Researchers Uncover Unpatched Windows Vulnerability That Leaks NTLMv2 Hashes 

A new Windows security vulnerability has been discovered that could allow attackers to steal NTLMv2 authentication hashes from users. The flaw affects the Windows Search URI handler and currently remains unpatched. Security researchers found that attackers can exploit the issue using specially crafted links. These links can be delivered through emails, websites, or other online … Continued

Global Crackdown Dismantles 9 Crime Groups Behind Illegal Streaming Networks

Law enforcement agencies from several countries have successfully dismantled nine organized crime groups involved in illegal streaming activities. The operation targeted networks that were distributing copyrighted television channels, sports broadcasts, movies, and other premium content without authorization. Authorities worked together to identify the people behind these services and disrupt their operations. The action is being … Continued

Unpatched Oracle PLM Bug Under Active Attack, CISA Alerts Organizations

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added an Oracle security flaw to its Known Exploited Vulnerabilities (KEV) Catalog after confirming that it is being actively exploited in real-world attacks. The vulnerability affects Oracle Agile Product Lifecycle Management (PLM), a platform used by organizations to manage product development and supply chain operations. The … Continued

SideCopy Targets Afghanistan Finance Ministry with Stealthy XenoRAT Campaign

A Pakistan-linked cyber espionage group known as SideCopy has been linked to a targeted cyberattack against Afghanistan’s Ministry of Finance. Security researchers identified the operation and named it Operation XENOFISCAL. The campaign was specifically aimed at finance-related government offices across Afghanistan. Investigators believe the attackers were conducting a focused intelligence-gathering operation rather than a large-scale … Continued

OverlayPhantom Android Banking Trojan Abuses Accessibility Services to Hijack Devices 

A newly discovered Android banking malware called OverlayPhantom has been identified by cybersecurity researchers as a serious threat to mobile users. The malware is mainly designed to steal banking credentials and monitor activity on infected devices. Researchers say it can also give attackers remote access to smartphones. The threat was recently discovered during investigations into … Continued

Kimsuky Evolves Cyber Operations with HelloDoor, HTTPSpy, and Remote Access Tactics 

Cybersecurity researchers have revealed that the North Korean-linked hacking group Kimsuky has expanded its cyber espionage toolkit with new malware and attack methods. The group is known for targeting government agencies, defense organizations, and research institutions. According to recent findings, Kimsuky is continuing to improve its operations to make attacks more effective. Experts say the … Continued

Carnival Cruise Confirms Data Breach Affecting Nearly 6 Million People

Carnival Corporation has confirmed a major cybersecurity breach that affected nearly 6 million people connected to the company. The incident was discovered in April 2026 after hackers gained unauthorized access to part of the company’s internal systems. According to the company, the attack happened through a social engineering method where employees were tricked into giving … Continued

GlassWorm Malware Network Taken Down After Massive Developer Supply Chain Attack

A major cybersecurity operation has disrupted the infrastructure behind the GlassWorm malware campaign. The operation was carried out by CrowdStrike, Google, and the Shadowserver Foundation. Security researchers said the malware mainly targeted software developers through infected VS Code extensions. The malicious extensions were uploaded to developer marketplaces to trick users into installing them. GlassWorm became … Continued

Newsletter line