Security News
Breach & incident coverage
Distinct breaches, incidents, and newly disclosed issues as they're reported — separate from the CVE-anchored advisories, which track confirmed exploited vulnerabilities specifically.
500 stories published
New Dolphin X Malware Uses AI to Profile and Rank High-Value Targets
The Dolphin X remote access trojan uses AI-powered victim profiling to score infected systems and prioritize targets for follow-on attacks.
Jul 23, 2026Bing Ads Malvertising Pushes Fake Claude Desktop App Delivering SectopRAT
Threat actors are abusing Bing search ads to distribute a fake Claude desktop app installer that drops the SectopRAT remote access trojan.
Jul 23, 2026Russian Hackers Exploit Zimbra Webmail Flaw to Steal Emails and 2FA Codes
Russian state-backed actors used a zero-click Zimbra webmail zero-day vulnerability to target Western organizations and siphon sensitive mailbox data.
Jul 23, 2026RefluxFS: Nine-Year-Old Linux Kernel Bug Grants Root Privileges
A newly discovered race condition in the Linux XFS filesystem driver, CVE-2026-64600, allows local attackers to elevate privileges to root.
Jul 23, 2026Check Point Patches Zero-Day Vulnerability CVE-2026-16232 Under Active Exploitation
Check Point has released emergency updates to address CVE-2026-16232, a security gateway zero-day vulnerability actively exploited in the wild.
Jul 23, 2026Inchcape Shipping Services Warns of Fraudulent Domains Impersonating Its Brand
Inchcape Shipping Services has identified and warned customers about fraudulent domains actively impersonating its brand for potential phishing.
Jul 20, 2026Japan's Largest Taxi Operator, Nihon Kotsu, Suffers Malware Attack Disrupting Services
Nihon Kotsu, Japan's largest taxi operator, has been hit by a malware attack leading to disruptions in dispatch, booking, and rental services.
Jul 20, 2026Microsoft Warns of Global Surge in ACR Stealer Malware Attacks
Microsoft has issued a warning regarding a significant increase in attacks leveraging the ACR Stealer malware to exfiltrate sensitive credentials.
Jul 20, 2026Jscrambler Suffers Supply Chain Compromise Via Stolen npm Credentials
A supply chain attack impacted Jscrambler, leading to malicious npm package releases that stole developer and cloud credentials.
Jul 20, 2026Actively Exploited Critical OS Command Injection Flaws in FortiSandbox (CVE-2026-39808,…
Two critical OS command injection vulnerabilities in FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS are actively exploited.
Jul 20, 2026Abbott Laboratories Investigates Multiple Cyber Incidents Amid Extortion Claims
Pharmaceutical giant Abbott Laboratories is investigating two separate cyber incidents, including data exfiltration claims by ShinyHunters.
Jul 20, 2026Microsoft SharePoint Server Actively Exploited Zero-Day Vulnerability (CVE-2026-56164)
A critical, actively exploited zero-day remote code execution vulnerability in Microsoft SharePoint Server has been patched.
Jul 20, 2026No news matches your search.