Automated Pentest Says You Are Secure? Security Experts Warn That Is Not the Full Story 

Many organizations today rely on automated penetration-testing tools to evaluate their cybersecurity defenses. These tools can quickly scan systems, identify known vulnerabilities, and generate reports that appear reassuring. However, security experts behind a recent webinar warn that a clean automated pentest report does not always mean an organization is truly secure. Automated tools can only … Continued

Anthropic Launches Claude Fable 5: Powerful New AI Model Arrives With Built-In Cybersecurity Safeguards 

Anthropic has officially introduced Claude Fable 5, describing it as the most powerful AI model the company has ever made available to the public. The new model belongs to Anthropic’s newly created “Mythos” class of AI systems, which are designed to handle more complex tasks, deeper reasoning, advanced coding work, and long-duration problem solving than … Continued

WhatsApp Uncovers New NSO Group-Linked Spearphishing Campaign Despite Court Ban 

WhatsApp has revealed that it recently disrupted a new wave of spearphishing attempts linked to the Israeli spyware company NSO Group. The discovery comes despite a permanent U.S. court injunction that previously barred NSO from targeting WhatsApp and its users. Meta, WhatsApp’s parent company, said the latest activity suggests that efforts connected to the spyware … Continued

LiteLLM Vulnerability Under Active Attack: Flaw Chain Enables Unauthenticated Remote Code Execution

A serious security flaw in LiteLLM, tracked as CVE-2026-42271, is now being actively exploited by attackers. The vulnerability was recently added to the U.S. Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities catalog after confirmed reports of real-world attacks. Security researchers warn that organizations using vulnerable LiteLLM deployments could face significant risks if the … Continued

20,000 Instagram Accounts Hijacked Through Meta AI Support Tool Abuse 

More than 20,000 Instagram accounts were reportedly taken over after hackers found a way to misuse Meta’s AI-powered support system. According to reports, the attackers exploited a flaw in an account recovery tool that was designed to help users regain access to their accounts. Meta has confirmed that around 20,000 accounts may have been affected … Continued

FIFA World Cup 2026 Scams Surge: Fake Ticket Sites, Banking Malware, and Login Theft Target Fans 

Cybersecurity researchers and the FBI have warned that scammers have already started targeting football fans ahead of the FIFA World Cup 2026. Even before the tournament begins, thousands of fake websites and online scams are being used to trick people into giving away personal information, login credentials, and banking details. Experts say cybercriminals are taking … Continued

Fake Software Sites Are Gaming Google Search to Deliver Malware, Researchers Warn

Cybersecurity researchers have uncovered a malware campaign that abuses Google search results to target users looking for popular open-source software. Attackers are creating fake websites that closely imitate legitimate project pages and then using SEO techniques to push those sites higher in search rankings. This increases the chances that users will visit a malicious website … Continued

CISA Warns of Critical Magento Flaw Under Active Attack: Thousands of Stores Potentially at Risk

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Magento-related vulnerability, tracked as CVE-2026-45247, to its Known Exploited Vulnerabilities (KEV) Catalog after confirming that it is being actively exploited in real-world attacks. The flaw affects Mirasvit Cache Warmer, a Magento extension used by online stores to improve website performance through full-page caching. … Continued

Newsletter line