Latest Cybersecurity News
View all →Inside the vault: how financial institutions protect their cloud environments
Financial institutions working in the cloud face a complex challenge: they not only have to protect and manage their customers’ data, but they also have…
CastleStealer: An Emerging Infostealer Growing More Sophisticated
First discovered in April 2026, CastleStealer is a C#-based information-stealing malware that has continued to add new capabilities since its emergence. Newer samples analyzed by…
Ransomware attack disrupts Japan’s IDCF Cloud used by govt clients
IDC Frontier, a major Japanese cloud and digital infrastructure company, disclosed that its IDCF Cloud service was targeted in a ransomware attack that caused an…
Hikvision Camera Vulnerability Targeted in Remote Code Execution Exploitation Attempts
Scanning and remote code execution attempts targeting video surveillance devices in Ukraine rose between September 21 and October 1, 2026. Most activity focused on CVE-2021-36260,…
WorkNest Secure Achieves CREST STAR-FS Accreditation for Red Teaming
WorkNest Secure has achieved CREST Simulated Targeted Attack & Response for Financial Services (STAR-FS) accreditation, recognising its ability to deliver intelligence-led red teaming assessments for…
Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware
A threat actor published a malicious version of the tensorlake npm package on October 8, 2026, embedding a new variant of the self-replicating Shai-Hulud supply-chain…
Midnight Mimosa Malware Found Preinstalled on Low-Cost Android Phones
Bitdefender researchers uncover Midnight Mimosa malware preinstalled on low-cost MediaTek Android phones enabling ad fraud and proxyware activity. Cybersecurity researchers at Bitdefender have identified a…
YouTubers targeted with fake sponsorships and “channel verification” phishing
Scammers are going after YouTube creators’ Google accounts by posing as a brand looking for sponsorship partners. By sending out personalized emails that reference a…
Attackers hijack country-code domains to impersonate Google and other services
According to Google, attackers compromised infrastructure behind three country-code domain namespaces—.gh (Ghana), .sl (Sierra Leone), and .as (American Samoa)—and used it to obtain unauthorized HTTPS…