Tag: cybersecurity

Apple Fixes Hide My Email Bug That Exposed Real Addresses In Mail Logs

Apple has fixed a Hide My Email vulnerability that could reveal users real email addresses in mail logs after rejected messages, following responsible disclosure by security researchers.

Trojanized Newtonsoft Json Package Targets Digitain Gaming Platform

Researchers discovered a trojanized NuGet package posing as Newtonsoft.Json that secretly targeted Digitain gaming systems while functioning as a legitimate library for other users.

Awan Distribution And Sophos Launch Independence Day Rewards Campaign For Channel Partners

Awan Distribution and Sophos have introduced a Pakistan Independence Day promotional campaign offering channel partners rewards of up to PKR 40,000 on Sophos XGS Firewall sales.

Thousands Of Malicious GitHub Repositories Distribute SmartLoader Malware Through AI Lures

Researchers have uncovered the FakeGit campaign using nearly 7,600 malicious GitHub repositories, including AI skills and MCP servers, to distribute SmartLoader and StealC malware.

Critical WordPress Vulnerabilities Trigger Widespread Scanning And Remote Code Execution Attacks

Security researchers are warning of widespread exploitation of two critical WordPress vulnerabilities that allow unauthenticated remote code execution and complete website compromise.

SonicWall SMA Zero Day Vulnerabilities Exploited Before Public Disclosure To Gain Root Access

Volexity has uncovered a threat actor exploiting SonicWall SMA 1000 zero day vulnerabilities before disclosure to gain root access and deploy custom malware on VPN appliances.

UAC-0145 Uses ClickFix CAPTCHA Technique To Deploy Malware On Ukrainian Devices

CERT-UA has linked UAC-0145 to a malware campaign using ClickFix CAPTCHA pages, PowerShell commands, and Android backdoors to target Ukrainian users.

NadMesh Botnet Targets Exposed AI Services To Steal Cloud Credentials And Kubernetes Tokens

Researchers have uncovered the NadMesh botnet targeting exposed AI services, cloud credentials, Kubernetes tokens, and administrative interfaces across internet facing systems.

OpenSSL HollowByte Flaw Could Cause Memory Exhaustion Through Small TLS Requests

Okta Red Team has disclosed the HollowByte flaw in OpenSSL, a denial of service issue that allows attackers to consume server memory using small TLS requests. Security updates are available for affected OpenSSL versions.

S2 Becomes Official Distributor Of Holm Security In Pakistan

S2 has announced its appointment as the official distributor of Holm Security in Pakistan, bringing the European attack surface and vulnerability management platform to organizations across the country.

OxBit Technologies To Host Live Webinar On SAP SODPulse For SAP SOD Reviews

OxBit Technologies will host a live webinar on July 22, 2026, showcasing SODPulse, a solution designed to simplify SAP Segregation of Duties reviews with browser based analysis, 446 plus pre built rules, and coverage across 15 plus SAP process areas.

CISA Adds Exploited Microsoft SharePoint CVE 2026 58644 Zero Day To Known Exploited Vulnerabilities Catalog

CISA has added the actively exploited Microsoft SharePoint vulnerability CVE 2026 58644 to its Known Exploited Vulnerabilities catalog and urged organizations to apply security updates immediately.

Recent articles

spot_img