The FBI has captured alleged Ploutus ATM malware developer Anibal Canelon Aguirre, a Tren de Aragua leader and the first cybercrime suspect on its Top 10 list.
FBI removed an Accenture contractor after a missed patch on a PeopleSoft-based HR portal was linked to a ShinyHunters breach exposing data on thousands of staff.
MALFEX, a long-running npm supply-chain malware campaign, has pushed eight malicious packages past 40k downloads, leaving several still live and unflagged.
FBI confirms multiple arrests tied to ShinyHunters' September breach of its FBIJobs portal, as suspects in Jordan and the Netherlands face investigation.
Researchers warn that the ClingSTUN Linux backdoor turns compromised devices into STUN-based proxies and exploits dozens of flaws for self-propagation.
Clover Health and Texas-based AngMar are notifying more than 250,000 patients after separate July cyberattacks exposed sensitive personal and medical data.
Citrix patched a NetScaler SAML zero-day, CVE-2026-88779, after denial-of-service attacks prompted CISA to add it to the KEV catalog and warn federal agencies.
Honeypot data shows quirky User-Agent strings now deliver XSS, ReDoS and RCE payloads, as attackers abuse HTTP headers to evade filters and hide in logs.