Payload Ransomware Group Hits Egyptian Oil Giant WASCO in Double-Extortion Attack
The Payload ransomware group has claimed a cyberattack against El Wastani Petroleum Company (WASCO), a major Egyptian oil and gas operator, using a double-extortion model that threatens to...
CVE-2026-39987: Critical Marimo Python Notebook RCE Exploited Within 10 Hours of Disclosure
A pre-authentication remote code execution flaw (CVSS 9.3) in the Marimo Python notebook framework was weaponized by attackers within just 10 hours of public disclosure. The vulnerability allows...
Adobe Breach: Threat Actor Claims 13 Million Support Tickets Stolen via BPO Hack — HackerOne Data at Risk
A threat actor known as "Mr. Raccoon" claims to have exfiltrated 13 million Adobe customer support tickets, 15,000 employee records, and unpublished HackerOne vulnerability reports through a compromised...
Smart Slider 3 Pro Plugin Backdoored via Supply Chain Attack — 800,000+ Sites at Risk
Threat actors compromised the update infrastructure of Nextend, the vendor behind Smart Slider 3 Pro, and pushed a fully backdoored plugin version to hundreds of thousands of WordPress...
Stryker Corporation Discloses Material Cybersecurity Incident Disrupting Global Manufacturing Operations
Stryker Corporation has disclosed a material cybersecurity incident that disrupted its global manufacturing, commercial, ordering, and distribution systems in March 2026. The medical device giant filed an amended...
LockBit 5.0 Ransomware-as-a-Service Platform Claims 207 Victims After Criminal Relaunch
LockBit has relaunched with a new LockBit 5.0 Ransomware-as-a-Service platform, already claiming 207 victims across manufacturing, healthcare, government, and construction sectors. The upgrade demonstrates the resilience of RaaS...
Windows Zero-Day “BlueHammer” Exploit Code Released — SYSTEM Privileges at Risk
Exploit code has been publicly released for BlueHammer, a Windows zero-day privilege escalation vulnerability that allows attackers to gain full SYSTEM or administrator access. The availability of working...
Critical Fortinet FortiClient EMS Zero-Day CVE-2026-35616 Actively Exploited — Patch Now
A critical zero-day in Fortinet FortiClient EMS (CVE-2026-35616, CVSS 9.8) is being actively exploited in the wild. CISA has added it to its Known Exploited Vulnerabilities catalog, mandating...