Cyber threats and incidents

Microsoft Patched Actively Exploited Office Zero-Day CVE-2026-21509 Bypassing OLE Mitigations

What happened The Microsoft Office zero-day patch addressed CVE-2026-21509, a high-severity security...

Fake Notepad++ and 7-Zip Websites Delivered Legitimate RMM Tools for Remote Control and PatoRAT Deployment

What happened The fake Notepad++ and 7-Zip distribution campaign used fraudulent websites...

CVE-2026-24061 Exposed GNU Inetutils telnetd Servers to Unauthenticated RCE via Argument Injection

What happened The GNU Inetutils telnetd vulnerability exposed large numbers of internet-accessible...

Lazarus Operation DreamJob Targeted European Drone Firms Using DLL Side-Loading and ScoringMathTea RAT

What happened The Lazarus targeting campaign, tracked as Operation DreamJob, was linked...

SyncFuture Phishing Campaign Abused Security Software and Microsoft-Signed Binaries for Multi-Stage Malware

What happened The SyncFuture campaign used phishing emails impersonating the India Income...

Popular

Daylight Security’s Viral Videos Reimagine The Black Hat Experience For CISOs

For all the attention cybersecurity conferences receive, the experience...

Fig Extends Platform Coverage to the Entire SecOps Engineering Lifecycle, Setting Resilience as the Default

The modern security operations center is built on a...

Microsoft’s Largest Patch Tuesday Ever Raises New Challenges for Security Teams

What happened Microsoft released its July 2026 Patch Tuesday update,...

ClickFix Evolves Into a Malware Ecosystem, Challenging Traditional Security Defenses

What happened ClickFix has grown from a simple social engineering...

Weak Router Security Continues to Fuel Russian Cyber Operations Against Critical Infrastructure

What happened US cybersecurity agencies, together with counterparts from more...