Category Archives: Threat Alerts
Microsoft Exchange Zero-Day (CVE-2026-42897) Exploited in the Wild
A critical Microsoft Exchange Zero-Day vulnerability, tracked as CVE-2026-42897, is currently seeing active exploitation against on-premises Outlook Web Access users. Continue reading
CalPhishing Campaign: Hijacking M365 via Outlook Calendar Invites
Security researchers have identified the CalPhishing campaign, a new threat using Outlook calendar invites and the EvilTokens kit to bypass MFA and hijack accounts. Continue reading
Cisco SD-WAN Zero-Day CVE-2026-20182 Exploited by UAT-8616
Cisco has issued emergency patches for a critical Cisco SD-WAN zero-day vulnerability, CVE-2026-20182, which is being actively exploited by the threat actor UAT-8616 to bypass authentication. Continue reading
Windows Zero-Day Exploits: YellowKey and GreenPlasma Released
New Windows zero-day exploits known as YellowKey and GreenPlasma have been publicly released, posing a critical threat to BitLocker encryption and system privilege security. Continue reading
ClickFix macOS Campaign Exploits AI Lures to Deploy Infostealers
A sophisticated ClickFix macOS campaign has been identified using sponsored AI-themed search results and shared chat interfaces to trick users into installing the MacSync infostealer. Continue reading
AI-generated zero-day exploit discovered by Google Threat Intelligence
Google researchers have documented the first confirmed AI-generated zero-day exploit used in the wild to bypass two-factor authentication in administrative tools. Continue reading
JDownloader Supply Chain Compromise: Python-Based RAT Distributed
A major JDownloader supply chain compromise has resulted in the distribution of a Python-based RAT through malicious installer links on the official website. Continue reading
Canvas LMS Attacks: ShinyHunters Escalates Campaign with Personalized Phishing
New reports reveal that Canvas LMS attacks have escalated to include sophisticated phishing and portal defacements, targeting students and faculty through stolen institutional data. Continue reading
Canvas LMS Breach: Global Extortion Targets 9,000 Schools
A massive Canvas LMS breach has escalated into a global extortion campaign, with ShinyHunters claiming to hold 275 million records from over 9,000 educational institutions worldwide. Continue reading