Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks

Thousands of Data Centers Exposed to Attacks Due to Decades-Old BMC Vulnerability A 22-year-old security flaw in Baseboard Management Controller (BMC) management processors has put thousands of data centers at risk of compromise. The vulnerability, which affects nearly 37,000 internet-exposed server-management interfaces, allows attackers to obtain password hashes and crack them offline. The issue stems … Read more

Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering

A Critical Vulnerability in Google’s Agent Development Kit Exposes Secrets and Enables Pull Request Tampering Google’s Agent Development Kit (ADK) for Python, a widely used framework for building automated AI agents, has been found to be vulnerable to a critical attack method. A security researcher from Pillar Security discovered that an attacker could manipulate the … Read more

TP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover

A critical vulnerability chain has been discovered in TP-Link’s Omada networking ecosystem, allowing attackers to potentially take control of entire fleets of managed devices. The weakness lies in the zero-touch provisioning (ZTP) system, which is designed to simplify network administration by automatically configuring routers, switches, and access points with minimal manual setup. The ZTP protocol … Read more

DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT

A Sophisticated Malware Campaign Exploits Web Vulnerabilities to Deliver Highly Capable Rats A complex and highly effective malware campaign has been uncovered, leveraging a combination of web application vulnerabilities and clever social engineering tactics to deliver two potent remote access tools (RATs) to unsuspecting victims. Dubbed “DoubleCup,” the operation is notable not only for its … Read more

New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root

A severe vulnerability in cPanel, a widely used web hosting control panel, has been discovered that could allow customers with access to their hosting accounts to gain elevated privileges and potentially take over entire databases. The flaw, which affects cPanel versions 11.x through 12.x, has significant implications for the security of thousands of websites and … Read more

River Bank Says Hackers Deleted Data Stolen in Ransomware Attack

River Bank’s Ransomware Nightmare Continues as Stolen Data is Deleted, but Questions Remain In a disturbing trend that highlights the ongoing threat of ransomware attacks, River Financial Corporation, the parent company behind River Bank & Trust, has revealed that hackers deleted data stolen during a high-profile attack in June. The incident, which occurred on June … Read more

Cyberattack Hits Liechtenstein’s Register of People Behind Companies and Foundations

Cyberattack Hits Liechtenstein’s Register of Economic Beneficiaries, Exposing 31,000 People’s Data A sophisticated cyberattack has compromised the sensitive information of approximately 31,000 individuals in Liechtenstein’s register of economic beneficiaries. The breach occurred last week when an unknown actor accessed the database at night on Wednesday and Thursday. Authorities discovered the intrusion on Thursday morning and … Read more

Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers

Microsoft’s Bug Bounty Program Soars to New Heights, Paying Out Over $20 Million to Researchers In a major milestone for cybersecurity research, Microsoft has announced that it paid out more than $20 million through its bug bounty programs over the past year. The company received 2,531 eligible reports from researchers across 64 countries, with 562 … Read more

Device Code Phishing Up 1,500% in 2026; Vishing Doubles

Phishing Tactics Evolve, Leaving Security Controls Behind In a dramatic escalation of social engineering tactics, device code phishing has skyrocketed by 15-fold in the first half of 2026, while voice phishing (vishing) has doubled in the same period. These newer techniques are allowing state-sponsored threat actors and cybercriminal groups to bypass traditional security controls and … Read more

CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises

Cybersecurity watchdogs are sounding alarm bells after a critical vulnerability in N-able’s N-central remote monitoring and management (RMM) software was added to the US Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities (KEV) catalog. This move follows reports of multiple customer compromises, underscoring the need for prompt action. The exploited flaw allows unauthorized access … Read more