Tag: cybersecurity

StopAndProtect Campaign Abuses WordPress Sites To Deliver Malware And Steal Data

Check Point Research uncovers StopAndProtect operation using nearly 2,000 hacked WordPress websites for malware distribution, surveillance, and data theft.

CISA Flags Apple Microsoft And VMware Vulnerabilities Exploited In Active Attacks

CISA adds four critical vulnerabilities affecting macOS, SharePoint, VMware vCenter, and Microsoft IKE Service Extensions to its KEV catalog.

Awan Distribution Hosts Reconnect Sophos Day In Karachi For Channel Partners

Awan Distribution organized Reconnect Sophos Day in Karachi, featuring updates on Sophos cybersecurity and networking solutions, partner incentives, business opportunities, and sales enablement.

CISA Warns Of Active Exploitation In Critical Ray Remote Code Execution Vulnerability

CISA has added a critical Ray vulnerability to its KEV catalog after active exploitation reports. The flaw could allow remote code execution through browser based DNS rebinding attacks.

Wiz Reveals GitHub Actions Workflow Vulnerability In Snowflake Repository

Wiz has disclosed a GitHub Actions workflow injection flaw in a Snowflake public repository that could allow crafted GitHub issues to trigger command execution and expose internal Jira credentials.

Critical Forminator Plugin Vulnerability Puts Thousands Of WordPress Sites At Risk

A critical vulnerability in the Forminator WordPress plugin could allow unauthenticated attackers to upload malicious PHP files and execute remote code on vulnerable websites.

Evooo1Bot Malware Targets Linux Devices Through Multiple Known Vulnerabilities

Fortinet researchers have identified the Evooo1Bot Linux botnet, which exploits multiple known vulnerabilities to compromise internet facing devices and convert them into SOCKS5 proxy nodes.

VMware vCenter Vulnerability Exploited In Global Campaign Linked To Suspected China Nexus Threat Actor

Researchers have linked active exploitation of VMware vCenter vulnerability CVE 2026 59310 to a suspected China nexus threat actor deploying backdoors, reverse SSH tools and Babuk derived ransomware.

CTM360 Report Reveals Browser In Browser Recruitment Phishing Campaign Targeting Enterprise Accounts

CTM360 has uncovered a large scale recruitment phishing campaign using Browser In Browser credential traps, fake interview pages and live MFA relay attacks to target enterprise accounts.

Saudi Arabia AI Security Challenges Increase As Enterprise Adoption Accelerates

TrendAI Saudi Arabia Managing Director Wasna Ben Gassem says AI adoption is advancing faster than enterprise security frameworks, highlighting the need for stronger governance and unified cybersecurity.

Critical SAP Commerce Cloud Flaw CVE 2026 58231 Draws Early Exploitation Activity

Security researchers have observed exploitation attempts targeting SAP Commerce Cloud vulnerability CVE 2026 58231 only days after SAP released a patch for the critical remote code execution flaw.

Updated CoolClient Malware Uses Signed Windows Rootkit For Advanced Stealth

Kaspersky has identified a new CoolClient malware variant linked to Mustang Panda that deploys a signed Windows kernel rootkit to hide malicious activity and strengthen persistence on compromised systems.

Recent articles

spot_img