• Home
  • Web
  • Branding
  • Print
  • 3D & Motion
  • Email Marketing
  • Digital Marketing
  • Presentations & Decks
  • Photography
  • Contact

Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack

SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data

Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads

LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts

RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata

11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot

Study of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking Risks

How Pentera Turns AI Security Workflows into Validation Engines

OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials

Grok Build Uploaded Entire Git Repositories to xAI Storage, Not Just Files It Read

U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support

148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet

Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths

CrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks

Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found

⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More

New MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email

Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft

Meta Files Patent for AI That Can Listen All Day and Track How You're Feeling

Thinking Fast and Slow in the SOC: The Case for Combining Autonomous AI with Analyst Copilots

Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory

Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365

iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days

Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install

Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns

Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions

URGENT – Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat

Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages

Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot

Laser Attack Resets Tangem Wallet Passwords on Cards That Can't Be Patched

Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws

New MODBEACON RAT Uses gRPC Streaming for Encrypted C2 Traffic

Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers

From 17,000 to 1.1 Million Assets: How Lumen Technologies Rebuilt Exposure Management at Scale

Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites

Study of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and Tracking

Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access

Attackers Exploit 'Ill Bloom' Vulnerability to Drain Over $5 Million From Cryptocurrency Wallets

Ransomware Negotiator Gets 70 Months in Prison for Aiding BlackCat Attacks

Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs

New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware

npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk

ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories

AI Attacks Move in Minutes. Join This Webinar on Building a Defense That Keeps Up

Summer of Clearinghouses

GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses

Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges

Meta's New AI Image Tool Lets Others Use Your Public Instagram Photos in AI Images

Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It

GhostApproval Symlink Flaws Could Let Malicious Repos Run Code in AI Coding Agents

Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes

AI Coding Agents Found Triggering Endpoint Security Rules Built to Catch Attackers

New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet Malware

Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS

New Ghost Phishing Wave Is Breaking Traditional Email Security

SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users

GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures

The Verification Step Is the New ATO Battleground in 2026

GitHub Copilot Refuses Harmful Requests in Chat, Then Writes Them in Code

China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware

15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros

CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV

RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service

Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots

DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts

Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data

Court Filing Reveals Windows Device ID Helped FBI Trace Alleged Scattered Spider Hacker

Writer AI Flaw Could Let Agent Previews Leak Session Tokens Across Tenants

What Changes When Your Software Supply Chain Includes AI Writing Your Code?

Suspected China-Aligned Hackers Exploit Roundcube Flaws Against Universities

CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware

BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA

Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations

16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems

Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure

⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More

How to Evaluate an AI SOC Platform in 2026: 6 Capabilities That Separate Leaders from Bolt-On AI solutions

Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT

New TrojPix Attack Leaks Data From Air-Gapped Systems via Video Cable Emissions

New Java-Based QuimaRAT MaaS Built to Run on Windows, Linux, and macOS

Opera GX Flaw Let Malicious Sites Auto-Install Mods to Steal Data From Visited Pages

SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing

U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case

North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign

Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices

New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android

New Avalon Malware Framework Packs CrownX Ransomware Capabilities

North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets

Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer

European Parliament Member Investigating Spyware Was Hacked With Pegasus

PamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login Passwords

Google Disrupts NetNut Residential Proxy Network Spanning 2 Million Home Devices

Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials

ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories

ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API

Identity Lifecycle Management Wasn't Built for AI Agents 

AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack

FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations

New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos

SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation

  • 1
  • 2
  • »

01792 951582

Swansea SA5 9DB.

Instagram    |    Linkedin
Work
  • Web
  • 3D & Motion
  • Brand Identity
  • Print
Information
  • Contact
  • FAQs
  • Terms & Conditions
  • Privacy Policy
  • Cookies

All content on this site © Pentagon Design Ltd. 2010 - 2026

Registered in England & Wales. No. 06061392