Microsoft confirms outage affecting search in Microsoft 365 apps

A Search Outage Hits Microsoft 365, Leaving Some Users Stranded Microsoft has confirmed an outage affecting search functionality within its Microsoft 365 suite of apps. The issue has left some users unable to search for content within SharePoint Online, OneDrive, Outlook on the web, and Outlook desktop. While the company hasn’t specified which regions are … Read more

CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE

A critical vulnerability in a widely used browser plugin has been flagged by US authorities as actively exploited, potentially giving hackers the keys to remote code execution and unleashing devastating attacks on unsuspecting users. The flaw, designated as Ray, resides within an innocuous-looking library that is embedded across multiple applications, including those related to financial … Read more

SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers

A Vulnerability in SafePal Hardware Wallets Exposed Personal Data of Thousands SafePal, a Singapore-based company that produces hardware wallets for cryptocurrency users, has disclosed a critical security flaw that exposed sensitive information about nearly 40,000 customers. The vulnerability, discovered by an anonymous researcher and reported to SafePal through their bug bounty program, allowed attackers to … Read more

Details emerge on BlackFile’s recent attacks on financial companies

A notorious cybercrime group, BlackFile, has been wreaking havoc on financial companies and other organizations across multiple industries. According to researchers at Google Threat Intelligence Group (GTIG), this threat actor has been active since the start of 2026, targeting victims with ease and extorting them for millions of dollars. BlackFile’s modus operandi is a perfect … Read more

Recent macOS Screen Sharing Vulnerability Exploited in Attacks

Threat actors are exploiting a recently patched macOS vulnerability to gain root access and deploy cryptominers on vulnerable systems. The bug, tracked as CVE-2026-65400, is an authentication issue in Screen Sharing that allows remote attackers to log in without valid credentials. The vulnerability has been observed being exploited by threat actors roughly a week after … Read more

Microsoft starts removing WMIC tool used by cybercriminals

A crucial tool for cybercriminals is being phased out by Microsoft, marking a significant step towards improving the security of Windows devices. The company has started removing the Windows Management Instrumentation Command-line (WMIC) tool from various versions of its operating system, including Windows 11 24H2 and 25H2. For those unfamiliar with WMIC, it’s a legacy … Read more

CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE

**Critical Flaw Exposed in Browsers, Triggers Remote Code Execution** The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a high-priority alert warning about an actively exploited vulnerability known as “Ray” that can grant attackers remote code execution (RCE) capabilities. This flaw affects multiple web browsers, including Google Chrome, Mozilla Firefox, and Microsoft Edge, putting … Read more

Details emerge on BlackFile’s recent attacks on financial companies

A Highly Organized Extortion Group Targets Financial Firms with Sophisticated Voice Phishing Attacks BlackFile, a cybercrime group tracked by Google Threat Intelligence Group as UNC6671 and associated with The Com, has been wreaking havoc on financial companies, law firms, and private equity firms since the start of this year. What’s alarming is that despite being … Read more

40,000 Impacted by SafePal Data Breach

SafePal Cryptocurrency Wallet Suffers Massive Data Breach, 40,000 Customers Impacted A massive data breach has left around 40,000 customers of SafePal, a popular cryptocurrency hardware wallet, vulnerable to potential financial loss. The attackers exploited a vulnerability in the order-tracking function of a customer order information plugin, gaining access to sensitive personal and order details. The … Read more