Over 60 Software Vendors Issue Security Fixes Across OS, Cloud, and Network Platforms

It’s Patch Tuesday, which means a number of software vendors have released patches for various security vulnerabilities impacting their products and services.
Microsoft issued fixes for 59 flaws, including six actively exploited zero-days in various Wi… Continue reading Over 60 Software Vendors Issue Security Fixes Across OS, Cloud, and Network Platforms

Posted in Uncategorized

Exposed Training Open the Door for Crypto-Mining in Fortune 500 Cloud Environments

Intentionally vulnerable training applications are widely used for security education, internal testing, and product demonstrations. Tools such as OWASP Juice Shop, DVWA, Hackazon, and bWAPP are designed to be insecure by default, making them useful fo… Continue reading Exposed Training Open the Door for Crypto-Mining in Fortune 500 Cloud Environments

Posted in Uncategorized

Microsoft Patches 59 Vulnerabilities Including Six Actively Exploited Zero-Days

Microsoft on Tuesday released security updates to address a set of 59 flaws across its software, including six vulnerabilities that it said have been exploited in the wild.
Of the 59 flaws, five are rated Critical, 52 are rated Important, and two are r… Continue reading Microsoft Patches 59 Vulnerabilities Including Six Actively Exploited Zero-Days

Posted in Uncategorized

SSHStalker Botnet Uses IRC C2 to Control Linux Systems via Legacy Kernel Exploits

Cybersecurity researchers have disclosed details of a new botnet operation called SSHStalker that relies on the Internet Relay Chat (IRC) communication protocol for command-and-control (C2) purposes.
“The toolset blends stealth helpers with legacy-era … Continue reading SSHStalker Botnet Uses IRC C2 to Control Linux Systems via Legacy Kernel Exploits

Posted in Uncategorized

North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations

The North Korea-linked threat actor known as UNC1069 has been observed targeting the cryptocurrency sector to steal sensitive data from Windows and macOS systems with the ultimate goal of facilitating financial theft.
“The intrusion relied on a social … Continue reading North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations

Posted in Uncategorized

DPRK Operatives Impersonate Professionals on LinkedIn to Infiltrate Companies

The information technology (IT) workers associated with the Democratic People’s Republic of Korea (DPRK) are now applying to remote positions using real LinkedIn accounts of individuals they’re impersonating, marking a new escalation of the fraudulent … Continue reading DPRK Operatives Impersonate Professionals on LinkedIn to Infiltrate Companies

Posted in Uncategorized

ZAST.AI Raises $6M Pre-A to Scale “Zero False Positive” AI-Powered Code Security

January 5, 2026, Seattle, USA — ZAST.AI announced the completion of a $6 million Pre-A funding round. This investment came from the well-known investment firm Hillhouse Capital, bringing ZAST.AI’s total funding close to $10 million. This marks a recogn… Continue reading ZAST.AI Raises $6M Pre-A to Scale “Zero False Positive” AI-Powered Code Security

Posted in Uncategorized

Warlock Ransomware Breaches SmarterTools Through Unpatched SmarterMail Server

SmarterTools confirmed last week that the Warlock (aka Storm-2603) ransomware gang breached its network by exploiting an unpatched SmarterMail instance.
The incident took place on January 29, 2026, when a mail server that was not updated to the latest … Continue reading Warlock Ransomware Breaches SmarterTools Through Unpatched SmarterMail Server

Posted in Uncategorized