Booking.com Data Breach Exposes Customer Reservation Details, Raising Phishing Risk for Travellers
Booking.com has notified customers of a data breach that exposed names, addresses, email addresses, phone numbers, and full reservation details. While payment data was not compromised, security experts...
APT28 Deploys New PRISMEX Malware Suite Against Ukraine and NATO in Sophisticated Espionage Campaign
Russia's APT28 (Fancy Bear) has launched a new campaign deploying the previously undocumented PRISMEX malware framework, which uses steganography, COM hijacking, and legitimate cloud services for C2. Targets...
CISA Adds Apache ActiveMQ CVE-2026-34197 to KEV Catalog as Active Exploitation Surges
CISA has added CVE-2026-34197, a high-severity (CVSS 8.8) deserialization flaw in Apache ActiveMQ Classic, to its Known Exploited Vulnerabilities catalog after active exploitation was detected within 48 hours...
Microsoft April 2026 Patch Tuesday: Actively Exploited SharePoint Zero-Day Among 167 Fixes
Microsoft's April 2026 Patch Tuesday patches 167 vulnerabilities including an actively exploited SharePoint Server zero-day (CVE-2026-32201) and a publicly disclosed Windows Defender race condition (CVE-2026-33825). Security teams should...
Chime Faces Class Action Lawsuit Over April 2026 Data Breach: Complaint Claims It ‘Could Have Been Prevented’
A class action lawsuit filed against neobank Chime Financial alleges the company 'lost control' of customer payment and personal data in an April 2026 breach. Plaintiffs claim Chime...
CERT-UA Exposes APT Malware Campaign Targeting Eastern European Governments and Municipal Hospitals
Ukraine's CERT-UA has disclosed a sophisticated infostealer campaign targeting government bodies and municipal healthcare institutions across Eastern Europe. The malware harvests credentials from Chromium browsers and exfiltrates WhatsApp...
CVE-2026-39987: Marimo RCE Zero-Day Exploited Within 10 Hours of Disclosure — 662 Attacks Recorded
A critical unauthenticated RCE vulnerability in the Marimo Python notebook framework (CVE-2026-39987) was actively exploited just 10 hours after public disclosure. Sysdig recorded 662 exploit events over four...
BLACKWATER Ransomware Debuts with Devastating Strike on Major Turkish Hospital Network, Claims 3.3 TB Stolen
A newly emerged ransomware group called BLACKWATER has claimed its first major victim: Medical Park Hospitals Group in Turkey, with 36 hospitals affected and 3.3 terabytes of sensitive...