This week's cybersecurity landscape is marked by a series of critical threats and vulnerabilities. Progress has urged ShareFile customers to shut down…
An unknown threat actor is exploiting CVE-2026-48558, a critical authentication bypass vulnerability in SimpleHelp (CVSS 10.0), to deliver two new malware families:…
AI Securityauthentication bypassBlackpoint CyberCISA
A heavily obfuscated Node.js loader delivered as jquery.js, executed via node.exe. It establishes encrypted communications with a remote server and retrieves additional…
Microsoft has issued a warning about an active phishing campaign targeting hotels and hospitality organizations across Europe and Asia since April 2026.…
Cybersecurity researchers have identified multiple ClickFix campaigns deploying three new malware loaders: BabaDeda Loader, Lorem Ipsum Loader, and Potemkin. These campaigns use…
Cybersecurity researchers at JFrog have uncovered a set of malicious npm packages that masquerade as legitimate PostCSS tools to deliver a Windows-based…