Cloud SecurityGreatness Expands Microsoft 365 Phishing with AiTM and Device Code Attacks
The phishing-as-a-service platform Greatness , active since at least mid-2022, has expanded its campaigns targeting Microsoft 365 users. The activity
Cloud SecurityThe phishing-as-a-service platform Greatness , active since at least mid-2022, has expanded its campaigns targeting Microsoft 365 users. The activity
VulnerabilitiesTP-Link fixed 15 ZTP vulnerabilities in Omada ecosystem that could lead to RCE and network compromise. Learn about impacts and security measures.
VulnerabilitiesOn August 4, 2026, CISA published an advisory on CVE-2026-18411 , a vulnerability affecting Acrisure KARR BT and DR-100 products. The issue stems from the
MalwarePalo Alto Networks Unit 42 has analyzed a new variant of XCSSET, dubbed v40 , which targets macOS developers through compromised Xcode projects and GitHub
MalwareThe ChainDrop npm supply-chain attack compromised 1,300 packages. Learn how it stole tokens and spread across CI/CD and developer environments.
RansomwareINC Ransomware exploits SonicWall SMA 1000 zero-day vulnerabilities since June 2026. Learn how the group uses phone calls and emails for extortion.
VulnerabilitiesA critical flaw in tl;dv exposes 180k meetings and 80k users. Attackers exploit missing Firestore rules to impersonate the bot and spy on live calls.
AITwo critical vulnerabilities in Google's Gemini ADK allow remote code execution and PR manipulation, highlighting severe supply chain risks for AI agents.
MalwareDOUBLECUP is a Russian loader-as-a-service using fake CAPTCHAs, steganography, and browser cache to deploy fileless malware like CountLoader and RATs.