News
Latest cybersecurity news — hacks, breaches, vulnerabilities, regulatory moves
Avalon Malware Framework Packs CrownX Ransomware and EDR-Killing Evasion
Researchers have documented a previously undocumented modular malware framework codenamed Avalon that bundles a full ransomware payload internally named CrownX. Rather than…
NewsSimpleHelp RMM Auth Bypass CVE-2026-48558 (CVSS 10.0) Exploited in MSP Supply-Chain Attacks
Attackers are actively exploiting CVE-2026-48558, a maximum-severity authentication-bypass flaw (CVSS 10.0) in SimpleHelp’s Remote Monitoring and Management (RMM) software, to deploy the…
NewsKemp LoadMaster Command Injection CVE-2026-8037 Under Active Exploitation
Attackers are actively probing and exploiting CVE-2026-8037, a critical operating-system command injection flaw in Progress Kemp LoadMaster, the load balancer and application…
NewsBad Epoll: Linux Kernel Flaw CVE-2026-46242 Hands Local Users Root
A newly disclosed Linux kernel vulnerability dubbed Bad Epoll (CVE-2026-46242) allows an ordinary local user — no special group memberships, no sudo…
AI SecurityJadePuffer: The First Ransomware Operation Run Entirely by an LLM Agent
Security researchers at Sysdig have documented what they assess to be the first ransomware operation conducted end-to-end by a large language model…
NewsDecades-Old FAT32 Filesystem Flaws Put Millions of Embedded Devices at Risk
Researchers have disclosed unpatched vulnerabilities in a filesystem implementation bundled into millions of embedded devices, headlined by CVE-2026-6682 — an integer overflow…
NewsCISA Flags Actively Exploited SharePoint RCE CVE-2026-45659 — Patch Now
CISA has added a high-severity Microsoft SharePoint Server flaw to its Known Exploited Vulnerabilities (KEV) catalog after confirming it is being exploited…
AI SecurityAI Tool Integrations Expose New Attack Surface: Inside MCP Security Risks
Model Context Protocol (MCP), the emerging standard that lets AI assistants connect to external tools and data sources, is rapidly becoming a…
DPDP ComplianceDPDP Significant Data Fiduciary Rules: What Indian Businesses Must Prepare For
India’s Ministry of Electronics and Information Technology (MeitY) has been expected to finalise the rules under the Digital Personal Data Protection (DPDP)…
NewsEdge Device Exploitation: VPN and Firewall Appliances Remain Top Initial Access Vector in 2026
Network edge appliances — VPN gateways, firewalls, load balancers, and SSL inspection proxies — have become the most reliable initial access vector…