Category Archives: Threat Alerts

Stay one step ahead of cybercriminals. Early warnings and detailed analysis of new social engineering scams, complex phishing campaigns, zero-day malware, and digital extortion methods.

Microsoft Exchange Zero-Day (CVE-2026-42897) Exploited in the Wild

A critical Microsoft Exchange Zero-Day vulnerability, tracked as CVE-2026-42897, is currently seeing active exploitation against on-premises Outlook Web Access users. Continue reading

Posted in Security & Privacy, Threat Alerts | Tagged , , , | Leave a comment

CalPhishing Campaign: Hijacking M365 via Outlook Calendar Invites

Security researchers have identified the CalPhishing campaign, a new threat using Outlook calendar invites and the EvilTokens kit to bypass MFA and hijack accounts. Continue reading

Posted in Security & Privacy, Threat Alerts | Tagged , , , | Leave a comment

Cisco SD-WAN Zero-Day CVE-2026-20182 Exploited by UAT-8616

Cisco has issued emergency patches for a critical Cisco SD-WAN zero-day vulnerability, CVE-2026-20182, which is being actively exploited by the threat actor UAT-8616 to bypass authentication. Continue reading

Posted in Security & Privacy, Threat Alerts | Tagged , , , | Leave a comment

Windows Zero-Day Exploits: YellowKey and GreenPlasma Released

New Windows zero-day exploits known as YellowKey and GreenPlasma have been publicly released, posing a critical threat to BitLocker encryption and system privilege security. Continue reading

Posted in Security & Privacy, Threat Alerts | Tagged , , , | Leave a comment

ClickFix macOS Campaign Exploits AI Lures to Deploy Infostealers

A sophisticated ClickFix macOS campaign has been identified using sponsored AI-themed search results and shared chat interfaces to trick users into installing the MacSync infostealer. Continue reading

Posted in Security & Privacy, Threat Alerts | Tagged , , , | Leave a comment

AI-generated zero-day exploit discovered by Google Threat Intelligence

Google researchers have documented the first confirmed AI-generated zero-day exploit used in the wild to bypass two-factor authentication in administrative tools. Continue reading

Posted in Security & Privacy, Threat Alerts | Tagged , , , | Leave a comment

JDownloader Supply Chain Compromise: Python-Based RAT Distributed

A major JDownloader supply chain compromise has resulted in the distribution of a Python-based RAT through malicious installer links on the official website. Continue reading

Posted in Security & Privacy, Threat Alerts | Tagged , , , | Leave a comment

Canvas LMS Attacks: ShinyHunters Escalates Campaign with Personalized Phishing

New reports reveal that Canvas LMS attacks have escalated to include sophisticated phishing and portal defacements, targeting students and faculty through stolen institutional data. Continue reading

Posted in Security & Privacy, Threat Alerts | Tagged , , , | Leave a comment

Canvas LMS Breach: Global Extortion Targets 9,000 Schools

A massive Canvas LMS breach has escalated into a global extortion campaign, with ShinyHunters claiming to hold 275 million records from over 9,000 educational institutions worldwide. Continue reading

Posted in Security & Privacy, Threat Alerts | Tagged , , , | Leave a comment