2026 stood as a turning point in cybersecurity, with cyberattacks surging in frequency, sophistication, and disruption. Rapid digital transformation and hyper-connected systems handed attackers unprecedented opportunities to exploit flaws.
From ransomware paralyzing critical infrastructure to AI-powered phishing schemes, cybercriminals...
A threat actor known as "skart7" is allegedly offering a zero-day Local Privilege Escalation (LPE) exploit targeting Apple's macOS operating system for sale on a prominent hacker forum.
This development represents a significant security concern for macOS users, particularly those...
Evan Frederick Light, a 22-year-old from Lebanon, Indiana, has been sentenced to 20 years in federal prison for orchestrating a sophisticated cyber intrusion that led to the theft of over $37 million in cryptocurrency.
The sentencing took place on February...
Microsoft has released a critical security update for its Edge browser, addressing multiple vulnerabilities that could allow attackers to execute remote code and compromise user systems.
Users are strongly urged to update their browsers immediately to mitigate potential risks.
Four significant...
ParrotOS, the cybersecurity-focused Linux distribution, has recently released its latest update, Parrot 6.3, which includes a number of new features, performance improvements, and updated tools to enhance the user experience.This release is designed to make ParrotOS faster, more stable,...
A moderate-severity Cross-Site Scripting (XSS) vulnerability has been identified in phpMyAdmin, a widely used open-source tool for managing MySQL databases.
This flaw, tracked as CVE-2025-24530, affects versions 5.x prior to 5.2.2 and is linked to the "Check tables" feature.
The vulnerability...
The development of generative AI offered both opportunities for beneficial productivity transformation and opportunities for malicious exploitation.
GhostGPT, an uncensored AI chatbot created specifically for cybercrime, is the most recent threat in this domain.
GhostGPT, which researchers at Abnormal Security identified,...
A newly discovered attack technique, dubbed the "cookie sandwich," enables attackers to bypass the HttpOnly flag on certain servers, exposing sensitive cookies, including session identifiers, to client-side scripts.
The "cookie sandwich" attack exploits flaws in how web servers parse cookies...
A sophisticated supply-chain attack targeting a South Korean VPN provider. The attack has been attributed to a previously undisclosed China-aligned Advanced Persistent Threat (APT) group, now named PlushDaemon.
The operation, discovered in May 2024, involved the compromise of IPany, a...
Cloudflare recently thwarted the largest distributed denial-of-service (DDoS) attack ever recorded, peaking at an unprecedented 5.6 terabits per second (Tbps).
The attack, which occurred on October 29, 2024, targeted an Internet Service Provider (ISP) in Eastern Asia and was...