Hackers Breach Zara-Linked Database, 197,000 Users Potentially Affected 

Global fashion brand Zara recently came under attention after reports claimed that personal information linked to nearly 197,000 people may have been exposed in a cybersecurity incident. The breach was reportedly connected to transaction-related databases associated with Zara’s parent company, Inditex. Cybersecurity monitoring platforms later highlighted the incident and described it as one of the … Continued

Hackers Abuse Google Ads to Steal GoDaddy ManageWP Logins Through Fake Phishing Pages 

A new phishing campaign has been discovered where hackers are abusing Google Ads to target users of GoDaddy ManageWP. Security researchers found that attackers created fake sponsored advertisements that appeared at the top of Google search results. Since these ads looked legitimate, many users clicked on them without suspicion. The campaign mainly targeted website administrators … Continued

PyPI Packages Spread ZiChatBot Malware on Windows and Linux Through Zulip APIs 

A new cybersecurity threat has recently been discovered after security researchers found several malicious Python packages on the Python Package Index (PyPI). These fake packages were designed to spread a dangerous malware known as “ZiChatBot” on both Windows and Linux systems. Since PyPI is one of the most trusted platforms for Python developers, the incident … Continued

Critical Palo Alto PAN-OS Flaw Under Active Exploitation Enables Remote Code Execution 

Cybersecurity researchers have warned about a critical security flaw affecting Palo Alto Networks’ PAN-OS software. The vulnerability, tracked as CVE-2026-0300, is reportedly being actively exploited in real-world attacks. Security experts say the flaw can allow remote code execution on vulnerable systems. The issue mainly affects internet-exposed PAN-OS User-ID Authentication Portal services. Researchers explained that the … Continued

New Stealthy Quasar Linux Malware Targets Developers and Cloud Environments 

Cybersecurity researchers have discovered a dangerous Linux malware called Quasar Linux, also known as QLNX. Experts say the malware mainly targets software developers and DevOps environments. It is designed to stay hidden inside systems for long periods without getting detected. Researchers believe its main goal is to steal sensitive credentials and gain deep access to … Continued

Critical MOVEit Automation Flaw Allows Authentication Bypass, Warns Progress Software

A serious cybersecurity issue has recently been identified in MOVEit Automation, a file transfer solution developed by Progress Software. The vulnerability is tracked as CVE-2026-4670 and has been classified as critical. It allows attackers to bypass authentication and access systems without valid login credentials. This is dangerous because authentication is the first layer of security … Continued

Mini Shai-Hulud Attack Targets SAP npm Packages, Exposes Developer Credentials 

A new cyberattack called “Mini Shai-Hulud” has been discovered and is linked to a group known as TeamPCP. This attack mainly targets software packages used in SAP development environments. Instead of directly hacking systems, the attackers chose a smarter approach by compromising trusted tools. These tools are used daily by developers, which makes the attack … Continued

Newsletter line