Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw

A freshly disclosed exploit for a pre-authentication code execution vulnerability in vBulletin, a popular online forum software, is wreaking havoc on unsuspecting users. The bug, first patched by vBulletin’s developers several months ago, has been exploited by attackers to inject malicious code and steal sensitive data from compromised websites. The vulnerable software, widely used by … Read more

Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack

Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack A devastating cyberattack has left one of the world’s largest beverage companies reeling. Coca-Cola has confirmed that its dairy products subsidiary, Fairlife, was hit by a ransomware attack from the Anubis group. The cybercriminals claim to have stolen over 1 terabyte (TB) of confidential data, including files … Read more

Nvidia and Tech Giants Launch AI Security Alliance

A group of tech giants, led by Nvidia, has launched a new initiative to develop and share open-source tools for securing artificial intelligence (AI) systems. The Open Secure AI Alliance brings together companies like Adobe, Cisco, IBM, Microsoft, and many others to create a collective defense against the growing threats in the AI security landscape. … Read more

MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection

A Stealthy RAT Hides in Plain Sight: MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection A sophisticated remote access trojan (RAT) has been discovered using a legitimate Windows feature to evade detection and remain hidden from users. MedusaHVNC, sold as malware-as-a-service (MaaS), is promoted through its own website and Telegram channel, and was analyzed … Read more

PTC Windchill Vulnerability Exploited in Ransomware Campaign

A Cl0p Ransomware Affiliate Exploits Critical PTC Windchill Vulnerability, Targeting Multiple Industries A critical remote code execution (RCE) vulnerability in PTC’s product lifecycle management (PLM) platforms Windchill and FlexPLM has been exploited by a Cl0p ransomware affiliate. The bug, tracked as CVE-2026-12569 with a CVSS score of 9.3, allows attackers to execute code on vulnerable … Read more

Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware

A sophisticated malware campaign, dubbed “Cruciferra Crypter,” has been uncovered, leveraging advanced techniques to evade detection and remain hidden on infected Windows systems. The malicious software employs two key tactics: Bring Your Own Vulnerability Disclosure (BYOVD) and process ghosting, making it a particularly challenging foe for cybersecurity teams. The Cruciferra Crypter malware operates by exploiting … Read more

Beelzebub Raises $3.4 Million for Hacker-Trapping Platform

Beelzebub Raises $3.4 Million for Innovative Hacker-Trapping Platform Italian cybersecurity startup Beelzebub has secured a significant seed funding round of €3 million ($3.4 million) led by VC United Ventures, bringing its total raised to $3.8 million. This injection of capital will enable the company to expand its research team, open new offices in Rome and … Read more

Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack

A major food and beverage company has fallen victim to a devastating data breach, with one of its dairy products subsidiaries caught in the crosshairs of a ruthless ransomware gang. Coca-Cola has confirmed that its Fairlife subsidiary was targeted by the Anubis group, resulting in the theft of sensitive data and disruption to operations. The … Read more

GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption

GitHub, the popular code-sharing and collaboration platform, has introduced a new feature aimed at mitigating the spread of malicious packages on its network. The company has implemented a 3-day cooldown period for Dependabot, its automated dependency management tool, in an effort to limit the adoption of compromised packages. This move comes as a response to … Read more

TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments

A sophisticated cyber threat group, known as TELESHIM, has been leveraging Telegram’s messaging platform to establish command and control (C2) channels for launching targeted attacks against Middle Eastern governments. This alarming trend highlights the evolving tactics of advanced persistent threats (APTs), which are increasingly exploiting popular communication tools to stay under the radar. TELESHIM’s exploitation … Read more