
Cyber Attacks
View all
ShinyHunters Hit as FBI Detains Suspected Member in Cybercrime Crackdown
Law enforcement authorities have detained a suspected member of the ShinyHunters cybercrime group, marking a significant disruption to the threat actor's operations.
Cloud Security
View allVulnerabilities
View all
AhsayCBS Backup Platform Vulnerabilities Exploited for Webshell and Miner Deployment
Threat actors are actively exploiting unpatched flaws in the AhsayCBS backup management platform to install webshells and cryptocurrency mining software.

AWS Ops Wheel flaws CVE-2026-6911 and CVE-2026-6912 expose infrastructure configs
Two security issues in AWS Ops Wheel allow potential exposure of sensitive cloud infrastructure configurations to unauthorized users.

Gutentype Object Injection: Critical Deserialization of Untrusted Data Affects Versions Through 2.1.12
The National Vulnerability Database rates CVE-2026-62046 as critical, warning that untrusted data handling in the Gutentype plugin enables object injection.

Convex Plugin Deserialization Vulnerability Enables Remote Object Injection on WordPress Sites
Deserialization of untrusted data in the Convex plugin exposes WordPress sites to remote object injection attacks requiring immediate attention.
Data Breaches
View allLatest news
Vulnerabilities
WPCOM Member Authentication Bypass Allows Unauthorised Admin Access via Social Login Flaws
A critical authentication bypass in the WPCOM Member plugin for WordPress allows attackers to hijack admin accounts by forging social login sessions without valid credentials.
Vulnerabilities
ThemeREX Greeny Object Injection Bug Affects All Versions to 2.10.0 With 9.8 CVSS Score
A critical vulnerability in the ThemeREX Greeny WordPress theme allows object injection through untrusted data deserialization in versions up to 2.10.0.
Vulnerabilities
TinaCMS CLI RCE in Pre-3.0.0 Versions Lets Attackers Run Code via Git Branch Names
A high-severity injection flaw in older versions of the TinaCMS CLI allows attackers to execute arbitrary code during preview builds by manipulating Git branch names.
Threat Intelligence
Implement Mean Time to Detect: A Step-by-Step Rollout Plan
Detecting threats faster requires mapping data sources to specific attacker actions, not just counting alerts from generic security tools.
Threat Intelligence
Unified Kill Chain: The 10 Questions You Need Answered
The Unified Kill Chain exposes how traditional models miss the critical window where attackers operate inside trusted network segments before exfiltrating data.
Malware & Ransomware
Stop Mobile Malware: Practical Prevention That Actually Works
Relying on app stores alone fails because malware hides in legitimate apps that steal credentials before they reach security filters.
Vulnerabilities
Exposed Admin Panels: How Attackers Gain Access Step by Step
Most administrative interfaces remain accessible to the public internet because default configurations prioritise convenience over isolation, leaving the back door open.
Malware & Ransomware
Disaster Recovery Plans: Definition, Purpose, and Execution Steps
A disaster recovery plan dictates how you restore systems after failure, distinct from the broader business continuity strategy that keeps operations running.











