GitLab Vulnerabilities Allow Attackers to Execute Remote Code on Default GitLab Installations
A newly disclosed exploit chain in GitLab shows how two long-buried memory-safety flaws in a Ruby JSON parsing library, Oj, could be combined to achieve…
A newly disclosed exploit chain in GitLab shows how two long-buried memory-safety flaws in a Ruby JSON parsing library, Oj, could be combined to achieve…
According to Mandiant’s M-Trends 2025 report, when organizations discover a ransomware intrusion on their own (without being tipped off by law enforcement or, ironically, by the…
A sophisticated phishing campaign that disguises malware delivery inside routine business communications, ultimately deploying Phantom Stealer v3.5.0 to harvest browser credentials, cookies, payment data, and…
Ransomware activity followed a recognizable pattern during the previous four years. Each year was defined by a dominant actor, its collapse, or a major supply…
For years, phishing campaigns targeting financial institutions followed the same playbook. Victims were tricked into entering usernames and passwords, attackers collected the credentials, and accounts…
Australian energy provider Origin Energy disclosed a data breach impacting customer data Pierluigi Paganini July 25, 2026 Origin Energy confirmed a data breach after a…
AI is no longer experimental—it’s embedded. According to a recent survey of 96 organizations conducted by Wiz and Gatepoint Research, 87% of respondents’ teams are…
A massive malvertising campaign is using fake Solana, Luno, and TradingView webpages with malicious JavaScript that instructs browsers to assemble malware directly in memory. The…
We are doing security drills diligently for the wrong catastrophe. Here is what actually duck and cover for cyber threat looks like. By Dr. Arun Lakhotia…
Google Threat Intelligence Group (GTIG) has introduced a unified cryptonym-based naming system for cyber threat actors, aiming to simplify attribution, improve analyst workflows, and eliminate…
An employee gets an email dressed as a password reset. She clicks the link, types her credentials into a page built to copy her company’s…
Swati KhandelwalJul 25, 2026Vulnerability / Application Security Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba’s JSON library for…