no alarms and no surprises please..
-
Novel KarstoRAT RAT Enables Webcam Monitoring, Audio Recording, and Remote Payload Execution
Novel KarstoRAT RAT Enables Webcam Monitoring, Audio Recording, and Remote Payload Execution A newly identified remote access trojan called KarstoRAT has been found in sandbox analyses and malware repositories since early 2026. The malware gives attackers a broad set of remote-control capabilities over compromised Windows machines, including webcam capture, audio recording, keylogging, screenshot theft, and…
-
TR-26-0132 (Google Chrome Güvenlik Bildirimi)
TR-26-0132 (Google Chrome Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0131 (TÜBİTAK BİLGEM YTE – Pardus Güvenlik Bildirimi)
TR-26-0131 (TÜBİTAK BİLGEM YTE – Pardus Güvenlik Bildirimi) Go to usom.gov
-
SAP-Related npm Packages Compromised in Credential-Stealing Supply Chain Attack
SAP-Related npm Packages Compromised in Credential-Stealing Supply Chain Attack Cybersecurity researchers are sounding the alarm about a new supply chain attack campaign targeting SAP-related npm Packages with credential-stealing malware. According to reports from Aikido Security, SafeDep, Socket, StepSecurity, and Google-owned Wiz, the campaign – calling itself the mini Shai-Hulud – has affected the following packages…
-
New Wave of DPRK Attacks Uses AI-Inserted npm Malware, Fake Firms, and RATs
New Wave of DPRK Attacks Uses AI-Inserted npm Malware, Fake Firms, and RATs Cybersecurity researchers have discovered malicious code in an npm package after a malicious package as a dependency to the project by Anthropic’s Claude Opus large language model (LLM). The package in question is “@validate-sdk/v2,” which is listed on npm as a utility…
-
Webinar: How to Automate Exposure Validation to Match the Speed of AI Attacks
Webinar: How to Automate Exposure Validation to Match the Speed of AI Attacks In February 2026, researchers uncovered a shift that completely changed the game: threat actors are now using custom AI setups to automate attacks directly into the kill chain. We aren’t just talking about AI writing better phishing emails anymore. We’re talking about…
-
What to Look for in an Exposure Management Platform (And What Most of Them Get Wrong)
What to Look for in an Exposure Management Platform (And What Most of Them Get Wrong) Every security team has a version of the same story. The quarter ends with hundreds of vulnerabilities closed. The dashboards are bursting with green. Then someone in a leadership meeting asks: “So, are we actually safer now?” Crickets. The…
-
Critical cPanel Authentication Vulnerability Identified — Update Your Server Immediately
Critical cPanel Authentication Vulnerability Identified — Update Your Server Immediately cPanel has released security updates to address a security issue impacting various authentication paths that could allow an attacker to obtain access to the control panel software. The problem affects all currently supported versions of cPanel and WebHost Manager (WHM), according to an alert published…
-
Claude Mythos Has Found 271 Zero-Days in Firefox
Claude Mythos Has Found 271 Zero-Days in Firefox That’s a lot. No, it’s an extraordinary number: Since February, the Firefox team has been working around the clock using frontier AI models to find and fix latent security vulnerabilities in the browser. We wrote previously about our collaboration with Anthropic to scan Firefox with Opus 4.6,…
-
ISC Stormcast For Thursday, April 30th, 2026 https://isc.sans.edu/podcastdetail/9912, (Thu, Apr 30th)
ISC Stormcast For Thursday, April 30th, 2026 https://isc.sans.edu/podcastdetail/9912, (Thu, Apr 30th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Danger of Libredtail [Guest Diary], (Wed, Apr 29th)
Danger of Libredtail [Guest Diary], (Wed, Apr 29th) [This is a Guest Diary by James Roberts, an ISC intern as part of the SANS.edu BACS program] Over the last few months, I have gained valuable experience working with the Internet Storm Center (ISC) operating a honeypot and analyzing its output via a SIEM environment. This…
-
Today’s Odd Web Requests, (Wed, Apr 29th)
Today’s Odd Web Requests, (Wed, Apr 29th) Today, two different “new” requests hit our honeypots. Both appear to be recon requests and not associated with specific vulnerabilities. But as always, please let me know if you have additional information 1 – Broadcom API Gateway GET /bam/restart/if/required Host: [redacted]:8080 Connection: close This request is targeting a Broadcom API…
-
Smashing Security podcast #465: This developer wanted to cheat at Roblox. It cost millions
Smashing Security podcast #465: This developer wanted to cheat at Roblox. It cost millions A developer at an AI startup wanted to cheat at Roblox. They downloaded a dodgy script on their work laptop. That one decision triggered a cascade of failures that ended with a $2 million data breach affecting hundreds of thousands of…
-
Alleged Silk Typhoon hacker extradited to the United States to face charges
Alleged Silk Typhoon hacker extradited to the United States to face charges A man accused of working as a hacker for China’s Ministry of State Security has been extradited to the USA from Italy, and faces – if found guilty – the prospect of decades behind bars. Read more in my article on the Hot…
-
Claude Mythos Fears Startle Japan’s Financial Services Sector
Claude Mythos Fears Startle Japan’s Financial Services Sector Global financial institutions are panicked over Anthropic’s new superhacker AI model. Cyber experts aren’t quite as worried. Nate Nelson Go to gbhackers.com
-
Reverse Engineering With AI Unearths High-Severity GitHub Bug
Reverse Engineering With AI Unearths High-Severity GitHub Bug Wiz used an AI reverse-engineering tool to pinpoint a vulnerability that previously would have been too costly and time-consuming to undertake. Alexander Culafi Go to gbhackers.com
-
AI Finds 38 Security Flaws in Electronic Health Record Platform
AI Finds 38 Security Flaws in Electronic Health Record Platform Flaws in OpenEMR’s platform — used by more than 100,000 healthcare providers — enabled database compromise, remote code execution, and data theft. Jai Vijayan Go to gbhackers.com
-
Vect 2.0 Ransomware Acts as Wiper, Thanks to Design Error
Vect 2.0 Ransomware Acts as Wiper, Thanks to Design Error The emerging ransomware has been deployed against victims of the TeamPCP supply chain attacks, but organizations should think twice before paying for a decryptor. Elizabeth Montalbano Go to gbhackers.com
-
Lotus Wiper Attack Targeted Venezuelan Energy Firms, Utilities
Lotus Wiper Attack Targeted Venezuelan Energy Firms, Utilities An analysis of the destructive malware reveals sophisticated living-off-the-land (LotL) techniques and detailed strategies for the widespread deletion of data. Robert Lemos Go to gbhackers.com
-
VECT 2.0 Ransomware Wipes Large Files Across Windows, Linux & ESXi
VECT 2.0 Ransomware Wipes Large Files Across Windows, Linux & ESXi The “new” VECT 2.0 ransomware is essentially a cross‑platform data wiper that permanently destroys most enterprise files rather than encrypting them for recovery. For any… Delivered by PolitePaul service Go to gbhackers.com
-
SLOTAGENT Malware Hides API Calls and Strings to Thwart Analysis
SLOTAGENT Malware Hides API Calls and Strings to Thwart Analysis A previously unknown remote access trojan (RAT), dubbed SLOTAGENT, after analyzing a suspicious ZIP archive uploaded from Japan to a public malware repository in early… Delivered by PolitePaul service Go to gbhackers.com
-
Vimeo Confirms Data Breach After Hackers Access User Database
Vimeo Confirms Data Breach After Hackers Access User Database Vimeo has officially confirmed a data breach affecting its user database. The security incident did not originate with Vimeo, but rather with Anodot, a… Delivered by PolitePaul service Go to gbhackers.com
-
LofyStealer Targets Minecraft Players via Node.js Loader and Browser Injection
LofyStealer Targets Minecraft Players via Node.js Loader and Browser Injection Minecraft players are being lured with a fake hacking tool called “Slinky” that secretly installs a powerful infostealer dubbed LofyStealer (also tracked as GrabBot),… Delivered by PolitePaul service Go to gbhackers.com
-
CISA Warns of Windows Shell Zero-Day Exploited in Attacks
CISA Warns of Windows Shell Zero-Day Exploited in Attacks The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert regarding a newly discovered zero-day vulnerability affecting Microsoft Windows. On April 28,… Delivered by PolitePaul service Go to gbhackers.com
-
Microsoft says backend change broke Teams Free chat and calls
Microsoft says backend change broke Teams Free chat and calls Microsoft is working to resolve a known issue that prevents some Microsoft Teams Free users from chatting and calling others. […] Sergiu Gatlan Go to bleepingcomputer
-
Broken VECT 2.0 ransomware acts as a data wiper for large files
Broken VECT 2.0 ransomware acts as a data wiper for large files Researchers are warning that the VECT 2.0 ransomware has a problem in the way it handles encryption nonces that leads to permanently destroying larger files rather than encrypt them. […] Bill Toulas Go to bleepingcomputer
-
Hackers are exploiting a critical LiteLLM pre-auth SQLi flaw
Hackers are exploiting a critical LiteLLM pre-auth SQLi flaw Hackers are targeting sensitive information stored in the LiteLLM open-source large-language model (LLM) gateway by exploiting a critical vulnerability tracked as CVE-2026-42208. […] Bill Toulas Go to bleepingcomputer
-
Video service Vimeo confirms Anodot breach exposed user data
Video service Vimeo confirms Anodot breach exposed user data Vimeo has disclosed that data belonging to some of its customers and users has been accessed without authorization following the recent breach at the Anodot data anomaly detection company. […] Bill Toulas Go to bleepingcomputer
-
US reportedly charges Scattered Spider hacker arrested in Finland
US reportedly charges Scattered Spider hacker arrested in Finland A 19-year-old dual United States and Estonian citizen arrested in Finland earlier this month faces federal charges in the U.S. alleging he was a prolific member of the notorious Scattered Spider hacking collective. […] Sergiu Gatlan Go to bleepingcomputer
-
New Vect 2.0 RaaS Operation Targets Windows, Linux, and ESXi Systems
New Vect 2.0 RaaS Operation Targets Windows, Linux, and ESXi Systems A new ransomware group known as Vect 2.0 has entered the global cyberthreat landscape, operating as a full Ransomware-as-a-Service (RaaS) platform that targets Windows, Linux, and VMware ESXi systems. The group first appeared in December 2025 and rapidly scaled its activity through February 2026,…
-
New VECT 2.0 Ransomware Destroys Files Over 128 KB Across Windows, Linux, and ESXi
New VECT 2.0 Ransomware Destroys Files Over 128 KB Across Windows, Linux, and ESXi A newly documented ransomware strain called VECT 2.0 has drawn serious attention from the cybersecurity community for a deeply damaging flaw in its design. Unlike typical ransomware that locks files and demands payment for decryption, VECT 2.0 permanently destroys any file…
-
New BlueNoroff Campaign Uses Fileless PowerShell and AI-Generated Zoom Lures
New BlueNoroff Campaign Uses Fileless PowerShell and AI-Generated Zoom Lures A dangerous new cyber campaign from North Korea’s Lazarus Group is targeting cryptocurrency and Web3 professionals using fake Zoom meeting interfaces, fileless PowerShell scripts, and AI-generated deepfake content. The group behind this activity is BlueNoroff, a financially motivated subgroup known for stealing digital assets. This…
-
cPanel Warns of Critical Authentication Flaw – Emergency Patch Released
cPanel Warns of Critical Authentication Flaw – Emergency Patch Released Web hosting control panel giant cPanel has issued an emergency security update to address a critical vulnerability affecting its core software. The security flaw directly impacts multiple authentication paths within the cPanel and Web Host Manager (WHM) ecosystem. System administrators and web hosting providers are…
-
New BlobPhish Attack Leverages Browser Blob Objects to Steal Users’ Login Credentials
New BlobPhish Attack Leverages Browser Blob Objects to Steal Users’ Login Credentials A sophisticated, memory-resident phishing campaign called BlobPhish, active since October 2024, that exploits browser Blob URL APIs to silently steal credentials from Microsoft 365 users, major U.S. banks, and financial platforms while remaining almost completely invisible to traditional security tools. BlobPhish is a…
-
TR-26-0130 (D Link Güvenlik Bildirimi)
TR-26-0130 (D Link Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0129 (Mozilla Firefox/Thunderbird/ESR Güvenlik Bildirimi)
TR-26-0129 (Mozilla Firefox/Thunderbird/ESR Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0128 (OpenClaw Güvenlik Zafiyeti)
TR-26-0128 (OpenClaw Güvenlik Zafiyeti) Go to usom.gov
-
TR-26-0127 (NVIDIA NVFlare Dashboard Güvenlik Bildirimi)
TR-26-0127 (NVIDIA NVFlare Dashboard Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0126 (GeoVision GV-IP Device Utility Güvenlik Zafiyeti)
TR-26-0126 (GeoVision GV-IP Device Utility Güvenlik Zafiyeti) Go to usom.gov
-
LiteLLM CVE-2026-42208 SQL Injection Exploited within 36 Hours of Disclosure
LiteLLM CVE-2026-42208 SQL Injection Exploited within 36 Hours of Disclosure In yet another instance of threat actors quickly jumping on the exploitation bandwagon, a newly disclosed critical security flaw in BerriAI’s LiteLLM Python package has come under active exploitation in the wild within 36 hours of the bug becoming public knowledge. The vulnerability, tracked as…
-
Researchers Discover Critical GitHub CVE-2026-3854 RCE Flaw Exploitable via Single Git Push
Researchers Discover Critical GitHub CVE-2026-3854 RCE Flaw Exploitable via Single Git Push Cybersecurity researchers have disclosed details of a critical security vulnerability impacting GitHub.com and GitHub Enterprise Server that could allow an authenticated user to obtain remote code execution with a single “git push” command. The flaw, tracked as CVE-2026-3854 (CVSS score: 8.7), is a…
-
Brazilian LofyGang Resurfaces After Three Years With Minecraft LofyStealer Campaign
Brazilian LofyGang Resurfaces After Three Years With Minecraft LofyStealer Campaign A cybercrime group of Brazilian origin has resurfaced after more than three years to orchestrate a campaign that targets Minecraft players with a new stealer called LofyStealer (aka GrabBot). “The malware disguises itself as a Minecraft hack called ‘Slinky,’” Brazil-based cybersecurity company ZenoX said in…
-
VECT 2.0 Ransomware Irreversibly Destroys Files Over 131KB on Windows, Linux, ESXi
VECT 2.0 Ransomware Irreversibly Destroys Files Over 131KB on Windows, Linux, ESXi Threat hunters are warning that the cybercriminal operation known as VECT 2.0 acts more like a wiper than a ransomware due to a critical flaw in its encryption implementation across Windows, Linux, and ESXi variants that renders recovery impossible even for the threat…
-
Why Secure Data Movement Is the Zero Trust Bottleneck Nobody Talks About
Why Secure Data Movement Is the Zero Trust Bottleneck Nobody Talks About Every security program is betting on the same assumption: once a system is connected, the problem is solved. Open a ticket, stand up a gateway, push the data through. Done. That assumption is wrong. It is also a major reason Zero Trust programs…
-
What Anthropic’s Mythos Means for the Future of Cybersecurity
What Anthropic’s Mythos Means for the Future of Cybersecurity Two weeks ago, Anthropic announced that its new model, Claude Mythos Preview, can autonomously find and weaponize software vulnerabilities, turning them into working exploits without expert guidance. These were vulnerabilities in key software like operating systems and internet infrastructure that thousands of software developers working on…
-
ISC Stormcast For Wednesday, April 29th, 2026 https://isc.sans.edu/podcastdetail/9910, (Wed, Apr 29th)
ISC Stormcast For Wednesday, April 29th, 2026 https://isc.sans.edu/podcastdetail/9910, (Wed, Apr 29th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
HTTP Requests with X-Vercel-Set-Bypass-Cookie Header, (Tue, Apr 28th)
HTTP Requests with X-Vercel-Set-Bypass-Cookie Header, (Tue, Apr 28th) This weekend, we saw a few requests to our honeypot that included an “X-Vercel-Set-Bypass-Cookie” header. A sample request: GET / HTTP/1.1 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/ *;q=0.8 Accept-Language: en-US,en;q=0.5 Accept-Encoding: gzip, deflate, br Cache-Control: no-cache Pragma: no-cache Connection: keep-alive X-Vercel-Set-Bypass-Cookie: samesite-none-secure Upgrade-Insecure-Requests:…
-
ISC Stormcast For Tuesday, April 28th, 2026 https://isc.sans.edu/podcastdetail/9908, (Tue, Apr 28th)
ISC Stormcast For Tuesday, April 28th, 2026 https://isc.sans.edu/podcastdetail/9908, (Tue, Apr 28th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
TeamPCP Supply Chain Campaign: Update 008 – 26-Day Pause Ends with Three Concurrent Compromises (Checkmarx KICS, Bitwarden CLI Cascade, xinference PyPI), CanisterSprawl npm Worm Identified, and Tier 1 Coverage Returns, (Mon, Apr 27th)
TeamPCP Supply Chain Campaign: Update 008 – 26-Day Pause Ends with Three Concurrent Compromises (Checkmarx KICS, Bitwarden CLI Cascade, xinference PyPI), CanisterSprawl npm Worm Identified, and Tier 1 Coverage Returns, (Mon, Apr 27th) This update succeeds TeamPCP Supply Chain Campaign Update 007, published April 8, 2026, which left the campaign in credential-monetization mode following the Cisco…
-
French police arrest 21-year-old “HexDex” hacker over 100 alleged data breaches
French police arrest 21-year-old “HexDex” hacker over 100 alleged data breaches A 21-year-old man suspected of conducting approximately 100 data breaches since late 2025 – including a hack of the French Ministry of National Education that exposed records on almost a quarter of a million employees – has been arrested at his home in western…
-
Weekly Update 501
Weekly Update 501 This is so “peak 2026” – writing an equality policy to ensure people treat our AI bot with the same respect as they do their human counterparts. It’s intentionally a bit tongue-in-cheek, but it’s there for a purpose: we simply don’t have the capacity to deal with every request we get, and…
-
BlueNoroff Uses Fake Zoom Calls to Turn Victims Into Attack Lures
BlueNoroff Uses Fake Zoom Calls to Turn Victims Into Attack Lures The North Korean group is using stolen victim videos, AI-generated avatars, and fake Zoom calls to scale malware attacks against cryptocurrency executives. Jai Vijayan Go to gbhackers.com
-
NSA Chief During Snowden Affair Shares Regrets, Reflections 13 Years Later
NSA Chief During Snowden Affair Shares Regrets, Reflections 13 Years Later Chris Inglis was the head civilian in charge at the NSA when the Snowden leak exploded. He gets candid about mistakes the organization made, and what CISOs need to know about spotting potential threats, media disclosures, and “enculturation.” Dark Reading Staff Go to gbhackers.com
-
Feuding Ransomware Groups Leak Each Other’s Data
Feuding Ransomware Groups Leak Each Other’s Data When 0APT and KryBit attacked each other, they exposed infrastructure and operational data, giving defenders rare insight into ransomware operations. Alexander Culafi Go to gbhackers.com
-
Vidar Rises to Top of Chaotic Infostealer Market
Vidar Rises to Top of Chaotic Infostealer Market The malware has filled the gap created by last year’s law enforcement takedowns of Lumma and Rhadamanthys. Jai Vijayan Go to gbhackers.com
-
Fresh Wave of GlassWorm VS Code Extensions Slices Through Supply Chain
Fresh Wave of GlassWorm VS Code Extensions Slices Through Supply Chain Attackers continue to scale a campaign to seed Open VSX with seemingly benign VS Code extensions that spread self-propagating malware. Elizabeth Montalbano Go to gbhackers.com
-
Microsoft Expands Copilot Agent Mode for Outlook Inbox and Calendar Tasks
Microsoft Expands Copilot Agent Mode for Outlook Inbox and Calendar Tasks Microsoft announced a major evolution for Copilot in Outlook, shifting the tool from a passive assistant to an autonomous agent. Instead of simply drafting… Delivered by PolitePaul service Go to gbhackers.com
-
Chinese-Backed Smishing Rings Scale Credential Theft via SMS and OTT Apps
Chinese-Backed Smishing Rings Scale Credential Theft via SMS and OTT Apps Chinese-language phishing-as-a-service (PhaaS) platforms are rapidly expanding their global reach by leveraging SMS and over-the-top (OTT) messaging channels such as iMessage and Rich Communication… Delivered by PolitePaul service Go to gbhackers.com
-
Sandworm Uses SSH-over-Tor Tunnel for Stealthy Long-Term Persistence
Sandworm Uses SSH-over-Tor Tunnel for Stealthy Long-Term Persistence A significant evolution in Sandworm (APT-C-13) tradecraft, revealing the group’s use of SSH-over-Tor tunneling to achieve long-term, covert persistence inside targeted networks. Sandworm, also… Delivered by PolitePaul service Go to gbhackers.com
-
WhatsApp Tests Encrypted Cloud Backup Service for Safer Message Storage
WhatsApp Tests Encrypted Cloud Backup Service for Safer Message Storage WhatsApp is actively developing an independent, first-party cloud backup service featuring mandatory end-to-end encryption. This upcoming feature aims to reduce users’ reliance on third-party… Delivered by PolitePaul service Go to gbhackers.com
-
Critical LiteLLM Flaw Enables Database Attacks Through SQL Injection
Critical LiteLLM Flaw Enables Database Attacks Through SQL Injection A critical pre-authentication SQL injection vulnerability, identified as CVE-2026-42208, has been discovered in the popular LiteLLM gateway, allowing attackers to access databases without credentials…. Delivered by PolitePaul service Go to gbhackers.com
-
Microsoft: New Remote Desktop warnings may display incorrectly
Microsoft: New Remote Desktop warnings may display incorrectly Microsoft has confirmed a new issue causing newly introduced Windows security warnings to display incorrectly when opening Remote Desktop (.rdp) files. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft asks iPhone users to reauthenticate after Outlook outage
Microsoft asks iPhone users to reauthenticate after Outlook outage After addressing a widespread outage that affected Outlook.com users worldwide on Monday, Microsoft has asked iPhone users to re-enter their credentials to regain access to their Outlook and Hotmail accounts via the default Mail app. […] Sergiu Gatlan Go to bleepingcomputer
-
Robinhood account creation flaw abused to send phishing emails
Robinhood account creation flaw abused to send phishing emails Online trading platform Robinhood’s account creation process was exploited by threat actors to inject phishing messages into legitimate emails, tricking users into believing their accounts had suspicious activity. […] Lawrence Abrams Go to bleepingcomputer
-
GlassWorm malware attacks return via 73 OpenVSX “sleeper” extensions
GlassWorm malware attacks return via 73 OpenVSX “sleeper” extensions A new wave of the Glassworm campaign is targeting the OpenVSX ecosystem with 73 “sleeper” extensions that turn malicious after an update. […] Bill Toulas Go to bleepingcomputer
-
Canada arrests three for operating “SMS blaster” device in Toronto
Canada arrests three for operating “SMS blaster” device in Toronto Canadian authorities have arrested three men for operating an “SMS blaster” device that pretends to be a cellular tower to send phishing texts to nearby phones. […] Bill Toulas Go to bleepingcomputer
-
Popular PyPI Package With 1 Million Monthly Downloads Hacked to Inject Malicious Scripts
Popular PyPI Package With 1 Million Monthly Downloads Hacked to Inject Malicious Scripts A major software supply chain attack has compromised the popular Python package elementary-data, exposing thousands of developers to massive credential theft. Threat actors successfully pushed a malicious version, 0.23.3, to the Python Package Index (PyPI) and poisoned the matching Docker images on the GitHub…
-
Windows Remote Desktop Leaves Behind Image Fragments Attackers Can Stitch Into Screenshots
Windows Remote Desktop Leaves Behind Image Fragments Attackers Can Stitch Into Screenshots Whenever someone uses Windows Remote Desktop, the operating system quietly saves visual fragments of the active session. As recently highlighted by SCYTHE Labs, attackers can easily extract these breadcrumbs and rebuild them into readable screenshots. This process requires no special privileges, takes just…
-
Multiple OpenClaw Vulnerabilities Enables Policy Bypass and Host Override
Multiple OpenClaw Vulnerabilities Enables Policy Bypass and Host Override Cybersecurity researchers have recently disclosed three moderate-severity vulnerabilities in OpenClaw, an AI agent framework previously known as Clawdbot and Moltbot. Distributed as an npm package, these security flaws allow bypasses of policy enforcement, gateway configuration mutations, and host override attacks that could lead to credential exposure.…
-
Linux ELF Malware Generator Evades ML Detection With Semantic-Preserving Changes
Linux ELF Malware Generator Evades ML Detection With Semantic-Preserving Changes Researchers from the Czech Technical University in Prague have developed a new adversarial malware generator targeting Linux ELF binaries. It achieves a 67.74% evasion rate against ML-based malware detectors while keeping the payload fully functional. Published on arXiv on April 24, 2026, the study by…
-
OilRig Hides C2 Configuration in Google Drive Image Using LSB Steganography
OilRig Hides C2 Configuration in Google Drive Image Using LSB Steganography A well-known Iranian state-sponsored hacking group called OilRig, also tracked as APT34 and Helix Kitten, has been found hiding its command-and-control (C2) server configuration inside a regular-looking image file stored on Google Drive. The threat group used a technique called LSB (Least Significant Bit)…
-
Microsoft Patches Entra ID Role Flaw That Enabled Service Principal Takeover
Microsoft Patches Entra ID Role Flaw That Enabled Service Principal Takeover An administrative role meant for artificial intelligence (AI) agents within Microsoft Entra ID could enable privilege escalation and identity takeover attacks, according to new findings from Silverfort. Agent ID Administrator is a privileged built-in role introduced by Microsoft as part of its agent identity…
-
Microsoft Confirms Active Exploitation of Windows Shell CVE-2026-32202
Microsoft Confirms Active Exploitation of Windows Shell CVE-2026-32202 Microsoft on Monday revised its advisory for a now-patched, high-severity security flaw impacting Windows Shell to acknowledge that it has been actively exploited in the wild. The vulnerability in question is CVE-2026-32202 (CVSS score: 4.3), a spoofing vulnerability that could allow an attacker to access sensitive information.…
-
Checkmarx Confirms GitHub Repository Data Posted on Dark Web After March 23 Attack
Checkmarx Confirms GitHub Repository Data Posted on Dark Web After March 23 Attack Checkmarx has disclosed that its ongoing investigation tied to the supply chain security incident has revealed that a cybercriminal group published data related to the company on the dark web. “Based on current evidence, we believe this data originated from Checkmarx’s GitHub…
-
⚡ Weekly Recap: Fast16 Malware, XChat Launch, Federal Backdoor, AI Employee Tracking & More
⚡ Weekly Recap: Fast16 Malware, XChat Launch, Federal Backdoor, AI Employee Tracking & More Everything is dumb again. This week feels broken in a very familiar way. Old tricks are back. New tools are doing shady crap. Supply chains got hit. Fake help desks worked. Weird research showed how easy some attacks still are. Most…
-
Mythos Changed the Math on Vulnerability Discovery. Most Teams Aren’t Ready for the Remediation Side
Mythos Changed the Math on Vulnerability Discovery. Most Teams Aren’t Ready for the Remediation Side Anthropic’s Claude Mythos Preview has dominated security discussions since its April 7 announcement. Early reporting describes a powerful cybersecurity-focused AI system capable of identifying vulnerabilities at scale and raising serious questions about how quickly organizations can validate, prioritize, and remediate…
-
Medieval Encrypted Letter Decoded
Medieval Encrypted Letter Decoded Sent by a Spanish diplomat. Apparently people have been working on it since it was rediscovered in 1860. Bruce Schneier Go to bruce schneier
-
UNC6692 Combines Social Engineering, Malware, Cloud Abuse
UNC6692 Combines Social Engineering, Malware, Cloud Abuse A newly discovered threat actor is using Microsoft Teams, AWS S3 buckets, and custom “Snow” malware in a multipronged campaign. Alexander Culafi Go to gbhackers.com
-
Unpatched ‘PhantomRPC’ Flaw in Windows Enables Privilege Escalation
Unpatched ‘PhantomRPC’ Flaw in Windows Enables Privilege Escalation A researcher discovered five different exploit paths that stem from an architectural weakness in how Windows’ Remote Procedure Call (RPC) mechanism handles connections to unavailable services. Elizabeth Montalbano Go to gbhackers.com
-
20-Year-Old Malware Rewrites History of Cyber Sabotage
20-Year-Old Malware Rewrites History of Cyber Sabotage Researchers have uncovered a malware framework dubbed “fast16” that predates Stuxnet by 5 years. Jai Vijayan Go to gbhackers.com
-
Parsing Agentic Offensive Security’s Existential Threat
Parsing Agentic Offensive Security’s Existential Threat Some fear frontier LLMs like Claude Mythos and Anthropic’s GPT-5.5 will lead to cybersecurity annihilation. Ari Herbert-Voss notes this could be an opportunity. Tara Seals Go to gbhackers.com
-
Linux ELF Malware Generator Evades ML Detection With Semantic-Preserving Changes
Linux ELF Malware Generator Evades ML Detection With Semantic-Preserving Changes As Linux continues to dominate high-performance computing, cloud services, and Internet of Things (IoT) devices, it has become a prime target for cybercriminals. However,… Delivered by PolitePaul service Go to gbhackers.com
-
Researchers Warn macOS textutil, KeePassXC Can Fuel Automation Attacks
Researchers Warn macOS textutil, KeePassXC Can Fuel Automation Attacks Researchers are warning that widely trusted local tools such as macOS’s textutil and KeePassXC can pose unexpected security risks when used within automated workflows…. Delivered by PolitePaul service Go to gbhackers.com
-
North Korean Hackers Target Pharma Firms with Malware-Laced Excel Attacks
North Korean Hackers Target Pharma Firms with Malware-Laced Excel Attacks North Korean state-backed hackers are using weaponized Excel-themed files to infect pharmaceutical and life science companies with malware, abusing Windows shortcut files, PowerShell, and… Delivered by PolitePaul service Go to gbhackers.com
-
OpenClaw Flaws Expose Systems to Policy Bypass Attacks
OpenClaw Flaws Expose Systems to Policy Bypass Attacks OpenClaw, a rapidly adopted open-source autonomous AI agent framework, has released critical security updates to address three moderate-severity vulnerabilities. Found in npm package versions… Delivered by PolitePaul service Go to gbhackers.com
-
Critical Gemini CLI Flaw Raises Supply Chain Security Concerns
Critical Gemini CLI Flaw Raises Supply Chain Security Concerns Google has rolled out urgent security updates for its Gemini CLI and the accompanying GitHub Action to address a critical vulnerability. Tracked as GHSA-wpqr-6v78-jr5g,… Delivered by PolitePaul service Go to gbhackers.com
-
American utility firm Itron discloses breach of internal IT network
American utility firm Itron discloses breach of internal IT network Itron, Inc. has disclosed, via an 8-K filing with the U.S. Securities and Exchange Commission (SEC), a cybersecurity incident in which an unauthorized third party accessed certain internal systems. […] Bill Toulas Go to bleepingcomputer
-
Vidar Malware Hides Second-Stage Payloads in JPEG and TXT Files to Evade Detection
Vidar Malware Hides Second-Stage Payloads in JPEG and TXT Files to Evade Detection Vidar, one of the most active information-stealing malware families, has taken on a new shape in 2026. Researchers have found that its latest version now conceals second-stage payloads inside JPEG image files and TXT documents, making it much harder for security tools…
-
Attackers Can Backdoor CODESYS Applications by Chaining Vulnerabilities
Attackers Can Backdoor CODESYS Applications by Chaining Vulnerabilities Multiple vulnerabilities in the CODESYS Control runtime, one of the world’s most widely adopted software-based programmable logic controller (Soft PLC) platforms. According to Nozomi Networks Labs researchers, by chaining these security flaws, an authenticated attacker can replace a legitimate industrial control application with a backdoored version, thereby…
-
Top 10 Best NDR (Network Detection and Response) Solutions in 2026
Top 10 Best NDR (Network Detection and Response) Solutions in 2026 In the modern enterprise, the network is the ultimate source of ground truth. As organizations accelerate their digital transformation and adopt complex, cloud-native security architectures, the traditional perimeter has dissolved. Threat actors routinely bypass endpoint defenses using compromised credentials, living-off-the-land (LotL) binaries, and highly…
-
‘fast16’ Malware with Sabotage Capabilities Attacking Ultra expensive Targets
‘fast16’ Malware with Sabotage Capabilities Attacking Ultra expensive Targets The fast16 malware is a recently exposed sabotage‑capable threat designed to target extremely high‑value environments and ultra‑expensive systems with precision. It does not behave like common commodity malware that aims for broad infections, but instead focuses on select victims where disruption or long‑term control can cause…
-
pentest-ai-agents – 28 Claude Code Subagents for Penetration Testing
pentest-ai-agents – 28 Claude Code Subagents for Penetration Testing A new open-source toolkit called pentest-ai-agents is redefining how security professionals leverage AI in penetration testing workflows, transforming Anthropic’s Claude Code into a fully specialized offensive security research assistant powered by 28 domain-specific subagents. Released by security researcher 0xSteph on GitHub, pentest-ai-agents is a collection of…
-
Helping Romance Scam Victims Require a Proactive, Empathic Approach
Helping Romance Scam Victims Require a Proactive, Empathic Approach People targeted by confidence schemes find getting help is a lonely road. Experts want law enforcement, financial and government institutions to work together and protect them. Bree Fowler Go to gbhackers.com
-
Microsoft rolls out revamped Windows Insider Program
Microsoft rolls out revamped Windows Insider Program Microsoft says it’s rolling out a revamped Windows Insider Program experience as part of the broader plans to address performance and reliability concerns affecting Windows 11. […] Mayank Parmar Go to bleepingcomputer
-
Threat actor uses Microsoft Teams to deploy new “Snow” malware
Threat actor uses Microsoft Teams to deploy new “Snow” malware A threat group tracked as UNC6692 uses social engineering to deploy a new, custom malware suite named ‘Snow’ which includes a browser extension, a tunneler, and a backdoor. […] Bill Toulas Go to bleepingcomputer
-
73 Open VSX Sleeper Extensions Linked to GlassWorm Activate New Malware Campaign
73 Open VSX Sleeper Extensions Linked to GlassWorm Activate New Malware Campaign The GlassWorm supply chain attack targeting the Open VSX marketplace has escalated with the discovery of 73 new “sleeper” extensions. Identified in April 2026, this cluster marks a dangerous shift in how threat actors distribute malware to software developers. This activity follows a…
-
Litecoin Zero-Day Vulnerability Exploited in DoS Attack, Disrupts Major Mining Pools
Litecoin Zero-Day Vulnerability Exploited in DoS Attack, Disrupts Major Mining Pools A critical zero-day vulnerability in the Litecoin network was actively exploited to launch a denial-of-service (DoS) attack, temporarily disrupting operations across major mining pools before developers issued a full patch. Security researchers confirmed the flaw allowed threat actors to inject an invalid MWEB (MimbleWimble…
-
New Windows RPC Vulnerability Lets Attackers Escalate Privileges Across All Windows Versions
New Windows RPC Vulnerability Lets Attackers Escalate Privileges Across All Windows Versions PhantomRPC, a newly identified architectural vulnerability in Windows Remote Procedure Call (RPC) that enables local privilege escalation to SYSTEM-level access, potentially affecting every version of Windows. The research was presented by Kaspersky application security specialist Haidar Kabibo at Black Hat Asia 2026 on…
-
CISA Warns of Multiple SimpleHelp Vulnerabilities Exploited in Attack
CISA Warns of Multiple SimpleHelp Vulnerabilities Exploited in Attack The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical alert regarding two actively exploited vulnerabilities in SimpleHelp remote support software. Remote access tools are highly valued targets for cybercriminals because they provide direct pathways into corporate networks. When compromised, these platforms allow threat actors…
-
Claude AI Agents Close 186 Deals in Anthropic’s Marketplace Experiment
Claude AI Agents Close 186 Deals in Anthropic’s Marketplace Experiment Anthropic’s “Project Deal” has demonstrated that AI agents can autonomously negotiate and close real-world transactions, but the experiment also surfaced a quiet, troubling asymmetry: not all AI representations are created equal. In December 2025, Anthropic transformed its San Francisco office into a live classified marketplace,…