Critical SmarterMail Vulnerability Puts Email Servers at Serious Risk
The Cyber Security Agency of Singapore (CSA) has issued an urgent warning about a critical security flaw affecting SmarterMail, a widely used email and collaboration platform. The vulnerability, tracked as CVE-2025-52691, has been given the highest possible severity score of…
How Hackers Exploit Google Cloud Workflows to Run Stealthy Phishing Campaigns

In this campaign, attackers begin by directing victims through a seemingly legitimate workflow that gives the attack an air of authenticity. The initial link sends users to content hosted on googleusercontent[.]com, a trusted Google-controlled domain, which helps lower suspicion. At…
Why Most Attack Surface Management Programs Struggle to Show Real ROI

Attack Surface Management (ASM) is often sold as a way to reduce risk. In reality, what many organizations get is more data. Security teams roll out ASM tools, asset inventories expand, alerts start firing, and dashboards fill up quickly. There…
APT36 Transparent Tribe Uses Sophisticated RAT Malware in New Espionage Campaigns

Transparent Tribe Expands Espionage Campaigns Using Advanced RAT Techniques A long-running cyber espionage group known as Transparent Tribe has been linked to a new wave of targeted attacks aimed at Indian government bodies, academic institutions, and other strategically sensitive organizations.…
Managed Security in 2026: Why the Old Model Is Breaking

Managed security services were built around people. Analysts investigated phishing clicks, suspicious logins, and endpoint misuse after alerts were triggered. That model is starting to crack. By 2026, much of what happens inside customer environments will no longer be driven…
How to Secure Your Website and WordPress Site

Website security is no longer optional. Whether you run a personal blog, an online store, or a business website, attackers are constantly looking for weak points to exploit. A single breach can lead to data loss, downtime, damaged reputation, or…
U.S. Lifts Sanctions on Individuals Linked to Predator Spyware Network

The U.S. Department of the Treasury has removed three individuals connected to the Intellexa Consortium from its sanctions list, raising new questions about the future oversight of commercial spyware operations. The individuals removed from the Office of Foreign Assets Control…
Fake Grubhub Crypto Emails Target Users With Bitcoin Scam

A new wave of phishing emails impersonating Grubhub has surfaced, tricking recipients with promises of massive cryptocurrency rewards. The fraudulent messages claim to offer a “Holiday Crypto Promotion,” encouraging users to send Bitcoin with the promise of receiving ten times…
Silver Fox Cyber Attacks Using Fake Tax Lures&Advanced Malware

A sophisticated cyber threat group known as Silver Fox has intensified its operations, shifting focus toward India by using tax-related phishing emails to spread a dangerous remote access trojan known as ValleyRAT. According to recent findings from cybersecurity researchers at…
Critical SmarterMail Vulnerability Puts Email Servers at Serious Risk

The Cyber Security Agency of Singapore (CSA) has issued an urgent warning about a critical security flaw affecting SmarterMail, a widely used email and collaboration platform. The vulnerability, tracked as CVE-2025-52691, has been given the highest possible severity score of…
Trust Wallet Confirms Security Breach Affecting Chrome Extension Users

Trust Wallet has confirmed a security incident involving its Chrome browser extension that resulted in the loss of approximately $7 million in cryptocurrency. The breach affected users running a specific version of the extension and has prompted an urgent security…
New Phishing Campaign Abuses npm Packages to Steal Corporate Credentials

Security researchers have uncovered a long-running and highly targeted phishing operation that abuses the npm ecosystem to steal login credentials from professionals working in sensitive industries. The campaign, which has been active for several months, relies on malicious npm packages…
Weekly Cybersecurity Brief: What Really Mattered This Week

This past week in cybersecurity wasn’t defined by one massive breach or headline-grabbing attack. Instead, it revealed something more troubling: a steady wave of smaller failures happening all at once. Trusted tools broke down. Old vulnerabilities resurfaced. And attackers moved…
NIST Releases New Guidance to Help Organizations Secure AI Systems

The National Institute of Standards and Technology (NIST) has introduced a new resource aimed at helping organizations safely adopt and manage artificial intelligence. The newly released draft, titled the Cybersecurity Framework Profile for Artificial Intelligence, expands on NIST’s widely used…
Active Exploitation of Fortinet FortiGate Devices Raises Alarm Across Security Community

Security researchers are warning of active intrusion attempts targeting Fortinet FortiGate devices, following the discovery of malicious single sign-on (SSO) activity linked to recently disclosed vulnerabilities. The activity was first identified last Friday, according to a new report from Arctic…
Credential-Stuffing Attacks Surge Against VPN Services: What Organizations Need to Know

A wave of coordinated credential-based cyberattacks has been targeting popular remote access technologies, including Palo Alto Networks GlobalProtect and Cisco SSL VPNs. According to recent findings from GreyNoise, the activity intensified in mid-December and appears to be part of a…
New Wave of Device Code Phishing Attacks Puts Microsoft 365 Users at Risk

Cybersecurity researchers are warning about a sharp rise in attacks using a technique known as device code phishing, a method increasingly favored by both state-sponsored and criminal hacking groups. According to a new report from Proofpoint, multiple threat actors —…
China-Linked Hackers Exploit Cisco Security Systems Through Misconfiguration Settings

Cybersecurity researchers have uncovered an ongoing campaign in which a China-linked hacking group is exploiting misconfigured Cisco security products to gain unauthorized access to targeted networks. According to Cisco, the attackers are taking advantage of insecure settings within its AsyncOS…
America’s Growing Risk: Why Open-Source Software Security Can No Longer Be Ignored

The United States’ growing dependence on open-source software is once again under scrutiny, as concerns rise over the security risks hidden inside widely used digital tools. Lawmakers are now warning that without stronger oversight, the country could be exposing itself…
