Alerts List
AL2026_04 Hackers Abuse OAuth Error Flows to Spread Malware (March 6th, 2026) 
Description  Researchers from Microsoft have identified phishing campaigns that abuse legitimate OAuth error and redirection mechanisms to bypass emai . . . Read more

Date Publish: Mar 6th 26
AL2026_03 CISA Flags VMware Aria Operations RCE Flaw as Exploited in Attacks (March 6th, 2026)
Description  The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability affecting VMware Aria Operations to its Kn . . . Read more

Date Publish: Mar 6th 26
AL2026_02 CISA Warns That RESURGE Malware Can Remain Dormant on Ivanti Devices (March 2nd, 2026) 
Description  The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning that a malware strain known as RESURGE can remain dorman . . . Read more

Date Publish: Mar 2nd 26
AL2026_01 Deepfakes and Injection Attacks Undermine Identity Verification Systems (March 2nd, 2026)
Description  Researchers have reported a growing trend of cybercriminals bypassing identity verification (IDV) systems using advanced deepfake technol . . . Read more

Date Publish: Mar 2nd 26
AL2025_51 Malicious VSCode Extensions Resurface on OpenVSX, Target Developers with Crypto-Stealers and Backdo
Description Researchers have observed a coordinated campaign (tracked as TigerJack) that publishes malicious Visual Studio Code (VSCode) extensions to . . . Read more

Date Publish: Oct 16th 25
AL2025_50 Oracle E-Business Suite Zero-Day (CVE-2025-61882) Exploited in Clop Data-Theft Campaign (October 7t
Description Oracle has released an emergency security update to address a critical, unauthenticated remote-code-execution vulnerability in Oracle E-Bu . . . Read more

Date Publish: Oct 7th 25
AL2025_49 Discord Support-Ticket Breach Exposes User Data (October 7th, 2025)
Description Discord disclosed that an unauthorized party gained limited access to a third-party customer service/ticketing system used by Discord, exp . . . Read more

Date Publish: Oct 7th 25
AL2025_48 Microsoft Outlook Stops Displaying Inline SVG Images Exploited in Phishing Attacks (October 07th, 2
Description Microsoft has implemented a security change in Outlook to block the display of inline SVG (Scalable Vector Graphics) images, following rec . . . Read more

Date Publish: Oct 7th 25
AL2025_47 New MatrixPDF toolkit turns PDFs into phishing and malware lures (October 02nd , 2025) 
Description  A new phishing and malware distribution toolkit called MatrixPDF has been discovered on cybercrime forums, enabling threat actors to tran . . . Read more

Date Publish: Oct 2nd 25
AL2025_46 Cisco ASA and FTD Zero-Day Vulnerabilities Actively Exploited in State-Sponsored Attacks (October 0
Description  Cisco has released emergency security patches for three critical zero-day vulnerabilities in Cisco Adaptive Security Appliance (ASA) and . . . Read more

Date Publish: Oct 2nd 25
AL2025_45 LockBit 5.0 Emerges- Cross Platform Ransomware Targets Windows, Linux and ESXi (September 30th, 202
Description A new iteration of the LockBit ransomware marketed as LockBit 5.0 has been observed in the wild. This variant includes cross-platform bina . . . Read more

Date Publish: Sep 30th 25
AL2025_44 AI-Driven Phishing Campaign Using LLM-Crafted SVG Files (September 30th, 2025)
Description Microsoft has identified a new phishing campaign targeting organizations that leverages large language models (LLMs) to create obfuscated . . . Read more

Date Publish: Sep 30th 25