‘Confused Deputy’ Flaws Persist in Google Cloud, Microsoft Azure

Significant security vulnerabilities have been discovered in two of the world’s leading cloud platforms, Microsoft Azure and Google Cloud Platform (GCP), allowing attackers to bypass critical access controls. These “confused deputy” flaws, which can be exploited to acquire administrative level permissions, have left enterprise and government resources at risk. Justin O’Leary, an independent security researcher, … Read more

New Certighost PoC exploit lets attackers hijack Windows domains

Windows Domains Left Vulnerable by Unpatched Certighost Exploit A potentially devastating vulnerability has been unearthed in Windows Active Directory Certificate Services, allowing authenticated attackers to hijack entire domains. The proof-of-concept exploit, dubbed “Certighost,” can be used to compromise even the most secure of networks. This critical flaw was patched as part of Microsoft’s July Patch … Read more

New Dysphoria DDoS botnet spreads to 200k devices worldwide

A Devastating DDoS Botnet Has Emerged, Threatening Global Stability A massive and highly resilient distributed denial of service (DDoS) botnet has been spreading rapidly across the globe, compromising over 200,000 devices in its wake. Dubbed Dysphoria, this botnet is using a novel combination of blockchain-based command-and-control (C2) resolution mechanisms and sophisticated networking techniques to evade … Read more

Arista patches VeloCloud Orchestrator zero-day exploited in attacks

A critical vulnerability in Arista’s VeloCloud Orchestrator (VCO) platform has been exploited by attackers, prompting the company to issue an emergency patch. The flaw, tracked as CVE-2026-16812, is a maximum-severity command injection bug that allows unauthenticated attackers to access privileged functionality and potentially compromise the confidentiality, integrity, and availability of the orchestrator and its managed … Read more

Hackers target US firms in FastJson RCE zero-day attacks

US Firms Under Attack as Hackers Exploit Critical Vulnerability in FastJson Library Hackers have been targeting US-based organizations with a devastating zero-day attack that leverages a critical vulnerability in the widely used FastJson Java library. The malicious activity, which has been observed by security researchers at ThreatBook and Imperva, affects various industries including finance, healthcare, … Read more

Coca-Cola confirms data theft in Fairlife ransomware attack

Coca-Cola Confirms Data Theft in Fairlife Ransomware Attack, Production Resumes Amid Investigation A devastating ransomware attack on Coca-Cola’s dairy subsidiary, Fairlife, has left the company scrambling to restore operations and protect its sensitive data. The global beverages giant confirmed that hackers stole data from Fairlife during a high-profile cyberattack earlier this month. While production in … Read more

New Certighost PoC exploit lets attackers hijack Windows domains

Windows Domain Hijacking Exploit Released, Warns of Significant Risks A new proof-of-concept exploit has been released for a previously patched vulnerability in Windows Active Directory Certificate Services, allowing attackers to potentially hijack entire domains. The exploit, dubbed “Certighost,” can be used by authenticated users to manipulate domain controller accounts and gain domain-level administrative capabilities. The … Read more

New Dysphoria DDoS botnet spreads to 200k devices worldwide

Dysphoria Botnet Expands to Over 200,000 Devices Worldwide, Threatening Global Networks A highly resilient and rapidly evolving botnet called Dysphoria has compromised over 200,000 devices worldwide, using them for distributed denial-of-service (DDoS) attacks and traffic relay operations. What’s more alarming is that this botnet leverages a covert blockchain-based command-and-control (C2) resolution mechanism to evade detection. … Read more

Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption

A New Chapter in IoT Botnet Evolution: Dysphoria Expands its Reach with Blockchain Command and Control The world of IoT botnets has just become even more complex, thanks to an emerging development involving a notorious threat actor group. Dysphoria, a highly sophisticated botnet, has recently expanded its capabilities by introducing a blockchain-based command and control … Read more

NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework

NVIDIA’s groundbreaking move to open-source its NOOA framework and form the 37-member Open Secure AI Alliance has sent shockwaves through the tech industry, sparking both excitement and trepidation among security professionals. At the heart of this initiative is a bold effort to harness artificial intelligence (AI) for cybersecurity, leveraging AI models to uncover previously unknown … Read more