Silent Patches Don’t Stop Attackers – They Blind Defenders

Silent Patches Do More Harm Than Good, Leaving Defenders in the Dark In recent months, several major vendors have chosen to quietly release security patches for critical vulnerabilities without issuing advisories or disclosing the details. This approach may seem like a reasonable way to prevent attackers from exploiting newly discovered bugs, but it’s actually doing … Read more

First Malware Built Specifically for Car Head Units Fuels Botnet

A New Front in Cybercrime: Malware Targets Car Infotainment Systems In a disturbing trend, researchers at Kaspersky have uncovered malware specifically designed for car head units, marking the first time this type of attack has been seen. The malicious code, linked to the notorious BadBox botnet, exploits vulnerabilities in software update systems to deliver stealthy … Read more

Police arrests dozens of suspects in global cybercrime crackdown

In a major blow to global cybercrime networks, law enforcement agencies from 22 countries have joined forces in a coordinated effort to dismantle African crime groups and disrupt their operations. Dubbed “Operation Jackal IV,” this international joint action has led to the arrest of 58 individuals linked to cybercrime networks, with dozens more suspects identified. … Read more

Hackers breached over 270 Zimbra servers in ongoing attacks

Cyber Attackers Breach Hundreds of Email Servers Using Unpatched Vulnerability A sophisticated cyber attack is unfolding on a massive scale, with over 270 email servers compromised using an unpatched vulnerability in the Zimbra Collaboration Suite (ZCS). The attack has been ongoing for weeks, and experts warn that hundreds of thousands of other servers remain vulnerable … Read more

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

A critical vulnerability in the miniOrange SAML (Security Assertion Markup Language) plugin for WordPress has been exploited by attackers, granting them full administrative access to compromised websites. The flaw allows hackers to escalate privileges from a standard user account to a WordPress administrator, effectively giving them control over the entire site. The miniOrange SAML plugin … Read more

Silent Patches Don’t Stop Attackers – They Blind Defenders

A Growing Concern in Cybersecurity: Silent Patches and Their Consequences In recent years, some vendors have adopted a practice known as “silent patching,” where they fix security vulnerabilities without publicly disclosing the issue or providing any information about the patch. This approach may seem reasonable at first glance, but it has serious consequences for defenders … Read more

First Malware Built Specifically for Car Head Units Fuels Botnet

Malware Specifically Designed for Car Head Units Ensnared in Botnet A disturbing trend has emerged in the world of cybersecurity, with researchers at Kaspersky discovering malware specifically designed to target car head units. This malicious software, linked to the notorious BadBox botnet, is a wake-up call for vehicle owners and manufacturers alike. The malware was … Read more

Police arrests dozens of suspects in global cybercrime crackdown

Global Cybercrime Crackdown Yields Dozens of Arrests and Millions in Seized Assets In a significant blow to transnational cybercrime networks, law enforcement agencies from 22 countries have identified over 260 suspects and arrested nearly 60 individuals linked to coordinated cyberattacks orchestrated by West African crime groups. The operation, dubbed “Operation Jackal IV,” targeted the Black … Read more

Hackers breached over 270 Zimbra servers in ongoing attacks

Over 270 Zimbra servers have been compromised by hackers in ongoing attacks that exploit a high-severity vulnerability in the email and collaboration suite. The attacks, which are being tracked as CVE-2026-73570, allow unauthenticated attackers to gain code execution remotely by exploiting a command injection weakness in the SNMP monitoring component when SNMP notifications are enabled. … Read more

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

A critical vulnerability in a widely-used WordPress plugin has left thousands of websites exposed to potential attacks, allowing malicious actors to gain administrator access. miniOrange’s SAML (Security Assertion Markup Language) implementation, which provides single sign-on functionality for WordPress sites, contains flaws that can be exploited by attackers. The issue, discovered through a real-world incident, reveals … Read more