Berlin Refuses to Pay Hackers After Government Network Attack

Berlin Tells Cyber Extortionists: “We’re Not Paying!” Berlin’s state government has confirmed it is facing an extortion attempt following the compromise of its administrative network, and officials have made one part of their response very clear. They’re not paying. Investigators discovered additional data had been removed from systems belonging to Berlin’s Senate Department for Mobility, […]

Read More

Five Critical WordPress Flaws Put Websites at Risk

Five WordPress Security Problems You Don’t Want to Ignore Everyone and their dog has created a website using WordPress (even us!), but that doesn’t mean its inheritently secure. WordPress administrators have been handed another compelling reason to check the updates page. Security researchers have disclosed five critical WordPress vulnerabilities affecting WPMU DEV Dashboard, Avada, TranslatePress, […]

Read More

Fire Ant Hijacks Cisco Routers and Hides the Evidence

Fire Ant Moves Into the Network’s Best Seat Fire ant, a China-linked cyber espionage operation, not the insects have been targeting some of the most trusted equipment inside corporate networks, including Cisco routers and authentication servers. And controlling the router is rather more useful to an attacker than compromising another laptop. Investigators from Sygnia discovered […]

Read More

Russian Threat Group ‘UAC-0099’ Uses Malware to Trick AI Security Tools

Hackers Are Now Trying to Scare the AI Cyber attackers have found another unusual way to hide malware: convincing the artificial intelligence analysing it that it would rather not look. Russia-aligned threat group UAC-0099 has been observed using a technique researchers have named GuardBreaker. Instead of simply attempting to hide malicious code through encryption or […]

Read More

Check Point VPN Flaw Exploited

Check Point VPN Flaw: Passwords Optional, Apparently Check Point warned that CVE-2026-50751, a critical flaw affecting Remote Access VPN and Mobile Access deployments using deprecated IKEv1, is being actively exploited. The logic flaw in certificate validation allows unauthenticated attackers to bypass password requirements and establish VPN sessions under specific configurations. Exploitation requires remote access or […]

Read More

One-Character Linux Kernel Flaw

Linux Kernel Bug: One Character, Root Access, Big Headache Researchers published working exploit details for CVE-2026-23111, a Linux kernel use-after-free in nf_tables that can let an unprivileged local user escalate to root and escape containers. The flaw was patched upstream in February 2026 and resulted from a one-character logic error. Exploits have been demonstrated across […]

Read More

LiteLLM Exploited

LiteLLM Flaw Turns AI Gateway Into an Attack Gateway CISA added LiteLLM CVE-2026-42271 to its Known Exploited Vulnerabilities catalogue after evidence of active exploitation. The flaw is a command injection vulnerability affecting LiteLLM versions 1.74.2 through before 1.83.7, allowing authenticated users to execute arbitrary commands on the host. Researchers also showed it could be chained […]

Read More

Chrome V8 Zero-Day

Chrome Zero-Day: Update Before Your Browser Gets Ideas Google released Chrome security updates fixing 74 vulnerabilities, including CVE-2026-11645, a high-severity V8 zero-day exploited in the wild. The issue is an out-of-bounds memory access flaw in Chrome’s JavaScript and WebAssembly engine that could allow remote code execution inside the browser sandbox via a crafted HTML page. […]

Read More

Veeam Backup & Replication RCE

Veeam RCE: Because Attackers Love Backups Too Veeam patched a critical remote code execution vulnerability in Backup & Replication, tracked as CVE-2026-44963 with a CVSS score of 9.4. The flaw allows an authenticated domain user to execute remote code on the backup server. It affects Veeam Backup & Replication 12.3.2.4465 and earlier version 12 builds, […]

Read More