Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development

Identity Exposure Unleashes Devastating Chain Reactions in Cyberattacks A disturbing trend has emerged in the world of cybercrime, where identity exposure is being used as a stepping stone to launch devastating attacks. The alarming reality is that once an attacker gains access to sensitive information about an individual or organization, they can exploit it to … Read more

New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

A new class of attacks has emerged, targeting sensitive information stored in password managers and multi-factor authentication (MFA) systems. Dubbed “Passkey Attacks,” these exploits can recover synced private keys or bypass phishing-resistant MFA, leaving users vulnerable to credential theft and identity compromise. The Passkey Attack methodology relies on exploiting a previously unknown vulnerability in the … Read more

Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development

Kimsuky’s Stealthy Offline AI Stack Exposes Millions to Phishing and Malware Attacks A sophisticated cyber threat actor group, Kimsuky, has been building an offline artificial intelligence (AI) stack that enables them to boost phishing attacks and automate malware development. This disturbing capability puts millions of individuals at risk, highlighting the evolving nature of cyber threats. … Read more

Metabase Patches Vulnerability Exploited as Zero-Day

Metabase Patches Critical SQL Injection Vulnerability Exploited in Wild A critical-severity SQL injection vulnerability in Metabase’s data analytics solutions has been exploited by attackers as a zero-day, allowing them to gain administrative access and steal sensitive data. The company has released urgent patches for the flaw, which affects multiple versions of its software. The vulnerability … Read more

New Jersey, Alabama Join States Targeted in Water Cyberattacks

The US Water Sector Under Siege: Cyberattacks Hit at Least 12 States, Raising Concerns Over Public Safety A growing number of states across the country are coming forward to confirm that their water and wastewater facilities have been targeted in a coordinated hacking campaign. At least 12 states have reportedly been affected, with New Jersey … Read more

Critical Progress LoadMaster flaw now actively exploited in attacks

Critical Progress LoadMaster Flaw Exposed to Hackers Worldwide A severe security vulnerability in the popular Application Delivery Controller (ADC) and server load balancer, Kemp LoadMaster, has been actively exploited by hackers. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned that this critical command injection flaw can allow unauthenticated attackers to execute arbitrary commands … Read more

Valve notifies Steam hardware customers of a data breach

Steam Hardware Customers Hit by Data Breach After CEVA Logistics Hacking Valve, the company behind the popular digital distribution platform Steam, is notifying its hardware customers in Europe that their data has been stolen following a hacking incident at its shipping partner, CEVA Logistics. The breach has exposed sensitive information, including names, addresses, phone numbers, … Read more

LexisNexis shuts down services after suspicious activity on servers

LexisNexis Shuts Down Services Amid Suspicious Activity on Third-Party Servers Global data analytics company LexisNexis has taken its Diligence, Metabase API, and Newsdesk services offline as a precautionary measure after detecting unusual activity on servers hosted by an unnamed third-party vendor. The move is part of the company’s response to the incident, which includes investigating … Read more

Corporate Data Stolen in Levi Strauss Cyberattack

Levi Strauss & Co Hit by Cyberattack, Corporate Data Stolen from Employee Computers In a disturbing revelation, denim giant Levi Strauss & Co has disclosed that it suffered a cyberattack earlier this week, resulting in the theft of corporate data from employee computers. The incident, which was caused by social engineering tactics, highlights the ongoing … Read more

CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability

Critical LoadMaster Vulnerability Exploited in the Wild, CISA Warns of Immediate Patching The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a urgent warning to federal agencies to patch a critical vulnerability in Progress Kemp LoadMaster that has been actively exploited by attackers. The flaw, tracked as CVE-2026-8037 with a CVSS score of 9.6, … Read more