Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated JavaScript from a publicly published Google Sheets document and injecting it into the victim's browser session. The actors use a variation on ClickFix social engineering.
CERT Polska warns that attackers are actively exploiting a chain of critical MikroTik RouterOS flaws to seize control of routers exposed to the internet.
This article reports that Adobe has patched a critical zero-day in Magento and Commerce, exploited to deploy a Rust backdoor and PHP web shell. The flaw, dubbed StyleSmuggler, allows unauthenticated code execution via template injection.
Cybersecurity researchers have disclosed details of a sprawling search engine optimization (SEO) poisoning campaign that paves the way for malware deployment and tech support scams. The campaign, discovered by the DFIR Report in March 2026, has been codenamed BengalSEO .
Exclusive: An exposed Advance Passenger Information System (APIS) database held 220 million passenger and crew records containing names, passport numbers, dates of birth, nationalities, and flight details spanning 2017 to 2026. Researchers accessed the Vietnam-linked system through a cloud-based path using default credentials.
Online dating app Grindr has agreed to pay $35.1 million to settle a UK privacy lawsuit related to the disclosure of users HIV status and other sensitive personal data to third-party advertising partners. The settlement covers claims brought by UK users under data protection laws.