Category Archives: Threat Alerts

Stay one step ahead of cybercriminals. Early warnings and detailed analysis of new social engineering scams, complex phishing campaigns, zero-day malware, and digital extortion methods.

FIRESTARTER Malware: CISA Warns of Persistence on Cisco Firewalls

CISA has updated its emergency directive warning that FIRESTARTER malware can survive firmware patches on Cisco devices, requiring advanced forensic removal methods. Continue reading

Posted in Security & Privacy, Threat Alerts | Tagged , , , | Leave a comment

TestFlight Phishing and QR Code Lures Rise in VIPRE Q1 2026 Report

The VIPRE Q1 2026 report reveals a surge in TestFlight phishing and QR-embedded PDF lures, marking a shift in social engineering tactics used to bypass security. Continue reading

Posted in Security & Privacy, Threat Alerts | Tagged , , , | Leave a comment

Kyber Ransomware Adopts Kyber1024 Post-Quantum Encryption

A new variant of Kyber Ransomware has been detected using Kyber1024 post-quantum cryptography to encrypt Windows and VMware ESXi endpoints, targeting high-value infrastructure. Continue reading

Posted in Security & Privacy, Threat Alerts | Tagged , , , | Leave a comment

Silent Subject Phishing: New VIP Campaign Bypasses Security

Security researchers have identified a surge in Silent Subject Phishing targeting corporate VIPs, using empty subject lines to evade traditional detection methods. Continue reading

Posted in Security & Privacy, Threat Alerts | Tagged , , , | Leave a comment

Checkmarx Supply Chain Attack: Malicious KICS Images and VS Code Extensions

A sophisticated Checkmarx supply chain attack has been identified, involving poisoned KICS Docker images and malicious VS Code extensions designed to exfiltrate sensitive credentials and developer tokens. Continue reading

Posted in Security & Privacy, Threat Alerts | Tagged , , , | Leave a comment

Vibe Coding Phishing: AI-Powered Softr Exploits Rise in 2026

Cisco Talos identifies vibe coding phishing as a top threat, utilizing AI-driven no-code platforms like Softr to automate credential harvesting at scale. Continue reading

Posted in Security & Privacy, Threat Alerts | Tagged , , , | Leave a comment

AI Voice Cloning: Post-Tax Refund Extortion and Digital Fraud Trends

The SENTINEL-FRAUD assessment highlights a significant rise in AI voice cloning used for post-tax refund extortion and sophisticated social engineering attacks. Continue reading

Posted in Security & Privacy, Threat Alerts | Tagged , , , | Leave a comment

Cisco SD-WAN Vulnerabilities Under Active Exploitation: CISA Issues Warning

CISA has added several Cisco SD-WAN vulnerabilities to its Known Exploited Vulnerabilities catalog following reports of attackers using a three-flaw chain to gain full administrative control of corporate networks. Continue reading

Posted in Security & Privacy, Threat Alerts | Tagged , , , | Leave a comment

SGLang RCE Vulnerability (CVE-2026-5760) Exploits AI Pipelines

Security researchers have identified a critical SGLang RCE vulnerability (CVE-2026-5760) that allows remote code execution through malicious GGUF model files. Continue reading

Posted in Security & Privacy, Threat Alerts | Tagged , , , | Leave a comment