‘The Internet is falling down’: Critical cPanel CRLF injection vulnerability puts tens of millions of websites at risk of total compromise – hosting providers urged to apply CVE-2026-41940 patch immediately

A new critical severity vulnerability can give attackers full control over WHM servers, allowing them to steal data, upload malware, and delete websites.

Researchers discover new all-in-one ‘Bluekit’ phishing kit capable of bypassing enterprise 2FA protocols and emulating 40+ global brands

Bluekit centralizes and automates entire phishing campaigns, and is capable of stealing sessions, avoiding detection, and spoofing locations.

Dental practice software maker fixes bug that exposed patients’ medical records

The security bug is now fixed, but the patient who found it said it was challenging to alert the software company about the issue.

Jan Lane illuminates the cybersecurity illusion leaders can no longer afford
Jan Lane illuminates the cybersecurity illusion leaders can no longer afford

Summary: AI-driven threats are accelerating as security stacks grow louder. Jan Lane argues that leadership clarity, AI integration, workforce awareness and diligence now determine cyber resilience. Rising cybersecurity budgets suggest preparedness, ye…

Exposed Data Illustrates the Nightmare Scenario for a Stalkerware Victim

Extremely sensitive personal data from a European celebrity that appears to have been compiled using spyware was publicly accessible until a researcher flagged the exposure.

‘This campaign works because it feels ordinary’: Experts reveal how hackers use fake DHL messages to lure in victims

Forcepoint uncovers new phishing campaign using DHL assets, and even found where the passwords are being sent to.