Skip to main content
LetsDefend Infosec LetsDefend Infosec
  • Home
  • Services
    • VAPT
    • Compliance
    • Virtual CISO
    • GRC Platform
    • Consulting
    • Managed Security
    • Anti-Phishing
    • Awareness Training
    View all services
    Products
    • TrueVigil
    • CyberIntellect
    View all products
  • About us
  • Blog
  • Contact
Our insights

Security insights that Cut Through the Noise. 

Timely breakdowns of breaches, vulnerabilities, and policy shifts, alongside practical write-ups on risk and compliance - the same plain-language approach we bring to every client engagement.

Illustration representing LetsDefend Infosec's insights and write-ups
All posts Cybercrime Data Breaches Data Privacy Law Enforcement Operations Malware Nation-State Threats Phishing Policy & Compliance Threat Actors Threat Intelligence Vulnerabilities
Latest
Vulnerabilities 28 Sep 2026 · 5 min read

Citrix NetScaler ADC & Gateway Critical RCE Vulnerabilities Actively Exploited

Citrix disclosed two critical remote code execution flaws in NetScaler ADC and NetScaler Gateway that are being exploited in the wild. Patches have been released, but one vulnerability affects every deployment, including default configurations.

Read article
Vulnerabilities
28 Sep 2026 4 min read

CISA Flags Actively Exploited SharePoint Flaw (CVE‑2026‑65660) with Federal Patch Deadline

CISA has added CVE‑2026‑65660 for Microsoft SharePoint to its Known Exploited Vulnerabilities catalog, confirming active exploitation and imposing a September 28 patch deadline for federal agencies. Immediate remediation is required.

#Vulnerabilities #Microsoft SharePoint #CISA
LetsDefend Infosec Read more
Vulnerabilities
28 Sep 2026 4 min read

Citrix NetScaler Zero‑Day Exploits (CVE‑2026‑88771/88772) Actively Attacked

Citrix disclosed two critical NetScaler remote code execution flaws, CVE‑2026‑88771 and CVE‑2026‑88772, that are currently being exploited. Security updates are available, and administrators are urged to shut down vulnerable appliances immediately.

#Vulnerabilities #Citrix #NetScaler
LetsDefend Infosec Read more
Threat Intelligence
23 Sep 2026 5 min read

EvilTokens Phishing-as-a-Service Disrupted After Compromising 12,000 Microsoft Accounts

Microsoft’s Digital Crimes Unit dismantled the EvilTokens phishing-as-a-service platform that had harvested over 12,000 Microsoft accounts across more than 10,000 organizations. This brief examines the incident, its technical underpinnings, impact, and immediate steps for defenders.

#Phishing #Threat Intelligence #Microsoft
LetsDefend Infosec Read more
Data Breaches
23 Sep 2026 4 min read

Swedish Regulator Fines Miljödata $183K for 2025 Data Breach Impacting 2.2 Million

Sweden’s data‑privacy authority IMY imposed a SEK 1.8 million fine on IT provider Miljödata after an August 2025 breach exposed personal data of 2.2 million individuals. The sanction highlights gaps in security controls and reinforces compliance expectations for service providers handling sensitive information.

#Data Breach #Regulatory Enforcement #Sweden
LetsDefend Infosec Read more
Data Breaches
23 Sep 2026 5 min read

Chinese-speaking Actor Exploits ZyXEL Switches and WordPress, Steals Data from Nearly 1,000 Devices

A Chinese-speaking threat group has actively exploited vulnerabilities in ZyXEL GS1900 Smart Managed Switches and WordPress, exfiltrating data from 996 devices and more than 18,500 database records. This brief examines the incident, technical vectors, impacted assets, and immediate mitigation steps.

#Vulnerabilities #Data Breaches #Threat Actors
LetsDefend Infosec Read more
Threat Actors
23 Sep 2026 5 min read

Microsoft Disrupts EvilTokens Device‑Code Phishing‑as‑a‑Service Platform

Microsoft, backed by a U.S. court order and a coalition of partners, seized 50 malicious sites and disabled over 150 domains to dismantle the EvilTokens AI‑driven phishing‑as‑a‑service operation that compromised thousands of Microsoft 365 accounts.

#Threat Intelligence #Phishing #Microsoft 365
LetsDefend Infosec Read more
Threat Intelligence
17 Sep 2026 4 min read

Fake CAPTCHA Scam Evolves: New Variant Lures Users into Malware Execution

A fresh twist on a known scam now disguises malicious downloads behind a counterfeit CAPTCHA prompt. Analysts break down the mechanics, potential impact, and steps organizations can take to protect users.

#social engineering #phishing #malware
LetsDefend Infosec Read more
Vulnerabilities
17 Sep 2026 4 min read

Active Exploitation of Cisco ISE Zero-Day Prompts Emergency Patch

Remote, unauthenticated attackers are actively exploiting a zero‑day authentication bypass in Cisco ISE. Cisco responded with an emergency patch. This brief outlines the incident, technical details, impact, and immediate mitigation steps.

#Cisco #Zero-Day #Authentication Bypass
LetsDefend Infosec Read more
Malware
17 Sep 2026 4 min read

Banking Malware Leverages KREMLIN Toolkit to Force‑Install Malicious Browser Extensions

Since mid‑2025, a banking‑focused malware campaign has used the KREMLIN toolkit to compel Chrome and Edge users to install malicious extensions that harvest credentials, session tokens, and other sensitive data.

#Malware #Browser Security #Credential Theft
LetsDefend Infosec Read more
  • « Previous
  • Next »
Showing 1 to 9 of 37 results
  • ‹
  • 1
  • 2
  • 3
  • 4
  • 5
  • ›
LetsDefend Infosec LetsDefend Infosec

Practical cybersecurity for organisations that need clarity, confidence, and room to grow.

Explore

  • Services
  • Products
  • About us
  • Blog
  • Contact

Services

  • VAPT
  • Compliance
  • Virtual CISO
  • GRC Platform
  • Consulting
  • Managed Security
  • Anti-Phishing
  • Awareness Training

Get in Touch

info@letsdefend.in

+91 7859957803

2nd Floor Ved Plaza Complex,
Meghraj Road, Modasa,
Gujarat-383315

© 2026 LetsDefend Infosec. Built around better security decisions.
Privacy policy Terms of use

Developer tools are open. Please close them to keep browsing.

Ready when you are.

Send us a quick note about your goals, timeline, or current challenge, and we’ll come back with a considered next step.

We only use the information you provide to respond to this enquiry. No credentials or sensitive data are requested here.

Talk to an expert.

Tell us a little about your goals, timeline, or current challenge, and one of our experts will come back with a considered next step.

Preferred contact method

We only use the information you provide to respond to this request. No credentials or sensitive data are requested here.