Microsoft Plugs Nearly 400 Security Holes

Microsoft’s latest Patch Tuesday update has plugged nearly 400 security vulnerabilities across its Windows operating systems and supported software, including one critical flaw that is already being actively exploited. The sheer volume of patches released by Microsoft has raised questions about whether artificial intelligence (AI) is truly effective in helping to identify and fix these … Read more

Delta probes Wi-Fi deauth attack on flight carrying DEF CON attendees

Unauthorized Wi-Fi Network Disrupts Flight Carrying DEF CON Attendees, Raises Concerns About In-Flight Security A bizarre incident unfolded on a Delta Air Lines flight from Las Vegas to Atlanta yesterday, when an unauthorized Wi-Fi network appeared on board, allegedly brought by passengers returning from the DEF CON 34 hacking conference. The rogue network was quickly … Read more

Cisco warns of ASA and FTD VPN flaw exploited to crash devices

A High-Severity VPN Flaw in Cisco Software is Being Actively Exploited, Causing Devices to Crash A critical vulnerability has been discovered in Cisco’s Secure Firewall Adaptive Security Appliance (ASA) and Threat Defense (FTD) software, which is being exploited by attackers to remotely crash affected devices. The flaw, tracked as CVE-2026-20349, affects devices running certain remote … Read more

DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt

A Novel Threat Emerges: DeadLock Ransomware Leverages Polygon Smart Contracts for Unprecedented Extortion Capabilities DeadLock, a highly sophisticated ransomware variant, has been making headlines in recent weeks due to its innovative use of Polygon smart contracts. This malware strain has successfully exploited a previously unknown vulnerability in the decentralized finance (DeFi) sector, allowing it to … Read more

Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE

A newly disclosed vulnerability in Microsoft’s SharePoint software has left organizations vulnerable to unauthenticated remote code execution (RCE) attacks, thanks to an AI-assisted exploit chain that exploits weaknesses in user identity exposure. Researchers have revealed a sophisticated attack path that leverages cross-domain privilege escalation to reach sensitive areas of the network, posing significant risks to … Read more

Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands

A Highly Sophisticated Phishing Campaign Exploits Job Seekers, Exposing Them to Malware-Ridden VPNs A recent investigation has uncovered a complex phishing scheme linked to the notorious threat actor Sandworm, which has been using fake job interviews as a ruse to trick unsuspecting individuals into installing malware-infested virtual private networks (VPNs). This cunning tactic not only … Read more

Microsoft releases Windows 10 KB5120249 extended security update

Microsoft has released a crucial Extended Security Update (ESU) for Windows 10, addressing critical vulnerabilities and bugs that could leave systems exposed to attacks. The update, marked as KB5120249, is mandatory for all affected versions of Windows 10 – specifically 22H2 and 21H2 – and includes the August 2026 Patch Tuesday security updates. To install … Read more

DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt

A New Low for Ransomware: DeadLock Exploits Polygon Smart Contracts, Making Extortion Even More Challenging to Disrupt Ransomware operators have always been adept at exploiting vulnerabilities and staying one step ahead of security measures. However, a recent development in the world of cybercrime takes the cake. The DeadLock ransomware has integrated with Polygon smart contracts, … Read more

Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE

Cybersecurity researchers have uncovered a sophisticated exploit chain that leverages AI-assisted attacks to gain unauthenticated remote code execution (RCE) on Microsoft SharePoint servers. The findings, disclosed in a recent report, expose a vulnerable pathway for attackers to breach corporate networks and compromise sensitive data. The exploit chain relies on a combination of social engineering tactics … Read more