no alarms and no surprises please..
-
Fixing the password problem is as easy as 123456
Fixing the password problem is as easy as 123456 How come it’s still possible to ‘secure’ an online account with a six-digit string? Go to eset
-
Ivanti EPMM CVE-2026-6973 RCE Under Active Exploitation Grants Admin-Level Access
Ivanti EPMM CVE-2026-6973 RCE Under Active Exploitation Grants Admin-Level Access Ivanti is warning that a new security flaw impacting Endpoint Manager Mobile (EPMM) has been explored in limited attacks in the wild. The high-severity vulnerability, CVE-2026-6973 (CVSS score: 7.2), is a case of improper input validation affecting EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1. It…
-
PCPJack Credential Stealer Exploits 5 CVEs to Spread Worm-Like Across Cloud Systems
PCPJack Credential Stealer Exploits 5 CVEs to Spread Worm-Like Across Cloud Systems Cybersecurity researchers have disclosed details of a new credential theft framework dubbed PCPJack that targets exposed cloud infrastructure and ousts any artifacts linked to TeamPCP from the environments. “The toolset harvests credentials from cloud, container, developer, productivity, and financial services, then exfiltrates the…
-
One Click, Total Shutdown: The “Patient Zero” Webinar on Killing Stealth Breaches
One Click, Total Shutdown: The “Patient Zero” Webinar on Killing Stealth Breaches The hardest part of cybersecurity isn’t the technology, it’s the people. Every major breach you’ve read about lately usually starts the same way: one employee, one clever email, and one “Patient Zero” infection. In 2026, hackers are using AI to make these “first…
-
PAN-OS RCE Exploit Under Active Use Enabling Root Access and Espionage
PAN-OS RCE Exploit Under Active Use Enabling Root Access and Espionage Palo Alto Networks has disclosed that threat actors may have attempted to unsuccessfully exploit a recently disclosed critical security flaw as early as April 9, 2026. The vulnerability in question is CVE-2026-0300 (CVSS score: 9.3/8.7), a buffer overflow vulnerability in the User-ID Authentication Portal…
-
ThreatsDay Bulletin: Edge Plaintext Passwords, ICS 0-Days, Patch-or-Die Alerts and 25+ New Stories
ThreatsDay Bulletin: Edge Plaintext Passwords, ICS 0-Days, Patch-or-Die Alerts and 25+ New Stories Bad week. Turns out the easiest way to get hacked in 2026 is still the same old garbage: shady packages, fake apps, forgotten DNS junk, scam ads, and stolen logins getting dumped into Discord channels like it’s normal. Some of these attack…
-
Donuts and Beagles: Fake Claude site spreads backdoor
Donuts and Beagles: Fake Claude site spreads backdoor <p>A malicious imitation of Anthropic’s Claude site leads to DLL sideloading – and a backdoor</p> Categories: Threat Research Tags: Claude, Beagle, Backdoor, malvertising, AI, DONUT, DLL sideloading, Sophos X-Ops Go to sophos
-
Smart Glasses for the Authorities
Smart Glasses for the Authorities ICE is developing its own version of smart glasses, with facial recognition tied to various databases. Bruce Schneier Go to bruce schneier
-
ISC Stormcast For Friday, May 8th, 2026 https://isc.sans.edu/podcastdetail/9924, (Fri, May 8th)
ISC Stormcast For Friday, May 8th, 2026 https://isc.sans.edu/podcastdetail/9924, (Fri, May 8th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Canvas Breach Disrupts Schools & Colleges Nationwide
Canvas Breach Disrupts Schools & Colleges Nationwide An ongoing data extortion attack targeting the widely-used education technology platform Canvas disrupted classes and coursework at school districts and universities across the United States today, after a cybercrime group defaced the service’s login page with a ransom demand that threatened to leak data from 275 million students…
-
After Replacing TeamPCP Malware, ‘PCPJack’ Steals Cloud Secrets
After Replacing TeamPCP Malware, ‘PCPJack’ Steals Cloud Secrets PCPJack makes innovative use of parquet files for stealthy, pre-validated target discovery as it canvasses multiple cloud environments. Nate Nelson Go to gbhackers.com
-
Has CISA Finally Found Its New Leader in Tom Parker?
Has CISA Finally Found Its New Leader in Tom Parker? Dark Reading investigates rumors that Tom Parker, a board room ‘operator’ and longtime cyber exec, could be next in line to take over CISA. Becky Bracken Go to gbhackers.com
-
World’s First AI-Driven Cyberattack Couldn’t Breach OT Systems
World’s First AI-Driven Cyberattack Couldn’t Breach OT Systems The most sophisticated AI-integrated campaign to date hit a brick wall in the form of a SCADA login screen. Nate Nelson Go to gbhackers.com
-
‘TrustFall’ Exposes Claude Code Execution Risk
‘TrustFall’ Exposes Claude Code Execution Risk Researchers find malicious repositories can trigger code execution in Claude Code with minimal or no user interaction. Jai Vijayan Go to gbhackers.com
-
Claude and SpaceX Join Forces to Enhance Large-Scale Compute Capacity
Claude and SpaceX Join Forces to Enhance Large-Scale Compute Capacity Anthropic has officially announced a massive strategic partnership with SpaceX to expand its computing capabilities significantly. This collaboration aims to provide the necessary infrastructure… Delivered by PolitePaul service Go to gbhackers.com
-
Spring Vulnerabilities Open Door to Arbitrary File Access and GCP Secret Leaks
Spring Vulnerabilities Open Door to Arbitrary File Access and GCP Secret Leaks Security researchers have identified four new vulnerabilities in the Spring Cloud Config Server, ranging from medium to critical severity. These newly disclosed flaws could… Delivered by PolitePaul service Go to gbhackers.com
-
Fake Claude AI Installers Used to Spread Malware in New Cyber Scam
Fake Claude AI Installers Used to Spread Malware in New Cyber Scam Hackers are abusing fake Claude AI installer pages promoted through Google Ads to trick users into running malware in a campaign. The operation combines… Delivered by PolitePaul service Go to gbhackers.com
-
Scammers Exploit Disposable VoIP Numbers to Bypass Reputation Blocking
Scammers Exploit Disposable VoIP Numbers to Bypass Reputation Blocking New tactics used by threat actors who embed phone numbers in scam emails as a key indicator of compromise (IOC), revealing how attackers exploit… Delivered by PolitePaul service Go to gbhackers.com
-
Google Chrome 148 Released With Fixes for 127 Security Flaws
Google Chrome 148 Released With Fixes for 127 Security Flaws Google has officially rolled out Chrome version 148 to the stable channel, delivering a massive security overhaul that addresses 127 vulnerabilities across Windows, Mac,… Delivered by PolitePaul service Go to gbhackers.com
-
Fake Claude AI website delivers new ‘Beagle’ Windows malware
Fake Claude AI website delivers new ‘Beagle’ Windows malware A fake version for the Claude AI website offers a malicious Claude-Pro Relay download that pushes a previously undocumented backdoor for Windows named Beagle. […] Bill Toulas Go to bleepingcomputer
-
Hackers abuse Google ads for GoDaddy ManageWP login phishing
Hackers abuse Google ads for GoDaddy ManageWP login phishing A phishing campaign delivered through Google sponsored search results is targeting credentials for ManageWP, GoDaddy’s platform for managing fleets of WordPress websites. […] Bill Toulas Go to bleepingcomputer
-
Critical vm2 sandbox bug lets attackers execute code on hosts
Critical vm2 sandbox bug lets attackers execute code on hosts A critical vulnerability in the popular Node.js sandboxing library vm2 allows escaping the sandbox and executing arbitrary code on the host system. […] Bill Toulas Go to bleepingcomputer
-
New Cisco DoS flaw requires manual reboot to revive devices
New Cisco DoS flaw requires manual reboot to revive devices Cisco patched a Crosswork Network Controller and Network Services Orchestrator denial-of-service vulnerability that requires manually rebooting targeted systems for recovery. […] Sergiu Gatlan Go to bleepingcomputer
-
DAEMON Tools devs confirm breach, release malware-free version
DAEMON Tools devs confirm breach, release malware-free version Disc Soft Limited, the maker of DAEMON Tools Lite, confirmed that the software had been trojanized in a supply chain attack and released a new, malware-free version. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers Used Claude AI to Attack on Water and Drainage Utility Systems
Hackers Used Claude AI to Attack on Water and Drainage Utility Systems A new threat intelligence report has revealed that an unknown group of hackers used a commercial AI tool to target the systems of a municipal water and drainage utility in Monterrey, Mexico. The attack, which took place in January 2026, marks one of…
-
Critical Ollama Memory Leak Vulnerability Exposes 300,000 Servers Globally
Critical Ollama Memory Leak Vulnerability Exposes 300,000 Servers Globally A major security flaw has placed Ollama, one of the most widely used platforms for running local AI models, at risk of a high-profile exposure event. The issue, dubbed “Bleeding Llama,” allows unauthenticated attackers to access the Ollama process and extract sensitive data directly from memory,…
-
Microsoft Teams for Android Allow Users to Join Third-Party Meetings via SIP
Microsoft Teams for Android Allow Users to Join Third-Party Meetings via SIP Microsoft is expanding interoperability in its mobile communication ecosystem by allowing Microsoft Teams users on Android devices to join third-party meetings via the Session Initiation Protocol (SIP). Recently detailed on the Microsoft 365 roadmap, this upcoming feature addresses a major enterprise demand for…
-
New ClickFix Attack Targets macOS Users With Fake Disk Cleanup and Utility Lures
New ClickFix Attack Targets macOS Users With Fake Disk Cleanup and Utility Lures A new wave of cyberattacks is putting macOS users in the crosshairs, and this time the bait looks almost too familiar. Attackers are disguising their malware as helpful disk cleanup tools and system utilities, tricking people into running dangerous commands directly on…
-
Massive 2.45B-Request DDoS Attack Used 1.2 Million IPs to Evade Rate Limits
Massive 2.45B-Request DDoS Attack Used 1.2 Million IPs to Evade Rate Limits Distributed Denial of Service (DDoS) campaign targeted a large-scale user-generated content platform, unleashing over 2.45 billion malicious requests in just five hours. Rather than relying on brute-force methods, the attackers distributed traffic across 1.2 million unique IP addresses. This structural shift exposed a fundamental…
-
vm2 Node.js Library Vulnerabilities Enable Sandbox Escape and Arbitrary Code Execution
vm2 Node.js Library Vulnerabilities Enable Sandbox Escape and Arbitrary Code Execution A dozen critical security vulnerabilities have been disclosed in the vm2 Node.js library that could be exploited by bad actors to break out of the sandbox and execute arbitrary code on susceptible systems. vm2 is an open-source library used to run untrusted JavaScript code…
-
Mirai-Based xlabs_v1 Botnet Exploits ADB to Hijack IoT Devices for DDoS Attacks
Mirai-Based xlabs_v1 Botnet Exploits ADB to Hijack IoT Devices for DDoS Attacks Cybersecurity researchers have exposed a new Mirai-derived botnet that self-identifies as xlabs_v1 and targets internet-exposed devices running Android Debug Bridge (ADB) to enlist them in a network capable of carrying out distributed denial-of-service (DDoS) attacks. Hunt.io, which detailed the malware, said it made…
-
MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware Attack
MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware Attack The Iranian state-sponsored hacking group known as MuddyWater (aka Mango Sandstorm, Seedworm, and Static Kitten) has been attributed to a ransomware attack in what has been described as a “false flag” operation. The attack, observed by Rapid7 in early 2026, has been found…
-
The Hacker News Launches ‘Cybersecurity Stars Awards 2026’ — Submissions Now Open
The Hacker News Launches ‘Cybersecurity Stars Awards 2026’ — Submissions Now Open For nearly 20 years, we at The Hacker News have mostly told scary stories about cyberspace — big hacks, broken systems, and new threats. But behind every headline, there’s a quieter, better story. It’s the story of leaders making tough calls under pressure,…
-
Your AI Agents Are Already Inside the Perimeter. Do You Know What They’re Doing?
Your AI Agents Are Already Inside the Perimeter. Do You Know What They’re Doing? Analysts recently confirmed what identity security teams have quietly feared: AI agents are being deployed faster than enterprises can govern them. In their inaugural Market Guide for Guardian Agents, Gartner states that “enterprise adoption of AI agents is accelerating, outpacing maturity…
-
Rowhammer Attack Against NVIDIA Chips
Rowhammer Attack Against NVIDIA Chips A new rowhammer attack gives complete control of NVIDIA CPUs. On Thursday, two research teams, working independently of each other, demonstrated attacks against two cards from Nvidia’s Ampere generation that take GPU rowhammering into new—and potentially much more consequential—territory: GDDR bitflips that give adversaries full control of CPU memory, resulting…
-
ISC Stormcast For Thursday, May 7th, 2026 https://isc.sans.edu/podcastdetail/9922, (Thu, May 7th)
ISC Stormcast For Thursday, May 7th, 2026 https://isc.sans.edu/podcastdetail/9922, (Thu, May 7th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
An Adaptive Cyber Analytics UI for Web Honeypot Logs [Guest Diary], (Wed, May 6th)
An Adaptive Cyber Analytics UI for Web Honeypot Logs [Guest Diary], (Wed, May 6th) [This is a Guest Diary by Eric Roldan, an ISC intern as part of the SANS.edu BACS program] Through the expansion of Large Language Models (LLMs), cybersecurity has exploded with a variety of tools for both offensive and defensive purposes. A…
-
ISC Stormcast For Wednesday, May 6th, 2026 https://isc.sans.edu/podcastdetail/9920, (Wed, May 6th)
ISC Stormcast For Wednesday, May 6th, 2026 https://isc.sans.edu/podcastdetail/9920, (Wed, May 6th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Cleartext Passwords in MS Edge? In 2026?, (Mon, May 4th)
Cleartext Passwords in MS Edge? In 2026?, (Mon, May 4th) Yup, that is for real. For me, this started with a post in X at hxxps://x.com/intcyberdigest/status/2051406295828250963?s=61 , which highlighted research by @L1v1ng0ffTh3L4N that found exactly this issue. Edge stores all of your browser passwords in clear text, even if you haven’t used them in this session, y’know, just…
-
SSL.com rotates their root certificate today, (Tue, May 5th)
SSL.com rotates their root certificate today, (Tue, May 5th) I just got an email from SSL.com last night, they are rotating out their root certificate today (May 5,2026). This is normal, business as usual stuff for a CA, but certificates get used for all kinds of things, and sometimes they aren’t used like they should…
-
Weekly Update 502
Weekly Update 502 It’s a fascinating display of leverage: the ShinyHunters folks, with very limited resources and experience (their demographic will be teenagers to their early 20s), consistently gaining access to the data of massive brands. Not through technical ingenuity alone (although I’m sure there’s a portion of that), but primarily through good ol’ social…
-
Yet Another Way to Bypass Google Chrome’s Encryption Protection
Yet Another Way to Bypass Google Chrome’s Encryption Protection Authors of the VoidStealer Trojan uncovered a way to get around Google’s App-Bound Encryption (ABE), opening the door to infostealers. Jai Vijayan Go to gbhackers.com
-
Instructure Breach Exposes Schools’ Vendor Dependence
Instructure Breach Exposes Schools’ Vendor Dependence ShinyHunters’ attack on Instructure, which owns the widely used Canvas learning management system (LMS), carries big questions about the trust educational institutions put into their vendors. Alexander Culafi Go to gbhackers.com
-
From Stuxnet to ChatGPT: 20 News Events That Shaped Cyber
From Stuxnet to ChatGPT: 20 News Events That Shaped Cyber As part of Dark Reading’s 20th anniversary celebration, its staff looks back on 20 of the biggest newmaking events from the past two decades that shaped our industry and the risk landscape for today’s security teams. Dark Reading Editorial Team Go to gbhackers.com
-
Salesforce Marketing Cloud Vulnerability Exposes Email Data Risk
Salesforce Marketing Cloud Vulnerability Exposes Email Data Risk Salesforce Marketing Cloud (SFMC) recently patched a cluster of high‑impact vulnerabilities that could have allowed attackers to read and enumerate marketing emails and subscriber… Delivered by PolitePaul service Go to gbhackers.com
-
Argo CD ServerSideDiff Flaw Allows Attackers to Extract Kubernetes Secrets
Argo CD ServerSideDiff Flaw Allows Attackers to Extract Kubernetes Secrets A critical vulnerability has been identified in Argo CD that could allow attackers with minimal privileges to extract highly sensitive Kubernetes Secrets directly from… Delivered by PolitePaul service Go to gbhackers.com
-
QLNX Targets Developers in Supply Chain Credential Theft Campaign
QLNX Targets Developers in Supply Chain Credential Theft Campaign QLNX is a newly documented Linux remote access trojan (RAT) that targets the theft on developers’ and DevOps credentials to hijack software supply chains. Recent… Delivered by PolitePaul service Go to gbhackers.com
-
Ransomware Gang Member Linked to Russian Cybercrime Group Sentenced to Prison
Ransomware Gang Member Linked to Russian Cybercrime Group Sentenced to Prison A Latvian national operating from Moscow has been sentenced to 102 months in federal prison for his role as a key negotiator within a… Delivered by PolitePaul service Go to gbhackers.com
-
Iran-Linked Hackers Target Oman Ministries in Webshell and Data Theft Campaign
Iran-Linked Hackers Target Oman Ministries in Webshell and Data Theft Campaign Iran-linked operators have mounted a broad espionage operation against multiple Omani ministries, abusing exposed webshells, SQL escalation scripts, and a poorly secured C2 server… Delivered by PolitePaul service Go to gbhackers.com
-
Palo Alto Networks warns of firewall RCE zero-day exploited in attacks
Palo Alto Networks warns of firewall RCE zero-day exploited in attacks Palo Alto Networks warned customers today that a critical-severity unpatched vulnerability in the PAN-OS User-ID Authentication Portal is being exploited in attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
New stealthy Quasar Linux malware targets software developers
New stealthy Quasar Linux malware targets software developers A previously undocumented Linux implant named Quasar Linux (QLNX) is targeting developers’ systems with a mix of rootkit, backdoor, and credential-stealing capabilities. […] Bill Toulas Go to bleepingcomputer
-
Instructure hacker claims data theft from 8,800 schools, universities
Instructure hacker claims data theft from 8,800 schools, universities The hacker behind a breach at education technology giant Instructure claims to have stolen 280 million data records for students and staff from 8,809 colleges, school districts, and online education platforms. […] Lawrence Abrams Go to bleepingcomputer
-
DAEMON Tools trojanized in supply-chain attack to deploy backdoor
DAEMON Tools trojanized in supply-chain attack to deploy backdoor Hackers trojanized installers for the DAEMON Tools software and since April 8, delivered a backdoor to thousands of systems that downloaded the product from the official website. […] Bill Toulas Go to bleepingcomputer
-
Student hacked Taiwan high-speed rail to trigger emergency brakes
Student hacked Taiwan high-speed rail to trigger emergency brakes A 23-year-old university student in Taiwan was arrested for interfering with the TETRA communication system used by the country’s high-speed railway network (THSR). […] Bill Toulas Go to bleepingcomputer
-
Azure AD Conditional Access Bypassed Via Phantom Device Registration and PRT Abuse
Azure AD Conditional Access Bypassed Via Phantom Device Registration and PRT Abuse Cloud identity security relies heavily on Microsoft Entra ID (formerly Azure AD) Conditional Access. It acts as the primary digital gatekeeper, checking user locations, calculating risk scores, and verifying device health before granting access. However, an authorized red team engagement by Howler Cell…
-
Ransomware and Data Extortion Groups Intensify Targeting of Aviation and Aerospace Sector
Ransomware and Data Extortion Groups Intensify Targeting of Aviation and Aerospace Sector The aviation and aerospace sector has become one of the most actively targeted industries by ransomware operators and data extortion groups in 2025 and 2026. From passenger-processing platforms to satellite-dependent navigation systems, attackers are finding that disrupting even a single vendor in the…
-
Critical Palo Alto Firewalls Vulnerability Exploited in the Wild to Gain Root Access
Critical Palo Alto Firewalls Vulnerability Exploited in the Wild to Gain Root Access Palo Alto Networks has disclosed a critical buffer overflow vulnerability in PAN-OS software, tracked as CVE-2026-0300, that is already being actively exploited in the wild. The flaw carries a CVSS 4.0 score of 9.3 (CRITICAL) and allows unauthenticated attackers to execute arbitrary…
-
Low Noise, High Confidence: Optimizing SOC Costs with Better Threat Intelligence
Low Noise, High Confidence: Optimizing SOC Costs with Better Threat Intelligence Robust defense systems are built on a clear understanding of current threats and the ability to translate it into consistent decisions and measurable outcomes at optimal cost. High-performing SOCs achieve this by eliminating unnecessary work and operationalizing threat data. At the core of this model lies threat intelligence that is: Relevant to active threats Actionable within existing workflows Curated to reduce false alerts Not all threat data sources meet these…
-
GnuTLS 3.8.13 Released with Fix for 12 Vulnerabilities Affecting Network Communications
GnuTLS 3.8.13 Released with Fix for 12 Vulnerabilities Affecting Network Communications GnuTLS version 3.8.13 has been officially released to patch a dozen security vulnerabilities, including critical flaws affecting secure network communications. The update is highly recommended for all systems using GnuTLS, as it addresses memory corruption, authentication bypasses, and certificate validation errors. Four vulnerabilities discovered…
-
A rigged game: ScarCruft compromises gaming platform in a supply-chain attack
A rigged game: ScarCruft compromises gaming platform in a supply-chain attack ESET researchers have investigated an ongoing attack by the ScarCruft APT group that targets the Yanbian region via backdoor-laced Windows and Android games Go to eset
-
Critical Apache HTTP/2 Flaw (CVE-2026-23918) Enables DoS and Potential RCE
Critical Apache HTTP/2 Flaw (CVE-2026-23918) Enables DoS and Potential RCE The Apache Software Foundation (ASF) has released security updates to address several security vulnerabilities in the HTTP Server, including a severe vulnerability that could potentially lead to remote code execution (RCE). The vulnerability, tracked as CVE-2026-23918 (CVSS score: 8.8), has been described as a case…
-
DAEMON Tools Supply Chain Attack Compromises Official Installers with Malware
DAEMON Tools Supply Chain Attack Compromises Official Installers with Malware A newly identified supply chain attack targeting DAEMON Tools software has compromised its installers to serve a malicious payload, according to findings from Kaspersky. “These installers are distributed from the legitimate website of DAEMON Tools and are signed with digital certificates belonging to DAEMON Tools…
-
China-Linked UAT-8302 Targets Governments Using Shared APT Malware Across Regions
China-Linked UAT-8302 Targets Governments Using Shared APT Malware Across Regions A sophisticated China-nexus advanced persistent threat (APT) group has been attributed to attacks targeting government entities in South America since at least late 2024 and government agencies in southeastern Europe in 2025. The activity is being tracked by Cisco Talos under the moniker UAT-8302, with…
-
The Back Door Attackers Know About — and Most Security Teams Still Haven’t Closed
The Back Door Attackers Know About — and Most Security Teams Still Haven’t Closed Every AI tool, workflow automation, and productivity app your employees connected to Google or Microsoft this year left something behind: a persistent OAuth token with no expiration date, no automatic cleanup, and in most organizations, no one watching it. Your perimeter…
-
MetInfo CMS CVE-2026-29014 Exploited for Remote Code Execution Attacks
MetInfo CMS CVE-2026-29014 Exploited for Remote Code Execution Attacks Threat actors are actively exploiting a critical security flaw impacting an open-source content management system (CMS) known as MetInfo, according to new findings from VulnCheck. The vulnerability in question is CVE-2026-29014 (CVSS score: 9.8), a code injection flaw that could result in arbitrary code execution. “MetInfo…
-
Middle East Cyber Battle Field Broadens — Especially in UAE
Middle East Cyber Battle Field Broadens — Especially in UAE As the war with Iran continues, breach attempts targeting the United Arab Emirates tripled in a few weeks — many targeting critical infrastructure. Robert Lemos Go to gbhackers.com
-
DarkSword Malware
DarkSword Malware DarkSword is a sophisticated piece of malware—probably government designed—that targets iOS. Google Threat Intelligence Group (GTIG) has identified a new iOS full-chain exploit that leveraged multiple zero-day vulnerabilities to fully compromise devices. Based on toolmarks in recovered payloads, we believe the exploit chain to be called DarkSword. Since at least November 2025, GTIG…
-
174: Pacific Rim
174: Pacific Rim For six years, Sophos fought a secret cyber war against a state-backed hacking group targeting its firewalls. This forced Sophos to drastically change tactics to properly secure their firewalls. Was it ethical? Was it effective? They disrupted nine zero-day attacks, exposed who was hacking them, and forced the hackers to change tactics.…
-
Trellix Source Code Breach Highlights Growing Supply Chain Threats
Trellix Source Code Breach Highlights Growing Supply Chain Threats Info is scant, but such breaches can reveal where a security product’s controls are located and how detections are designed, giving attackers a leg up. Rob Wright Go to gbhackers.com
-
Microsoft Edge Stores Passwords in Process Memory, Posing Enterprise Risk
Microsoft Edge Stores Passwords in Process Memory, Posing Enterprise Risk A proof-of-concept exploit (PoC) shows how someone with admin privileges can exploit the issue to steal passwords, and thus use them to engage in further malicious activity. Elizabeth Montalbano Go to gbhackers.com
-
How the Story of a USB Penetration Test Went Viral
How the Story of a USB Penetration Test Went Viral Two decades ago Dark Reading posted its first blockbuster — a story from a pen tester who sprinkled rigged thumb drives around a credit union parking lot and let curious employees do the rest. This episode looks back at the history-making column with its author…
-
WhatsApp Security Flaw Enables Malicious URL Execution Through Instagram Reels
WhatsApp Security Flaw Enables Malicious URL Execution Through Instagram Reels WhatsApp has recently patched two notable security vulnerabilities that could have allowed attackers to execute malicious links and disguise dangerous files. The most alarming… Delivered by PolitePaul service Go to gbhackers.com
-
Education Sector Hit by Espionage, Phishing, and Supply Chain Attacks
Education Sector Hit by Espionage, Phishing, and Supply Chain Attacks Educational institutions are now facing a coordinated mix of state espionage, spear‑phishing, and supply chain intrusions, even as classic ransomware and vulnerability volumes show… Delivered by PolitePaul service Go to gbhackers.com
-
Code of Conduct Phish Hits 35,000 Users in Multi-Stage AiTM Attack
Code of Conduct Phish Hits 35,000 Users in Multi-Stage AiTM Attack A highly sophisticated phishing campaign leveraging code-of-conduct-themed lures has targeted more than 35,000 users across 13,000 organizations. The multi-stage attack, observed between April 14 and… Delivered by PolitePaul service Go to gbhackers.com
-
Qualcomm Chipset Vulnerabilities Raise Alarm Over Remote Code Execution Risk
Qualcomm Chipset Vulnerabilities Raise Alarm Over Remote Code Execution Risk Qualcomm Technologies has released its May 2026 security bulletin, addressing a sweeping array of vulnerabilities across its proprietary and open-source software ecosystems. Threat actors… Delivered by PolitePaul service Go to gbhackers.com
-
Attackers Exploit Amazon SES to Send Authenticated Phishing Emails
Attackers Exploit Amazon SES to Send Authenticated Phishing Emails Attackers are increasingly abusing Amazon Simple Email Service (SES) to deliver highly convincing phishing emails that bypass traditional security controls, marking a growing trend… Delivered by PolitePaul service Go to gbhackers.com
-
ScarCruft hackers push BirdCall Android malware via game platform
ScarCruft hackers push BirdCall Android malware via game platform The North Korean hacker group APT37 has been delivering an Android version of a backdoor called BirdCall in a supply-chain attack through a video game platform. […] Bill Toulas Go to bleepingcomputer
-
Weaver E-cology critical bug exploited in attacks since March
Weaver E-cology critical bug exploited in attacks since March Hackers have been exploiting a critical vulnerability (CVE-2026-22679) in the Weaver E-cology office automation since mid-March to run discovery commands. […] Bill Toulas Go to bleepingcomputer
-
Amazon SES increasingly abused in phishing to evade detection
Amazon SES increasingly abused in phishing to evade detection The Amazon Simple Email Service (SES) is being increasingly abused to send convincing phishing emails that can bypass standard security filters and render reputation-based blocks ineffective. […] Bill Toulas Go to bleepingcomputer
-
Backdoored PyTorch Lightning package drops credential stealer
Backdoored PyTorch Lightning package drops credential stealer A malicious version of the PyTorch Lightning package published on the Python Package Index (PyPI) delivers a credential-stealing payload targeting browsers, environment files, and cloud services. […] Bill Toulas Go to bleepingcomputer
-
Trellix discloses data breach after source code repository hack
Trellix discloses data breach after source code repository hack Cybersecurity firm Trellix disclosed a data breach after attackers gained access to “a portion” of its source code repository. […] Sergiu Gatlan Go to bleepingcomputer
-
Beware of Fake ‘Notepad++ for Mac’ Website, Possibly Could Harm your Machine
Beware of Fake ‘Notepad++ for Mac’ Website, Possibly Could Harm your Machine A fake website claiming to offer an official macOS version of the popular text editor Notepad++ has been making rounds online, raising serious cybersecurity concerns across the tech community. The site, operating under the domain notepad-plus-plus-mac.org, falsely presents itself as the official release…
-
Critical Android Zero-Click Vulnerability Grants Remote Shell Access
Critical Android Zero-Click Vulnerability Grants Remote Shell Access Google has published the May 2026 Android Security Bulletin, alerting the ecosystem to a highly severe remote code execution (RCE) flaw. Tracked as CVE-2026-0073, this critical vulnerability resides deep within the core Android System component. It allows an attacker to gain remote shell access without requiring a…
-
pnpm 11 Turns On Minimum Release Age by Default to Reduce npm Supply Chain Risk
pnpm 11 Turns On Minimum Release Age by Default to Reduce npm Supply Chain Risk The npm ecosystem has long been a target for supply chain attacks, where threat actors exploit the open nature of public package registries to push malicious code into developer environments. With pnpm 11, the package manager takes a direct step…
-
Microsoft Edge Stores All Saved Passwords in Cleartext Process Memory at Launch
Microsoft Edge Stores All Saved Passwords in Cleartext Process Memory at Launch A security researcher has discovered that Microsoft Edge decrypts every stored password into process memory the moment the browser launches and keeps them there as cleartext, regardless of whether the user ever visits those sites. The finding, disclosed on April 29 by PaloAltoNtwks…
-
Critical Apache HTTP Server Flaw Exposes Millions of Servers to RCE Attacks
Critical Apache HTTP Server Flaw Exposes Millions of Servers to RCE Attacks The Apache Software Foundation has released a critical security update for Apache HTTP Server, patching five vulnerabilities, including a dangerous double-free flaw capable of enabling Remote Code Execution (RCE) in version 2.4.67, released on May 4, 2026. All users running version 2.4.66 or…
-
TR-26-0161 (D Link Çoklu Ürün Güvenlik Bildirimi)
TR-26-0161 (D Link Çoklu Ürün Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0160 (OPPO ColorOS Assistant Güvenlik Zafiyeti)
TR-26-0160 (OPPO ColorOS Assistant Güvenlik Zafiyeti) Go to usom.gov
-
TR-26-0159 (GnuTLS Güvenlik Bildirimi)
TR-26-0159 (GnuTLS Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0158 (Notepad++ Güvenlik Bildirimi)
TR-26-0158 (Notepad++ Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0157 (n8n Otomasyon Güvenlik Zafiyeti)
TR-26-0157 (n8n Otomasyon Güvenlik Zafiyeti) Go to usom.gov
-
Phishing Campaign Hits 80+ Orgs Using SimpleHelp and ScreenConnect RMM Tools
Phishing Campaign Hits 80+ Orgs Using SimpleHelp and ScreenConnect RMM Tools An active phishing campaign has been observed targeting multiple vectors since at least April 2025 with legitimate Remote Monitoring and Management (RMM) software as a way to establish persistent remote access to compromised hosts. The activity, codenamed VENOMOUS#HELPER, has impacted over 80 organizations, most…
-
Progress Patches Critical MOVEit Automation Bug Enabling Authentication Bypass
Progress Patches Critical MOVEit Automation Bug Enabling Authentication Bypass Progress Software has released updates to address two security flaws in MOVEit Automation, including a critical bug that could result in an authentication bypass. MOVEit Automation (formerly Central) is a secure, server-based managed file transfer (MFT) solution used to schedule and automate file movement workflows in…
-
⚡ Weekly Recap: AI-Powered Phishing, Android Spying Tool, Linux Exploit, GitHub RCE & More
⚡ Weekly Recap: AI-Powered Phishing, Android Spying Tool, Linux Exploit, GitHub RCE & More This week, the shadows moved faster than the patches. While most teams were still triaging last month’s alerts, attackers had already turned control panels into kill switches, kernels into open doors, and open-source pipelines into silent delivery systems. The game has…
-
2026: The Year of AI-Assisted Attacks
2026: The Year of AI-Assisted Attacks On December 4, 2025, a 17-year-old was arrested in Osaka under Japan’s Unauthorized Access Prohibition Act. The young man had run malicious code to extract the personal data of over 7 million users of Kaikatsu Club, Japan’s largest internet cafe chain. When asked, the young man shared his motivation…
-
Silver Fox Deploys ABCDoor Malware via Tax-Themed Phishing in India and Russia
Silver Fox Deploys ABCDoor Malware via Tax-Themed Phishing in India and Russia The China-based cybercrime group known as Silver Fox has been linked to a new campaign targeting organizations in Russia and India with a new malware called ABCDoor. The activity involved using phishing emails that mimic correspondence from the Income Tax Department of India…
-
Hacking Polymarket
Hacking Polymarket Polymarket is a platform where people can bet on real-world events, political and otherwise. Leaving the ethical considerations of this aside (for one, it facilitates assassination), one of the issues with making this work is the verification of these real-world events. Polymarket gamblers have threatened a journalist because his story was being used…
-
Teenager alleged to be Scattered Spider hacker arrested in Finland, faces US extradition
Teenager alleged to be Scattered Spider hacker arrested in Finland, faces US extradition Here’s a tip for you all. Unless you want to draw attention to yourself as a cybercriminal, don’t flaunt your diamond-encrusted “HACK THE PLANET” necklace on Snapchat, or pose as a Sopranos crime boss while the FBI is reportedly closing in. Read…
-
RMM Tools Fuel Stealthy Phishing Campaign
RMM Tools Fuel Stealthy Phishing Campaign Attackers are abusing two remote monitoring and management (RMM) tools to evade detection in a campaign that has impacted over 80 organizations so far. Jai Vijayan Go to gbhackers.com