EU Targets Russian Intelligence Officers Accused of Running a Yearslong Cyber Spying Campaign

The European Union has taken a decisive step against Russian cyber espionage, imposing sanctions on nine individuals and four entities accused of participating in a yearslong campaign to undermine EU governments and critical infrastructure. The move targets those responsible for a sprawling online spying network that has been active since 2010, with attacks detected in … Read more

Zimbra Patches Critical Code Execution Vulnerability

Critical Vulnerability in Zimbra Collaboration Software Puts Users at Risk of Code Execution A severe vulnerability has been discovered in the popular collaboration software Zimbra, which could allow hackers to execute malicious code on users’ devices simply by sending a specially crafted email. The flaw affects the Classic Web Client and could potentially grant access … Read more

RabbitMQ Vulnerability Threatens Enterprise Systems

A critical vulnerability in RabbitMQ, a popular open-source message broker, has been discovered by cybersecurity firm Miggo. The flaw, tracked as CVE-2026-5721 (CVSS score of 8.7), allows attackers to obtain the broker’s confidential OAuth secret, potentially granting them access to sensitive data and systems. The vulnerability affects RabbitMQ instances where the administrator has set up … Read more

Pentagon Suspends CMMC Phase 2 as It Rethinks Contractor Cybersecurity Rules

The Pentagon has put the brakes on its ambitious Cybersecurity Maturity Model Certification (CMMC) program, at least for now. The move comes as a welcome relief to small and non-traditional businesses that have been struggling to comply with the rigorous cybersecurity standards required by the framework. Under the CMMC, companies handling sensitive government information must … Read more

Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths

A year-long operation, linked to ShinyHunters, a notorious hacking collective, has compromised sensitive data from Salesforce customers worldwide. The breach, which began in August 2025 and continued until May of this year, allowed attackers to pilfer sensitive information through three distinct vectors. At the heart of the operation was AI-powered threat research, which enabled the … Read more

Turning the Tables on Email Scammers With ‘ScamBuster’

The cat-and-mouse game between email scammers and their victims is about to take a dramatic turn. A new open-source tool called ScamBuster, developed by French engineer Laurent Giovannoni, uses artificial intelligence (AI) to “scam the scammers” at scale. Instead of simply deleting phishing emails, ScamBuster engages with attackers using AI-driven human personas, gathering crucial data … Read more

GigaWiper Lets Threat Actors Choose Their Own Destructive Attack

A New Breed of Malware Lets Attackers Choose Their Own Destructive Path In a disturbing development that highlights the evolving tactics of cyber threat actors, researchers have uncovered a novel modular malware that allows attackers to choose how they want to destroy a targeted system. Dubbed GigaWiper, this malware combines multiple malware capabilities into a … Read more

‘Yellow Teams’ Are Defining the Future of AI Security

As AI models like Claude Mythos and GPT-5.5 gain widespread attention for their potential in cybersecurity, a new breed of engineers is emerging to shape the future of artificial intelligence security. Dubbed “yellow teams,” these innovators are building both defenses against advanced AI attacks and frameworks that attackers will utilize to carry out those assaults. … Read more

Cybersecurity M&A Roundup: 37 Deals Announced in June 2026

Cybersecurity firms are on a buying spree, with 37 merger and acquisition deals announced in June alone. This trend is not new, but its pace and scale are unprecedented. In fact, 2025 saw over 420 cybersecurity-related acquisitions, making it one of the busiest years on record. One of the most significant deals was 1Password’s acquisition … Read more

Weak Security Continues to Fuel Russian Cyberattacks

Russian State-Sponsored Hackers Exploit Weak Network Security to Gain Access to Critical Infrastructure Worldwide A joint advisory from US cybersecurity agencies and their counterparts in a dozen allied countries has revealed that state-sponsored threat actors affiliated with Russia’s Federal Security Service (FSB) Center 16 continue to compromise weakly protected routers and other networking equipment to … Read more