Latest Cyber Security News

Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk

Kali365 is turning a legitimate Microsoft login into a gateway to corporate data. The phishing kit targets US organizations with attacker-controlled device...

Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup

Swati KhandelwalAug 05, 2026Vulnerability / DevOps An unauthenticated attacker can read any file the service account can access on Gitea, the self-hosted Git...

Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

Attacker-controlled instructions can make Atlassian's Rovo assistant collect Jira or Confluence data that a signed-in user can access, then send it to an...

New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens

Swati KhandelwalAug 08, 2026Email Security / Vulnerability New research shows content inside an email can escape its message boundary and interfere with the...

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

Ravie LakshmananAug 08, 2026Zero-Day / Vulnerability Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package...

Spark RAT Targets Cambodia, Abuses Vulnerable OPSWAT Driver to Disable Security Tools

Individuals and organizations in Cambodia have emerged as...

New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access

Academic researchers have disclosed a Rowhammer attack impacting...

CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs

Ravie LakshmananAug 27, 2026Vulnerability / Web Security The...

Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler

Ravie LakshmananAug 26, 2026Malware / Cyber Espionage Cybersecurity...

NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions

Cybersecurity researchers have disclosed details of a new...

CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing

Swati KhandelwalAug 26, 2026Red Teaming / Security Operations...