no alarms and no surprises please..
-
AI-Generated Workflows Are a Silent Security Disaster
AI-Generated Workflows Are a Silent Security Disaster Teams are dealing with a truly dangerous problem — automation that works, but that no one understands. Yelena Mujibur Sheikh Go to gbhackers.com
-
NIST Enrichment Reductions Impact CVE Coverage, Accuracy
NIST Enrichment Reductions Impact CVE Coverage, Accuracy The National Institute of Standards and Technology (NIST) scaled back on the number of CVEs it selects for in-depth analysis, but the move has produced mixed results, according to researchers. Rob Wright Go to gbhackers.com
-
Kali Linux 2026.2 Release With new Hacking Tool and With Updated Desktop Environments
Kali Linux 2026.2 Release With new Hacking Tool and With Updated Desktop Environments Kali Linux 2026.2 arrives on schedule in the final week of Q2 with a pragmatic blend of desktop environment refreshes, infrastructure hardening, and practical… Delivered by PolitePaul service Go to gbhackers.com
-
Boss Scam Uses DLL Sideloading to Hijack WhatsApp Web and Defraud Enterprises
Boss Scam Uses DLL Sideloading to Hijack WhatsApp Web and Defraud Enterprises The new “Boss Scam” is a sharp escalation in CEO fraud: attackers now combine impersonation, Windows DLL sideloading, and WhatsApp Web session theft to… Delivered by PolitePaul service Go to gbhackers.com
-
Japan Hotel Industry Targeted With TONResolver RAT and Guest Complaint Phishing Emails
Japan Hotel Industry Targeted With TONResolver RAT and Guest Complaint Phishing Emails Japan’s hotel sector is the latest target of a sophisticated phishing and remote-access trojan (RAT) campaign that leverages guest-complaint lures and an unusual resilience… Delivered by PolitePaul service Go to gbhackers.com
-
Mustang Panda Targets India’s Government and Energy Sectors With ZOHOMURK and MINIRECON
Mustang Panda Targets India’s Government and Energy Sectors With ZOHOMURK and MINIRECON Two concurrent espionage campaigns by Mustang Panda targeting Indian government and energy-sector organisations, deploying a novel malware suite that includes SHARDLOADER, MINIRECON and ZOHOMURK…. Delivered by PolitePaul service Go to gbhackers.com
-
Malicious Chromium Extension Spoofs Perplexity AI to Hijack Browser Searches
Malicious Chromium Extension Spoofs Perplexity AI to Hijack Browser Searches A malicious Chromium extension that impersonated the Perplexity AI brand to intercept browser searches and capture keystrokes before delivering users to legitimate search results…. Delivered by PolitePaul service Go to gbhackers.com
-
Kali Linux 2026.2 released with 9 new tools, NetHunter updates
Kali Linux 2026.2 released with 9 new tools, NetHunter updates Kali Linux 2026.2, the second release of the year, is now available for download, featuring 9 new tools and numerous Kali NetHunter improvements. […] Sergiu Gatlan Go to bleepingcomputer
-
Blackfield ransomware asks Nidec Corporation for $2 million ransom
Blackfield ransomware asks Nidec Corporation for $2 million ransom The Blackfield ransomware gang is asking for a $2 million ransom from Nidec Corporation, a large Japanese manufacturer of electronic components for automotive and computing applications. […] Bill Toulas Go to bleepingcomputer
-
CISA: Windows BlueHammer flaw now exploited by ransomware gangs
CISA: Windows BlueHammer flaw now exploited by ransomware gangs CISA confirmed on Monday that ransomware gangs are now exploiting a Microsoft Defender privilege escalation vulnerability, dubbed BlueHammer, that has previously been abused in zero-day attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
Nissan discloses employee data breach linked to Oracle zero-day attacks
Nissan discloses employee data breach linked to Oracle zero-day attacks Nissan is warning that it suffered a data breach affecting current and former employees after threat actors exploited an Oracle PeopleSoft vulnerability in data theft attacks previously linked to the ShinyHunters extortion group. […] Lawrence Abrams Go to bleepingcomputer
-
NAIC says public data stolen in ShinyHunters’ PeopleSoft breach
NAIC says public data stolen in ShinyHunters’ PeopleSoft breach The National Association of Insurance Commissioners (NAIC) says the ShinyHunters extortion group stole only publicly available data, outdated logs, and configuration files after breaching its systems by exploiting a zero-day vulnerability in an Oracle PeopleSoft server. […] Bill Toulas Go to bleepingcomputer
-
Kali Linux 2026.2 Released With 9 New Tools and VM Boot Tweaking
Kali Linux 2026.2 Released With 9 New Tools and VM Boot Tweaking Kali Linux team officially released Kali Linux 2026.2 right on schedule at the close of Q2 2026, delivering a compelling mix of desktop environment upgrades, infrastructure modernization, VM performance enhancements, and nine brand-new tools for penetration testers and security researchers. This release bumps…
-
Nissan Confirms Data Breach Following Oracle PeopleSoft 0-Day Attacks
Nissan Confirms Data Breach Following Oracle PeopleSoft 0-Day Attacks Nissan Americas has officially confirmed a data breach affecting current and former employees across four countries after threat actors exploited a critical zero-day vulnerability in Oracle PeopleSoft software, a campaign attributed to the ShinyHunters extortion group. The attack stems from CVE-2026-35273, a CVSS 9.8-rated unauthenticated Server-Side…
-
WhatsApp Launches New Username Feature to Communicate Without Exposing Phone Numbers
WhatsApp Launches New Username Feature to Communicate Without Exposing Phone Numbers WhatsApp introduces a new privacy update that lets users connect using unique handles, eliminating the need to share phone numbers with strangers or new group members. Earlier, we detailed that WhatsApp is preparing to roll out a long-anticipated username feature. Now WhatsApp has officially…
-
EvilTokens Phishing Breaches Finance Firms Using “Ghost” Code Across U.S. and European Businesses
EvilTokens Phishing Breaches Finance Firms Using “Ghost” Code Across U.S. and European Businesses EvilTokens can keep serious account-takeover activity out of your SOC’s view by relying on “ghost” code that only surfaces after the browser decrypts it. Because of this, analysis that looks only at the static URL can overlook the part of the attack that…
-
New Claude Code Attack Allows Attackers to Take Full Control of Developers’ Systems
New Claude Code Attack Allows Attackers to Take Full Control of Developers’ Systems Researchers at Mozilla’s Zero Day Investigative Network (0DIN) have demonstrated a proof-of-concept attack that shows how a completely clean-looking GitHub repository can trick AI-powered coding agents like Claude Code into silently opening a reverse shell on a developer’s machine, without a single…
-
Inside the inbox: Why cybercriminals want to break into your email account
Inside the inbox: Why cybercriminals want to break into your email account Your inbox is an identity system all of its own: whoever owns it may own a lot more Go to eset
-
Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild
Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild A critical security flaw impacting Oracle E-Business Suite has come under active exploitation in the wild, according to Defused Cyber. The vulnerability, tracked as CVE-2026-46817 (CVSS score: 9.8), refers to an improper privilege management and authentication flaw in Oracle Payments that could be abused to…
-
Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input
Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input Microsoft has found a malicious Chrome extension that posed as the AI search engine Perplexity and quietly logged what people searched for. It routed every query and every character typed into the address bar through an attacker-controlled server before redirecting users to real results. Microsoft…
-
WhatsApp is Finally Getting Usernames to Help Keep Phone Numbers Private
WhatsApp is Finally Getting Usernames to Help Keep Phone Numbers Private WhatsApp on Monday officially announced the start of global reservations of usernames with an aim to protect the privacy of more than three billion users on the messaging platform. The optional feature is designed to help users connect with someone on the service through…
-
Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks
Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks The China-aligned espionage group Mustang Panda is running two campaigns against the Indian government and hydropower targets, deploying new malware and turning a legitimate cloud service into its command channel. Acronis Threat Research Unit found active compromises inside Indian government networks, including machines used by senior…
-
⚡ Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and More
⚡ Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and More This week was a reminder that attackers do not always need big tricks. One small mistake, one old access path, one missed patch, and suddenly the door is open. The noise is not all noise, either. Forums are talking, researchers are…
-
Factoring RSA Keys with Many Zeros
Factoring RSA Keys with Many Zeros Interesting research on a new class of weak RSA keys: keys with lots of zeros. It turns out that these keys are out in the wild. The badkeys project is an open-source service that checks public keys for known vulnerabilities. While developing this tool, Hanno collected a massive number…
-
Robot Police Officers
Robot Police Officers We’ve taken one small step towards robot police officers: a drone capable of disarming a suspect: In a June 22 video posted on the Sacramento County Sheriff’s Office’s Instagram page, an officer wearing goggles can be seen operating a drone to retrieve a knife from an armed suspect hiding inside a cluttered…
-
‘Djinn’ Stealer Targets Cloud, AI Credentials
‘Djinn’ Stealer Targets Cloud, AI Credentials The infostealer was delivered via CVE-2026-48558, a critical authentication bypass vulnerability in SimpleHelp, targeting credentials linking development and admin environments to wider enterprise systems. Jai Vijayan Go to gbhackers.com
-
Vulnerabilities Expose Private Data in Indian Government Systems
Vulnerabilities Expose Private Data in Indian Government Systems One critical vulnerability, among many discovered by a researcher, could have allowed anyone to walk in and take over a national government portal. Nate Nelson Go to gbhackers.com
-
Can Clothes Make You Invisible to Facial Recognition?
Can Clothes Make You Invisible to Facial Recognition? Does life feel Orwellian sometimes? One researcher has a solution for you: graphic tees that confuse the neural networks in surveillance cameras. Nate Nelson Go to gbhackers.com
-
Iran, Russia, China Target Water Systems for Sabotage
Iran, Russia, China Target Water Systems for Sabotage Nation-state attackers breach water systems through weak passwords, exposed PLCs, and poor segmentation — not sophisticated malware. Alexander Culafi Go to gbhackers.com
-
Amazon Q VS Extension Flaw Leads to Cloud Credential Theft
Amazon Q VS Extension Flaw Leads to Cloud Credential Theft Adversaries could plant a malicious repository that can execute arbitrary code and steal cloud credentials by exploiting the vulnerability, which showcases growing MCP risk. Elizabeth Montalbano Go to gbhackers.com
-
Critical Hoppscotch Vulnerability Lets Attackers Overwrite JWT_SECRET and Forge Admin Tokens
Critical Hoppscotch Vulnerability Lets Attackers Overwrite JWT_SECRET and Forge Admin Tokens A critical security vulnerability, identified as CVE-2026-50160, has been discovered in the self-hosted Hoppscotch backend. This vulnerability allows unauthenticated attackers to overwrite sensitive configuration… Delivered by PolitePaul service Go to gbhackers.com
-
ClawHavoc Attack Hits ClawHub With 1,184 Malicious Skills and 247,000 Installations
ClawHavoc Attack Hits ClawHub With 1,184 Malicious Skills and 247,000 Installations The AI-agent ecosystem experienced its largest supply-chain compromise to date when ClawHavoc detonated across ClawHub, the official skill marketplace for OpenClaw. Our full AIG-powered… Delivered by PolitePaul service Go to gbhackers.com
-
Langflow RCE Vulnerability Exploited to Deploy Monero Cryptominer on Exposed AI Servers
Langflow RCE Vulnerability Exploited to Deploy Monero Cryptominer on Exposed AI Servers Threat actors are actively exploiting CVE-2026-33017, a critical unauthenticated remote code execution (RCE) vulnerability in Langflow, to compromise internet-exposed AI application servers and silently… Delivered by PolitePaul service Go to gbhackers.com
-
New Windows Injection Technique Hijacks Win32k Callback Dispatch to Execute Shellcode
New Windows Injection Technique Hijacks Win32k Callback Dispatch to Execute Shellcode A newly documented injection technique abuses the kernel-to-user callback dispatch path used by the Windows graphical subsystem (win32k.sys) to achieve remote code execution while… Delivered by PolitePaul service Go to gbhackers.com
-
Critical Dell Wyse Management Suite Vulnerabilities Let Attackers Execute Remote Code
Critical Dell Wyse Management Suite Vulnerabilities Let Attackers Execute Remote Code Dell Technologies has disclosed several critical vulnerabilities in its Wyse Management Suite (WMS) that could enable remote attackers to execute arbitrary code and fully… Delivered by PolitePaul service Go to gbhackers.com
-
Data breach exposes up to 14.2 million email logins at six ISPs
Data breach exposes up to 14.2 million email logins at six ISPs Japanese telecommunications operator KDDI Corporation disclosed a data breach where threat actors gained access to one of its email systems used by five other internet service providers (ISPs) in the country. […] Bill Toulas Go to bleepingcomputer
-
China’s New Zhipu AI Reportedly Matches Claude Mythos in Vulnerability Detection
China’s New Zhipu AI Reportedly Matches Claude Mythos in Vulnerability Detection Zhipu AI’s open-weight GLM-5.2 model is reportedly performing on par with Anthropic’s restricted Claude Mythos in specific cybersecurity and software vulnerability detection tasks, a development that is intensifying concerns inside the U.S. government about the effectiveness of its AI export control strategy. Zhipu AI…
-
RedAmon AI Tool that Chains Reconnaissance, Exploitation, and Post-exploitation
RedAmon AI Tool that Chains Reconnaissance, Exploitation, and Post-exploitation A new open-source offensive security platform called RedAmon is redefining automated penetration testing by chaining reconnaissance, exploitation, post-exploitation, AI-driven triage, and automated code remediation all into a single end-to-end pipeline that culminates in a GitHub pull request with the fix already written. RedAmon is a modular,…
-
OpenAI Released GPT-5.6 Sol With Limited Access and Strong Cyberattack Protections
OpenAI Released GPT-5.6 Sol With Limited Access and Strong Cyberattack Protections OpenAI has officially begun a limited preview of the GPT‑5.6 model series Sol, Terra, and Luna, positioning its flagship Sol as the company’s most capable and security-hardened AI model to date, available initially only to a small group of trusted partners at the formal…
-
Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer
Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer Cybersecurity researchers have uncovered two hijacked npm packages and a cluster of Go packages that are designed to deploy a Python-based information stealer on compromised Windows, Linux, and macOS hosts. “This attack avoids the most common npm execution paths through lifecycle scripts,…
-
ISC Stormcast For Monday, June 29th, 2026 https://isc.sans.edu/podcastdetail/9986, (Mon, Jun 29th)
ISC Stormcast For Monday, June 29th, 2026 https://isc.sans.edu/podcastdetail/9986, (Mon, Jun 29th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
YARA-X 1.18.0 and 1.19.0 Release, (Sun, Jun 28th)
YARA-X 1.18.0 and 1.19.0 Release, (Sun, Jun 28th) YARA-X’s 1.18.0 release brings 3 improvements and 2 bugfixes. One of the improvements is a new command-line option, –cpu-limit, allowing one to limit the amount of CPU YARA requires. YARA-X’s 1.19.0 release brings 4 improvements and 2 bugfixes. Didier Stevens Senior handler blog.DidierStevens.com (c) SANS Internet Storm…
-
Clean GitHub repo tricks AI coding agents into running malware
Clean GitHub repo tricks AI coding agents into running malware An agentic coding tool tasked with cloning and setting up a seemingly benign GitHub repository could execute a malicious payload that remains invisible to security scanners, AI agents, and human reviewers. […] Bill Toulas Go to bleepingcomputer
-
Ukraine Says Russian Intelligence Used Fake Support Texts to Steal Messaging Credentials
Ukraine Says Russian Intelligence Used Fake Support Texts to Steal Messaging Credentials The Security Service of Ukraine (SSU) said it, together with the U.S. Federal Bureau of Investigation (FBI), uncovered a long-running campaign orchestrated by Russian intelligence services to break into the messaging accounts of government officials, military personnel, politicians, and activists in Ukraine, Europe,…
-
OpenAI Previews GPT-5.6 Sol With Restricted Access and Stronger Cyber Safeguards
OpenAI Previews GPT-5.6 Sol With Restricted Access and Stronger Cyber Safeguards OpenAI on Friday released three versions of GPT-5.6, called Sol, Terra, and Luna, as a limited preview to a small number of companies as part of an ongoing engagement with the U.S. government. While Sol is the latest flagship model and the most powerful,…
-
Third-Party Breaches Teach Education Sector a Costly Lesson in Vendor Risk
Third-Party Breaches Teach Education Sector a Costly Lesson in Vendor Risk Rising threats from third-party actors are forcing institutions to play defense to protect student data from ransomware and other attacks. Bree Fowler Go to gbhackers.com
-
Claude Mythos 5 Redeployed to Help U.S. Organizations Strengthen Cyber Defense
Claude Mythos 5 Redeployed to Help U.S. Organizations Strengthen Cyber Defense Anthropic has officially restored access to its Claude Mythos 5 artificial intelligence model for a select group of U.S. organizations tasked with defending critical… Delivered by PolitePaul service Go to gbhackers.com
-
Critical Linux Kernel Flaw Allows Unprivileged Users to Gain Full Root Access
Critical Linux Kernel Flaw Allows Unprivileged Users to Gain Full Root Access A newly disclosed flaw in the Linux kernel’s traffic-control subsystem, now assigned CVE-2026-46331 and referred to as “Pedit COW,” has been found to grant… Delivered by PolitePaul service Go to gbhackers.com
-
Cloud Bucket Hijacking Lets Attackers Silently Exfiltrate AWS, Google Cloud Data
Cloud Bucket Hijacking Lets Attackers Silently Exfiltrate AWS, Google Cloud Data A critical cloud storage attack technique that exploits a fundamental architectural vulnerability shared across all major cloud service providers. The technique, dubbed cloud bucket hijacking,… Delivered by PolitePaul service Go to gbhackers.com
-
Linux Kernel DirtyClone Vulnerability Lets Local Attackers Gain Root Privileges
Linux Kernel DirtyClone Vulnerability Lets Local Attackers Gain Root Privileges A critical Local Privilege Escalation flaw has been uncovered within the Linux kernel, allowing unprivileged local users to seamlessly gain root access by manipulating… Delivered by PolitePaul service Go to gbhackers.com
-
Amazon Q Developer Vulnerability Allows Code Execution via Malicious Repositories
Amazon Q Developer Vulnerability Allows Code Execution via Malicious Repositories A critical security flaw discovered in the Amazon Q Developer Extension for Visual Studio Code (VS Code) left developers vulnerable to arbitrary code execution… Delivered by PolitePaul service Go to gbhackers.com
-
FBI: Russian hackers now target Signal backup recovery keys
FBI: Russian hackers now target Signal backup recovery keys The FBI and CISA are warning that a phishing campaign targeting Signal users tied to Russian intelligence services has evolved to steal Signal Backup Recovery Keys, allowing attackers to access victims’ historical messages. […] Lawrence Abrams Go to bleepingcomputer
-
CISA sets urgent deadline to fix Cisco flaw exploited in attacks
CISA sets urgent deadline to fix Cisco flaw exploited in attacks The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is giving federal agencies until Sunday to patch a vulnerability in Cisco Unified Communications Manager Server that is being actively exploited. […] Bill Toulas Go to bleepingcomputer
-
Polymarket customers lose $3 million in supply-chain attack
Polymarket customers lose $3 million in supply-chain attack Polymarket says it will fully reimburse customers who lost an estimated $3 million after hackers injected a malicious script into the platform’s frontend following a breach at a third-party vendor. […] Bill Toulas Go to bleepingcomputer
-
Cybersecurity firms targeted by fraudulent OpenAI organization invites
Cybersecurity firms targeted by fraudulent OpenAI organization invites Threat actors are creating OpenAI tenants that impersonate legitimate companies and inviting employees to join them, in what appears to be a ploy to trick targets into submitting sensitive company information in chats and projects. […] Lawrence Abrams Go to bleepingcomputer
-
Your First GRC Agent: A Red Teamer’s Walkthrough
Your First GRC Agent: A Red Teamer’s Walkthrough AI won’t replace GRC analysts, but it can eliminate much of the repetitive work they do. Anecdotes walks through building an agent that continuously monitors controls, identifies evidence gaps, and opens remediation tasks. […] Sponsored by Anecdotes Go to bleepingcomputer
-
Anthropic Confirms Claude Mythos 5 Redeployment for US Critical Infrastructure Organizations
Anthropic Confirms Claude Mythos 5 Redeployment for US Critical Infrastructure Organizations Anthropic has confirmed that Claude Mythos 5, its most powerful AI cybersecurity model, will be redeployed to a select set of U.S. organizations responsible for operating and defending critical infrastructure, following a government-led review process that began on June 12, 2026. Claude Mythos first…
-
New Bucket Hijacking Attack Allows Hackers to Reroute Cloud Data Streams to External Storage
New Bucket Hijacking Attack Allows Hackers to Reroute Cloud Data Streams to External Storage A critical cloud storage attack technique dubbed “bucket hijacking” a method that enables threat actors to silently redirect an organization’s active cloud data streams, including audit logs and telemetry, into attacker-controlled external storage buckets across major cloud platforms. The technique has…
-
New DirtyClone Linux Vulnerability Allows Attackers to Gain Root Access Via Cloned Packets
New DirtyClone Linux Vulnerability Allows Attackers to Gain Root Access Via Cloned Packets A new Linux kernel local privilege escalation vulnerability, dubbed “DirtyClone” (CVE-2026-43503), that allows unprivileged local users to gain full root access by manipulating cloned network packets through the XFRM/IPsec subsystem, all without leaving a trace in kernel logs or audit records. DirtyClone…
-
Amazon Q Vulnerability Let Attackers Execute Code and Access Sensitive Cloud Environments
Amazon Q Vulnerability Let Attackers Execute Code and Access Sensitive Cloud Environments A high-severity vulnerability in the Amazon Q Developer Extension for Visual Studio Code (VS Code), Amazon’s AI-powered coding assistant. Tracked as CVE-2026-12957 and CVE-2026-12958 and disclosed by Wiz Research, the flaws allowed attackers to achieve arbitrary code execution and cloud credential theft simply…
-
New Linux pedit COW Exploit Allows Attackers to Gain System Root Access
New Linux pedit COW Exploit Allows Attackers to Gain System Root Access A newly disclosed Linux kernel vulnerability combining a Copy-on-Write (COW) page-cache corruption flaw with the net/sched subsystem’s act_pedit component is enabling unprivileged local attackers to escalate privileges to full root access on several major Linux distributions. The exploit, dubbed packet_edit_meme, has been verified…
-
SMB cyber readiness: the road to resilience starts here
SMB cyber readiness: the road to resilience starts here Your business may be small, but its attack surface is anything but. Readiness is the first step to resilience. Go to eset
-
FBI Warns Russian Intelligence Hackers Target Signal Backup Recovery Keys
FBI Warns Russian Intelligence Hackers Target Signal Backup Recovery Keys The FBI and CISA have updated their March warning about Russian intelligence phishing Signal accounts, and the operators have added a step: they now coax targets into handing over their Signal Backup Recovery Key. Hand it over once, and the attacker can restore the account’s backup, read…
-
New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks
New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks A newly discovered cyber attack campaign has been observed delivering a previously undocumented malware family called SharkLoader that acts as a loader for deploying Cobalt Strike Beacon on compromised hosts. Kaspersky, which is tracking the activity under the moniker StrikeShark, said the campaign has targeted a…
-
Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign
Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign A Chinese-speaking advanced persistent threat (APT) actor has been linked to a new custom backdoor called TinyRCT as part of cyber attacks aimed at government entities and critical infrastructure in Southeast Asia. The activity, particularly aimed at state-owned enterprises in the energy and government sectors,…
-
New Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries
New Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries A flaw in the Linux kernel’s traffic-control subsystem can let a local unprivileged user gain root on affected systems. CVE-2026-46331, nicknamed “pedit COW,” is an out-of-bounds write in the packet-editing action (act_pedit) that corrupts shared page-cache memory. A public, working exploit appeared within a day…
-
Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs
Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs A high-severity flaw in Amazon Q Developer let a malicious repository run commands and steal a developer’s cloud credentials. The path was short: a developer opens the repo, trusts the workspace, and Amazon Q does the rest. Amazon has patched it. Tracked…
-
The Chinese Control the Majority of Argentina’s Squid Fleet
The Chinese Control the Majority of Argentina’s Squid Fleet Chinese companies control nearly two-thirds of Argentina’s own squid fleet. Bruce Schneier Go to bruce schneier
-
Meta Is Testing Facial Recognition for Police and Military
Meta Is Testing Facial Recognition for Police and Military We know that ICE wants to deploy eyeglasses with facial recognition that can identify people in real time. Turns out Meta is prototyping the feature with a Pentagon supplier. (Alternate news story.) Bruce Schneier Go to bruce schneier
-
One Million Passports Leaked Online
One Million Passports Leaked Online A database of almost a million passports from around the world was leaked online. Note what happened. A high-value credential—a passport—was used in an ancillary low-value authentication system: ID verification for cannabis dispensaries. And it’s the low-value system that got hacked, putting the high-value credential at risk. Bruce Schneier Go…
-
AI Decline? Confidence in Autonomous Penetration Testing Falls
AI Decline? Confidence in Autonomous Penetration Testing Falls Companies are still experimenting with automated AI systems to find security weaknesses, but fewer are relying on the technology. Robert Lemos Go to gbhackers.com
-
Cisco Adds NHI to Security Stack With Astrix, WideField Acquisitions
Cisco Adds NHI to Security Stack With Astrix, WideField Acquisitions Cisco joins a growing list of security platform providers who are betting that securing the agentic workforce means turning identity into the primary control plane. Jeffrey Schwartz Go to gbhackers.com
-
AI Won’t Wipe-Out Entry-Level Cybersecurity Jobs
AI Won’t Wipe-Out Entry-Level Cybersecurity Jobs Instead of eliminating jobs for early-career cyber pros, AI is creating new opportunities for candidates with strong human decision-making skills. Jon France Go to gbhackers.com
-
Meeting Trump’s 2030 Quantum Deadline Will be Expensive, Complex
Meeting Trump’s 2030 Quantum Deadline Will be Expensive, Complex Getting accurate visibility into IT and OT systems will be compounded by multivendor environments, misaligned update life cycles, and interoperability gaps. Alexander Culafi Go to gbhackers.com
-
Thanks for Crushing the Submissions Inbox. We’re Trying to Keep Up
Thanks for Crushing the Submissions Inbox. We’re Trying to Keep Up It might be taking a bit longer than usual to respond to your submissions — here’s why. Becky Bracken Go to gbhackers.com
-
Hackers Exploit WinRAR CVE-2025-8088 to Plant Startup Shortcut and Run PowerShell Loader
Hackers Exploit WinRAR CVE-2025-8088 to Plant Startup Shortcut and Run PowerShell Loader Hackers have weaponized a WinRAR path-traversal flaw tracked as CVE-2025-8088 to silently plant a Startup shortcut and run a multi-stage PowerShell loader that maps… Delivered by PolitePaul service Go to gbhackers.com
-
Scammers Abuse Shopify to Send Fake Invoices and Steal Credentials via Fake Support Calls
Scammers Abuse Shopify to Send Fake Invoices and Steal Credentials via Fake Support Calls Scammers are increasingly exploiting Shopify’s ecosystem and its Shop order-tracking app to deliver fraudulent invoices directly into users’ purchase histories, marking a shift from… Delivered by PolitePaul service Go to gbhackers.com
-
Russian Authorities Used Cellebrite UFED to Break Into Human Rights Activist’s iPhone
Russian Authorities Used Cellebrite UFED to Break Into Human Rights Activist’s iPhone Russian authorities leveraged Cellebrite’s Universal Forensic Extraction Device (UFED) to gain access to a detained human rights activist’s iPhone, according to a detailed forensic… Delivered by PolitePaul service Go to gbhackers.com
-
KuinaExtractor Stealer Targets Browser Data, Crypto Wallets, Roblox, Steam, and Discord
KuinaExtractor Stealer Targets Browser Data, Crypto Wallets, Roblox, Steam, and Discord A previously undocumented Rust-based infostealer they call KuinaExtractor, a family that has evolved from a capable early prototype into a hardened, stealth-focused threat now… Delivered by PolitePaul service Go to gbhackers.com
-
WhatsApp Adds Security Warning Before Users Start Chat With Unknown Numbers
WhatsApp Adds Security Warning Before Users Start Chat With Unknown Numbers WhatsApp has introduced a new proactive security feature that warns users before they start conversations with unknown phone numbers. This update, currently being rolled… Delivered by PolitePaul service Go to gbhackers.com
-
Anthropic is testing desktop-like Claude Cowork for mobile
Anthropic is testing desktop-like Claude Cowork for mobile Anthropic appears to be testing Claude Cowork support on mobile, allowing you to manage long-running Claude tasks from your phone. […] Mayank Parmar Go to bleepingcomputer
-
Poland busts SIM-swapping gang tied to millions in crypto theft
Poland busts SIM-swapping gang tied to millions in crypto theft Authorities in Poland have arrested four members of an organized cybercrime group accused of breaching telecommunications partners and hijacking email accounts to carry out SIM-swapping attacks. […] Bill Toulas Go to bleepingcomputer
-
Order-tracking app Shop abused to push callback phishing attacks
Order-tracking app Shop abused to push callback phishing attacks Threat actors are increasingly abusing Shop, the order-tracking app from Shopify, by adding fake purchase receipts in users’ order histories to trick them into providing sensitive data or installing remote access software. […] Bill Toulas Go to bleepingcomputer
-
Microsoft quietly extends free Windows 10 ESU support to October 2027
Microsoft quietly extends free Windows 10 ESU support to October 2027 Microsoft has quietly extended its free Windows 10 Extended Security Updates (ESU) program for consumers by an additional year, allowing enrolled devices to continue receiving security updates until October 12, 2027. […] Lawrence Abrams Go to bleepingcomputer
-
New macOS malware embeds fake errors to confuse AI analysis tools
New macOS malware embeds fake errors to confuse AI analysis tools A newly discovered macOS malware dubbed “Gaslight” is designed to confuse AI-assisted malware analysis tools by hiding prompt injection strings and fake debugging data within the executable. […] Lawrence Abrams Go to bleepingcomputer
-
CL-STA-1062 Hackers Use TinyRCT Backdoor to Target Southeast Asian Governments
CL-STA-1062 Hackers Use TinyRCT Backdoor to Target Southeast Asian Governments A Chinese-speaking threat group known as CL-STA-1062 has been running a quiet but aggressive campaign against government agencies and critical energy infrastructure across Southeast Asia. The attackers, active since at least March 2022, spent much of 2025 targeting state-owned enterprises with a toolkit that blends…
-
Miasma Malware Uses binding.gyp and Bun to Execute Hidden Payloads in npm Packages
Miasma Malware Uses binding.gyp and Bun to Execute Hidden Payloads in npm Packages Supply chain attackers are getting more creative, and the latest threat is proof of that. A malware campaign known as Miasma has been caught hiding inside widely used npm packages, using a clever mix of tools and techniques to stay hidden while…
-
Minecraft Malware Loader Uses RSA-Signed Smart Contract Updates for Persistent C2
Minecraft Malware Loader Uses RSA-Signed Smart Contract Updates for Persistent C2 A new and highly sophisticated malware loader has been found hiding inside what appears to be a harmless Minecraft mod. Researchers have uncovered a campaign that blends blockchain technology and social engineering to steal player credentials and deliver additional malicious payloads. The damage is…
-
CISA Warns of Cisco Unified CM Vulnerability Exploited in Attacks
CISA Warns of Cisco Unified CM Vulnerability Exploited in Attacks CISA has added a critical server-side request forgery (SSRF) vulnerability affecting Cisco Unified Communications Manager (Unified CM) to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies and organizations to apply patches immediately amid active exploitation in the wild. The flaw, tracked as CVE-2026-20230, enables…
-
Microsoft Extends Windows 10 Security Updates for Users Up to October 2027
Microsoft Extends Windows 10 Security Updates for Users Up to October 2027 Microsoft has quietly expanded its Windows 10 Extended Security Updates (ESU) program, allowing consumers to receive critical security patches through October 12, 2027, an additional year beyond the program’s originally planned expiration date of October 12, 2026. Windows 10 officially reached its end…
-
Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances
Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances ESET Research analyzes Gamaredon’s new toolset and the group’s growing reliance on legitimate online services to hide its C&C infrastructure and exfiltrate stolen data Go to eset
-
Chrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection Capability
Chrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection Capability An analysis of a popular Google Chrome ad block extension for YouTube has uncovered the ability to execute arbitrary JavaScript code. According to Island, the extension, named Adblock for YouTube (ID: cmedhionkhpnakcndndgjdbohmhepckk), has more than 10 million installs and carries a Featured badge…
-
ThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More Stories
ThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More Stories It’s dumb out there again. This week has the usual smell of prod on fire and nobody wanting to admit who left the door open — old creds still working, trusted apps doing sketchy crap, browser tricks jumping the fence,…
-
Surviving the Mythos Era: Richard Bejtlich on the Case for NDR
Surviving the Mythos Era: Richard Bejtlich on the Case for NDR Despite the abundance of telemetry at analysts’ disposal, many security operations teams struggle to answer a few basic questions during incident investigation: What happened? What evidence do we have? How do we know we’re seeing it all, in context? Answering these questions requires teams…
-
New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis
New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis A previously undocumented Rust-based macOS implant and information stealer has been found to embed a prompt injection payload designed to trick a malware analyst’s artificial intelligence (AI) tools and trick it into aborting or refusing an analysis of the artifact. The malware has been…
-
New Mistic Backdoor Linked to KongTuke in ClickFix and ModeloRAT Campaigns
New Mistic Backdoor Linked to KongTuke in ClickFix and ModeloRAT Campaigns A new, stealthy backdoor named Mistic has been deployed as part of suspected financially motivated attacks aimed at multiple organizations spanning insurance, education, IT, and professional services sectors since April 2026. According to Symantec and Carbon Black’s Threat Hunter Team, the backdoor, also tracked…
-
AI and Liability
AI and Liability Earlier this month, a German court ruled that Google is liable for its AI search summaries. Rejecting defenses like “users can check for themselves,” and that they generally know “that information generated with AI should not be blindly trusted,” the court held that the AI’s summaries are reflections of the company and…
-
Interesting Paper Exploring Prompt Injection
Interesting Paper Exploring Prompt Injection This is a fascinating explotation of how LLMs fall for prompt injection attacks. It turns out that they learn to recognize the style of text in different role/instruction blocks, and not just the tags. Their conclusion: Role tags were a formatting trick that became the security architecture and the cognitive…
-
What do Ports Hear When Nobody’s Listening? An Assessment of Automated Cybercrime [Guest Diary], (Wed, Jun 24th)
What do Ports Hear When Nobody’s Listening? An Assessment of Automated Cybercrime [Guest Diary], (Wed, Jun 24th) [This is a Guest Diary by Nicole Phillips, an ISC intern as part of the SANS.edu BACS program] “I was just sitting here enjoying the company. Plants got a lot to say, if you take the time to…
-
Linux Process Name Masquerading, (Wed, Jun 24th)
Linux Process Name Masquerading, (Wed, Jun 24th) In a previous diary, I talked about stack strings[1] with a practical example of them. Since my SEC670 class, I’m even more interested in malware obfuscation techniques. I had a look at process names. When you list running processes on a computer, can you trust what you see? If you’re…