DocGo Inc., a prominent healthcare and ambulance transportation service provider, has confirmed a cybersecurity incident that compromised the integrity of its systems. The breach, which specifically targeted the company’s U.S.-based ambulance transportation business, resulted in unauthorized access and acquisition of …
Microsoft Unveils Air-Gapped GPT-4 for U.S. Intelligence Agencies
Microsoft has announced the deployment of an air-gapped GPT-4 AI model specifically designed for the US Intelligence Community. This initiative represents a significant milestone in utilizing generative AI technologies in secure government environments. This ensures that top-secret data remains isolated …
Akamai to Acquire API Security Startup Noname for $450 Million
Akamai Technologies, Inc. is set to acquire Noname Security, a top API security vendor, for $450 million, signaling a major move to boost its API security capabilities. This acquisition marks a pivotal moment in the cybersecurity landscape, as Akamai aims …
Hunters Announces Full Adoption of OCSF and Introduces OCSF-Native Search
Hunters, the pioneer in modern SOC platforms, today announced its full adoption of the Open Cybersecurity Schema Framework (OCSF), coupled with the launch of groundbreaking OCSF-native Search capability. This strategic advancement underscores Hunters’ commitment to standardizing and enhancing cybersecurity operations …
NCA Reveals Identity of LockBit Ransomware Group Leader
The UK’s National Crime Agency (NCA) announced a major breakthrough today in investigating the notorious LockBit ransomware gang. LockBit, a ransomware-as-a-service (RaaS) operation, has been responsible for numerous high-profile cyberattacks since its emergence in 2019. The group is known for …
HijackLoader Using Weaponized PNG Files To Deliver Multiple Malware
HijackLoader, a modular malware loader observed in 2023, is evolving with new evasion techniques, as it is a variant using a PNG image to deliver next-stage malware like Amadey and Racoon Stealer. The variant includes new modules (modCreateProcess, modUAC) for …
Yoast SEO Plugin XSS Flaw Exposes 5 Million+ WordPress Websites to Attack
A critical cross-site scripting (XSS) vulnerability has been discovered in the popular Yoast SEO WordPress plugin, potentially putting over 5 million websites at risk of compromise. The flaw was found by security researcher Bassem Essam and reported via the Wordfence …
MITRE Shares Details on Nation-State Hackers’ Intrusion into Research Network
The MITRE Corporation, a not-for-profit organization that operates research and development centers for the U.S. government, has disclosed that sophisticated nation-state hackers recently compromised one of its internal research and development networks. The intrusion, believed to have been carried out …
Oracle Weblogic Server Flaw Allows Attackers Full Control – PoC Released
A new secondary JNDI injection vulnerability was discovered in a recent version of WebLogic, allowing attackers to trigger JNDI injection during another JNDI lookup process, effectively enabling Remote Code Execution (RCE) on the targeted system. A patch has been implemented …
Microsoft Defender XDR Expanded to Malicious OAuth Apps With the Power of AI
In an update to its security operations suite, Microsoft has announced the expansion of its Defender Extended Detection and Response (XDR) capabilities to include advanced AI-powered detection and mitigation of threats posed by malicious OAuth applications. This enhancement is part …




