Cybersecurity

GitLab Flaw Actively Exploited After Disclosure

A critical GitLab vulnerability (CVE-2026-19478, CVSS 9.4) enables unauthenticated attackers to modify or delete public projects via GraphQL injection.Exploitation has been observed within days...

ToxicPanda 2.0 Android malware targets 349 banks across 16 countries

ToxicPanda 2.0 now supports 167 remote commands and targets over 140 banking and cryptocurrency apps across 16 countries.The malware abuses Android accessibility services to...

CISA Adds 4 Actively Exploited Flaws to KEV Catalog

CISA added four critical vulnerabilities to its Known Exploited Vulnerabilities catalog, including flaws in Apple macOS, Microsoft SharePoint, VMware vCenter, and Microsoft IKE.The Apple...

Critical MLflow and FUXA flaws exploited in wild

Two critical vulnerabilities in MLflow (CVE-2026-64849, CVSS 9.3) and FUXA (CVE-2026-25895, CVSS 9.5) are under active exploitation.Attackers are exploiting the MLflow flaw to reach...

City Forum campaign steals data via Salesforce, ServiceNow guest access

A single server (158.220.87.87) has been systematically extracting data from Salesforce and ServiceNow customer portals for over a year, using a purpose-built Go program.Named...

StubMaker: 16 typosquat RubyGems packages steal data

Cybersecurity researchers have discovered a new typosquatting campaign, tracked as StubMaker, targeting RubyGems users with a Windows-based information stealer.The 16 malicious gem packages were...

SharePoint CVE-2026-55040 exploited after PoC release

Threat actors are actively exploiting a critical Microsoft SharePoint vulnerability (CVE-2026-55040, CVSS 9.1) after a proof-of-concept code was released by Rapid7.The flaw allows unauthenticated...

Chrome Store Hit: 737 Fake VPN Extensions Target Russian Users

737 malicious Chrome extensions, impersonating 66 VPN brands like NordVPN and Proton VPN, routed Russian users' browser traffic through a single SOCKS5 proxy infrastructure.Over...

Latest news

AI Safety Group METR Hit By Two Cyber Attacks in 2026

AI safety non-profit METR suffered two security incidents in 2026 involving attempted system access and stolen API keys.A March...

Saylor’s Strategy Resumes Bitcoin Buying with $370M Splash

Michael Saylor’s Strategy resumed its Bitcoin buying spree after a nearly 10-week pause, accumulating $370 million in BTC on...

Abbott Halts Texas State Funding for Flock Surveillance Cameras

Texas Gov. Greg Abbott ordered state agencies to halt funding for Flock Safety's AI-powered surveillance cameras.State funds helped install...