Data Breaches & Scandals

INTERPOL’s Operation Ramz just arrested 201 cybercriminals across 13 MENA countries in historic crackdown

INTERPOL's largest coordinated cybercrime operation in Middle East and North Africa nets 201 arrests across…

NGINX vulnerability CVE-2026-42945 exploited in the wild within days of disclosure — 9.2 severity score

Critical NGINX flaw with 9.2 severity score actively exploited days after disclosure. Millions of servers…

Microsoft’s Azure Backup quietly fixed a critical vulnerability in May 2026 — but rejected the researcher’s report and issued no CVE

Microsoft patched a critical Azure Backup vulnerability without a CVE or acknowledgment. The security researcher's…

More News

Bluekit phishing kit just added AI—now criminals can launch 40 targeted attacks in minutes

Criminals are weaponizing AI to automate phishing attacks. A new kit called Bluekit includes 40 templates and AI features to…

SAP npm packages just got hijacked by hackers calling themselves mini Shai-Hulud — stealing developer credentials at scale

Five security firms expose coordinated supply chain attack on SAP npm packages. Developers' credentials stolen via malware-laced code.

Critical GitHub flaw CVE-2026-3854 lets attackers execute code with single git push command

A critical GitHub vulnerability (CVE-2026-3854) allows authenticated users to execute remote code with a single git push command, threatening millions…

Checkmarx’s own GitHub repository just leaked on the dark web after March 23 supply chain attack

Security software maker Checkmarx confirms its own GitHub data was stolen and posted on the dark web following a March…