COMMTEL and National Radio Telecommunication Corporation have signed a strategic partnership to deliver advanced Managed Detection and Response services for public and private sector cybersecurity in Pakistan.
Security researchers have published public exploits for Linux kernel vulnerability CVE 2026 23111, allowing local privilege escalation to root and container escape on affected systems.
Cybersecurity researchers have uncovered OP-512, a newly identified espionage focused threat cluster targeting Microsoft IIS servers using a custom web shell framework linked with moderate to high confidence to China.
Threat actor PCPJack hijacked 230 AWS, Google Cloud, and Microsoft Azure servers to establish a covert SMTP relay network, according to Hunt.io findings.
Russian linked hacking group Gamaredon has exploited a WinRAR vulnerability to deploy GammaWorm and GammaSteel malware targeting Ukraine, according to cybersecurity firm Sekoia.
North Korean threat actor Kimsuky has intensified cyberattacks targeting South Korean military and corporate organizations, deploying HTTPSpy malware, HelloDoor, and abusing VS Code tunneling for covert access.
Iran linked hacking group MuddyWater has launched a cyber espionage campaign targeting organizations across nine countries using DLL side loading, credential theft, and covert access techniques.
ANY.RUN outlines three SOC strategies to improve early threat detection, faster alert triage, and response readiness through threat intelligence and malware analysis tools.
Agentic AI is transforming Network Detection and Response by improving threat detection, reducing false positives, automating alert triage, and enhancing SOC efficiency.
This week’s cybersecurity developments included Linux kernel flaws, Microsoft Defender zero days, GitHub supply chain compromises, active router botnets, and increasing exploitation of vulnerabilities worldwide.
Kaspersky’s latest ransomware report highlights evolving cybercriminal tactics, including encryption less extortion, EDR killers, and the sale of stolen credentials through Telegram channels and dark web forums.
European and North American authorities have dismantled First VPN Service, a criminal VPN infrastructure reportedly used by 25 ransomware groups to conceal cyberattacks, fraud, and data theft operations.