Don’t miss

Energy sector orgs targeted with AiTM phishing campaign

Energy sector orgs targeted with AiTM phishing campaign 2026-01-22 at 15:19 By Zeljka Zorz Organizations in the energy sector are being targeted with phishing emails aimed at compromising enterprise accounts, Microsoft warns. The attack campaign The attacks started with phishing emails with “NEW PROPOSAL – NDA” in the subject line, coming from a compromised email […]

Energy sector orgs targeted with AiTM phishing campaign Read More »

Exposed training apps are showing up in active cloud attacks

Exposed training apps are showing up in active cloud attacks 2026-01-22 at 09:06 By Sinisa Markovic Security teams often spin up vulnerable applications for demos, training, or internal testing. A recent Pentera research report documents how those environments are being left exposed on the public internet and actively exploited. The research focuses on intentionally vulnerable

Exposed training apps are showing up in active cloud attacks Read More »

Unbounded AI use can break your systems

Unbounded AI use can break your systems 2026-01-22 at 08:01 By Help Net Security In this Help Net Security video, James Wickett, CEO of DryRun Security, explains cyber risks many teams underestimate as they add AI to products. He focuses on how fast LLM features are pushed into live applications without limits or guardrails. The

Unbounded AI use can break your systems Read More »

Fully patched FortiGate firewalls are getting compromised via CVE-2025-59718?

Fully patched FortiGate firewalls are getting compromised via CVE-2025-59718? 2026-01-21 at 22:22 By Zeljka Zorz CVE-2025-59718, a critical authentication bypass flaw that attackers exploited in December 2025 to compromise FortiGate appliances, appears to persist in newer, purportedly fixed releases of the underlying FortiOS. According to Fortinet, CVE-2025-59718 had been fixed in FortiOS versions 7.6.4 or

Fully patched FortiGate firewalls are getting compromised via CVE-2025-59718? Read More »

RCE flaw in Cisco enterprise communications products probed by attackers (CVE-2026-20045)

RCE flaw in Cisco enterprise communications products probed by attackers (CVE-2026-20045) 2026-01-21 at 20:57 By Zeljka Zorz Cisco has fixed a critical remote code execution vulnerability (CVE-2026-20045) in some of its unified communications solutions that’s being targeted by attackers in the wild, the company announced on Wednesday via a security advisory. About CVE-2026-20045 CVE-2026-20045 is

RCE flaw in Cisco enterprise communications products probed by attackers (CVE-2026-20045) Read More »

RansomHub claims alleged breach of Apple partner Luxshare

RansomHub claims alleged breach of Apple partner Luxshare 2026-01-21 at 14:34 By Zeljka Zorz Chinese electronic manufacturer and Apple partner Luxshare Precision Industry has allegedly been breached by affiliates of the RansomHub ransomware-as-a-service outfit. Luxshare is one of the primary assemblers of Apple’s wireless earbuds, iPhones, and Vision Pro devices, as well as a producer

RansomHub claims alleged breach of Apple partner Luxshare Read More »

Linux users targeted by crypto thieves via hijacked apps on Snap Store

Linux users targeted by crypto thieves via hijacked apps on Snap Store 2026-01-21 at 12:17 By Zeljka Zorz Cryptocurrency thieves have found a new way to turn trusted software packages for Linux on the Snap Store into crypto-stealing malware, Ubuntu contributor and former Canonical developer Alan Pope warned. SnapScope web app identifies malicious snaps (Source:

Linux users targeted by crypto thieves via hijacked apps on Snap Store Read More »

Pro-Russian hacktivist campaigns continue against UK organizations

Pro-Russian hacktivist campaigns continue against UK organizations 2026-01-21 at 12:00 By Sinisa Markovic The UK’s National Cyber Security Centre reports ongoing cyber operations by Russian-aligned hacktivist groups targeting organizations in the UK and abroad. NoName057(16) remains active In December 2025, the NCSC co signed an advisory warning that pro-Russian hacktivist groups were conducting cyber operations

Pro-Russian hacktivist campaigns continue against UK organizations Read More »

Cybercriminals speak the language young people trust

Cybercriminals speak the language young people trust 2026-01-21 at 08:30 By Sinisa Markovic Criminal groups actively recruit, train, and retain people in structured ways. They move fast, pay in crypto, and place no weight on age. Young people are dealing with a new kind of addiction. It isn’t drugs, alcohol, or gambling. It’s screens. Constant

Cybercriminals speak the language young people trust Read More »

Bandit: Open-source tool designed to find security issues in Python code

Bandit: Open-source tool designed to find security issues in Python code 2026-01-21 at 08:04 By Sinisa Markovic Bandit is an open-source tool that scans Python source code for security issues that show up in everyday development. Many security teams and developers use it as a quick way to spot risky coding patterns early in the

Bandit: Open-source tool designed to find security issues in Python code Read More »

The 2026 State of Pentesting: Why delivery and follow-through matter more than ever

The 2026 State of Pentesting: Why delivery and follow-through matter more than ever 2026-01-21 at 07:34 By Help Net Security Penetration testing has evolved significantly over the past several years. While uncovering exploitable vulnerabilities remains the core goal, the real differentiator today is how findings are handled after the testing concludes. The method of reporting,

The 2026 State of Pentesting: Why delivery and follow-through matter more than ever Read More »

Initial access broker pleads guilty to selling access to 50 corporate networks

Initial access broker pleads guilty to selling access to 50 corporate networks 2026-01-20 at 15:43 By Zeljka Zorz A 40-year-old Jordanian man has admitted to selling unauthorized access to computer networks of at least 50 companies, the US Attorney’s Office of the District of New Jersey has announced. Feras Khalil Ahmad Albashiti has pleaded guilty

Initial access broker pleads guilty to selling access to 50 corporate networks Read More »

Confusion and fear send people to Reddit for cybersecurity advice

Confusion and fear send people to Reddit for cybersecurity advice 2026-01-20 at 09:00 By Sinisa Markovic A strange charge appears on a bank account. An email claims a package is on the way. A social media account stops accepting a password that worked yesterday. When these moments hit, many people do the same thing. They

Confusion and fear send people to Reddit for cybersecurity advice Read More »

Product showcase: PrivacyHawk for iOS helps users track and remove personal data from data brokers

Product showcase: PrivacyHawk for iOS helps users track and remove personal data from data brokers 2026-01-20 at 08:06 By Anamarija Pogorelec Every interaction online, from signing up for a newsletter to making a purchase, leaves a trace. These traces are collected by data brokers and resold to advertisers, analytics firms, or, in some cases, criminals

Product showcase: PrivacyHawk for iOS helps users track and remove personal data from data brokers Read More »

Fake browser crash alerts turn Chrome extension into enterprise backdoor

Fake browser crash alerts turn Chrome extension into enterprise backdoor 2026-01-19 at 17:21 By Zeljka Zorz Browser extensions are a high-risk attack vector for enterprises, allowing threat actors to bypass traditional security controls and gain a foothold on corporate endpoints. Case in point: A recently identified malicious extension called NexShield proves that a single user

Fake browser crash alerts turn Chrome extension into enterprise backdoor Read More »

Law enforcement tracks ransomware group blamed for massive financial losses

Law enforcement tracks ransomware group blamed for massive financial losses 2026-01-19 at 14:00 By Sinisa Markovic Law enforcement agencies in Ukraine and Germany have identified two members of a Russian-affiliated ransomware group and carried out searches in western Ukraine. Search (Source: Cyber ​​Police of Ukraine) Investigators also named the alleged organizer, a Russian national, and

Law enforcement tracks ransomware group blamed for massive financial losses Read More »

Global tensions are pushing cyber activity toward dangerous territory

Global tensions are pushing cyber activity toward dangerous territory 2026-01-19 at 09:48 By Sinisa Markovic Cybersecurity is inseparable from geopolitics. Ongoing conflicts, sanctions, trade wars, geoeconomic rivalry, and technological competition have pushed state competition into cyberspace. States use cyber operations to exert pressure on rivals, enabling disruption without resorting to conventional weapons. Infrastructure vulnerabilities in

Global tensions are pushing cyber activity toward dangerous territory Read More »

Bytebase: Open-source database DevOps tool

Bytebase: Open-source database DevOps tool 2026-01-19 at 09:19 By Sinisa Markovic Bytebase is a DevOps platform for managing database schema and data changes through a structured workflow. It provides a central place for teams to submit change requests, run reviews, and track executions across environments. The open-source edition is designed for organizations that want to

Bytebase: Open-source database DevOps tool Read More »

Review: AI Strategy and Security

Review: AI Strategy and Security 2026-01-19 at 09:00 By Mirko Zorz AI Strategy and Security is a guide for organizations planning enterprise AI programs. The book targets technology leaders, security professionals, and executives responsible for strategy, governance, and operational execution. It treats AI adoption as an organizational discipline that spans planning, staffing, security engineering, risk

Review: AI Strategy and Security Read More »

Cisco fixes AsyncOS vulnerability exploited in zero-day attacks (CVE-2025-20393)

Cisco fixes AsyncOS vulnerability exploited in zero-day attacks (CVE-2025-20393) 2026-01-16 at 17:05 By Zeljka Zorz Cisco has finally shipped security updates for its Email Security Gateway and Secure Email and Web Manager devices, which fix CVE-2025-20393, a vulnerability in the devices’ AsyncOS that has been exploited as a zero-day by suspected Chinese attackers since at

Cisco fixes AsyncOS vulnerability exploited in zero-day attacks (CVE-2025-20393) Read More »

Scroll to Top