PoisonedRefresh rootkit injects PHP web shells into F5 BIG-IP APM Apache memory, leaving no disk artifacts. SophosLabs published a detailed technical analysi...
An Ohio man was sentenced to 15 years in prison for multiple cybercrimes, including sextortion and cyberstalking of numerous victims using AI-generated sexua...
CRPx0 is a cybercrime operation that started off operating a scam before pivoting into a fully-blown ransomware and cryptocurrency business. Read more in my ...
A newly published proof-of-concept (PoC) called ShieldCrash reveals an unpatched vulnerability in Microsoft Defender that allows a local attacker to gain arb...
cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related priv...
Best value overall: Bitdefender — competent managed XDR at pricing that mid-market organizations can approve, which most of this list cannot claim. Best dete...
Best value overall: Huntress — published pricing, purpose-built for small business, and genuinely good at the threats that segment faces. Best response autho...
Google has fixed 230 vulnerabilities in Chrome, including a zero-day flaw, CVE-2026-87491, with an in-the-wild exploit. “Google is aware that an exploit for ...
The researcher Chaotic Eclipse released ShieldCrash, a PoC exploit for a Microsoft Defender Zero-Day vulnerability. Security researcher Chaotic Eclipse, also...
Best value overall: Microsoft Defender XDR — included in Microsoft 365 E5 and genuinely strong across Microsoft’s own surface, which for most organizations i...
Best value overall: Microsoft Defender for Endpoint P2 — included in Microsoft 365 E5 and genuinely competitive, which makes its marginal cost zero for a lar...
Best value overall: Bitdefender — leading detection at mid-range pricing with a light footprint. Best free option: Malwarebytes’ scanner, which cleans an inf...
Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an ana...
An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldCrash" right after Microsoft ...
cPanel has disclosed CVE-2026-67401, a SQL injection vulnerability in its EmailTrack functionality. This flaw allows an authenticated account holder to creat...
Fortinet has disclosed a critical vulnerability involving improper access control in the FortiSandbox web interfaces. This issue could allow an unauthenticat...
Information-stealing malware is expanding its collection logic to target locally stored data from AI coding agents, including Claude, Cursor, Codex, Cline, C...
September 2026 Patch Tuesday fixes a record 974 CVEs including 2 exploited zero-days, 20 wormable bugs, and a critical Exchange RCE via Visio email. Microsof...