CISA urges immediate action on actively exploited Fortinet flaws

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning to government agencies to take immediate action against two critical security vulnerabilities in Fortinet’s threat detection platform, FortiSandbox. These flaws have been actively exploited by attackers in the wild, allowing unauthorized code execution through low-complexity command injection attacks. The good news is … Read more

US charges two over laundering $43 million from investment fraud

Two Individuals Charged with Laundering $43 Million from Investment Fraud Schemes In a major blow to international cybercrime syndicates, US prosecutors have charged two individuals with their roles in a large-scale money laundering operation that funneled at least $43 million in stolen funds from investment scams into bank accounts in China. Zhuoying Chen and Haojie … Read more

CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV

A Critical SharePoint Vulnerability Has Been Added to CISA’s KEV List, Posing Significant Risks for Enterprises Worldwide The US Cybersecurity and Infrastructure Security Agency (CISA) has taken swift action by adding a zero-day vulnerability in Microsoft SharePoint, known as CVE-2026-58644, to its Known Exploited Vulnerabilities (KEV) list. This move is a timely warning to organizations … Read more

Coca-Cola Suspends US Fairlife Production Due to Ransomware Attack

Coca-Cola Suspends US Fairlife Production Amid Ransomware Attack Coca-Cola has halted production at its US subsidiary Fairlife, a dairy company that distributes ultra-filtered milk, after detecting a ransomware attack. The incident, which is still under investigation, highlights the increasing threat of cybercrime to critical infrastructure and supply chains. Fairlife, based in Chicago, is a wholly … Read more

Fresh SharePoint Vulnerability Exploited Soon After Disclosure

A critical vulnerability in Microsoft SharePoint is being actively exploited by threat actors just days after its disclosure. The flaw, tracked as CVE-2026-58644 and fixed in July’s Patch Tuesday updates, allows attackers to execute arbitrary code remotely on a SharePoint Server, putting sensitive data at risk. The vulnerability affects authenticated users with Site Owner privileges, … Read more

CISA urges immediate action on actively exploited Fortinet flaws

A critical vulnerability in Fortinet’s threat detection platform has been exploited by attackers, prompting a warning from the US Cybersecurity and Infrastructure Security Agency (CISA) that government agencies must take immediate action to patch the flaw. The affected vulnerability, one of two actively exploited issues in the FortiSandbox platform, was addressed by Fortinet on April … Read more

US charges two over laundering $43 million from investment fraud

Cybercrime’s Dirty Money Trail Unraveled: US Charges Two for Laundering $43 Million from Investment Scams In a significant blow to international cybercrime, US prosecutors have charged two individuals with laundering millions of dollars stolen through investment scams. Zhuoying Chen and Haojie Zhang, a 27-year-old man and a 38-year-old woman respectively, allegedly managed a complex network … Read more

CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV

Cybersecurity authorities have just added a critical vulnerability, CVE-2026-58644, to the US government’s Known Exploited Vulnerabilities (KEV) catalog, sparking concerns among organizations using Microsoft SharePoint. This zero-day Remote Code Execution (RCE) flaw has been exploited by attackers in the wild since its discovery, leaving users vulnerable to data breaches and system compromise. The exploit targets … Read more

Two Scattered Spider Hackers Sentenced to Jail in UK

Two key members of the notorious Scattered Spider cybercrime group have been sentenced to lengthy prison terms in the UK, marking a significant victory for law enforcement agencies battling online threats. Thalha Jubair, 20, and Owen Flowers, 18, were found guilty of their roles in a massive 2024 cyberattack on Transport for London (TfL), which … Read more