News

KPMG Ethical Wall Failure

KPMG Just Admitted the “Wall” Inside Its Own Firm Doesn’t Exist

The CyberSec Guru

KPMG admits Optus client data crossed into a Telstra audit bid. Full timeline, whistleblower retaliation, and the regulatory gaps that let it happen

Klue Salesforce Breach

Klue Salesforce Breach Explained: Icarus OAuth Attack

The CyberSec Guru

Inside the Klue Salesforce breach: how Icarus stole OAuth tokens, the API attack chain, IOCs, victim list, and how to detect and respond

CVE-2026-42530 & CVE-2026-42055

Two 9.2s in stock NGINX: inside the HTTP/3 QPACK use-after-free and the gRPC heap overflow F5 just patched

The CyberSec Guru

F5 patched two critical NGINX flaws (CVSS 9.2): a QPACK use-after-free in HTTP/3 and a gRPC heap overflow. Full technical breakdown and PoCs

FortiBleed

FortiBleed: How a Russian-Speaking Threat Group Quietly Compromised 75,000 Fortinet Firewalls Worldwide

The CyberSec Guru

FortiBleed exposed verified credentials for 75,000 Fortinet firewalls across 194 countries. Here's the full technical breakdown of how it was all done

Mastra npm Supply Chain Attack

How 144 Mastra npm Packages Got Poisoned in Under an Hour And Nobody Noticed Until It Was Too Late

The CyberSec Guru

144 Mastra npm packages were compromised on June 17, 2026 via easy-day-js, a typosquatted dependency that drops a cross-platform infostealer

How a Single Rogue BGP Announcement Took Telegram Offline Across Three Continents

How a Single Rogue BGP Announcement Took Telegram Offline Across Three Continents

The CyberSec Guru

A single unauthorized BGP route from Reliance AS18101 redirected Telegram's global traffic into a blackhole taking users offline in India and more

PSN Single-Letter Username Glitch

PSN’s One-Letter Username Glitch: What Actually Happened Under the Hood

The CyberSec Guru

A PSN glitch let users claim single-letter usernames blocked since 2006. Here's the validation failure behind it and what Sony will likely do next

CVE-2026-50751

The VPN Authentication Bypass That Let Ransomware Actors Walk Right In: A Deep Dive into CVE-2026-50751

The CyberSec Guru

CVE-2026-50751 is a CVSS 9.3 auth bypass in Check Point VPN exploited since May 7, 2026. Full technical breakdown, IOCs, patches and more

CVE-2026-53435

CVE-2026-53435: Inside the Jenkins Deserialization Chain That’s Being Exploited Right Now

The CyberSec Guru

CVE-2026-53435 is a high-severity Jenkins deserialization flaw (CVSS 8.8) under active exploitation. Full technical breakdown: gadget chain, PoC

HDFC AMC Data Breach

HDFC AMC Got Breached. Here’s What Actually Happened And What Morpheus’s 680 GB Haul Means for Your Data

The CyberSec Guru

HDFC AMC's VMware infrastructure was breached by ransomware group Morpheus, exposing 680 GB of investor PAN, bank, and SIM data. Details