Why Even the Best Edge Security Still Misses High-Risk Sessions

As it turns out, even the most robust edge security measures can be bypassed by sophisticated attackers who expertly hide their malicious activity within seemingly legitimate user sessions. Despite having a multitude of security controls at our disposal, including request inspection, credential validation, device fingerprinting, and automation signals, cybercriminals continue to evade detection. The reason … Read more

Critical Langflow flaw exploited to steal OpenAI and AWS keys

A critical vulnerability in Langflow, an open-source framework for building AI applications, has been exploited by threat actors to steal sensitive credentials and keys. The attack vector targets the code validator in Langflow’s custom component editor, allowing attackers to execute arbitrary code without authentication with root privileges. The vulnerability, CVE-2026-0768, was disclosed in January but … Read more

Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems

A sophisticated cyberattack has unfolded in Brazil, where a group of hackers known as Breeze Comet have compromised multiple payment systems, executing hundreds of fraudulent transactions and leaving victims with significant financial losses. The brazen heist highlights the importance of robust security measures, particularly in the realm of identity exposure. At its core, this attack … Read more

Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure

Critical Flaw in JFrog Artifactory Exposes Users to Admin Token Theft A critical vulnerability in JFrog’s popular Artifactory software has been exploited by attackers, just days after its disclosure. The flaw allows unauthorized access to admin tokens, potentially giving hackers complete control over affected systems. JFrog Artifactory is a widely used platform for managing and … Read more

Why Even the Best Edge Security Still Misses High-Risk Sessions

Despite the proliferation of edge security controls, attackers are still managing to evade detection by hiding in plain sight. Security teams have at their disposal a range of tools designed to inspect requests, validate credentials, and identify automation signals – but even with the best technology, malicious actors can slip through undetected. The problem lies … Read more

Novocure data breach affects more than 1,400 cancer patients

A major healthcare company’s sensitive patient data has been compromised in a cyberattack, leaving over 1,400 cancer patients vulnerable to potential identity theft and medical record tampering. Novocure, a global oncology firm specializing in non-invasive electromagnetic field therapy for cancer tumors, revealed that its network was breached in mid-August, exposing the private information of employees … Read more

Hackers push malicious Virtualizor update in BGP hijacking attack

A Sophisticated Cyberattack Targets Virtualizor VPS Management Software A highly coordinated cyberattack has targeted the Virtualizor virtual private server (VPS) management software, leaving a small number of users vulnerable to potential security breaches. The attackers exploited a Border Gateway Protocol (BGP) hijacking attack to redirect update requests for Virtualizor to malicious servers, allowing them to … Read more

Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests

Iranian hackers have been using a sophisticated tactic to deliver cross-platform Remote Access Trojans (RATs) to unsuspecting victims, with the attackers posing as recruiters offering coding tests. This brazen approach has allowed them to successfully compromise multiple organizations across various industries, exploiting vulnerabilities in human psychology and technical systems alike. The modus operandi of these … Read more

13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds

A sophisticated malware campaign has been uncovered, targeting unpatched iPhones and exploiting a vulnerability in their package management system. At least 13 malicious packages have been discovered on Packagist, a popular PHP library repository, which are designed to steal cryptocurrency wallet seeds from unsuspecting iPhone users. The attack begins when an iPhone user installs one … Read more

Novocure data breach affects more than 1,400 cancer patients

A devastating data breach has struck cancer treatment company Novocure, exposing sensitive information of over 1,400 US cancer patients and an undisclosed number of employees. The attack, which occurred in mid-August, highlights the ongoing vulnerability of healthcare organizations to cyber threats. Novocure, a global oncology company with operations in multiple continents, is known for its … Read more