Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0

A critical security update from Cisco has brought attention to a set of vulnerabilities that could allow attackers to gain elevated privileges and access sensitive data. The company’s patches address nine flaws in its Crosswork and Secure Workload products, with five of them scoring a maximum 10.0 on the Common Vulnerability Scoring System (CVSS). These … Read more

Money and Mindset: The Two Biggest Roadblocks to Cyber Policing

Cybersecurity Training Falls Short as Cybercrime Continues to Evolve A recent incident in Texas highlighted the importance of adequate cybersecurity training for law enforcement. Malware was discovered hidden within body camera footage uploaded by police, putting sensitive data at risk as it traveled through the chain of command. This is just one example of how … Read more

SickKids data breach exposes employee and job applicant info

The Hospital for Sick Children in Toronto has disclosed a data breach that exposed personal information of current and former employees, job applicants, and possibly others. The breach was caused by a vulnerability in third-party software used by the hospital and other organizations. According to SickKids, the incident allowed unauthorized access to employee data on … Read more

Hackers abuse FTP server banners to deliver new Windows malware

As threat actors continue to find new and creative ways to deliver malware, researchers have uncovered a novel technique being used to distribute two previously undocumented remote access trojans (RATs) named E4del and PINHOLE. By exploiting FTP server banners, hackers are able to hide malicious commands that instruct the malware stager on what actions to … Read more

Microsoft warns of max severity Entra ID flaw exploited in attacks

Microsoft has issued a critical security patch to fix a maximum-severity vulnerability in its Entra ID identity and access management (IAM) platform, which has already been exploited by attackers. The bug, tracked as CVE-2026-69836, allowed threat actors with no privileges to gain code execution on the system, making it a serious concern for organizations using … Read more

GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure

A newly disclosed vulnerability in GitLab’s code repository management tool, identified as CVE-2026-19478, has been actively exploited by attackers just days after its public disclosure. The exploit allows malicious actors to escape restricted areas of a network and gain elevated access to sensitive systems, making it a top priority for organizations using the platform. The … Read more

Pakistan’s Transparent Tribe Refreshes Toolset for Afghan Cyberattacks

Pakistan’s Transparent Tribe Cyber Espionage Campaign Escalates in Afghanistan and India A sophisticated nation-state threat actor has been conducting a relentless cyber espionage campaign against high-value targets in Afghanistan, with some attempts also aimed at government agencies in India. The threat actor, known as Transparent Tribe (aka APT 36), is believed to be operating on … Read more

Money and Mindset: The Two Biggest Roadblocks to Cyber Policing

Cybersecurity Challenges Plague Law Enforcement Agencies, Leaving Them Vulnerable to Attacks Law enforcement agencies are struggling to keep pace with the rapidly evolving threat landscape of cybercrime. A recent incident in Texas highlights the risks when police departments fail to prioritize adequate cybersecurity training for their officers. Malware was discovered hidden inside body camera footage … Read more

N-able Bug Exposes Password Vault Master Keys

A Critical Vulnerability in N-able’s Passportal Exposes Password Vault Master Keys A disturbing security flaw has been discovered in Passportal, a popular password manager used by thousands of managed service providers (MSPs) and small to medium-sized businesses (SMBs). The vulnerability allows any malicious website to gain complete, persistent access to customers’ vaults, putting sensitive credentials … Read more

Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution

Microsoft’s Entra ID Flaw Exposes Organizations Worldwide to Devastating Attacks A critical vulnerability in Microsoft’s Entra Identity platform has been exploited in the wild, allowing attackers to execute malicious code on affected systems. The flaw, which has been assigned a CVSS (Common Vulnerability Scoring System) rating of 10.0, is considered one of the most severe … Read more