Industry news, vulnerability disclosures, compliance updates, and threat intelligence—handpicked for relevance to your environment.
Each item includes our perspective on why it matters to your security posture.
CISA's Sunday deadline hits for two exploited FortiSandbox flaws, Checkmarx exposes a blockchain-C2 npm supply chain attack on Vite developers, a new Spirals ransomware strain encrypts a network in 24 hours, and Abbott fights a dual extortion claim.
Read source →CISA fast-tracks a critical SharePoint deserialization bug into KEV, WordPress force-patches a pre-auth RCE chain dubbed wp2shell, North Korean hackers hide malware in SVG images, and 23andMe pays $18M over its 2023 breach.
Read source →SAP patches a max-impact CVSS 9.9 NetWeaver flaw, a 16-year-old Linux KVM bug lets guest VMs escape to the host, an unpatched Windows flaw mounts admin hives, Kaspersky exposes a patient SE Asia espionage campaign, and Scattered Spider's TfL hackers get 5.5 years.
Read source →A ShareFile zero-day forces customers to pull servers offline, 292 fake GitHub repos spread a Chrome-encryption-bypassing infostealer, a ransomware crew's Bosch 'proof' turns out to be a public manual, and an unpatched Claude for Chrome flaw lets rogue extensions read your Gmail.
Read source →Microsoft's record-breaking Patch Tuesday closes two zero-days already under attack, a 15-year-old Linux kernel bug hands out root, SonicWall SMA appliances get chained in the wild, and Japan's largest taxi operator goes dark.
Read source →A joint advisory on Russian FSB router hacking, a compromised npm package dropping a Rust infostealer, Progress Software's emergency ShareFile shutdown, and CISA confirming ransomware gangs are exploiting a Microsoft Defender flaw.
Read source →This week's cybersecurity roundup: Russian hackers hijacking doorbell cameras to track NATO weapons shipments, a Linux kernel root flaw hitting Android, a new Entra passkey vishing campaign, and prompt injection hidden in images to fool AI code reviewers.
Read source →This week's cybersecurity roundup: a DHS platform breach, a Dutch telecom hack traced to an insider, six new U-Boot bootloader flaws, a critical Zimbra XSS bug, and two fresh CISA KEV additions.
Read source →A roundup of the week's key cybersecurity news: actively exploited CVEs, a major insurance data breach, an npm supply chain attack, and a new SharePoint extortion group.
Read source →An INTERPOL-coordinated operation across 97 countries closed over 23,000 fraud cases, froze 31,014 bank accounts, and identified 142,000+ victims of social engineering scams.
Why it matters: Scale like this tells you social engineering isn't a fringe risk — it's an industrialized criminal supply chain with the same maturity as any other cybercrime market. If your security awareness training still frames phishing and BEC as isolated incidents rather than organized fraud, this is a good prompt to update it.
Read source →