SAP Fixes Critical Security Flaws in NetWeaver and Commerce Cloud, Urges Immediate Patching

SAP has released new security updates to fix several serious vulnerabilities affecting its enterprise software products. As part of its latest Security Patch Day, the company addressed 16 security issues, including three critical vulnerabilities in SAP NetWeaver, SAP Commerce Cloud, and SAP AppRouter. These flaws could expose organizations to serious security risks if they are … Continued

148 Fake npm Packages Turn Browsers Into a Hidden DDoS Botnet

A new cybersecurity investigation has uncovered a large campaign involving 148 malicious npm packages that pretended to be harmless student web proxy tools. Security researchers at JFrog found that these packages were not designed to attack developers who downloaded them. Instead, they targeted students and other users who opened the proxy websites, secretly turning their … Continued

US and Allies Warn of Russian Cyber Threats Targeting Critical Infrastructure

The United States and several international cybersecurity agencies have issued a new joint warning about ongoing cyber threats linked to Russian intelligence services. The advisory says these threat actors are actively targeting critical infrastructure organizations by exploiting vulnerable and poorly secured network devices. Officials are urging organizations to strengthen their cyber defenses immediately to reduce … Continued

Critical Joomla Zero-Day Flaws in iCagenda and Balbooa Forms Actively Exploited by Hackers

A serious cybersecurity issue has been discovered in two popular Joomla extensions, iCagenda and Balbooa Forms. Security researchers confirmed that both vulnerabilities were being actively exploited by attackers before official fixes were released, making them true zero-day vulnerabilities. Because these extensions are widely used on Joomla websites, thousands of websites could have been exposed to … Continued

New MODBEACON RAT Hides Encrypted C2 Traffic Using gRPC Streaming

Security researchers have uncovered a new remote access trojan (RAT) called MODBEACON, a highly modular malware believed to be used by a Silver Fox-linked Ghost malware distributor. The malware was discovered during investigations into targeted attacks against organizations in Asia. Unlike common malware that spreads widely, MODBEACON appears to be deployed only against selected victims, … Continued

Global Anti-Fraud Crackdown Leads to 5,800 Arrests Across 97 Countries

Police agencies from around the world have carried out one of the biggest anti-fraud operations ever, leading to the arrest of more than 5,800 suspects involved in cyber-enabled financial crimes. The coordinated crackdown targeted criminal networks operating across multiple countries and focused on disrupting large-scale fraud activities. Authorities also seized large amounts of illegal assets … Continued

New HalluSquatting Attack Tricks AI Coding Assistants Into Installing Malware

A newly discovered cyberattack technique called HalluSquatting has revealed a serious security risk for developers who rely on AI coding assistants. Security researchers found that attackers can take advantage of AI-generated mistakes by creating fake software packages with names that AI models invent but do not actually exist. If developers trust these suggestions without checking … Continued

15-Year-Old GhostLock Linux Flaw Enables Root Access and Container Escape Across Major Distros

A newly disclosed Linux kernel vulnerability named GhostLock (CVE-2026-43499) has raised serious security concerns after researchers revealed that it had remained hidden in the operating system for nearly 15 years. The flaw affects most major Linux distributions and allows a local attacker to gain full root privileges on an unpatched system. Security researchers also confirmed … Continued

Newsletter line