Threat actors began actively exploiting CVE-2026-22679, a critical, unauthenticated remote code execution (RCE) vulnerability in Weaver (Fanwei) E-cology...
Cyber Attack
North Korea-aligned APT group ScarCruft (APT37) has been caught compromising a legitimate gaming platform to deliver a...
A rogue website, notepad-plus-plus-mac.org, has been fraudulently impersonating the official Notepad++ project by offering an unauthorized macOS...
Instructure, the education technology company behind the widely used Canvas learning management system (LMS), has confirmed a...
The Emergency patches for critical and high vulnerabilities in MOVEit Automation that could allow unauthenticated remote attackers...
A critical remote code execution vulnerability in FreeBSD’s default DHCP client (dhclient) allows a rogue DHCP server...
A coordinated wave of Microsoft Teams phishing campaigns is targeting enterprise employees in 2026, with threat actors...
The notorious threat actor group ShinyHunters has posted what they claim is the stolen Accord Healthcare database...
A new phishing-as-a-service (PhaaS) kit that rolls domain registration, credential harvesting, session hijacking, antibot cloaking, and an...
A new Vect ransomware-as-a-service (RaaS) operation has rapidly emerged as one of 2026’s most tactically sophisticated threats, combining...