When the breach doesn’t happen, the real warning begins https://etimg.etb2bimg.com/thumb/msid-131169830,imgsize-6906,width-1200,height=627,overlay-etciso,resizemode-75/data-breaches/when-the-breach-doesnt-happen-the-real-warning-begins.jpg In cybersecurity, the incident that makes headlines is usually the one that succeeds. The ransomware spreads, the systems go down, the data leaks, and the postmortem begins. But some of the most important warnings arrive earlier, in quieter form. A phishing payload slips through but gets stopped on execution. A ...
Read More »Vulnerabilities & Exploits
Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign
Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign [og_img] A Chinese-speaking advanced persistent threat (APT) actor has been linked to a new custom backdoor called TinyRCT as part of cyber attacks aimed at government entities and critical infrastructure in Southeast Asia. The activity, particularly aimed at state-owned enterprises in the energy and government sectors, has been attributed to ...
Read More »India’s Tata Electronics hit by cyber breach claiming to expose Apple, Tesla trade secrets
India’s Tata Electronics hit by cyber breach claiming to expose Apple, Tesla trade secrets https://etimg.etb2bimg.com/thumb/msid-131924293,imgsize-236570,width-1200,height=627,overlay-etciso,resizemode-75/data-breaches/indias-tata-electronics-hit-by-cyber-breach-claiming-to-expose-apple-tesla-trade-secrets.jpg Tata Electronics said on Monday it had detected a recent “cybersecurity incident”, after researchers said World Leaks posted purported component design and specification papers of Apple and Tesla, both customers of the Indian group. The ransomware group has posted more than 200,000 files on the ...
Read More »FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation
FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation https://firewall.firm.in/wp-content/uploads/2026/06/fortigate.jpg A Russian-speaking initial access broker (IAB) driven by financial gain is assessed to be behind a large-scale credential-harvesting operation known as FortiBleed that has targeted over 430,000 FortiGate firewalls globally. The campaign, active since February 2026, involves collecting credential lists, searching for exposed services, brute-forcing accessible systems, and deploying bespoke ...
Read More »ServiceNow data breach: Software bug exposed customer data to internet access
ServiceNow data breach: Software bug exposed customer data to internet access https://etimg.etb2bimg.com/thumb/msid-131675065,imgsize-2031894,width-1200,height=627,overlay-etciso,resizemode-75/data-breaches/servicenow-data-breach-software-bug-exposed-customer-data-to-internet-access.jpg Cloud technology giant ServiceNow has notified some of its customers that a software bug on its platform was allowing anyone on the internet to access their data. According to a report in TechCrunch, a knowledge base article, which ServiceNow has hidden behind a login wall but has been ...
Read More »Agentjacking Attack Tricks AI Coding Agents Into Running Malicious Code
Agentjacking Attack Tricks AI Coding Agents Into Running Malicious Code Cybersecurity researchers have described what they say is a new class of attack that can trick artificial intelligence (AI) coding agents into running arbitrary code on developer machines. Called Agentjacking by Tenet Security, the attack can be triggered by means of a fake error report crafted using Sentry, an open-source ...
Read More »AI-related data breaches surging, Hackers are increasingly using AI to detect software vulnerabilities
AI-related data breaches surging Hackers are increasingly using AI to detect software vulnerabilities, which has shortened the time that targets have to respond to threats, Verizon said in an annual report tracking data breaches. Verizon said using software flaws in data surpassed stolen credentials for the first time. It said in a review of more than 31,000 incidents, 31% of ...
Read More »Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit
Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit https://firewall.firm.in/wp-content/uploads/2026/05/marimo.png Ravie LakshmananMay 29, 2026Vulnerability / Artificial Intelligence An unknown threat actor has been observed using a large language model (LLM) agent to conduct post-compromise actions after obtaining initial access following the exploitation of a publicly-accessible Marimo network using a recently disclosed vulnerability. “The attacker compromised an internet-reachable Marimo notebook ...
Read More »NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE
NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE https://firewall.firm.in/wp-content/uploads/2026/05/nginx.jpg Ravie LakshmananMay 17, 2026Server Security / Vulnerability A newly disclosed security flaw impacting NGINX Plus and NGINX Open has come under active exploitation in the wild, days after its public disclosure, according to VulnCheck. The vulnerability, tracked as CVE-2026-42945 (CVSS score: 9.2), is a heap buffer overflow ...
Read More »TCLBANKER Banking Trojan Targets Financial Platforms via WhatsApp and Outlook Worms
TCLBANKER Banking Trojan Targets Financial Platforms via WhatsApp and Outlook Worms https://firewall.firm.in/wp-content/uploads/2026/05/banking.jpg Threat hunters have flagged a previously undocumented Brazilian banking trojan dubbed TCLBANKER that’s capable of targeting 59 banking, fintech, and cryptocurrency platforms. The activity is being tracked by Elastic Security Labs under the moniker REF3076. The malware family is assessed to be a major update of the Maverick, ...
Read More »
Firewall Security Company India Complete Firewall Security Solutions Provider Company in India











