Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
The iPhone of a Serbian student protest member was infected with NSO Group's Pegasus spyware via a zero-click iMessage exploit, according to Citizen Lab and the SHARE Foundation. The infection occurred between December 2025 and January 2026, though additional infections may have occurred, and Apple addressed the vulnerability in iOS 18.4.1.
This article discusses the rise of supply chain attacks in 2026 as a dominant threat vector, citing the Verizon DBIR data and the MOVEit attack as examples. It argues that traditional security tools fail to detect poisoned dependencies, making threat intelligence essential for early warning.
A security researcher known as Chaotic Eclipse has released a proof-of-concept exploit called FalconFlank, which demonstrates a privilege escalation vulnerability in CrowdStrike Falcon by abusing the office malicious macros remediation feature. The PoC works on fully updated Windows 11 25H2 or Windows Server 2025 with CrowdStrike Falcon installed, and the researcher notes that CrowdStrike may already have detections in place.
CISA added seven vulnerabilities to its KEV catalog after observing active exploitation, including flaws in SonicWall SMA 1000, Sangoma Switchvox, JFrog Artifactory, and others. Attackers are deploying reverse shells and crypto miners using these exploits.
Multiple vulnerabilities were identified in GitHub Enterprise Server. A remote attacker could exploit some of these vulnerabilities to trigger security restriction bypass, remote code execution and spoofing on the targeted system.
In this article Risk to enterprise environments Attack chain overview Mitigation and response recommendations Learn more Microsoft Threat Intelligence has observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT or helpdesk personnel and socially engineer users into granting an interactive remote session. Once remote control is established via RMM tools, the threat actor uses PowerShell to download and silently install a malicious MSI package, which in turn stages a portable Node.js runtime and an obfuscated JavaScript implant that provides persistent command execution and command and control (C2).