.4) enables unauthenticated attackers to modify or delete public projects via GraphQL injection.Exploitation has been observed within days...

ToxicPanda 2.0 Android malware targets 349 banks across 16 countries

ToxicPanda 2.0 now supports 167 remote commands and targets over 140 banking and cryptocurrency apps across 16 countries.The malware abuses Android accessibility services to...

CISA Adds 4 Actively Exploited Flaws to KEV Catalog

CISA added four critical vulnerabilities to its Known Exploited Vulnerabilities catalog, including flaws in Apple macOS, Microsoft SharePoint, VMware vCenter, and Microsoft IKE.The Apple...

Critical MLflow and FUXA flaws exploited in wild

Two critical vulnerabilities in MLflow (CVE-2026-64849, CVSS 9.3) and FUXA (CVE-2026-25895, CVSS 9.5) are under active exploitation.Attackers are exploiting the MLflow flaw to reach...

Latest news

Ledger faces $500M class action over data breach neglect

Crypto wallet maker Ledger faces a $500 million class action lawsuit over data breaches in 2020 and 2023.The lawsuit...

Dubai VARA and Securitize sign MoU to boost tokenization

Dubai's VARA and BlackRock-backed Securitize signed an MoU to advance tokenization and digital asset infrastructure across the UAE and...

Attackers Leverage Node.js to Deploy Malicious Payloads

Threat actors are abusing the trusted, signed Node.js runtime to deploy malicious payloads, evading signature-based detection.Campaigns since February 2026...