Latest news

Payload Ransomware Group Hits Egyptian Oil Giant WASCO in Double-Extortion Attack
Ransomware

Payload Ransomware Group Hits Egyptian Oil Giant WASCO in Double-Extortion Attack

11 April 2026 dark6

The Payload ransomware group has claimed a cyberattack against El Wastani Petroleum Company (WASCO), a major Egyptian oil and gas...
CVE-2026-39987: Critical Marimo Python Notebook RCE Exploited Within 10 Hours of Disclosure
Vulnerability

CVE-2026-39987: Critical Marimo Python Notebook RCE Exploited Within 10 Hours of Disclosure

11 April 2026 dark6

A pre-authentication remote code execution flaw (CVSS 9.3) in the Marimo Python notebook framework was weaponized by attackers within just...
Adobe Breach: Threat Actor Claims 13 Million Support Tickets Stolen via BPO Hack — HackerOne Data at Risk
Databreach

Adobe Breach: Threat Actor Claims 13 Million Support Tickets Stolen via BPO Hack — HackerOne Data at Risk

11 April 2026 dark6

A threat actor known as "Mr. Raccoon" claims to have exfiltrated 13 million Adobe customer support tickets, 15,000 employee records,...
Smart Slider 3 Pro Plugin Backdoored via Supply Chain Attack — 800,000+ Sites at Risk
Malware

Smart Slider 3 Pro Plugin Backdoored via Supply Chain Attack — 800,000+ Sites at Risk

11 April 2026 dark6

Threat actors compromised the update infrastructure of Nextend, the vendor behind Smart Slider 3 Pro, and pushed a fully backdoored...
Stryker Corporation Discloses Material Cybersecurity Incident Disrupting Global Manufacturing Operations
Databreach

Stryker Corporation Discloses Material Cybersecurity Incident Disrupting Global Manufacturing Operations

10 April 2026 dark6

Stryker Corporation has disclosed a material cybersecurity incident that disrupted its global manufacturing, commercial, ordering, and distribution systems in March...
LockBit 5.0 Ransomware-as-a-Service Platform Claims 207 Victims After Criminal Relaunch
Ransomware

LockBit 5.0 Ransomware-as-a-Service Platform Claims 207 Victims After Criminal Relaunch

10 April 2026 dark6

LockBit has relaunched with a new LockBit 5.0 Ransomware-as-a-Service platform, already claiming 207 victims across manufacturing, healthcare, government, and construction...
Windows Zero-Day “BlueHammer” Exploit Code Released — SYSTEM Privileges at Risk
Vulnerability

Windows Zero-Day “BlueHammer” Exploit Code Released — SYSTEM Privileges at Risk

10 April 2026 dark6

Exploit code has been publicly released for BlueHammer, a Windows zero-day privilege escalation vulnerability that allows attackers to gain full...
Critical Fortinet FortiClient EMS Zero-Day CVE-2026-35616 Actively Exploited — Patch Now
Vulnerability

Critical Fortinet FortiClient EMS Zero-Day CVE-2026-35616 Actively Exploited — Patch Now

10 April 2026 dark6

A critical zero-day in Fortinet FortiClient EMS (CVE-2026-35616, CVSS 9.8) is being actively exploited in the wild. CISA has added...
CVSS 10.0: Critical Flowise AI Vulnerability Is Being Actively Exploited — 15,000+ Instances Still Exposed
AI

CVSS 10.0: Critical Flowise AI Vulnerability Is Being Actively Exploited — 15,000+ Instances Still Exposed

9 April 2026 dark6

A maximum-severity RCE vulnerability (CVE-2025-59528, CVSS 10.0) in the popular Flowise AI agent builder is under active attack. Over 15,000...
Chrome’s Fourth Zero-Day of 2026: CISA Orders Federal Agencies to Patch CVE-2026-5281 by April 15
Vulnerability

Chrome’s Fourth Zero-Day of 2026: CISA Orders Federal Agencies to Patch CVE-2026-5281 by April 15

9 April 2026 dark6

Google has patched CVE-2026-5281, a use-after-free zero-day in Chrome’s WebGPU engine already exploited in the wild. It’s the fourth Chrome...
Unpatched Adobe Reader Zero-Day Has Been Silently Exploiting Users Since December
Vulnerability

Unpatched Adobe Reader Zero-Day Has Been Silently Exploiting Users Since December

9 April 2026 dark6

A highly sophisticated zero-day exploit targeting Adobe Reader has been active since December 2025, requiring just a single click to...
APT28’s FrostArmada: How Russian Hackers Built an 18,000-Router Army to Steal Microsoft 365 Credentials
Cybercrime

APT28’s FrostArmada: How Russian Hackers Built an 18,000-Router Army to Steal Microsoft 365 Credentials

9 April 2026 dark6

Russia’s APT28 compromised over 18,000 routers across 120 countries to silently hijack DNS and steal Microsoft 365 credentials from government...