ClickFix Campaign Exploits Fake BSODs to Infiltrate European Hospitality Sector

A new ClickFix social engineering campaign is actively targeting the hospitality sector across Europe, deploying deceptive Windows Blue Screen of Death (BSOD) screens to coerce …

Read more

Escalating Threat: Corporate Data Under Siege on Cloud File-Sharing Platforms

Threat actor Zestix is actively offering corporate data stolen from dozens of companies, following successful breaches of their ShareFile, Nextcloud, and OwnCloud instances. This ongoing …

Read more

Critical Authentication Bypass Flaw Exposes IBM API Connect Systems

IBM has recently disclosed a critical security flaw, tracked as CVE-2025-13915, within its API Connect authentication system, allowing remote attackers to bypass established security mechanisms …

Read more

Critical Exposure: Over 10,000 Fortinet Firewalls Remain Vulnerable to Five-Year-Old 2FA Bypass

Over 10,000 Internet-exposed Fortinet firewalls are currently susceptible to active exploitation of a five-year-old two-factor authentication (2FA) bypass vulnerability, posing a significant and persistent security …

Read more

Cybercriminals Weaponize Google Cloud’s Application Integration in Multi-Stage Phishing

Cybercriminals are actively exploiting Google Cloud’s Application Integration service to launch multi-stage phishing campaigns, impersonating legitimate Google-generated messages to deceive recipients. Cybersecurity researchers, including those …

Read more

Cyber Deception: ShinyHunters Claims Resecurity Breach, Firm Cries Honeypot

The notorious ShinyHunters hacking collective recently alleged a successful breach of cybersecurity firm Resecurity’s internal systems, claiming to have exfiltrated a significant volume of proprietary …

Read more