Latest Cybersecurity News and Articles


Cisco Warns of More Catalyst SD-WAN Flaws Exploited in the Wild

05 March 2026
The networking giant has added the recently patched CVE-2026-20128 and CVE-2026-20122 to the list of exploited vulnerabilities. The post Cisco Warns of More Catalyst SD-WAN Flaws Exploited in the Wild appeared first on SecurityWeek.

Dust Specter Targets Iraqi Officials with New SPLITDROP and GHOSTFORM Malware

05 March 2026
A suspected Iran-nexus threat actor has been attributed to a campaign targeting government officials in Iraq by impersonating the country's Ministry of Foreign Affairs to deliver a set of never-before-seen malware. Zscaler ThreatLabz, which observed the activity in January 2026, is tracking the cluster under the name Dust Specter. The attacks, which manifest in the form of two different

Reclaim Security Raises $20 Million to Accelerate Remediation

05 March 2026
The company will expand its engineering team, deepen integrations, and accelerate go-to-market initiatives. The post Reclaim Security Raises $20 Million to Accelerate Remediation appeared first on SecurityWeek.

Where Multi-Factor Authentication Stops and Credential Abuse Starts

05 March 2026
Organizations typically roll out multi-factor authentication (MFA) and assume stolen passwords are no longer enough to access systems. In Windows environments, that assumption is often wrong. Attackers still compromise networks every day using valid credentials. The issue is not MFA itself, but coverage.  Enforced through an identity provider (IdP) such as Microsoft Entra ID, Okta, or

LeakBase Cybercrime Forum Shut Down, Suspects Arrested

05 March 2026
The stolen credential marketplace had been active since 2021 and in late 2025 it counted 142,000 users.  The post LeakBase Cybercrime Forum Shut Down, Suspects Arrested appeared first on SecurityWeek.

APT28-Linked Campaign Deploys BadPaw Loader and MeowMeow Backdoor in Ukraine

05 March 2026
Cybersecurity researchers have disclosed details of a new Russian cyber campaign that has targeted Ukrainian entities with two previously undocumented malware families named BadPaw and MeowMeow. "The attack chain initiates with a phishing email containing a link to a ZIP archive. Once extracted, an initial HTA file displays a lure document written in Ukrainian concerning border crossing appeals

Cisco Patches Critical Vulnerabilities in Enterprise Networking Products

05 March 2026
Cisco has rolled out patches for 48 vulnerabilities in Firewall ASA, Secure FMC, and Secure FTD products. The post Cisco Patches Critical Vulnerabilities in Enterprise Networking Products appeared first on SecurityWeek.

Europol-Led Operation Takes Down Tycoon 2FA Phishing-as-a-Service Linked to 64,000 Attacks

05 March 2026
Tycoon 2FA, one of the prominent phishing-as-a-service (PhaaS) toolkits that allowed cybercriminals to stage adversary-in-the-middle (AitM) credential harvesting attacks at scale, was dismantled by a coalition of law enforcement agencies and security companies. The subscription-based phishing kit, which first emerged in August 2023, was described by Europol as one of the largest phishing

FBI and Europol Seize LeakBase Forum Used to Trade Stolen Credentials

05 March 2026
A joint law enforcement operation has dismantled LeakBase, one of the world's largest online forums for cybercriminals to buy and sell stolen data and cybercrime tools. The LeakBase forum, per the U.S. Department of Justice (DoJ), had over 142,000 members and more than 215,000 messages between members as of December 2025. Those attempting to access the forum's website ("leakbase[.]la") are now

Nation-State iOS Exploit Kit ‘Coruna’ Found Powering Global Attacks

04 March 2026
Google and iVerify analysis reveals a powerful exploit kit originally used by Russian state actors that is now appearing in broader criminal campaigns. The post Nation-State iOS Exploit Kit ‘Coruna’ Found Powering Global Attacks appeared first on SecurityWeek.

Tycoon 2FA Phishing Platform Dismantled in Global Takedown

04 March 2026
The phishing-as-a-service platform was used to send fraudulent emails to over 500,000 organizations every month. The post Tycoon 2FA Phishing Platform Dismantled in Global Takedown appeared first on SecurityWeek.

New LexisNexis Data Breach Confirmed After Hackers Leak Files

04 March 2026
The hackers claim to have stolen 2GB of files, including 400,000 personal information records.  The post New LexisNexis Data Breach Confirmed After Hackers Leak Files appeared first on SecurityWeek.

149 Hacktivist DDoS Attacks Hit 110 Organizations in 16 Countries After Middle East Conflict

04 March 2026
Cybersecurity researchers have warned of a surge in retaliatory hacktivist activity following the U.S.-Israel coordinated military campaign against Iran, codenamed Epic Fury and Roaring Lion. "The hacktivist threat in the Middle East is highly lopsided, with two groups, Keymous+ and DieNet, driving nearly 70% of all attack activity between February 28 and March 2," Radware said in a Tuesday

Iran Conflict and Cybersecurity: What to Expect in the Next 30 Days

04 March 2026
What to expect as the conflict between the United States and Iran unfolds. 

Zurich Acquires Beazley in $11 Billion Deal to Lead Cyberinsurance

04 March 2026
The deal awaits final shareholder and regulatory approvals and is expected to be completed in the second half of 2026. The post Zurich Acquires Beazley in $11 Billion Deal to Lead Cyberinsurance appeared first on SecurityWeek.

Hacker Conversations: Inti De Ceukelaire, Raging Against the Machine Creatively

04 March 2026
A Belgian national, De Ceukelaire’ did not set out to be a hacker. Like many hackers he was born with the potential to become one and only gradually realized he is one. The post Hacker Conversations: Inti De Ceukelaire, Raging Against the Machine Creatively appeared first on SecurityWeek.

Examining North Korea’s Cybercrime Economy

04 March 2026
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Mar. 4, 2026 – Read the full story in Finextra It is estimated that one third to a half of North Korea’s budget comes from cyberfraud and extortion. Finextra reports that most of these The post Examining North Korea’s Cybercrime Economy appeared first on Cybercrime Magazine.

Coruna iOS Exploit Kit Uses 23 Exploits Across Five Chains Targeting iOS 13–17.2.1

04 March 2026
Google said it identified a "new and powerful" exploit kit dubbed Coruna (aka CryptoWaters) targeting Apple iPhone models running iOS versions between 13.0 and 17.2.1. The exploit kit featured five full iOS exploit chains and a total of 23 exploits, Google Threat Intelligence Group (GTIG) said. It's not effective against the latest version of iOS. The findings were first reported by WIRED. "The

How Pirated Software Turns Helpful Employees Into Malware Delivery Agents

04 March 2026
Employees seeking free versions of paid software may unknowingly install malware-laced “cracked” apps that can steal credentials, deploy cryptominers, or open the door to ransomware. The post How Pirated Software Turns Helpful Employees Into Malware Delivery Agents appeared first on SecurityWeek.

AI Security Firm JetStream Launches With $34 Million in Seed Funding

04 March 2026
The startup aims to provide organizations with visibility into how AI operates across their environment. The post AI Security Firm JetStream Launches With $34 Million in Seed Funding appeared first on SecurityWeek.