Blog
APT29 Ghost Login: Russian Spies Bypass MFA Using Google OAuth and WhatsApp — GTIG Reveals Three Active Espionage Clusters
Google GTIG exposes three Russian APT29-linked clusters (UNC6293, UNC7005, UNC5976) abusing OAuth device-code flows and WhatsApp device-linking to bypass MFA and target defence, diplomacy and academia.
Read More →CVE-2026-55040 + CVE-2026-63520 (CVSS 9.1): Attackers Now Forge SharePoint Admin Credentials — No Password Required
CVE-2026-55040 (CVSS 9.1) lets attackers forge SharePoint JWT tokens with no credentials. Chained with CVE-2026-63520, it enables unauthenticated RCE. CISA KEV-listed Aug 18, 2026.
Read More →The Gentlemen Ransomware: India in the Crosshairs as 500+ Victims Fall and FortiGate Backdoors Enable Global Strikes
The Gentlemen ransomware group has claimed 500+ victims across 66 countries, exploiting FortiGate CVE-2024-55591. Four Indian firms already hit — act now.
Read More →RUSTSEC-2026-0260: North Korean Hackers Poison arrayref Rust Crate With Build-Time Infostealer — 245 Million Downloads at Risk
DPRK-linked attackers poisoned the arrayref Rust crate with build-time malware hitting 245M downloads. Learn how the attack worked and how to secure your CI/CD pipeline.
Read More →CVE-2026-69836 (CVSS 10.0): Microsoft Entra ID’s Maximum-Severity Deserialization RCE Was Exploited Before You Knew It Existed
Microsoft Entra ID carries a CVSS 10.0 deserialization RCE (CVE-2026-69836) already exploited in the wild. Server-side patch applied—here's what your security team must verify now.
Read More →CVE-2026-19490 (CVSS 9.3): Critical Citrix NetScaler Auth Bypass Puts 22,000+ Gateway Appliances at Risk — Patch Before Exploitation Begins
CVE-2026-19490 (CVSS 9.3) is a critical authentication bypass in Citrix NetScaler ADC and Gateway — patch to builds 14.1-73.32 or 13.1-63.21 immediately before exploitation begins.
Read More →CVE-2026-68820 (CVSS 7.0): Lazarus Weaponises Windows afd.sys Zero-Day Against Indian Aerospace and Defence — CISA Patch Deadline Today
CVE-2026-68820: Lazarus Group's Windows afd.sys zero-day hit Indian aerospace and defence firms for 5 weeks. CISA KEV deadline is August 25 — patch now.
Read More →CVE-2025-62593 (CVSS 9.4): Ray AI Framework’s DNS Rebinding Flaw Turns GPU Clusters Into Crypto Mining Botnets — CISA Deadline Is Today
CVE-2025-62593 (CVSS 9.4) enables DNS rebinding RCE in Ray AI framework. ShadowRay 2.0 turns GPU clusters into crypto botnets. CISA patch deadline: August 20, 2026.
Read More →CVE-2026-33824 (CVSS 9.8): Windows IKEv2 Double-Free RCE Now Actively Exploited — CISA KEV Alert August 2026
CISA confirmed active exploitation of CVE-2026-33824 on August 18, 2026. This CVSS 9.8 Windows IKEv2 double-free flaw grants SYSTEM-level RCE via UDP 500/4500 — no credentials, no interaction. Patch now.
Read More →CVE-2026-8037 (CVSS 9.6): Progress LoadMaster Command Injection Exploited in the Wild — 792 Attacks, CISA KEV Listed
CVE-2026-8037 is a CVSS 9.6 unauthenticated command injection flaw in Progress Kemp LoadMaster. With 792 exploit attempts in 41 days and CISA KEV listed, patch to GA 7.2.63.2 or LTSF…
Read More →