Over 900 Oracle E-Business instances exposed to ongoing attacks

Over 900 Oracle E-Business instances exposed to ongoing attacks, with malicious actors exploiting a critical security flaw that allows for low-complexity takeovers. The vulnerability, tracked as CVE-2026-46817, was patched by Oracle in May but has since been actively exploited, according to threat intelligence firm Defused. Oracle’s E-Business Suite (EBS) is a widely used business software … Read more

Turning Indicators into Intelligence in OpenCTI with Criminal IP

A New Era in Threat Intelligence: OpenCTI Teams Up with Criminal IP to Transform Indicators into Structured Intelligence In a major breakthrough for cybersecurity teams, the integration of Criminal IP’s threat intelligence with OpenCTI is revolutionizing the way indicators are analyzed and utilized. This powerful combination is transforming isolated IP addresses, domains, and URLs into … Read more

Hackers target Microsoft 365 accounts with 81 million login attempts

A massive password-spraying campaign has targeted Microsoft 365 accounts with a staggering 81 million login attempts over just two weeks. The attack, which exploited valid username and password combinations exposed in past breaches, has left at least 78 businesses across 64 organizations compromised. The alarming numbers highlight the importance of robust security measures, particularly when … Read more

Webinar: Why traditional email security is no longer enough

Email Security No Longer Enough as Modern Attacks Exploit Trust Traditional email defenses are failing to keep pace with the evolving landscape of cyber threats. For years, organizations have relied on secure email gateways, reputation services, and signature-based detection to stop phishing attacks before they reached employees. However, today’s attackers are increasingly exploiting trusted identities … Read more

DHS confirms hackers breached HSIN info-sharing platform

Cyber Attack on DHS Info-Sharing Platform Raises Security Concerns Across the US A recent cyber attack has compromised the Homeland Security Information Network (HSIN), a sensitive information-sharing platform used by federal, state, local, and private-sector partners. The Department of Homeland Security is currently investigating the breach, which is believed to have occurred sometime between late … Read more

New ChocoPoC malware targets researchers via trojanized PoC exploits

Cybersecurity Researchers Targeted by Malicious Proof-of-Concept Exploits Delivering ChocoPoC RAT A sophisticated campaign has been uncovered, where multiple proof-of-concept (PoC) exploits on GitHub are being used to deliver a Python-based remote access trojan (RAT) named ChocoPoC. The malware is designed to target cybersecurity researchers and has the capability to execute commands, steal sensitive data, and … Read more

Kubota says hackers had month-long access to network systems

Kubota’s Network Breach Exposes Employee Data to Hackers for Over a Month Japanese industrial giant Kubota has revealed that its network systems were compromised by hackers for over a month, leaving sensitive employee data vulnerable. The breach, which occurred between March 16 and April 20 this year, exposed personal information of employees and their dependents, … Read more

FortiBleed credential-theft campaign linked to Lynx ransomware

A massive credential-theft campaign linked to two notorious ransomware operations has exposed over 73,000 Fortinet devices and compromised an estimated 430,000 firewalls worldwide. The operation, dubbed “FortiBleed,” has been tied to members of the INC and Lynx ransomware-as-a-service (RaaS) groups by researchers at SOCRadar. The campaign’s scope is staggering, with over 19,000 devices deploying traffic … Read more

Webinar: Why traditional email security is no longer enough

Traditional Email Security is No Longer Enough: How Behavioral AI Can Help As we’ve seen all too often, phishing attacks have evolved beyond relying on malicious attachments or suspicious domains. Today’s attackers are becoming increasingly adept at impersonating trusted colleagues, vendors, and business partners, using legitimate authentication workflows to blend into everyday business communications. This … Read more

DHS confirms hackers breached HSIN info-sharing platform

The Department of Homeland Security’s (DHS) sensitive information-sharing platform, the Homeland Security Information Network (HSIN), has been breached by an unknown threat actor. The intrusion occurred sometime between late May and early June, with DHS currently investigating the attack to determine the extent of the compromise. HSIN is a critical tool used by federal, state, … Read more