Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

Cybersecurity researchers have discovered a severe vulnerability in Microsoft SharePoint that allows attackers to bypass authentication and gain unauthorized access to sensitive data. The flaw, which was publicly disclosed earlier this week, has left many organizations scrambling to patch their systems and mitigate potential risks. SharePoint is a popular collaboration platform used by millions of … Read more

Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset

A Sophisticated Campaign Targets Salesforce and ServiceNow with Custom Toolset Researchers at Reco have uncovered a stealthy and innovative campaign that’s been targeting both Salesforce and ServiceNow using a custom-made multi-platform toolset. Dubbed “City-Forum”, this campaign has been exploiting vulnerabilities in both platforms, primarily focusing on unauthenticated guest user access. The primary targets of the … Read more

WhatsApp Unveils New Scam Alert Feature

WhatsApp has just unveiled a new Scam Alert feature, designed to protect users from phishing attacks and scams. This optional tool uses machine learning to analyze incoming messages for suspicious patterns, flagging potential threats without compromising end-to-end encryption. The feature is still in its beta phase, but it’s an exciting development that could help reduce … Read more

Mindgard Raises $30 Million to Protect AI Systems

Mindgard Secures $30 Million to Protect Against AI Risks In a significant move to bolster defenses against the growing threat of artificial intelligence (AI) security risks, Mindgard, an AI security startup, has raised $30 million in a Series A funding round. This investment brings the company’s total funding close to $42 million and paves the … Read more

Belgium’s eID Authentication Opens Citizen Accounts to RCE

Belgian Citizens’ eID Accounts Exposed to Remote Code Execution Threats A severe vulnerability in a widely-used browser extension has compromised the security of millions of Belgian citizens’ electronic ID (eID) accounts. The Connective signing extension, which allows users to authenticate with government and banking services online using their physical smart cards, contains critical flaws that … Read more

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

A Critical SharePoint Vulnerability Exposes Organizations Worldwide to Cyber Threats Attackers have been exploiting a previously disclosed authentication bypass vulnerability in Microsoft SharePoint, compromising sensitive data and leaving many organizations vulnerable to cyber threats. The issue allows attackers to gain unauthorized access to privileged sites, essentially creating a backdoor for malicious activities. The vulnerability, first … Read more

SharePoint Vulnerability Exploited Shortly After PoC Release

SharePoint Vulnerability Exploited in the Wild, Puts Users at Risk A recently patched SharePoint vulnerability is being actively exploited by attackers, just days after a proof-of-concept (PoC) exploit was released. The weakness, tracked as CVE-2026-55040, allows an unauthenticated attacker to bypass security features and access sensitive data on a SharePoint site. Microsoft had fixed the … Read more

Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA

Critical Infrastructure Under Siege as Gunra Ransomware Gang Exploits Fortinet Flaws A sophisticated ransomware-as-a-service (RaaS) operation is wreaking havoc on critical infrastructure targets worldwide, exploiting known vulnerabilities in firewalls and VPN appliances to bypass even the most robust defenses. The Gunra gang, which emerged in spring 2025, has been using leaked Conti code and outdated … Read more

Microsoft’s Patch Tuesday Deluge Continues With August Updates

Microsoft’s August Patch Tuesday Release Brings 421 Critical Vulnerabilities, but Prioritization is Key Microsoft has released its latest batch of security updates, addressing a staggering 421 unique Common Vulnerability and Exposure (CVE) issues. This massive patch release marks the second consecutive month where Microsoft’s fixes have far exceeded the typical volume of security updates. Of … Read more

Walmart Leaders Transform Security Operations Without Going Bananas

Walmart Transforms Security Operations with Trust, Innovation, and a Dash of Humor In a major shift in approach, Walmart has successfully scaled up its cybersecurity defenses without stifling innovation or slowing down business operations. The retail giant’s leadership team has adopted an innovative strategy that balances security value with operational efficiency, fostering trust and collaboration … Read more