Metabase has released security updates after confirming active exploitation of a zero day vulnerability that allows attackers to gain administrator access without authentication.
Research presented at Black Hat USA 2026 demonstrates CSS based attack techniques affecting major webmail services, highlighting risks involving passwords, authentication tokens, and AI connected email workflows.
Researchers have uncovered a new malware campaign using malicious Google Ads to distribute CastleStealer through a newly identified loader called OXLOADER, employing advanced obfuscation and evasion techniques.
Organizations are increasingly expanding EDR capabilities with proactive hardening and managed detection and response to improve cyber resilience and reduce operational pressure on security teams.
North Korean threat actor Kimsuky has intensified cyberattacks targeting South Korean military and corporate organizations, deploying HTTPSpy malware, HelloDoor, and abusing VS Code tunneling for covert access.
Trillium Information Security Systems, in collaboration with IBM, hosted a cybersecurity event in Lahore focused on identity security, endpoint protection, and secrets management with leading CISOs and security experts.
Kaspersky’s latest ransomware report highlights evolving cybercriminal tactics, including encryption less extortion, EDR killers, and the sale of stolen credentials through Telegram channels and dark web forums.
New cybersecurity research highlights how vulnerable Windows kernel mode drivers may remain exploitable without dedicated hardware, raising concerns around BYOVD attacks and endpoint security risks.
A malvertising campaign targets U.S. users searching for tax forms, delivering ScreenConnect malware and HwAudKiller to bypass EDR using a Huawei driver.
China’s CNCERT warns that OpenClaw AI agent security weaknesses could enable prompt injection attacks, endpoint compromise, and sensitive data exfiltration.
Microsoft reports a ClickFix social engineering campaign abusing Windows Terminal to execute malicious commands and deploy Lumma Stealer targeting browser credentials.
Nets International Pakistan becomes a Kaspersky Gold Partner to enhance enterprise cybersecurity offerings in Pakistan with advanced threat protection and endpoint security solutions.
Kaspersky rolls out discounted access to its Next EDR Foundations solution for new customers, offering advanced threat detection and global intelligence-backed protection until August 2025.