Metabase has released security updates after confirming active exploitation of a zero day vulnerability that allows attackers to gain administrator access without authentication.
Research presented at Black Hat USA 2026 demonstrates CSS based attack techniques affecting major webmail services, highlighting risks involving passwords, authentication tokens, and AI connected email workflows.
Researchers have uncovered the NadMesh botnet targeting exposed AI services, cloud credentials, Kubernetes tokens, and administrative interfaces across internet facing systems.
Acronis has uncovered two cyber espionage campaigns by Mustang Panda targeting Indian government and hydropower organizations using new malware and Zoho WorkDrive as a command and control channel.
BeyondTrust outlines why identity security, privilege management, and assume breach strategies have become essential as enterprises face growing risks from AI driven attacks, machine identities, and trusted access abuse.
Google has patched a security flaw in the Vertex AI SDK for Python that could allow attackers to hijack machine learning model uploads through bucket squatting and execute malicious code within Google’s serving infrastructure.
Google uncovers a China linked cyber espionage campaign that abused Google Workspace rules to steal sensitive research and defense emails from organizations across United States and Canada.
RedSecLabs and RapidCompute have announced a strategic alliance to provide cybersecurity, cloud security, and compliance focused services for enterprises and regulated industries in Pakistan.
Cybersecurity researchers have identified six vulnerabilities in protobuf.js that could expose Node.js applications to remote code execution and denial of service attacks, impacting cloud services, AI systems, and CI/CD pipelines.
Threat actor PCPJack hijacked 230 AWS, Google Cloud, and Microsoft Azure servers to establish a covert SMTP relay network, according to Hunt.io findings.
Garaj has welcomed Alkhidmat Foundation Pakistan to its sovereign cloud infrastructure, supporting the migration of a nationally scaled mission critical application with zero operational disruption.
A new supply chain attack called Miasma has compromised Red Hat npm packages to steal credentials, target CI/CD environments, and deploy a self propagating malware campaign affecting developers and cloud systems.
An in-depth analysis of Data Security Posture Management (DSPM), risk-led cyber security, access governance, AI-driven data exposure, and evolving cyber resilience strategies in Pakistan’s growing digital economy.
PwC partners with Google Cloud to introduce an AI powered managed security service using agentic workflows, targeting mid sized and smaller enterprises with unified detection and response capabilities.