We are always asked what we are reading and paying attention to, whilst we want to keep you updated with this there is just too much stuff. Here is a sample of the daily reading lists.
... Your Car Run Better. Car Care Garage•371K views · 27:17. Go to channel Cybernews · World's Deadliest Computer Virus: WannaCry. Cybernews•4.1M views.
Go to External Site
... malware delivery mechanism. The technique utilizes a malicious Microsoft Edge browser extension that exploits the Chrome native messaging protocol ...
Go to External Site
A critical vulnerability in a package that is never invoked by your application may represent a different level of immediate risk than a lower ...
Go to External Site
The Four Critical Vulnerability Groups in Welsh Schools Amid Historic Heatwave. A rare 40°C Met Office red alert has forced Welsh schools to ...
Go to External Site
Kaspersky has released its Sustainability Report for 2024–2025, outlining how the company is working toward a safer and more resilient digital ...
Go to External Site
Threat intelligence report with 1298 extracted IOCs, MITRE ATT&CK mapping, and hunting context. Free by SOCRadar.
Go to External Site
Ankura presents a curated collection of expert insights spanning cybersecurity threats, regulatory compliance, dispute resolution, and enterprise ...
Go to External Site
Kaspersky says attackers are using fake WhatsApp document attachments to run VBScript malware and install ManageEngine RMM Central.
Go to External Site
We're partnering with Drydock so maintainers can see exactly what's inside a package before they approve it, catching malware before it ships instead ...
Go to External Site
SecOps leaders must tackle cost and risk to deliver autonomous vulnerability operations. But with frontier AI, it's critical.
Go to External Site
Incransom hits Belpointe Asset Management in a significant ransomware incident, threatening to leak 400GB of data.
Go to External Site
The FBI said in a public service announcement that cyber criminals are using traffic distribution systems to gain access to victim networks for ...
Go to External Site
Beyond these forums, we encountered dedicated cybercrime marketplaces. These function like online stores where hackers and fraudsters can buy and sell ...
Go to External Site
... critical vulnerability. This dichotomy presents a strategic challenge for Estonian fencing, requiring a focused approach to mental resilience and ...
Go to External Site
Another critical vulnerability, CVE-2026-41948, has a CVSS score of 9.4 and affects the Plugin Daemon service, which executes plugins. This flaw ...
Go to External Site
Named Cordyceps after the parasitic fungus known for taking over its hosts, this critical vulnerability quietly burrows into software development ...
Go to External Site
Throughout the operation, the attackers used CyberStrike, a legitimate open-source penetration testing AI agent, to automate reconnaissance ...
Go to External Site
This global campaign affects regions including Asia and South America, masquerading as Windows updates to bypass security. Users are urged to ...
Go to External Site
Users must install latest Windows updates to receive new certificates, as failure to update could cause serious boot failures. While the deadline ...
Go to External Site
GPT-5.5-Cyber is meant for narrower, higher-risk authorized workflows such as red teaming, exploit validation, penetration testing, reverse ...
Go to External Site
Picus does it too, with Autonomous Penetration Testing. No argument there. But, while automating the launch makes you faster; it doesn't change ...
Go to External Site
Attacker bypassed AI guardrails by disguising malicious activity as legitimate penetration testing, compromising multiple accommodation companies.
Go to External Site
It is important to distinguish several sources: the NCSC's March blog, the April assessment of Claude Mythos Preview and later AISI assessments. On ...
Go to External Site
INCENTIVE FOR CENTENARIANS. Dr. Cesar A. Adegue, director of the National Commission of Senior Citizens (NCSC) in the Davao Region (right), ...
Go to External Site
23.06.2026 - Last week, the NCSC received a higher than usual number of reports about a scam involving fake voicemail messages sent via email.
Go to External Site
One of the most talked about concerns is exposure to malware. Untrusted streaming sites often have hidden scripts or misleading download buttons that ...
Go to External Site
A breach at a Texas Parks and Wildlife Department vendor exposed personal information belonging to more than three million Texans.
Go to External Site
The operation that compromised dozens of Mastra AI framework packages has, according to Microsoft, a clear culprit: North Korea's Sapphire Sleet, ...
Go to External Site
SocGholish uses traffic distribution systems (TDSs) to provide initial access into victims' networks for cybercrime groups such as the notorious ...
Go to External Site
Microsoft warns of a new dual-action cryptocurrency clipper (CryptoBandits Malware) spreading through USB devices to alter wallet addresses and ...
Go to External Site
Meta has paused its controversial employee-tracking program. Unfortunately, employee privacy wasn't what stopped it.
Go to External Site
I4C warns that cybercriminals are hijacking executive WhatsApp accounts and impersonating senior leaders to trick finance teams into transferring ...
Go to External Site
JFrog Security Research has disclosed a critical vulnerability in FFmpeg, dubbed PixelSmash (CVE-2026-8461), carrying a CVSS score of 8.8 (High).
Go to External Site
However, standard sintered NdFeB magnets have a critical vulnerability: their magnetic performance degrades significantly at elevated temperatures.
Go to External Site
... critical vulnerability to the bloc's economic sovereignty. The digital euro aims to reclaim control over the continent's daily financial ...
Go to External Site
Why This Matters for the Supply Chain. For investors and industry observers, this incident highlights a critical vulnerability in global supply chains ...
Go to External Site
Older iPhone users now have a reason to worry after a cybersecurity group has revealed a critical vulnerability in Apple's older chips that may help ...
Go to External Site
A critical vulnerability has been disclosed in FFmpeg's MagicYUV decoder that allows attackers to weaponize… 1 hour ago. Hackers Using ...
Go to External Site
A critical vulnerability has been disclosed in FFmpeg's MagicYUV decoder that allows attackers to weaponize… 45 minutes ago. Hackers Using ...
Go to External Site
A critical vulnerability has been disclosed in FFmpeg's MagicYUV decoder that allows attackers to weaponize… 22 minutes ago. Hackers Using ...
Go to External Site
A critical vulnerability has been disclosed in FFmpeg's MagicYUV decoder that allows attackers to weaponize seemingly harmless media files and, in ...
Go to External Site
The highly porous borders between the DRC, Uganda, and Kenya represent a critical vulnerability for the entire region. The Kenyan Ministry of ...
Go to External Site
The incidents, which occurred immediately after the drivers unleashed maximum power from their hybrid systems, have laid bare a critical vulnerability ...
Go to External Site
Cybersecurity experts in Nairobi warn that the proliferation of AI tools capable of bypassing standard firewalls presents a critical vulnerability for ...
Go to External Site
... critical vulnerability in the global industrial supply chain. This concentration of risk among foreign nationals is not accidental; it is a ...
Go to External Site
This is the first research of this kind to be undertaken in Africa, and it highlights a critical vulnerability for one of South Africa's most ...
Go to External Site
One specific result: OpenAI found CVE-2026-8390, a critical vulnerability in Firefox, during safety evaluations. Mozilla patched it two days ...
Go to External Site
A critical vulnerability in the FFmpeg media processing framework allows attackers to execute arbitrary code via malicious video files.
Go to External Site
A critical vulnerability has been disclosed in FFmpeg's MagicYUV decoder that allows attackers to weaponize… 2 hours ago. All Rights ReservedView ...
Go to External Site
Massive Fuel Transfer Rates. During a mid-air hookup, time is a critical vulnerability. The high-pressure boom system transfers fuel at an incredible ...
Go to External Site
The files use names in different languages and even pretend to be Windows updates to dodge security checks. Kaspersky's advice? Don't open ...
Go to External Site
... Windows updates, but will lose access to new early-boot protections ... Microsoft says devices that no longer receive Windows updates will ...
Go to External Site
Threat intelligence report with 1492 extracted IOCs, MITRE ATT&CK mapping, and hunting context. Free by SOCRadar.
Go to External Site
23.06.2026 - Last week, the NCSC received a higher than usual number of reports about a scam involving fake voicemail messages sent via email.
Go to External Site
Recently, Splunk Attack Analyzer (SAA) superseded Secure Malware Analytics (SMA) as the official malware threat analysis platform at Black Hat. With ...
Go to External Site
macOS Terminal (Illustration): Danger from problematic commands. (Image: Dragon Claws / Shutterstock). at 1:05 pm CEST.
Go to External Site
India's cybercrime agency has warned organisations about a growing fraud known as the "Boss Scam" or CEO impersonation scam.
Go to External Site
A new wave of scam websites is offering something millions of people want: a way to play Grand Theft Auto VI before it comes out.
Go to External Site
It can perform penetration testing, vulnerability analysis, and malicious code analysis. OpenAI explained, “Our goal is to provide AI to as many ...
Go to External Site
He has more than 20 years of experience scaling cybersecurity companies, with expertise in penetration testing, security program transformation, risk ...
Go to External Site
Reliability is built into the product at every level: from LFP cells that have passed nail penetration testing, to flame-retardant materials that ...
Go to External Site
“One day, I hope to work for some type of government agency, doing penetration testing like one of our instructors actually does,” he said.
Go to External Site
The Hacker News (@TheHackersNews). 68 likes. ⚡ Canada's spy service got a court order to remotely clean #malware-infected devices.
Go to External Site
... (NCSC) were expected to face major cuts. "The deep state firings have begun," a source told CNN, which first reported the news of the terminations ...
Go to External Site
ncsc.gov.uk + 3. Recent AI restrictions highlight security concerns. The Trump administration's export-control directive on Anthropic's Fable 5 and ...
Go to External Site
Horne said the NCSC managed more than 200 incidents affecting CNI and its supporting systems in the year to May 2026, a volume mirroring the agency's ...
Go to External Site
Is a-9999.a-dc-msedge.net safe? Check risk score, DNS history, and phishing & malware campaigns linked to this domain.
Go to External Site
Attackers backdoored ShapedPlugin Pro updates, stealing credentials, 2FA codes, wp-config.php data, and WooCommerce order details.
Go to External Site
Avast One Premium brings together enhanced antivirus and a collection of other security, privacy, and performance features for all your devices, ...
Go to External Site
The UK's National Cyber Security Centre (NCSC) has published an analysis directed at organizations about the latent risks of vibe coding, a rising ...
Go to External Site
... NCSC New Zealand). The agencies urge leaders to treat cyber risk as a ... NCSC said they are accessing frontier models and working with ...
Go to External Site
... NCSC, the UK's NCSC, the US NSA, and CISA. The core message: frontier AI models are anticipated to exceed current industry expectations. The ...
Go to External Site
... critical vulnerability remediation gap in open-source software. More than 30 open-source projects have committed to participate, including: cURL ...
Go to External Site
In a sellout venue operating at a capacity of 52,497 fans, the presence of an incendiary device represents a critical vulnerability in the event's ...
Go to External Site
The Log4j vulnerability incident a few years ago was a typical example—a widely used open-source tool was found to have a critical vulnerability, ...
Go to External Site
Rootkits are sneaky malware that hide deep in your system. Learn how to detect and remove them, and find out how Panda Security keeps you ...
Go to External Site
The Indian Cyber Crime Coordination Centre (I4C) has observed an emerging trend in cybercrime referred to as the "Boss Scam" or CEO impersonation ...
Go to External Site
Move past basic credential harvesting. Discover how modern attackers use ClickFix, BitB, and OAuth consent phishing—and how to train your users ...
Go to External Site
b6e41b35fd514049f7384bc05a560210 — MD5 hash analysis: malware family, threat-actor attribution, MITRE ATT&CK mapping, and first/last-seen data.
Go to External Site
OceanLotus APT32 targets Southeast Asia with spearphishing, supply chain attacks, custom malware, and DLL sideloading.
Go to External Site
Is 38.47.123.84.nip.io safe? Check risk score, DNS history, and phishing & malware campaigns linked to this domain. Free threat intel — no signup.
Go to External Site
... critical vulnerability. AI-driven tools enable highly convincing scams, including deepfakes and personalized spear phishing messages, increasing ...
Go to External Site
Is mathfocus.gr safe? Check risk score, DNS history, and phishing & malware campaigns linked to this domain. Free threat intel — no signup.
Go to External Site
QiAnXin XLab uncovered “AryStinger,” malware exploiting old D-Link/Linksys router flaws (CVE‑2013‑3307, CVE‑2016‑5681) to build a ...
Go to External Site