FBI Probes Service Selling 153M+ Drivers Licenses

The dark web has given birth to a new identity theft service that’s selling digital scans of over 153 million drivers’ licenses from the United States and Canada. This staggering number was confirmed by interviews with individuals whose licenses are available for purchase on this service, which claims to have obtained these images from an … Read more

Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks

Nearly 22,000 Microsoft Exchange Servers at Risk of Hijack Attacks as Patch Remains Unapplied A staggering number of Microsoft Exchange servers remain unpatched against a critical security flaw that allows attackers to hijack user mailboxes. According to recent findings by Shadowserver, a threat intelligence watchdog group, nearly 22,000 Exchange servers are still vulnerable to the … Read more

Critical Langflow flaw exploited to steal OpenAI and AWS keys

A Critical Vulnerability in Langflow Framework Exposes OpenAI and AWS Keys to Attackers Threat actors have been exploiting a critical vulnerability in Langflow, an open-source framework for building AI applications, to steal credentials, tokens, and keys from vulnerable instances. According to threat intelligence firm VulnCheck, over 360 attacks were detected on its honeypots in the … Read more

Aesto Health says data breach affects over 9.5 million patients

A massive data breach at Aesto Health has compromised sensitive information for over 9.5 million individuals, sparking concerns about the security of healthcare organizations’ patient data. The company, which provides software-as-a-service solutions to help healthcare providers manage electronic health records, disclosed the attack in a recent statement. The breach occurred between December 2 and 18, … Read more

Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems

**Brazilian Payment Systems Hit by Sophisticated Fraud Scheme** A recent wave of coordinated attacks on Brazilian payment systems has left hundreds of unsuspecting victims financially exposed. Breeze Comet, a highly sophisticated malware strain, has been successfully used to execute massive numbers of fraudulent transactions across multiple platforms. The attackers’ modus operandi is centered around exploiting … Read more

Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure

A Critical Flaw in JFrog Artifactory Exposed to Admin Token Theft, Just Days After Patch In a shocking display of speed and determination, attackers have exploited a critical vulnerability in JFrog’s Artifactory software just days after its disclosure. The flaw allows unauthorized access to admin tokens, which can grant malicious actors complete control over the … Read more

Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks

A staggering 22,000 Microsoft Exchange servers remain unpatched and vulnerable to hijack attacks, leaving users’ email accounts at risk of being taken over by attackers. The security flaw, tracked as CVE-2026-62911, affects Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition (SE) software, allowing authorized attackers to elevate privileges and gain control over … Read more

Why Even the Best Edge Security Still Misses High-Risk Sessions

As it turns out, even the most robust edge security measures can be bypassed by sophisticated attackers who expertly hide their malicious activity within seemingly legitimate user sessions. Despite having a multitude of security controls at our disposal, including request inspection, credential validation, device fingerprinting, and automation signals, cybercriminals continue to evade detection. The reason … Read more

Critical Langflow flaw exploited to steal OpenAI and AWS keys

A critical vulnerability in Langflow, an open-source framework for building AI applications, has been exploited by threat actors to steal sensitive credentials and keys. The attack vector targets the code validator in Langflow’s custom component editor, allowing attackers to execute arbitrary code without authentication with root privileges. The vulnerability, CVE-2026-0768, was disclosed in January but … Read more

Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems

A sophisticated cyberattack has unfolded in Brazil, where a group of hackers known as Breeze Comet have compromised multiple payment systems, executing hundreds of fraudulent transactions and leaving victims with significant financial losses. The brazen heist highlights the importance of robust security measures, particularly in the realm of identity exposure. At its core, this attack … Read more