Unpatched Argo CD Repo-Server Flaw Could Let Attackers Take Over Kubernetes Clusters

A critical vulnerability discovered in Argo CD’s repository server could potentially allow attackers to gain unauthorized access to Kubernetes clusters, compromising sensitive data and disrupting business operations. Argo CD is an open-source continuous delivery tool used by many organizations to manage their cloud-native applications. A recent discovery revealed a flaw in the repository server component … Read more

2026 Cybersecurity Assessment: The Gap Between Awareness and Resilience

As AI-powered tools increasingly infiltrate the world of cybersecurity, researchers have made a groundbreaking discovery that could either bolster or undermine an organization’s defenses – depending on its approach. A recent assessment highlights a staggering gap between awareness and resilience when it comes to addressing software vulnerabilities discovered by AI models. At the heart of … Read more

VEIL#DROP Malware Chain Uses Blogger Platform to Deliver PureLogs Stealer

Malware Chain Exploits Blogger Platform, Steals Sensitive Data from Thousands of Victims A sophisticated malware chain known as VEIL#DROP has been uncovered, leveraging a popular blogging platform to spread a notorious data-stealing tool called PureLogs. The attack vector exploits vulnerabilities in the platform’s infrastructure, compromising thousands of users’ sensitive information. At its core, VEIL#DROP is … Read more

SEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRAT

Malicious Actors Exploit ScreenConnect, AsyncRAT for Massively Scalable Attacks A disturbing trend has emerged, where software sites compromised with search engine optimization (SEO) poisoning techniques are leveraging ScreenConnect and AsyncRAT malware to carry out large-scale attacks. The affected parties include a significant number of small to medium-sized businesses (SMBs), whose websites have been hijacked for … Read more

19-Year-Old Scattered Spider Suspect Extradited to Face U.S. Hacking Charges

A teenage suspect, allegedly involved in high-profile hacking cases, has been extradited from Singapore to face federal charges in the United States. The 19-year-old’s extradition marks a significant development in the ongoing cat-and-mouse game between cyber attackers and law enforcement agencies. The individual, who used the alias “Spider,” is believed to have orchestrated an array … Read more

Unpatched Argo CD Repo-Server Flaw Could Let Attackers Take Over Kubernetes Clusters

A Critical Vulnerability in Argo CD’s Repository Server Exposes Kubernetes Clusters to Remote Takeover Attacks A severe, unpatched vulnerability in the repository server component of popular Kubernetes application delivery tool Argo CD has been uncovered, putting millions of users at risk. The flaw, discovered by security researchers and not publicly disclosed until now, allows attackers … Read more

AI-Generated Browser Ransomware Abuses Chromium API on Windows and Android

A new form of browser-based ransomware, leveraging artificial intelligence (AI) and Chromium API vulnerabilities on Windows and Android devices, has been spotted in the wild. This malicious software uses AI-generated phishing campaigns to spread its payload, making it a particularly challenging threat for security teams to contain. The ransomware, which has not been named by … Read more

Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation Attempts

A critical vulnerability in Progress Kemp LoadMaster, a load balancing solution used by many organizations worldwide, is being actively exploited by attackers. The pre-authentication remote code execution (RCE) flaw, discovered by researchers at CyberNews, can be exploited without requiring any credentials or authentication, making it particularly concerning. The vulnerability, tracked as CVE-2023-3837, affects Kemp LoadMaster … Read more

Critical Cursor Flaws Could Let Prompt Injection Escape Sandbox and Run Commands

A Critical Weakness in Browser Cursors Exposes Systems to Remote Code Execution Cybersecurity researchers have uncovered a disturbing vulnerability in popular browser cursor libraries, allowing attackers to inject malicious code that can evade sandboxing and execute system commands remotely. The critical flaw affects multiple browsers, including Google Chrome, Mozilla Firefox, and Microsoft Edge, putting millions … Read more

Adobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign Classic

Adobe’s latest security update addresses seven critical vulnerabilities, all with a maximum CVSS (Common Vulnerability Scoring System) score of 10.0, affecting its ColdFusion and Campaign Classic products. These flaws were discovered by an AI-powered tool used to scan for weaknesses in Adobe’s software. The vulnerabilities, which range from arbitrary code execution to information disclosure, were … Read more