Cyber Attack
U.S. Offers $10 Million Reward for Chinese Hacker Behind Alleged COVID-19 Research Cyberattacks
The U.S. Department of State is offering a reward of up to $10 million for information regarding Zhang Yu, a Chinese national accused of...
Cyber Security News
12 Best SAST Tools Compared (2026): Features & Pricing
GitHub CodeQL is the bundled baseline for GitHub estates, Snyk Code and SonarQube lead the developer-first lane, and Checkmarx/Veracode/Fortify anchor enterprise assessment.
Twelve options priced...
cyber security
Critical Citrix NetScaler CVE-2026-88771 Exploited for Reverse Shells and Persistent Access
Attackers are exploiting CVE-2026-88771, a critical pre-authentication command-injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway, to deploy reverse shells, create privileged accounts, and...
cyber security
Hackers Abuse GitHub Actions to Steal SSH Keys, Cloud Credentials and Access Tokens
Hackers are abusing GitHub Actions to steal SSH keys, cloud credentials, and access tokens through malicious workflows disguised as security checks.
The workflows targeted...
cyber security
PoeLLM Malware Hijacks 3,400+ Servers for Crypto Mining and Botnet Expansion
A cryptocurrency mining campaign dubbed PoeLLM has compromised more than 3,400 servers by targeting exposed AI infrastructure and other internet-facing applications.
Active since April 2026,...
cyber security
Malicious npm Packages Steal Browser Passwords, Discord Tokens and Crypto Wallets.
MALFEX, a persistent npm supply-chain campaign distributing Windows malware through eight malicious packages.
Linked to an apparent single operator active since August 2023, the...
cyber security
EY Data Breach Exposes Goldman Sachs and Man Group Clients’ Tax and Financial Data
Ernst & Young (EY) has warned that a data breach exposed personal and financial information belonging to clients of Goldman Sachs’ wealth management division...
CVE/vulnerability
Critical Progress DataDirect GenAI Flaw Lets Attackers Execute Arbitrary OS Commands
Progress has disclosed a critical command injection vulnerability in the Early Access Release of its DataDirect Autonomous REST Connector AI Model Generator agents.
This...