From Disclosure to Exploitation: Russian-Linked Hackers Abuse Microsoft Office Flaw Just Days After Patch Release

A serious security flaw was recently discovered in Microsoft Office, and hackers moved extremely fast to exploit it. Within just three days of Microsoft releasing a fix, Russian-linked cyber attackers began using the bug in real-world attacks. This incident highlights how quickly cyber threats can evolve once a vulnerability becomes public. It also shows the … Continued

Notepad++ Hosting Breach Linked to China-Associated Lotus Blossom Hacking Group

Notepad++, a widely used open-source text editor, was recently affected by a serious cybersecurity incident. Investigators confirmed that the attack targeted the hosting infrastructure used to distribute software updates. The breach has been linked to a China-associated hacking group known as Lotus Blossom. The software itself was not exploited directly. The attack took place over … Continued

When Antivirus Updates Become the Attack Vector: eScan Hit by a Multi-Stage Supply-Chain Compromise

Cybersecurity researchers have reported a serious incident involving eScan antivirus software, where attackers compromised one of its update servers. Instead of sending a normal security update, the server delivered malicious files to users. This type of attack is known as a supply-chain attack and is considered highly dangerous. The issue came to light after abnormal … Continued

Compromised Developer Credentials Trigger GlassWorm Supply-Chain Attack on Open VSX

A serious supply-chain attack has been uncovered on the Open VSX extension registry, a platform widely used by developers to download and manage coding extensions. In this incident, attackers compromised a legitimate developer account and used it to publish malicious updates. The attack relied on abusing existing trust rather than exploiting the platform itself. This … Continued

Google Disrupts IPIDEA, One of the World’s Largest Residential Proxy Networks

Google has announced a major cybersecurity operation against IPIDEA, one of the world’s largest residential proxy networks. The action was carried out by Google’s Threat Intelligence Group to stop widespread abuse of consumer internet connections. According to Google, the network was being heavily misused by cybercriminals. The disruption is aimed at protecting everyday users and … Continued

Fortinet Patches CVE-2026-24858 Following Active Exploitation of FortiOS SSO

Fortinet has released emergency security updates after confirming active exploitation of a serious vulnerability in its FortiOS Single Sign-On system. The flaw, tracked as CVE-2026-24858, allows attackers to bypass authentication controls. Security researchers found that the issue was already being abused in real-world attacks. This made immediate patching critical. The vulnerability affects how Fortinet devices … Continued

Newsletter line