Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts

Google has introduced a new feature that allows users locked out of their accounts to recover access through facial recognition technology. This move comes after years of criticism over password-related lockouts, which often leave users unable to regain control over their Google services. The introduction of selfie video recovery is part of Google’s ongoing efforts … Read more

Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers

Cybersecurity experts are sounding the alarm after discovering that attackers have exploited GitHub Actions Runners, a popular automation tool, to compromise cPanel and WHM servers on a massive scale. The attack vector leverages a critical vulnerability in the way these tools interact with each other, highlighting the need for increased vigilance in protecting server infrastructure. … Read more

How Synthetic Identity Fraud is Coming for Machine Identities

Synthetic Identity Fraud is Spreading its Reach, Targeting Machines and Humans Alike A new wave of cyber threats is sweeping the globe, one that threatens not just human identities but also machine ones. Synthetic identity fraud, a type of attack where attackers create fake online personas using stolen or fabricated information, has long plagued human … Read more

StrongestLayer Raises $4.1 Million in Seed Funding Extension

StrongestLayer, a San Francisco-based cybersecurity startup, has just secured an additional $4.1 million in seed funding, bringing its total investment to a substantial $9.3 million. This influx of capital will fuel the company’s go-to-market strategy and platform expansion efforts. What makes StrongestLayer stand out is its AI-native email security platform, designed to combat modern email … Read more

US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices

The US government has sounded a warning bell about Iranian hackers targeting critical infrastructure organizations in the United States and elsewhere. The threat groups, linked to the Iranian government, have been using advanced tactics to infiltrate industrial control systems (ICS) made by top manufacturers such as Siemens, Schneider Electric, and Rockwell Automation. According to a … Read more

Brazilian Banking Trojan Actively Spreading in Portugal

Brazilian Banking Trojan Still Wreaking Havoc in Portugal A long-forgotten banking malware has resurfaced to wreak havoc on Portuguese organizations, with researchers at Acronis discovering that it’s still being used in attacks today. The “Lampion” Trojan, named after Japanese-style paper lanterns, originated in Brazil and first emerged around the 2019 holiday season. The attackers have … Read more

Check Point warns of SmartConsole zero-day exploited in attacks

A Critical Vulnerability in Check Point’s SmartConsole Exposes Organizations to Unprecedented Risk Check Point Software, a leading Israeli cybersecurity firm, has issued an urgent advisory warning of an actively exploited zero-day flaw in its SmartConsole graphical user interface (GUI) admin panel. The vulnerability, tracked as CVE-2026-16232, allows unauthenticated attackers to obtain an application login token … Read more

Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access

A critical vulnerability in Check Point’s SmartConsole management console has been patched, but not before attackers exploited it to gain full administrative access to affected systems. The flaw, discovered by researchers at Check Point itself, allowed unauthorized users to execute arbitrary code on vulnerable machines, potentially leading to devastating consequences. The vulnerability, identified as CVE-2023-3664, … Read more

Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks

A fourth SharePoint vulnerability has been exploited in a wave of attacks that have shaken organizations worldwide. The flaw, tracked as CVE-2026-50522, was patched by Microsoft on July 14 with its latest Patch Tuesday updates, but threat actors were quick to capitalize on it. Microsoft describes CVE-2026-50522 as a critical remote code execution vulnerability stemming … Read more

Vibe-Coded Apps Riddled With Exploitable Security Flaws

A Worrying Trend Emerges in the World of Vibe-Coded Apps: Security Flaws Galore The use of artificial intelligence (AI) to assist or perform code generation, known as vibe coding, is on the rise. According to a report from Hostinger, 90% of developers now regularly use at least one AI tool at work. While this trend … Read more