Our own breakdowns of what happened
Meta Rewards Security Expert $78,000 After Support System Flaw Exposed User Information
Meta paid a significant bug bounty after a researcher found improper access controls in its customer support platform.
Read full story βLuxury Giant EstΓ©e Lauder Hit by Major Database Breach Through Enterprise Software Vulnerability
EstΓ©e Lauder confirms attackers stole sensitive customer data after exploiting a security flaw in business management software.
Read full story βHackers Found Using Microsoft 365 Calendar as Secret Messaging System
Attackers leverage hijacked Office 365 accounts to hide malware commands in calendar events, evading detection.
Read full story βMajor VPN Vulnerability Becomes Active Weapon in Ransomware Attacks
Cybercriminals exploiting critical Palo Alto security flaw to launch ransomware campaigns against businesses worldwide.
Read full story βZimbra Releases Emergency Security Fixes for Multiple Critical Flaws
Popular email platform Zimbra patched severe security holes that could let attackers take control of systems and steal data.
Read full story βHackers Already Targeting ServiceNow Software Flaw Just Days After Details Released
Attackers are exploiting a newly discovered ServiceNow flaw that allows them to run malicious code remotely on company systems.
Read full story βClover Health Hit by Cyberattack Through Manipulated Employee Access
Healthcare insurance firm Clover Health confirms attackers gained access to sensitive patient and employee data via social engineering tactics.
Read full story βHackers Deploy New Ransomware Targeting AI Systems Through ServiceNow Vulnerability
Attackers exploiting ServiceNow flaw to install AI-focused ransomware that destroys machine learning models and data.
Read full story βCritical WordPress Flaws Create Perfect Storm for Website Takeovers
Two newly discovered WordPress vulnerabilities working together allow hackers complete control of websites without needing login credentials.
Read full story βWordPress Plugin Flaw Triggers Wave of Automated Attacks as Hackers Share Easy-to-Use Tools
A serious vulnerability in a WordPress plugin is spreading rapidly as criminals use publicly available hacking tools to target websites.
Read full story βCryptocurrency Platform Loses Millions After Attackers Exploit Corporate Network Flaws
Hackers breached a crypto firm through unpatched security gaps in widely-used VPN equipment, stealing $23.7M in digital assets.
Read full story βMajor Beauty Brand Hit by Software Vulnerability Attack; Hackers Steal Customer Data
EstΓ©e Lauder discloses breach tied to unpatched software flaw affecting personnel systems and customer information.
Read full story βLuxury Beauty Giant EstΓ©e Lauder Hit by Security Vulnerability in Business Software
EstΓ©e Lauder confirms customer data was compromised through a weakness in Oracle's enterprise accounting system.
Read full story βAI Coding Tools Exploited to Steal Model Data and Deploy Ransomware
Security researchers reveal how attackers manipulated AI assistants to bypass safety measures and encrypt critical machine learning systems.
Read full story βMassive GitHub Poisoning Attack: Over 7,600 Repositories Weaponized to Deliver Malware
Attackers compromised thousands of code repositories to distribute dangerous malware to unsuspecting developers.
Read full story βAttackers Weaponize Microsoft Graph to Hide Command-and-Control Traffic
Cybercriminals deploy HollowGraph malware exploiting Microsoft's legitimate cloud service for hidden hacker communications.
Read full story βCybercriminals Used AI to Build Deceptive Attack Tool, Accidentally Exposed by Server Slip-Up
Hackers leveraged artificial intelligence to create sophisticated phishing attacks through WebDAV, revealing how automation is making cybercrime easier.
Read full story βHackers Quietly Broke Into SonicWall Systems for Weeks, Planting Hidden Backdoors
Cybercriminals exploited unknown security gaps in SonicWall firewalls to install malicious software for extended periods before fixes arrived.
Read full story βHackers Hide Instructions Inside Fake Calendar Events to Control Stolen Data
Researchers discover malware using Microsoft 365 calendars as hidden messaging system for cyberattacks.
Read full story βNew Malware Weaponizes Microsoft 365 Calendar to Hide Attack Commands and Stolen Data
Cybercriminals discovered they can stash malicious instructions and sensitive files inside Microsoft 365 calendar events dated decades in the future.
Read full story βMajor Accounting Firm Hit by Cyberattack; Millions Face Identity Risk
Hackers infiltrated Ernst & Young's vendor platform, exposing sensitive personal and financial records of numerous individuals.
Read full story βExpert Creates Tool to Track Major Data Breaches While Avoiding Damage Estimates
New database helps track significant cybersecurity incidents without calculating financial fallout from breaches.
Read full story β