Canadian Man Pleads Guilty in Snowflake Extortions

A Canadian Man’s Descent into Cybercrime: Guilty Plea Reveals Extensive Hacking and Extortion Scheme Connor Riley Moucka, a 26-year-old from Kitchener, Ontario, has pleaded guilty to computer fraud and conspiracy to hack and extort over 165 organizations that used the cloud data storage provider Snowflake. The extensive hacking and extortion scheme, which spanned from February … Read more

CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild

A Critical Vulnerability in TeamCity is Being Actively Exploited, Warns CISA The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about an actively exploited vulnerability in JetBrains’ TeamCity software. The flaw, identified as CVE-2026-63077, allows attackers to execute arbitrary code on vulnerable systems, giving them unrestricted access to sensitive data and potentially … Read more

Ransom Cartel Creator Gets 16 Years in Prison for Operating Ransomware-as-a-Service

A notorious creator of ransomware-as-a-service (RaaS) platforms has been sentenced to 16 years in prison, bringing a significant blow to the cybercrime ecosystem. The case marks a major milestone in the global fight against ransomware attacks, which have been on the rise in recent years. The individual, identified as a key player in the “DarkSide” … Read more

Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells

Chinese-Made Routers Ship with Stealthy Backdoor, Leaving Users Exposed to Cyber Threats A disturbing discovery has been made in the world of network security, revealing that a significant number of Chinese-made Zbtlink routers are shipping with a built-in backdoor that allows unauthenticated access to root shells. This means that anyone can gain complete control over … Read more

Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities

Cybersecurity researchers have uncovered a staggering number of Rockwell Automation Programmable Logic Controllers (PLCs) exposed online, leaving over 4,400 industrial control systems vulnerable to cyber attacks. What’s more alarming is that at least 22 of these compromised devices are located in cities that have been the target of water attacks in the past, raising concerns … Read more

ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories

Identity exposure has long been a significant concern for individuals and organizations alike, but its consequences can be far-reaching and devastating. A recent spate of high-profile security breaches highlights the alarming ease with which attackers can exploit exposed identities to gain unfettered access to sensitive systems and data. At the heart of this issue lies … Read more

Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access

Cybersecurity experts have uncovered a sophisticated attack technique that leverages Oracle’s database software to gain unauthorized access to Windows systems. The exploit, which involves compiling a malicious “khunt” inside the Oracle database, has been used in real-world attacks to breach even the most secure networks. The attackers behind this campaign appear to be highly skilled … Read more

AI Recommendation Poisoning: How “Ask AI” Buttons Silently Alter LLM Memory

A Silent Threat Lurks in AI Recommendation Systems: How “Ask AI” Buttons Can Compromise Large Language Models Artificial intelligence (AI) has become ubiquitous in our daily lives, from virtual assistants to content recommendation engines. However, a growing concern among cybersecurity experts is that these AI systems can be manipulated in ways that compromise their integrity … Read more

Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses

Apple’s iCloud Private Relay, touted as a robust tool for protecting user anonymity online, has been found vulnerable to exploitation through WebKit proxy bypasses. This means that even when users are connected to iCloud Private Relay, their real IP addresses can be exposed under certain conditions. The issue affects millions of Apple device owners worldwide … Read more

CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps

A Critical Flaw in Five Crypto Wallet Apps Has Resulted in $5.7 Million Stolen, Highlighting the Importance of Secure Random Number Generation in Cryptocurrency Security. The theft of a staggering $5.7 million from five popular cryptocurrency wallet apps has been attributed to a critical flaw in their underlying code. The vulnerability, rooted in the use … Read more