Abdullah Brothers & Co. has onboarded FlowHCM to enhance HR operations through a connected platform designed to support workforce management and business growth.
Microtech Inc. has received the Authorized Distributor Certificate from ZKTeco Inc., strengthening their partnership to expand security and smart technology solutions.
Kaspersky has uncovered a Silver Fox campaign that disguises the ValleyRAT backdoor as signed Chinese adware, using DLL sideloading to evade security controls and gain full access to compromised systems.
Cybersecurity researchers have identified 19 Chrome and Edge extensions containing wallet stealing and cryptocurrency draining capabilities. The campaign has reportedly been active since February 2024 and uses compromised and newly created browser extensions.
Recorded Future has identified a new HOOKEDGE backdoor linked to APT28, targeting government and diplomatic organizations in Romania, Spain, and Türkiye through malicious Microsoft Word documents.
Arctic Wolf has identified the new GoCaracal malware framework, linking it with medium confidence to Dark Caracal and revealing its use of Ethereum smart contracts to update command and control infrastructure.
Researchers have uncovered a malware campaign using FTP banners as dead drop resolvers to deliver E4del and PINHOLE RATs, introducing a new technique for command and control operations.
Security researchers have observed exploitation attempts targeting SAP Commerce Cloud vulnerability CVE 2026 58231 only days after SAP released a patch for the critical remote code execution flaw.
Kaspersky has identified a new CoolClient malware variant linked to Mustang Panda that deploys a signed Windows kernel rootkit to hide malicious activity and strengthen persistence on compromised systems.
Security researchers warn that a newly disclosed GeoServer zero day SQL injection vulnerability is being actively targeted and could lead to remote code execution on vulnerable systems.
Cybersecurity agencies from South Korea and the United States have warned that Gunra ransomware operators are exploiting Fortinet and Schneider Electric vulnerabilities to compromise critical infrastructure organizations worldwide.
CISA has added the actively exploited N-able N-central authentication bypass vulnerability CVE 2026 18577 to its KEV catalog following customer compromises and reports of ongoing attacks.
Researchers report that the Dysphoria IoT botnet has adopted blockchain based name services and infected device relays after law enforcement disrupted JackSkid infrastructure, making the botnet more resilient.
Resecurity Pakistan has signed an MOU with Skills Share Hub to deliver hands on cybersecurity training focused on threat intelligence, incident response, and digital risk management.