Posts of last few hours
Please support the site operations by clicking ads.
Organizations should patch all customer-managed NetScaler ADC and Gateway appliances immediately, investigate for pre-patch compromise, and restrict the appliances' access to sensitive internal systems.
The post Actively Exploited NetScaler Vulnerabilities appeared first on Sygnia.
Cloudflare is building a certificate authority to make post-quantum website authentication practical without burdening TLS connections with oversized signatures. The company plans to issue conventional certificates alongside Merkle Tree Certificates, or MTCs, and is targeting early 2027 for admission to Chrome’s new Quantum-resistant Root Store; standard MTC issuance will be free. The initiative addresses a […]
The post Cloudflare Builds Post-Quantum CA With Merkle Tree Certificates for Faster Quantum-Safe TLS appeared first on Cyber Security News.
Google released a Chrome Stable update fixing 32 security vulnerabilities across Windows, macOS, and Linux, including one critical and multiple high-severity flaws in V8, ANGLE, GPU, WebGPU, Bluetooth, Passwords, and UI components. Chrome version 154.0.8037.92/.93 is being rolled out to Windows and Mac users, while Linux users will receive version 154.0.8037.92. Google said it will […]
The post Google Releases Chrome Update With 32 Security Fixes for Windows, Mac and Linux appeared first on Cyber Security News.
Google has warned that threat actors are actively exploiting two critical Citrix NetScaler zero-day vulnerabilities to gain root access, install stealthy web shells, and move into victim networks. The activity has affected organizations in North America and Europe, including government, financial services, technology, education, legal, and professional-services sectors. Mandiant Consulting and Google Threat Intelligence Group […]
The post Google Warns of Hackers Actively Exploiting Citrix 0-Day Vulnerabilities to Deploy Web Shells appeared first on Cyber Security News.
Russian state-linked hackers have expanded a phishing operation that uses a new RedFlick delivery chain to reach more than 100 organizations. The campaign replaces an obvious malicious attachment with a conversation that looks like ordinary professional correspondence. The activity was recorded in at least 13 campaigns from January through August 2026, chiefly affecting organizations in […]
The post Russian Hackers Target 100+ Organizations With New RedFlick Phishing Attack appeared first on Cyber Security News.
Investigating a phishing alert often means working through several layers of activity before an analyst can confidently close or escalate the case. Modern campaigns can hide malicious activity behind encrypted traffic, CAPTCHA challenges, redirects, browser scripts, and token-based authentication, leaving analysts to reconstruct the attack before they can determine what happened. The investigation does not […]
The post Phishing Response: 3 Steps SOC Teams Can Take to Investigate Threats Faster appeared first on Cyber Security News.
PaperPhone is a large headless-browser network built to make automated web requests look like ordinary mobile traffic. It does not rely on a single obvious source. Instead, it spreads activity across thousands of addresses while repeatedly presenting fabricated phone and browser identities. The operation exposes weaknesses in simple IP-based defenses. Websites facing this traffic may […]
The post PaperPhone Headless Browser Network Uses 75,000 IPs and Fabricated Mobile Identities Across 43 Countries appeared first on Cyber Security News.
Latest Blog Posts
- 8 hours 6 minutes ago
- 8 hours 6 minutes ago
- 8 hours 7 minutes ago
- 8 hours 7 minutes ago
- 8 hours 7 minutes ago
- 8 hours 7 minutes ago
- 8 hours 7 minutes ago
- 8 hours 7 minutes ago
- 8 hours 7 minutes ago
- 8 hours 7 minutes ago