Cisco finally confirms attackers exploiting Unified CM flaw

A Critical Vulnerability in Cisco’s Unified Communications Manager is Being Actively Exploited by Attackers A major cybersecurity vulnerability has been confirmed to be actively exploited by attackers, putting thousands of businesses and organizations at risk. Cisco Systems, a leading provider of networking equipment and software, has finally acknowledged that its Unified Communications Manager (Unified CM) … Read more

FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations

**AI-Powered Attackers Leverage FortiBleed Flaw to Steal Sensitive Data** A highly sophisticated cyberattack has been linked to two notorious ransomware operations, exploiting a previously unknown vulnerability in a popular software package. The attack, dubbed “FortiBleed,” uses artificial intelligence (AI) to scan for and exploit vulnerabilities in network devices, highlighting the growing threat of AI-powered attacks. … Read more

Opera rolls out Paste Protect feature to fight ClickFix attacks

Opera has rolled out a new security feature called Paste Protect, designed to block ClickFix-style attacks that trick users into executing malicious commands through social engineering. This technique, known as ClickFix, involves deceiving victims into copying and pasting potentially destructive code or commands into their command-line interface, where they execute with the user’s privileges, bypassing … Read more

AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack

A sophisticated AI-powered cyberattack has exploited a known vulnerability in Langflow, an open-source Python library used for image processing and deep learning tasks, to automate database ransomware attacks on unsuspecting organizations. The attack highlights the increasingly complex threat landscape and underscores the need for vigilance against emerging security risks. The vulnerability, discovered by researchers last … Read more

CISA: Microsoft SharePoint RCE flaw now actively exploited

A Critical SharePoint Flaw is Being Actively Exploited by Hackers, Says CISA The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning that a high-severity vulnerability in Microsoft’s SharePoint platform is being exploited by attackers. This flaw, tracked as CVE-2026-45659, allows hackers to execute arbitrary code on unpatched SharePoint servers with just low-level … Read more

Cisco finally confirms attackers exploiting Unified CM flaw

Attackers are now exploiting a critical vulnerability in Cisco’s Unified Communications Manager (Unified CM) software, despite patches being released just over a month ago. This development highlights the ongoing threat of cyberattacks on business communication systems and emphasizes the importance of prompt patching and security measures. Unified CM is a central control system used by … Read more

FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations

A devastating credential theft campaign, dubbed FortiBleed, has been linked to notorious ransomware operations Inc and Lynx. The attack, which leverages vulnerabilities in enterprise security solutions, has compromised sensitive information from numerous organizations worldwide, leaving businesses scrambling to contain the damage. At its core, FortiBleed exploits a specific weakness in Fortinet’s SSL/TLS (Secure Sockets Layer/Transport … Read more

AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack

A sophisticated AI-powered attack has leveraged a previously unknown vulnerability in Langflow, an open-source framework for natural language processing, to automate a database ransomware assault on several high-profile targets. The AI agent exploited the Remote Code Execution (RCE) flaw, dubbed “LangFlow-1,” to breach sensitive databases and encrypt crucial data. The exploitation of LangFlow-1 marks a … Read more

Safe Events Start With Threat Intel and Digital Security

Major events like sports championships, festivals, and government celebrations attract global attention, but they also come with significant cybersecurity risks. These threats don’t appear out of nowhere; rather, they’re often well-planned and executed by malicious actors who begin gathering intelligence months or even years in advance. When we think about event security, our minds often … Read more

‘Phantom Squatting’: An Emerging AI-Driven Supply Chain Threat

Cybercriminals are using a new and insidious attack vector called “phantom squatting” to threaten the software supply chain. By exploiting the tendency of large language models (LLMs) to “hallucinate” or generate fictional web domains for legitimate brands, attackers can register nonexistent domains linked to these brands, creating a perfect trap for unsuspecting users. The technique … Read more