Fake Shopify Invoices Steal User Credentials
Cybersecurity researchers have uncovered a new phishing campaign in which scammers abuse Shopify and its Shop order-tracking app to deliver fake invoices directly to users. Instead of relying on traditional [...]
Langflow RCE Vulnerability: Unauthenticated Code Execution Risk
A critical security vulnerability, CVE-2026-33017, has been discovered in Langflow, an open-source platform used to build AI workflows, large language model (LLM) applications, and Retrieval-Augmented Generation (RAG) pipelines. Researchers report [...]
ManageEngine AD360 Vulnerability Discovered
ManageEngine has released security updates to address a critical vulnerability, CVE-2026-11374, affecting its AD360 identity and access management platform. The flaw impacts several integrated products that rely on AD360 for [...]
Microsoft Teams-Themed Attack Deploys Remote Access Tool
Security researchers have uncovered an active phishing campaign that leverages Microsoft Teams-themed lures to distribute legitimate remote access software configured for unauthorized access. By impersonating trusted workplace collaboration services, threat [...]
Malware Hidden in Fake Android Reader App
Cybersecurity researchers have uncovered a new Android malware campaign that used a fake document reader application to distribute the Anatsa banking trojan. The app appeared to be a legitimate file-reading [...]