CISA Warning: Iranian-Affiliated Hackers Targeting US Critical Infrastructure PLCs to Cause Disruption
CISA has issued an urgent advisory (AA26-097A) warning that Iranian-affiliated APT actors have been actively targeting internet-exposed Programmable Logic Controllers across U.S. critical infrastructure since at least March...
Russia’s APT28 Deploys New PRISMEX Malware in Espionage Campaign Targeting Ukraine and NATO Allies
Russia-linked APT28 (Fancy Bear) has launched a new spear-phishing espionage campaign deploying PRISMEX, a previously undocumented malware suite combining steganography, COM hijacking, and cloud-based C2 infrastructure. Targets span...
APT Iran Claims 375TB Breach of Lockheed Martin — F-35 Blueprints and Source Code Allegedly Stolen
Pro-Iranian hacktivist group APT Iran claims to have stolen 375 terabytes of data from Lockheed Martin, including alleged F-35 blueprints and internal source code. The group is demanding...
Google Patches Actively Exploited Chrome Zero-Day CVE-2026-5281 — Update Now
Google has confirmed that CVE-2026-5281, a high-severity use-after-free vulnerability in Chrome's Dawn WebGPU implementation, is being actively exploited in the wild. CISA has added the flaw to its...
Payload Ransomware Group Hits Egyptian Oil Giant WASCO in Double-Extortion Attack
The Payload ransomware group has claimed a cyberattack against El Wastani Petroleum Company (WASCO), a major Egyptian oil and gas operator, using a double-extortion model that threatens to...
CVE-2026-39987: Critical Marimo Python Notebook RCE Exploited Within 10 Hours of Disclosure
A pre-authentication remote code execution flaw (CVSS 9.3) in the Marimo Python notebook framework was weaponized by attackers within just 10 hours of public disclosure. The vulnerability allows...
Adobe Breach: Threat Actor Claims 13 Million Support Tickets Stolen via BPO Hack — HackerOne Data at Risk
A threat actor known as "Mr. Raccoon" claims to have exfiltrated 13 million Adobe customer support tickets, 15,000 employee records, and unpublished HackerOne vulnerability reports through a compromised...
Smart Slider 3 Pro Plugin Backdoored via Supply Chain Attack — 800,000+ Sites at Risk
Threat actors compromised the update infrastructure of Nextend, the vendor behind Smart Slider 3 Pro, and pushed a fully backdoored plugin version to hundreds of thousands of WordPress...