Knowledge Base

Security Resources

Real-time industry news and expert insights to help you stay ahead of emerging threats.

23 articles • Page 1 of 3
Ethical HackingThe Hacker News

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

Updated July 18, 2026: the two flaws now carry CVE IDs, the full mechanism has been published, a persistent-object-cache condition has surfaced, and a working proof-of-concept is public. The story...

2d ago
Read more
CISO in a BoxSchneier on Security

Friday Squid Blogging: Squid Washing Up on Cape Cod Beach

Lots of articles about this. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.

2d ago
Read more
Ethical HackingThe Hacker News

OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests

Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts....

2d ago
Read more
Ethical HackingDark Reading

Inc Ransomware Exploits SonicWall SMA Zero-Days

When chained together, the two vulnerabilities allow threat actors to gain root-level capabilities on SonicWall's mobile access appliances.

2d ago
Read more
DevSecOpsThe Hacker News

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT

Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack. The malicious package...

2d ago
Read more
DevSecOpsThe Hacker News

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens

A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator's own dashboard claims 3,811 unique AWS keys. A Shodan harvester keeps the scan queue stocked with...

2d ago
Read more
CISO in a BoxDark Reading

The Real AI Threat Is Blind Trust

AI models left to both interpret and execute commands eliminate critical cybersecurity oversight.

2d ago
Read more
Ethical HackingThe Hacker News

GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft

Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster dubbed CylindricalCanine. Expel, which shared technical details of the event,...

2d ago
Read more
Ethical HackingThe Hacker News

Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images

North Korean threat actors linked to the Contagious Interview campaign have been observed employing steganography in SVG image files to conceal malicious payloads as part of a campaign using fake job...

2d ago
Read more

Showing 1-9 of 23 articles

Stay Updated

Subscribe to our newsletter for the latest cybersecurity insights, threat alerts, and practical security tips delivered to your inbox.

No spam. Unsubscribe anytime. Unsubscribe here

Need Professional Security Help?

Our team is ready to help you implement the security best practices discussed in these resources.

Lisa

Security Assistant

10 left

Hi! I'm Lisa, your security assistant from LockedCyber. I'm here to help you with:


  • Security questions - From basic concepts to POPIA compliance
  • Service guidance - Finding the right security solution for your needs
  • Best practices - Practical tips to improve your security posture

How can I help you today?