Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
A data-theft campaign is exploiting Salesforce Experience Cloud and ServiceNow customer portals to steal information exposed to anonymous users. Attackers employ custom tools designed to extract data from misconfigured portal instances.
A new Android malware combination uses WindRelay, an NFC relay tool, alongside the SpyNote RAT to intercept card data and transmit it to attackers in real time. The campaign can take out loans and relay victims' credit card information.
AWS introduces IAM role manager to automate the creation of IAM roles when building new applications. It provisions and attaches appropriate roles during service creation, allowing developers to focus on building without needing deep IAM expertise.
A long-running data theft campaign called City-Forum has been active since at least March 2025. It targets organizations across multiple sectors using custom tooling to compromise Salesforce and ServiceNow environments.
Hackers are actively exploiting a critical vulnerability, CVE-2026-71362, in Adobe Commerce and Magento e-commerce platforms. Successful exploitation can permit attackers to hijack customer accounts.
More than 737 malicious Chrome Web Store extensions impersonate popular VPN and proxy services while routing user traffic through SOCKS5 proxies operated by a single provider. These fake extensions can expose browsing activity or intercept data.