Cybersecurity researchers have uncovered Showboat, a Linux malware targeting a Middle East telecom provider, featuring SOCKS5 proxy capabilities and links to China affiliated threat activity clusters.
Threat actors compromised popular GitHub Actions workflows to exfiltrate CI/CD credentials through malicious code, raising concerns around software supply chain security and GitHub repository integrity.
Microsoft has disclosed active exploitation of CVE 2026 42897 affecting on premises Exchange Server deployments, allowing spoofing and JavaScript execution through crafted emails in Outlook Web Access.
A critical cPanel vulnerability CVE 2026 41940 is being actively exploited to target government, military, and MSP networks globally, enabling authentication bypass and remote control, with thousands of systems impacted.
AI assisted cyber attacks are rising sharply in 2026, lowering barriers for attackers, accelerating exploit timelines, and increasing phishing, malware, and supply chain threats globally.
Researchers uncover a global IRSF scam using fake CAPTCHA pages and over 120 Keitaro campaigns driving SMS fraud, crypto theft, and large scale cybercrime operations.
Tropic Trooper launches a cyber campaign using a trojanized SumatraPDF reader and GitHub powered AdaptixC2 to target users in Taiwan, Japan, and South Korea.
Chartered Institute of Bankers of Nigeria CIBN faces alleged 250GB data breach exposing member PII, identity documents, academic certificates, and source code.
CISA updates its Known Exploited Vulnerabilities catalog with eight new flaws, including Cisco SD WAN Manager issues, urging federal agencies to patch by April and May 2026.
A zero day vulnerability in Adobe Reader has been actively exploited via malicious PDF files since December 2025, enabling data theft, payload delivery, and potential remote execution.
Flowise AI platform suffers a critical CVSS 10.0 code injection vulnerability, exposing over 12,000 instances to remote code execution and full system compromise.