Fresh SharePoint Vulnerability Exploited Soon After Disclosure

A critical vulnerability in Microsoft SharePoint is being actively exploited by threat actors just days after its disclosure. The flaw, tracked as CVE-2026-58644 and fixed in July’s Patch Tuesday updates, allows attackers to execute arbitrary code remotely on a SharePoint Server, putting sensitive data at risk. The vulnerability affects authenticated users with Site Owner privileges, … Read more

CISA urges immediate action on actively exploited Fortinet flaws

A critical vulnerability in Fortinet’s threat detection platform has been exploited by attackers, prompting a warning from the US Cybersecurity and Infrastructure Security Agency (CISA) that government agencies must take immediate action to patch the flaw. The affected vulnerability, one of two actively exploited issues in the FortiSandbox platform, was addressed by Fortinet on April … Read more

US charges two over laundering $43 million from investment fraud

Cybercrime’s Dirty Money Trail Unraveled: US Charges Two for Laundering $43 Million from Investment Scams In a significant blow to international cybercrime, US prosecutors have charged two individuals with laundering millions of dollars stolen through investment scams. Zhuoying Chen and Haojie Zhang, a 27-year-old man and a 38-year-old woman respectively, allegedly managed a complex network … Read more

CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV

Cybersecurity authorities have just added a critical vulnerability, CVE-2026-58644, to the US government’s Known Exploited Vulnerabilities (KEV) catalog, sparking concerns among organizations using Microsoft SharePoint. This zero-day Remote Code Execution (RCE) flaw has been exploited by attackers in the wild since its discovery, leaving users vulnerable to data breaches and system compromise. The exploit targets … Read more

Two Scattered Spider Hackers Sentenced to Jail in UK

Two key members of the notorious Scattered Spider cybercrime group have been sentenced to lengthy prison terms in the UK, marking a significant victory for law enforcement agencies battling online threats. Thalha Jubair, 20, and Owen Flowers, 18, were found guilty of their roles in a massive 2024 cyberattack on Transport for London (TfL), which … Read more

Legacy Systems, Real-World Impacts: The Reality of OT Security

Legacy Systems, Real-World Impacts: The Reality of OT Security As a cybersecurity journalist, I’ve witnessed firsthand the growing concern around operational technology (OT) security. It’s an area where legacy systems meet harsh realities, putting critical infrastructure and lives at risk. Recently, I had the opportunity to explore this complex world through the lens of vulnerability … Read more

1M+ Emails Use Hidden Text to Dupe AI Security Filters

As many as 1 million retail-themed phishing emails have been evading both static and artificial intelligence-powered email security checks by using a simple yet effective technique called text salting. This tactic involves peppering spam content with innocuous filler words or stories to break up malicious language, making it harder for automated filters to detect. The … Read more

Agentic AI Is Untamable: Ask the Right Security Questions

Agentic AI Is Creating Unpredictable Risks for Organizations, Demanding a Fundamental Shift in Security Thinking The notion that artificial intelligence (AI) can be controlled and predicted has been turned on its head by the emergence of agentic systems. These intelligent agents are capable of adapting to their environment and making decisions autonomously, creating significant risks … Read more

New Spirals ransomware encrypts victim network in under 24 hours

A new and highly aggressive strain of ransomware, dubbed Spirals, has been uncovered by researchers at Symantec’s Threat Hunter Team. This powerful threat not only encrypted a corporate network in under 24 hours but also displayed a chilling level of sophistication and speed. The attack, which occurred in June, targeted an IT services firm in … Read more

1M+ Emails Use Hidden Text to Dupe AI Security Filters

Cyberattackers have devised a sneaky way to evade email security filters, exploiting a weakness in artificial intelligence-powered detection tools. Since April, over 1 million retail-themed phishing emails have slipped into inboxes, using hidden text to make malicious social engineering appear legitimate. These emails are not just any ordinary spam messages. They employ obvious social engineering … Read more