Ransomware-as-a-service operation The Gentlemen suffered a major May 2026 breach, exposing 16GB of internal data including affiliate details and victim information.
A fresh variant of the self-propagating Shai-Hulud npm worm was detected on April 30, 2026, reigniting concerns about autonomous supply chain attacks capable of evading traditional security controls. The malware,…
Villager represents a significant evolution in offensive security tooling by leveraging artificial intelligence to orchestrate sophisticated attack chains. Unlike traditional penetration testing frameworks that rely on scripted playbooks, Villager operates as an AI-native penetration testing framework that integrates multiple security tools through a distributed architecture.
In an unprecedented display of cybercriminal sophistication, security researchers have uncovered a Linux malware campaign that turns conventional attack methodology on its head. The malware, dubbed "DripDropper," employs a counterintuitive strategy: exploiting vulnerabilities and then patching them to maintain exclusive access to compromised systems.
A serious flaw in Microsoft's recent Windows 11 updates is reportedly causing solid-state drives and hard disk drives to fail completely, prompting the tech giant to work urgently with hardware partners on a solution.
Microsoft is currently grappling with a significant service disruption that has left thousands of users unable to access key productivity platforms, including Office.com and the company's AI-powered Copilot assistant. The outage, which began in the early morning hours of August 20, 2025, has primarily impacted customers across North America, though the full scope of the incident remains under investigation.
A threat actor operating under the alias "Chucky_BF" has surfaced on a prominent cybercrime forum claiming to possess a massive trove of PayPal user credentials. The cybercriminal is advertising what they describe as the "Global PayPal Credential Dump 2025," containing allegedly 15.8 million email and password combinations from PayPal users worldwide.
Cybercriminals are conducting highly targeted spear-phishing campaigns across multiple regions, including the United States, Europe, Baltic countries, and the Asia-Pacific region. The attacks specifically target businesses through personalized emails that create urgency by threatening copyright or intellectual property infringement lawsuits.
A security researcher has disclosed a critical vulnerability in Fortinet's FortiWeb web application firewall that enables complete authentication bypass, allowing attackers to impersonate any user, including administrators. The flaw, designated CVE-2025-52970 and nicknamed "FortMajeure," represents a significant security concern for organizations relying on FortiWeb for web application protection.