Threat actor PCPJack hijacked 230 AWS, Google Cloud, and Microsoft Azure servers to establish a covert SMTP relay network, according to Hunt.io findings.
Engro and Baidu have signed an MoU to explore collaboration in AI infrastructure, research, talent development, and industry applications across the region.
North Korean threat actor Kimsuky has intensified cyberattacks targeting South Korean military and corporate organizations, deploying HTTPSpy malware, HelloDoor, and abusing VS Code tunneling for covert access.
Iran linked hacking group MuddyWater has launched a cyber espionage campaign targeting organizations across nine countries using DLL side loading, credential theft, and covert access techniques.
ANY.RUN outlines three SOC strategies to improve early threat detection, faster alert triage, and response readiness through threat intelligence and malware analysis tools.
Agentic AI is transforming Network Detection and Response by improving threat detection, reducing false positives, automating alert triage, and enhancing SOC efficiency.
This week’s cybersecurity developments included Linux kernel flaws, Microsoft Defender zero days, GitHub supply chain compromises, active router botnets, and increasing exploitation of vulnerabilities worldwide.
Kaspersky’s latest ransomware report highlights evolving cybercriminal tactics, including encryption less extortion, EDR killers, and the sale of stolen credentials through Telegram channels and dark web forums.
European and North American authorities have dismantled First VPN Service, a criminal VPN infrastructure reportedly used by 25 ransomware groups to conceal cyberattacks, fraud, and data theft operations.
Cybersecurity researchers have uncovered Showboat, a Linux malware targeting a Middle East telecom provider, featuring SOCKS5 proxy capabilities and links to China affiliated threat activity clusters.
Threat actors compromised popular GitHub Actions workflows to exfiltrate CI/CD credentials through malicious code, raising concerns around software supply chain security and GitHub repository integrity.
Microsoft has disclosed active exploitation of CVE 2026 42897 affecting on premises Exchange Server deployments, allowing spoofing and JavaScript execution through crafted emails in Outlook Web Access.
A critical cPanel vulnerability CVE 2026 41940 is being actively exploited to target government, military, and MSP networks globally, enabling authentication bypass and remote control, with thousands of systems impacted.
AI assisted cyber attacks are rising sharply in 2026, lowering barriers for attackers, accelerating exploit timelines, and increasing phishing, malware, and supply chain threats globally.