In Nginx Proxy Manager (NPM), if you are obtaining certificates via DNS challenge (such as wildcard certificates), the DNS ...
This is an explanation of the Reverse Engineering challenge 'crackme-py' from CyLab Security Academy (formerly picoCTF). You ...
TIKTOUK targets exposed WordPress backups to steal cloud and email credentials, with 50,000 credentials found across 37,000 domains.
A TerminalFix intrusion campaign that uses ClickFix-style social engineering, PowerShell execution, DLL sideloading, and a ...
The OpenStack community released OpenStack 2026.2 (Hibiscus) on September 30, 2026, the 34th release of the open source cloud infrastructure software, adding confidential-computing support for AMD and ...
Russian state threat actor Star Blizzard is using email conversations to deliver malware after victims respond to seemingly ...
Ransomware victim volumes remain persistent amid major ecosystem churn: ThreatLabz tracked 7,366 victims listed on ransomware leak sites, representing only a 3% YoY decline. Qilin, Akira and INC ...
Cisco Talos finds rising ransomware activity in Japan, with 90 observed victims and signs that Qilin-linked attack scripts ...
Storm-3168, an AI-orchestrated threat actor also known as JADEPUFFER, used two compromised service principals to delete 100+ ...
A Python-based malware builder can turn a single stealer into Windows programs for different operators. The tool packages a ...
Researchers have published a report reconstructing how a swarm of OpenAI agents compromised Hugging Face in July 2026, ...