HOOKEDGE: APT28 Hides C2 Traffic Inside Microsoft Edge
HOOKEDGE: APT28 Hides C2 Traffic Inside Microsoft Edge

An agenda for a meeting pops up, seemingly from a government ministry. This document prompts the...

miniOrange SAML Flaw Lets Anyone Log In as WordPress Admin
miniOrange SAML Flaw Lets Anyone Log In as WordPress Admin

Your scanner indicates that the plugin is already patched. There is no new update available...

WordlistLoader and SynkLoader Target Windows Credentials
WordlistLoader and SynkLoader Target Windows Credentials

An invitation comes through from the company IT help desk. The message invites you to download a...

Zimbra RCE Flaw Under Active Attack, CISA Sets Deadline
Zimbra RCE Flaw Under Active Attack, CISA Sets Deadline

Today, over 12,000 Zimbra mail servers are openly accessible on the Internet, and the attacker...

Medusa 2026: The Ransomware Stage Begins After Identity and Remote Management Are Lost
Medusa 2026: The Ransomware Stage Begins After Identity and Remote Management Are Lost

The latest Medusa federal advisory outlines an easily replicable chain of events leading from...

Heights Finance Breach Exposes 1.2 Million People
Heights Finance Breach Exposes 1.2 Million People

On May 7, Heights Finance identified a situation where a person accessed a cloud platform which...

Ransomware on vCenter May Be a Cover, Not the Goal
Ransomware on vCenter May Be a Cover, Not the Goal

When hackers were exploiting the severe vulnerability in VMware vCenter, they were busy creating...

A 2014 Certificate Still Loads Kernel Rootkits in 2026
A 2014 Certificate Still Loads Kernel Rootkits in 2026

The digital signature which authenticates this rootkit has expired as of September 2014. It...

Eight AI Agents Breached 21 Government Systems in Four Days
Eight AI Agents Breached 21 Government Systems in Four Days

The hackers did not discover any new vulnerabilities. Rather, they discovered that there was one...