Microsoft Patch Tuesday February 2026 Microsoft released its February 2026 Patch Tuesday updates on February 10, addressing 54 vulnerabilities, including six zero-days across Windows, Office, Azure, and developer tools. The …
FortiSandbox XSS Vulnerability Let Attackers Run Arbitrary Commands
FortiSandbox XSS Vulnerability Fortinet has disclosed a high-severity cross-site scripting (XSS) vulnerability in its FortiSandbox platform, tracked as CVE-2025-52436 (FG-IR-25-093), that enables unauthenticated attackers to execute arbitrary commands on affected …
Threat Hunting Is Critical to SOC Maturity but Often Misses Real Attacks
Threat Hunting Is Critical to SOC High-performing SOC teams are increasingly turning to sandbox-derived threat intelligence to make threat hunting repeatable and impactful. Tools like ANY.RUN’s TI Lookup enables faster …
FortiOS Authentication Bypass Vulnerability Lets Attackers Bypass LDAP Authentication
FortiOS Authentication Bypass Vulnerability Fortinet has disclosed a high-severity authentication bypass vulnerability in FortiOS, tracked as CVE-2026-22153 (FG-IR-25-1052), that could allow unauthenticated attackers to sidestep LDAP authentication for Agentless VPN …
APT36 Hacker Group Attacking Linux Systems with New Tools to Disturb Services
For more than a decade, Indian government and defense organizations have operated under a constant digital shadow. A tightly connected espionage ecosystem, primarily involving the Transparent Tribe (APT36) group and …
Threat Actors Weaponizes Bing Ads Attack Users with Azure Tech Support Scams
A sophisticated tech support scam campaign has emerged, exploiting Bing search advertisements to redirect unsuspecting users to fraudulent pages hosted on Microsoft Azure Blob Storage. This operation has affected users …
UNC1069 Hackers Attacking Finance Sector with New Tools and AI-Enabled Social Engineering
North Korean threat actors, tracked as UNC1069, have intensified their attacks on the cryptocurrency and finance sectors using a sophisticated blend of novel malware and artificial intelligence. Active since at …
Threat Actors Exploiting React2Shell Vulnerability Using AI-Generated Malware
React2Shell Vulnerability AI-Generated Malware A fully AI-generated malware campaign actively exploiting the “React2Shell” vulnerability, detected within Darktrace’s “CloudyPots” global honeypot network, the intrusion highlights a critical shift in cybercrime: the …
VoidLink Linux C2 Highlights LLM-Generated Malware with Multi-Cloud and Kernel-Level Stealth
A sophisticated Linux malware framework known as VoidLink has emerged as a concerning example of AI-assisted threat development, combining advanced multi-cloud targeting capabilities with kernel-level stealth mechanisms. The malware represents …
Attackers Weaponizing Windows Shortcut File to Deliver Global Group Ransomware
The cyber threat landscape is witnessing the resurgence of the Phorpiex botnet, a long-standing malware-as-a-service platform active for over a decade. In a recent high-volume campaign, attackers are distributing phishing …
