OWASP has launched the Open Automated Security Initiative for Software (OASIS), a global community effort designed to close the gap between finding vulnerabilities in open source code and actually fixing …
Attackers Abuse Trusted Cloud Services to Hide Phishing Attacks Against Financial Organizations
Cybercriminals are increasingly weaponizing trusted cloud platforms such as Microsoft Azure, Google Firebase, Google Cloud Storage, Amazon Web Services, and Cloudflare to host phishing infrastructure aimed squarely at the financial …
Five Hackers Plead Guilty to ATM Jackpotting Attacks Using Malware to Dispense Cash
Five Venezuelan nationals have pleaded guilty in a U.S. federal case involving attempted ATM jackpotting attacks. This criminal technique uses malware to force cash machines to dispense money without legitimate …
Hackers Actively Exploiting Critical Langflow RCE and Rails Vulnerability
Two critical vulnerabilities affecting Langflow and Ruby on Rails deployments are being actively exploited, with attackers quickly moving from public disclosure to reconnaissance, secret harvesting, and potential remote code execution, …
Hackers Pose as Recruiters and Send Fake Coding Tests to Infect Software Developers
Cybercriminals are posing as recruiters to turn routine job interviews into malware traps for software developers. Their latest campaign delivers two cross-platform remote access tools, NodeRabbit and PollCat, through coding …
Hackers Weaponize Microsoft Teams Help Desk Calls for Malware and Network Lateral Movement
Attackers are turning Microsoft Teams help desk calls into an entry point for malware and network compromise. A campaign tracked as Spring Ring used external accounts that resembled internal IT …
Boston Scientific Cyberattack Disrupts Medical Device Manufacturing and Global Operations
Boston Scientific is investigating a cybersecurity incident that disrupted parts of its global operations, affecting manufacturing, order processing, and product shipments. The company said the incident was detected on August …
Hackers Pose as OpenAI, Anthropic and DeepSeek to Steal Credentials and Secrets
Threat actors are impersonating web crawlers from OpenAI, Anthropic, DeepSeek, and other major organizations to scan websites for exposed credentials and sensitive configuration files, targeting misconfigured servers that may leak …
JFrog Artifactory Auth Bypass Exploited in Attacks to Gain Admin Access
A critical authentication bypass vulnerability in JFrog Artifactory, tracked as CVE-2026-82329, is being actively exploited, allowing unauthenticated attackers with network access to gain administrator-level privileges. WatchTowr said its intelligence team …
21,000+ Microsoft Exchange Servers Remain Exposed to Active CVE-2026-62911 Exploitation
Nearly 22,000 Microsoft Exchange servers worldwide are still running unpatched for CVE-2026-62911, a critical authentication-bypass vulnerability that attackers can exploit to seize control of enterprise email infrastructure. According to daily …
