Carnival Cruise Confirms Data Breach Affecting Nearly 6 Million People

Carnival Corporation has confirmed a major cybersecurity breach that affected nearly 6 million people connected to the company. The incident was discovered in April 2026 after hackers gained unauthorized access to part of the company’s internal systems. According to the company, the attack happened through a social engineering method where employees were tricked into giving … Continued

GlassWorm Malware Network Taken Down After Massive Developer Supply Chain Attack

A major cybersecurity operation has disrupted the infrastructure behind the GlassWorm malware campaign. The operation was carried out by CrowdStrike, Google, and the Shadowserver Foundation. Security researchers said the malware mainly targeted software developers through infected VS Code extensions. The malicious extensions were uploaded to developer marketplaces to trick users into installing them. GlassWorm became … Continued

Gitea Security Flaw Exposes Private Container Images Without Login 

A major security vulnerability has been discovered in Gitea, a widely used open-source Git hosting platform. Researchers revealed that the flaw could allow anyone to access private container images without logging in. The issue has been identified as CVE-2026-27771 and affects versions earlier than 1.26.2. Security experts warned that the vulnerability could expose sensitive software … Continued

Microsoft Defender Can Now Automatically Isolate Hacked Endpoints During Cyberattacks 

Microsoft has introduced a new cybersecurity feature in Microsoft Defender for Endpoint that can automatically isolate compromised devices during an active cyberattack. The feature is currently available in preview mode and is designed to help organizations stop attacks before they spread across the network. It works as part of Microsoft’s growing focus on automated cyber … Continued

Hackers Hijack 700+ Ghost CMS Websites in Massive ClickFix Malware Campaign 

A critical vulnerability in Ghost CMS, identified as CVE-2026-26980, has been exploited by attackers in a large-scale malware campaign. Security researchers confirmed that more than 700 websites were compromised during the attacks. The flaw received a high severity score of 9.4 because of the serious risks it created. Many of the targeted websites were running … Continued

China-Linked Webworm Hackers Exploit Discord and Microsoft Graph to Target EU Governments

China-linked cyber espionage group “Webworm” has recently been linked to a major hacking campaign targeting European government organizations and other important sectors. Security researchers discovered that the attackers were using trusted online services like Discord and Microsoft Graph to secretly communicate with infected systems. This method allowed the hackers to hide their activity inside normal … Continued

Police Shut Down “First VPN” Used by Ransomware Gangs Worldwide 

Police and international cybercrime agencies have shut down a VPN service called “First VPN” that was allegedly being used by ransomware groups and cybercriminals. Authorities said the service helped attackers hide their identities during online crimes. The operation involved several countries working together to track and seize the VPN’s infrastructure. Officials believe the platform was … Continued

Content Delivery Exploit Opens Thousands of Trusted Websites to Brand Hijacking and Malicious Script Attacks 

Cybersecurity researchers have recently warned about a serious attack method that is targeting websites through content delivery systems, also called CDNs. These systems are commonly used to improve website speed and performance by delivering files quickly to users. Many popular websites depend on third-party scripts and external services every day. Attackers are now exploiting these … Continued

Newsletter line