no alarms and no surprises please..
-
Researchers Uncover Pre-Stuxnet ‘fast16’ Malware Targeting Engineering Software
Researchers Uncover Pre-Stuxnet ‘fast16’ Malware Targeting Engineering Software Cybersecurity researchers have discovered a new Lua-based malware created years before the notorious Stuxnet worm that aimed to sabotage Iran’s nuclear program by destroying uranium enrichment centrifuges. According to a new report published by SentinelOne, the previously undocumented cyber sabotage framework dates back to 2005, primarily targeting…
-
Hackers Exploit Agent ID Administrator Role to Hijack Service Principals
Hackers Exploit Agent ID Administrator Role to Hijack Service Principals A severe scoping vulnerability was recently discovered in Microsoft Entra ID’s new Agent Identity Platform. The security flaw allowed users assigned the Agent ID… Delivered by PolitePaul service Go to gbhackers.com
-
GPT-5.5 Bio Bug Bounty Program Aims to Improve AI Safety and Performance
GPT-5.5 Bio Bug Bounty Program Aims to Improve AI Safety and Performance OpenAI has officially launched the GPT-5.5 Bio Bug Bounty program to strengthen safeguards against emerging biological risks. As artificial intelligence models become more advanced,… Delivered by PolitePaul service Go to gbhackers.com
-
Claude Desktop Reportedly Adds Browser Access Bridge for Chromium Browsers
Claude Desktop Reportedly Adds Browser Access Bridge for Chromium Browsers A detailed cybersecurity report published by privacy expert Alexander Hanff on April 18, 2026, reveals that Anthropic’s Claude Desktop application for macOS silently installs… Delivered by PolitePaul service Go to gbhackers.com
-
ADT confirms data breach after ShinyHunters leak threat
ADT confirms data breach after ShinyHunters leak threat Home security giant ADT has confirmed a data breach after the ShinyHunters extortion group threatened to leak stolen data unless a ransom is paid. […] Lawrence Abrams Go to bleepingcomputer
-
Firestarter malware survives Cisco firewall updates, security patches
Firestarter malware survives Cisco firewall updates, security patches Cybersecurity agencies in the U.S. and U.K. are warning about a custom malware called Firestarter persisting on Cisco Firepower and Secure Firewall devices running Adaptive Security Appliance (ASA) or Firepower Threat Defense (FTD) software. […] Bill Toulas Go to bleepingcomputer
-
Windows Update gets new controls to reduce forced restarts
Windows Update gets new controls to reduce forced restarts Microsoft is rolling out Windows Update improvements that give users more control over how updates are installed while reducing disruption from frequent or poorly timed restarts. […] Lawrence Abrams Go to bleepingcomputer
-
New BlackFile extortion group linked to surge of vishing attacks
New BlackFile extortion group linked to surge of vishing attacks A new financially motivated hacking group tracked as BlackFile has been linked to a wave of data theft and extortion attacks against retail and hospitality organizations since February 2026. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft to roll out Entra passkeys on Windows in late April
Microsoft to roll out Entra passkeys on Windows in late April Microsoft will roll out passkey support for phishing-resistant passwordless authentication to Microsoft Entra‑protected resources from Windows devices starting late April. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers Can Abuse Entra Agent ID Administrator Role to Hijack Service Principals
Hackers Can Abuse Entra Agent ID Administrator Role to Hijack Service Principals A critical scope overreach vulnerability was recently identified in the Microsoft Entra Agent Identity Platform. The newly introduced Agent ID Administrator role allowed accounts to hijack arbitrary service principals and escalate privileges across the entire tenant. Microsoft has fully patched this behavior across…
-
ADT Confirms Data Breach Following ShinyHunters Data Leak Claim
ADT Confirms Data Breach Following ShinyHunters Data Leak Claim Home security giant ADT Inc. has confirmed a data breach after the notorious threat group ShinyHunters claimed to have stolen over 10 million records and issued a ransom ultimatum — “Pay or Leak.” ADT, headquartered in Boca Raton, Florida, disclosed the incident via a Form 8-K…
-
Hackers Exploiting Cisco Firepower Devices’ Using n-day Vulnerabilities to Gain Unauthorized Access
Hackers Exploiting Cisco Firepower Devices’ Using n-day Vulnerabilities to Gain Unauthorized Access State-sponsored threat actors are actively targeting Cisco Firepower devices by chaining known vulnerabilities to deploy a highly customized backdoor. Cisco Talos recently discovered that the espionage-focused threat group UAT-4356 is exploiting two n-day vulnerabilities, tracked as CVE-2025-20333 and CVE-2025-20362, to infiltrate Firepower Extensible…
-
Claude Desktop Reportedly Adds Browser Access Bridge to Multiple Chromium-Based Browsers
Claude Desktop Reportedly Adds Browser Access Bridge to Multiple Chromium-Based Browsers A recent technical audit by privacy researcher Alexander Hanff has revealed that Anthropic’s Claude Desktop application for macOS silently installs a Native Messaging bridge into the directories of several Chromium-based browsers. This undocumented behavior occurs without user consent, raising significant privacy and security concerns…
-
Hackers Use Fake CAPTCHA Pages to Trigger Costly International SMS Fraud
Hackers Use Fake CAPTCHA Pages to Trigger Costly International SMS Fraud Most internet users are familiar with CAPTCHA tests, simple challenges like selecting traffic lights or typing distorted letters to confirm they are human. But cybercriminals have found a way to weaponize this process. Hackers are now building fake CAPTCHA pages that trick users into…
-
The calm before the ransom: What you see is not all there is
The calm before the ransom: What you see is not all there is A breach claims the systems as well as the confidence that was, in retrospect, a major vulnerability Go to eset
-
CISA Adds 4 Exploited Flaws to KEV, Sets May 2026 Federal Deadline
CISA Adds 4 Exploited Flaws to KEV, Sets May 2026 Federal Deadline The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added four vulnerabilities impacting SimpleHelp, Samsung MagicINFO 9 Server, and D-Link DIR-823X series routers to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The list of vulnerabilities is below –…
-
FIRESTARTER Backdoor Hit Federal Cisco Firepower Device, Survives Security Patches
FIRESTARTER Backdoor Hit Federal Cisco Firepower Device, Survives Security Patches The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has revealed that an unnamed federal civilian agency’s Cisco Firepower device running Adaptive Security Appliance (ASA) software was compromised in September 2025 with a new malware called FIRESTARTER. FIRESTARTER, per CISA and the U.K.’s National Cyber Security…
-
NASA Employees Duped in Chinese Phishing Scheme Targeting U.S. Defense Software
NASA Employees Duped in Chinese Phishing Scheme Targeting U.S. Defense Software The Office of Inspector General (OIG) of the U.S. National Aeronautics and Space Administration (NASA) has revealed how a Chinese national posed as a U.S. researcher as part of a spear-phishing campaign to obtain sensitive information from the space agency, as well as from…
-
Bridging the AI Agent Authority Gap: Continuous Observability as the Decision Engine
Bridging the AI Agent Authority Gap: Continuous Observability as the Decision Engine The AI Agent Authority Gap – From Ungoverned to Delegation As discussed in our previous article, AI agents are exposing a structural gap in enterprise security, but the problem is often framed too narrowly. The issue is not simply that agents are new…
-
26 FakeWallet Apps Found on Apple App Store Targeting Crypto Seed Phrases
26 FakeWallet Apps Found on Apple App Store Targeting Crypto Seed Phrases Cybersecurity researchers have discovered a set of malicious apps on the Apple App Store that impersonate popular cryptocurrency wallets in an attempt to steal recovery phrases and private keys since at least fall 2025. “Once launched, these apps redirect users to browser pages…
-
Supply chain attacks hit Checkmarx and Bitwarden developer tools
Supply chain attacks hit Checkmarx and Bitwarden developer tools Two supply chain attacks, same day, same command-and-control domain Categories: Threat Research Tags: Supply chain, Sophos X-Ops, pipeline, Bitwarden, Checkmarx Go to sophos
-
Friday Squid Blogging: How Squid Survived Extinction Events
Friday Squid Blogging: How Squid Survived Extinction Events Science news: Scientists have finally cracked a long-standing mystery about squid and cuttlefish evolution by analyzing newly sequenced genomes alongside global datasets. The research reveals that these bizarre, intelligent creatures likely originated deep in the ocean over 100 million years ago, surviving mass extinction events by retreating…
-
Hiding Bluetooth Trackers in Mail
Hiding Bluetooth Trackers in Mail It was used to track a Dutch naval ship: Dutch journalist Just Vervaart, working for regional media network Omroep Gelderland, followed the directions posted on the Dutch government website and mailed a postcard with a hidden tracker inside. Because of this, they were able to track the ship for about…
-
US Busts Myanmar Ring Targeting US Citizens in Financial Fraud
US Busts Myanmar Ring Targeting US Citizens in Financial Fraud Some 29 people were charged, including a Cambodian senator, and authorities seized more than 500 Web domains tied to fake investment sites. Nate Nelson Go to gbhackers.com
-
Glasswing Secured the Code. The Rest of Your Stack Is Still on You
Glasswing Secured the Code. The Rest of Your Stack Is Still on You Forgotten integrations, shadow IT, SaaS, and now shadow AI and agents are everywhere, and attackers don’t need sophisticated AI models to take advantage. Ron Peled Go to gbhackers.com
-
AI Phishing Is No. 1 With a Bullet for Cyberattackers
AI Phishing Is No. 1 With a Bullet for Cyberattackers In the last six months, companies have seen a significant influx of AI-powered phishing, as cyberattackers progress from small campaigns to 1-to-1 personalized attacks. Robert Lemos Go to gbhackers.com
-
North Korea’s Lazarus Targets macOS Users via ClickFix
North Korea’s Lazarus Targets macOS Users via ClickFix Lazarus continues leveraging ClickFix for initial access and data theft, in this case, against Mac-centric organizations and their high-value leaders. Alexander Culafi Go to gbhackers.com
-
Fake CAPTCHA Scam Triggers Costly SMS Fraud
Fake CAPTCHA Scam Triggers Costly SMS Fraud Hackers are abusing fake CAPTCHA pages to run a silent but lucrative international SMS fraud scheme, turning routine “prove you’re human” checks into a… Delivered by PolitePaul service Go to gbhackers.com
-
Hackers Exploit Cisco Firepower N-Day Flaws for Unauthorized Access
Hackers Exploit Cisco Firepower N-Day Flaws for Unauthorized Access A state-sponsored threat actor known as UAT-4356 is actively exploiting known vulnerabilities in Cisco Firepower devices to deploy a sophisticated custom backdoor. UAT-4356 exploited two n-day vulnerabilities, CVE-2025-20333 and CVE-2025-20362m… Delivered by PolitePaul service Go to gbhackers.com
-
Hackers Exploit Pastebin PowerShell Script to Hijack Telegram Sessions
Hackers Exploit Pastebin PowerShell Script to Hijack Telegram Sessions Hackers are experimenting with a new Telegram‑focused session stealer that hides in a Pastebin‑hosted PowerShell script posing as a Windows telemetry update, giving defenders… Delivered by PolitePaul service Go to gbhackers.com
-
Xiongmai IP Camera Flaw Lets Attackers Bypass Authentication
Xiongmai IP Camera Flaw Lets Attackers Bypass Authentication A critical security vulnerability has been identified in Hangzhou Xiongmai Technology’s XM530 IP Cameras, putting countless commercial facilities at risk. This severe flaw allows… Delivered by PolitePaul service Go to gbhackers.com
-
Void Dokkaebi Hackers Spread Malware Through Fake Job Interviews
Void Dokkaebi Hackers Spread Malware Through Fake Job Interviews Void Dokkaebi, also known as Famous Chollima, is expanding its cyber operations by turning fake job interviews into a large-scale malware distribution campaign targeting… Delivered by PolitePaul service Go to gbhackers.com
-
Hackers exploit file upload bug in Breeze Cache WordPress plugin
Hackers exploit file upload bug in Breeze Cache WordPress plugin Hackers are actively exploiting a critical vulnerability in the Breeze Cache plugin for WordPress that allows uploading arbitrary files on the server without authentication. […] Bill Toulas Go to bleepingcomputer
-
Bitwarden CLI npm package compromised to steal developer credentials
Bitwarden CLI npm package compromised to steal developer credentials The Bitwarden CLI was briefly compromised after attackers uploaded a malicious @bitwarden/cli package to npm containing a credential-stealing payload capable of spreading to other projects. […] Lawrence Abrams Go to bleepingcomputer
-
Trigona ransomware attacks use custom exfiltration tool to steal data
Trigona ransomware attacks use custom exfiltration tool to steal data Recently observed Trigona ransomware attacks are using a custom, command-line tool to steal data from compromised environments faster and more efficiently. […] Bill Toulas Go to bleepingcomputer
-
New Checkmarx supply-chain breach affects KICS analysis tool
New Checkmarx supply-chain breach affects KICS analysis tool Hackers have compromised Docker images, VSCode and Open VSX extensions for the Checkmarx KICS analysis tool to harvest sensitive data from developer environments. […] Bill Toulas Go to bleepingcomputer
-
Cosmetics giant Rituals discloses data breach affecting customers
Cosmetics giant Rituals discloses data breach affecting customers Dutch cosmetics giant Rituals disclosed a data breach after attackers stole the personal information of an undisclosed number of customers from its “My Rituals” membership database. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers Use Telegram Bots to Track 900+ Successful React2Shell Exploits
Hackers Use Telegram Bots to Track 900+ Successful React2Shell Exploits A newly exposed server has revealed how a threat actor used automated tools, AI assistance, and Telegram bots to silently hack into more than 900 companies around the world. The operation, built around a tool called “Bissa scanner,” targeted internet-facing web applications at a massive…
-
Ransomware Hackers Develop Custom Exfiltration Tool to Steal Sensitive Data
Ransomware Hackers Develop Custom Exfiltration Tool to Steal Sensitive Data Ransomware attackers are no longer relying only on widely known tools to steal data. Affiliates linked to the Trigona ransomware group have taken a more calculated approach by building their own custom data exfiltration tool, one that gives them greater precision, speed, and control over…
-
Hackers Abuse SS7 and Diameter Protocols to Track Mobile Users Worldwide
Hackers Abuse SS7 and Diameter Protocols to Track Mobile Users Worldwide A major investigation has revealed that sophisticated threat actors are exploiting fundamental vulnerabilities in global mobile networks to track users worldwide. By abusing legacy 3G SS7 and 4G Diameter signaling protocols, hackers are successfully bypassing telecom firewalls to conduct silent, cross-border espionage. The extensive…
-
Microsoft Teams Issue Blocking Users From Joining Meetings Following Edge browser update
Microsoft Teams Issue Blocking Users From Joining Meetings Following Edge browser update Microsoft is actively investigating a known issue preventing some users from joining Microsoft Teams meetings on Windows devices, following a recent update to the Microsoft Edge browser. The disruption is affecting organizations, including those using NHSmail infrastructure, with reports indicating that scheduled meetings…
-
Hackers Leverage Microsoft Teams to Breach Organizations Posing as IT Helpdesk Staff
Hackers Leverage Microsoft Teams to Breach Organizations Posing as IT Helpdesk Staff A newly identified threat group, UNC6692, has been caught running a sophisticated multistage intrusion campaign that uses Microsoft Teams impersonation, a custom modular malware suite, and cloud infrastructure abuse to deeply penetrate enterprise networks, all without exploiting a single software vulnerability. Google Threat…
-
GopherWhisper: A burrow full of malware
GopherWhisper: A burrow full of malware ESET Research has discovered a new China-aligned APT group that we’ve named GopherWhisper, which targets Mongolian governmental institutions Go to eset
-
UNC6692 Impersonates IT Helpdesk via Microsoft Teams to Deploy SNOW Malware
UNC6692 Impersonates IT Helpdesk via Microsoft Teams to Deploy SNOW Malware A previously undocumented threat activity cluster known as UNC6692 has been observed leveraging social engineering tactics via Microsoft Teams to deploy a custom malware suite on compromised hosts. “As with many other intrusions in recent years, UNC6692 relied heavily on impersonating IT helpdesk employees,…
-
Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign
Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign Bitwarden CLI has been compromised as part of the newly discovered and ongoing Checkmarx supply chain campaign, according to new findings from JFrog and Socket. “The affected package version appears to be @bitwarden/[email protected], and the malicious code was published in ‘bw1.js,’ a file included in the…
-
ThreatsDay Bulletin: $290M DeFi Hack, macOS LotL Abuse, ProxySmart SIM Farms +25 New Stories
ThreatsDay Bulletin: $290M DeFi Hack, macOS LotL Abuse, ProxySmart SIM Farms +25 New Stories You scroll past one incident and see another that feels familiar, like it should have been fixed years ago, but it still works with small changes. Same bugs. Same mistakes. The supply chain is messy. Packages you did not check are…
-
[Webinar] Mythos Reality Check: Beating Automated Exploitation at AI Speed
[Webinar] Mythos Reality Check: Beating Automated Exploitation at AI Speed Imagine a world where hackers don’t sleep, don’t take breaks, and find weak spots in your systems instantly. Well, that world is already here. Thanks to AI, attackers are now launching automated, large-scale exploits faster than ever before. The time you have to fix a…
-
Project Glasswing Proved AI Can Find the Bugs. Who’s Going to Fix Them?
Project Glasswing Proved AI Can Find the Bugs. Who’s Going to Fix Them? Last week, Anthropic announced Project Glasswing, an AI model so effective at discovering software vulnerabilities that they took the extraordinary step of postponing its public release. Instead, the company has given access to Apple, Microsoft, Google, Amazon, and a coalition of others…
-
FBI Extracts Deleted Signal Messages from iPhone Notification Database
FBI Extracts Deleted Signal Messages from iPhone Notification Database 404 Media reports (alternate site): The FBI was able to forensically extract copies of incoming Signal messages from a defendant’s iPhone, even after the app was deleted, because copies of the content were saved in the device’s push notification database…. The news shows how forensic extraction—when…
-
ISC Stormcast For Friday, April 24th, 2026 https://isc.sans.edu/podcastdetail/9906, (Fri, Apr 24th)
ISC Stormcast For Friday, April 24th, 2026 https://isc.sans.edu/podcastdetail/9906, (Fri, Apr 24th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Apple Patches Exploited Notification Flaw, (Thu, Apr 23rd)
Apple Patches Exploited Notification Flaw, (Thu, Apr 23rd) Apple yesterday released iOS/iPadOS 26.4.2 and iOS/iPadOS 18.7.8. This update fixes a single Notification Services vulnerability, CVE-2026-28950: Impact: Notifications marked for deletion could be unexpectedly retained on the device Description: A logging issue was addressed with improved data redaction. Apple did not mark the vulnerability as exploited.…
-
Tropic Trooper APT Takes Aim at Home Routers, Japanese Targets
Tropic Trooper APT Takes Aim at Home Routers, Japanese Targets The Chinese state-sponsored cyber threat is known for moving fast and trying odd attack vectors; now it’s branching out in tools, victimology, and TTPs. Tara Seals Go to gbhackers.com
-
Chinese APT Abuses Multiple Cloud Tools to Spy on Mongolia
Chinese APT Abuses Multiple Cloud Tools to Spy on Mongolia The threat actor gave itself plenty of options to support command and control, tapping Microsoft Outlook, Slack, Discord, and file.io for online espionage. Nate Nelson Go to gbhackers.com
-
Bad Memories Still Haunt AI Agents
Bad Memories Still Haunt AI Agents Cisco found and fixed a significant vulnerability in the way Anthropic handles memories, but experts warn that mishandled memory files will continue threaten AI systems. Robert Lemos Go to gbhackers.com
-
Malicious npm Package Hijacks Hugging Face for Malware Delivery
Malicious npm Package Hijacks Hugging Face for Malware Delivery Malicious npm package js-logger-pack is now abusing Hugging Face not just as a malware CDN, but also as a live exfiltration backend for stolen data, turning… Delivered by PolitePaul service Go to gbhackers.com
-
Outlook Mailboxes Used to Conceal Linux GoGra Backdoor Traffic
Outlook Mailboxes Used to Conceal Linux GoGra Backdoor Traffic A newly discovered Linux variant of the GoGra backdoor is being used by the Harvester advanced persistent threat (APT) group to conduct stealthy cyber… Delivered by PolitePaul service Go to gbhackers.com
-
Attackers Exploit LMDeploy Flaw in the Wild Within 12 Hours of Advisory
Attackers Exploit LMDeploy Flaw in the Wild Within 12 Hours of Advisory A critical Server-Side Request Forgery (SSRF) vulnerability in LMDeploy’s vision-language module was exploited in active attacks just 12 hours and 31 minutes after its… Delivered by PolitePaul service Go to gbhackers.com
-
North Korean Fake IT Workers Infiltrate Firms to Dodge Sanctions
North Korean Fake IT Workers Infiltrate Firms to Dodge Sanctions North Korean threat actors are once again leveraging deceptive remote work schemes to infiltrate global organizations, using fake IT worker personas to generate revenue… Delivered by PolitePaul service Go to gbhackers.com
-
Lazarus Lures Developers With Backdoored Coding Tests
Lazarus Lures Developers With Backdoored Coding Tests North Korea-linked hackers are using AI-assisted malware and backdoored coding challenges to quietly loot millions in cryptocurrency from Web3 developers. Expel assesses with high confidence… Delivered by PolitePaul service Go to gbhackers.com
-
‘Zealot’ Shows What AI’s Capable of in Staged Cloud Attack
‘Zealot’ Shows What AI’s Capable of in Staged Cloud Attack The proof of concept revealed AI-based attacks unfold too fast for human defenders to respond, and that AI evinced more autonomous behavior than expected. Jai Vijayan Go to gbhackers.com
-
Apple fixes bug that let the FBI recover deleted Signal messages
Apple fixes bug that let the FBI recover deleted Signal messages Apple has released out-of-band security updates for iPhone and iPad devices to fix a Notification Services flaw that could allow notifications marked for deletion to remain stored on the device. […] Lawrence Abrams Go to bleepingcomputer
-
New Mirai campaign exploits RCE flaw in EoL D-Link routers
New Mirai campaign exploits RCE flaw in EoL D-Link routers A new Mirai-based malware campaign is actively exploiting CVE-2025-29635, a high-severity command-injection vulnerability affecting D-Link DIR-823X routers, to enlist devices into the botnet. […] Bill Toulas Go to bleepingcomputer
-
Kyber ransomware gang toys with post-quantum encryption on Windows
Kyber ransomware gang toys with post-quantum encryption on Windows A new Kyber ransomware operation is targeting Windows systems and VMware ESXi endpoints in recent attacks, with one variant implementing Kyber1024 post-quantum encryption. […] Bill Toulas Go to bleepingcomputer
-
Spain dismantles major $4.7M manga piracy platform, arrests four
Spain dismantles major $4.7M manga piracy platform, arrests four The Spanish police have dismantled the largest Spanish-language manga piracy platform, operating since 2014, with millions of monthly users from around the globe. […] Bill Toulas Go to bleepingcomputer
-
Inside Caller-as-a-Service Fraud: The Scam Economy Has a Hiring Process
Inside Caller-as-a-Service Fraud: The Scam Economy Has a Hiring Process Fraud operations now operate like call centers, complete with hiring, training, and performance tracking. Flare reveals how cybercriminals manage “Caller-as-a-Service” operations like a professional sales team. […] Sponsored by Flare Go to bleepingcomputer
-
Critical Pack2TheRoot Vulnerability Let Attackers Gain Root Access or Compromise the System
Critical Pack2TheRoot Vulnerability Let Attackers Gain Root Access or Compromise the System A high-severity privilege escalation vulnerability, dubbed Pack2TheRoot (CVE-2026-41651, CVSS 3.1: 8.8), has been publicly disclosed by Deutsche Telekom’s Red Team, affecting multiple major Linux distributions in their default installations. The flaw allows any local unprivileged user to silently install or remove system packages,…
-
Apple Fixes Notification Privacy Flaw That Allowed FBI to Access Deleted Signal Messages
Apple Fixes Notification Privacy Flaw That Allowed FBI to Access Deleted Signal Messages Apple released iOS 26.4.2 and iPadOS 26.4.2 on April 22, 2026, to patch a critical notification privacy vulnerability that allowed law enforcement to extract Signal message content from iPhones — even after the app had been deleted. The flaw, tracked as CVE-2026-28950,…
-
Checkmarx KICS Official Docker Repo Compromised to Inject Malicious Code
Checkmarx KICS Official Docker Repo Compromised to Inject Malicious Code A significant supply chain attack targeting the official checkmarx/kics Docker Hub repository, where threat actors pushed trojanized images capable of harvesting and exfiltrating sensitive developer credentials and infrastructure secrets. Docker’s internal monitoring flagged suspicious activity around KICS image tags on April 22, 2026, and promptly…
-
109 Fake GitHub Repositories Used to Deliver SmartLoader and StealC Malware
109 Fake GitHub Repositories Used to Deliver SmartLoader and StealC Malware A large-scale malware distribution campaign has been uncovered involving 109 fake GitHub repositories that were used to trick users into downloading two dangerous malware tools named SmartLoader and StealC. The campaign was carefully built around cloned versions of legitimate open-source projects, making it hard…
-
Malicious Google Ads Target Crypto Users With Wallet Drainers and Seed Phrase Theft
Malicious Google Ads Target Crypto Users With Wallet Drainers and Seed Phrase Theft Cybercriminals are now using Google’s own advertising platform to steal cryptocurrency from unsuspecting users. They place fake ads that look exactly like real links to popular crypto applications, and when users click on them, they land on websites designed to drain their…
-
TR-26-0121 (Flowise AI Güvenlik Zafiyeti)
TR-26-0121 (Flowise AI Güvenlik Zafiyeti) Go to usom.gov
-
TR-26-0120 (Microsoft ASP.NET Core Güvenlik Bildirimi)
TR-26-0120 (Microsoft ASP.NET Core Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0119 (OpenClaw Güvenlik Zafiyeti)
TR-26-0119 (OpenClaw Güvenlik Zafiyeti) Go to usom.gov
-
TR-26-0118 (Electric SQL Güvenlik Bildirimi)
TR-26-0118 (Electric SQL Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0117 (Anviz CX2 Lite/CX7 Güvenlik Zafiyeti)
TR-26-0117 (Anviz CX2 Lite/CX7 Güvenlik Zafiyeti) Go to usom.gov
-
Malicious KICS Docker Images and VS Code Extensions Hit Checkmarx Supply Chain
Malicious KICS Docker Images and VS Code Extensions Hit Checkmarx Supply Chain Cybersecurity researchers have warned of malicious images pushed to the official “checkmarx/kics” Docker Hub repository. In an alert published today, software supply chain security company Socket revealed that unknown threat actors managed to have overwritten existing tags, including v2.1.20 and alpine, while also…
-
Self-Propagating Supply Chain Worm Hijacks npm Packages to Steal Developer Tokens
Self-Propagating Supply Chain Worm Hijacks npm Packages to Steal Developer Tokens Cybersecurity researchers have flagged a fresh set of packages that have been compromised by bad actors to deliver a self-propagating worm that spreads through stolen developer npm tokens. The supply chain worm has been detected by both Socket and StepSecurity, with the companies tracking…
-
Harvester Deploys Linux GoGra Backdoor in South Asia Using Microsoft Graph API
Harvester Deploys Linux GoGra Backdoor in South Asia Using Microsoft Graph API The threat actor known as Harvester has been attributed to a new Linux version of its GoGra backdoor deployed as part of attacks likely targeting entities in South Asia. “The malware uses the legitimate Microsoft Graph API and Outlook mailboxes as a covert…
-
Lotus Wiper Malware Targets Venezuelan Energy Systems in Destructive Attack
Lotus Wiper Malware Targets Venezuelan Energy Systems in Destructive Attack Cybersecurity researchers have discovered a previously undocumented data wiper that has been used in attacks targeting Venezuela at the end of last year and the start of 2026. Dubbed Lotus Wiper, the novel file wiper has been used in a destructive campaign targeting the energy…
-
Toxic Combinations: When Cross-App Permissions Stack into Risk
Toxic Combinations: When Cross-App Permissions Stack into Risk On January 31, 2026, researchers disclosed that Moltbook, a social network built for AI agents, had left its database wide open, exposing 35,000 email addresses and 1.5 million agent API tokens across 770,000 active agents. The more worrying part sat inside the private messages. Some of those…
-
Strengthening authentication with passkeys: A CISO playbook
Strengthening authentication with passkeys: A CISO playbook Our passkey rollout took three tries. Here’s a playbook to make your implementation smoother. Categories: Security Operations Tags: CISO, playbook, toolkit, passkeys Go to sophos
-
ICE Uses Graphite Spyware
ICE Uses Graphite Spyware ICE has admitted that it uses spyware from the Israeli company Graphite. Bruce Schneier Go to bruce schneier
-
ISC Stormcast For Thursday, April 23rd, 2026 https://isc.sans.edu/podcastdetail/9904, (Thu, Apr 23rd)
ISC Stormcast For Thursday, April 23rd, 2026 https://isc.sans.edu/podcastdetail/9904, (Thu, Apr 23rd) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Smashing Security podcast #464: Rockstar got hacked. The data was junk. The secrets it revealed were not
Smashing Security podcast #464: Rockstar got hacked. The data was junk. The secrets it revealed were not A company that ran anonymous tip lines for 35,000 American schools – handling reports of bullying, weapons, and self-harm – boasted on its website that it had suffered zero security breaches in over 20 years. A hacker called…
-
‘The Gentlemen’ Rapidly Rises to Ransomware Prominence
‘The Gentlemen’ Rapidly Rises to Ransomware Prominence Not nearly as polite as the name suggests, the ransomware gang has impressed researchers with its speed in scaling up operations — and its sophistication. Alexander Culafi Go to gbhackers.com
-
DPRK Fake Job Scams Self-Propagate in ‘Contagious Interview’
DPRK Fake Job Scams Self-Propagate in ‘Contagious Interview’ A compromised developer’s repository serves as a worm-like infection vector to spread remote access Trojans (RATs) and other malware. Elizabeth Montalbano Go to gbhackers.com
-
Lotus Wiper Hits Energy Sector in Destructive Cyberattack
Lotus Wiper Hits Energy Sector in Destructive Cyberattack Hackers have deployed a new destructive malware, dubbed Lotus Wiper , in a targeted cyberattack against energy and utilities organizations in Venezuela, aiming not to extort… Delivered by PolitePaul service Go to gbhackers.com
-
Critical Spring Authorization Server Issue Exposes Systems to XSS and SSRF Attacks
Critical Spring Authorization Server Issue Exposes Systems to XSS and SSRF Attacks A critical vulnerability, tracked as CVE-2026-22752, has been disclosed in Spring Security Authorization Server, affecting organizations running Dynamic Client Registration endpoints. The flaw allows attackers… Delivered by PolitePaul service Go to gbhackers.com
-
Critical Bamboo Data Centre and Server Flaw Enables Command Injection Attacks
Critical Bamboo Data Centre and Server Flaw Enables Command Injection Attacks Atlassian has disclosed a critical OS Command Injection vulnerability (CVE-2026-21571) in Bamboo Data Centre and Server, with a CVSS score of 9.4, enabling authenticated… Delivered by PolitePaul service Go to gbhackers.com
-
Microsoft warns of fake IT worker identities infiltrating cloud environments
Microsoft warns of fake IT worker identities infiltrating cloud environments Microsoft is warning that North Korea‑aligned group Jasper Sleet is abusing remote hiring to slip fake IT workers into cloud environments by posing as… Delivered by PolitePaul service Go to gbhackers.com
-
Auraboros RAT Adds Live Audio, Keylogging, and Cookie Theft via Open C2 Panel
Auraboros RAT Adds Live Audio, Keylogging, and Cookie Theft via Open C2 Panel A fully exposed command-and-control (C2) panel for a previously undocumented remote access trojan (RAT) framework dubbed Auraboros, supporting live audio streaming, intensive keylogging, browser credential… Delivered by PolitePaul service Go to gbhackers.com
-
New GoGra malware for Linux uses Microsoft Graph API for comms
New GoGra malware for Linux uses Microsoft Graph API for comms A Linux variant of the GoGra backdoor uses legitimate Microsoft infrastructure, relying on an Outlook inbox for stealthy payload delivery. […] Bill Toulas Go to bleepingcomputer
-
Microsoft releases emergency patches for critical ASP.NET flaw
Microsoft releases emergency patches for critical ASP.NET flaw Microsoft has released out-of-band (OOB) security updates to patch a critical ASP.NET Core privilege escalation vulnerability. […] Sergiu Gatlan Go to bleepingcomputer
-
Over 1,300 Microsoft SharePoint servers vulnerable to spoofing attacks
Over 1,300 Microsoft SharePoint servers vulnerable to spoofing attacks Over 1,300 Microsoft SharePoint servers exposed online remain unpatched against a spoofing vulnerability that was exploited as a zero-day and is still being abused in ongoing attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
French govt agency confirms breach as hacker offers to sell data
French govt agency confirms breach as hacker offers to sell data France Titres, the government agency in France for issuing and managince administrative documents has disclosed a data breach after a threat actor claimed the attack and stealing citizen data. […] Bill Toulas Go to bleepingcomputer
-
New Lotus data wiper used against Venezuelan energy, utility firms
New Lotus data wiper used against Venezuelan energy, utility firms A previously undocumented data-wiping malware dubbed Lotus was used last year in targeted attacks against energy and utilities organizations in Venezuela. […] Bill Toulas Go to bleepingcomputer
-
Critical Atlassian Bamboo Data Center and Server Flaw Enables Command Injection Attacks
Critical Atlassian Bamboo Data Center and Server Flaw Enables Command Injection Attacks Atlassian has disclosed two significant security vulnerabilities affecting its Bamboo Data Center and Server product, including a critical OS command injection flaw and a high-severity denial-of-service issue tied to a third-party dependency. Organizations running affected versions are strongly urged to apply patches immediately.…
-
1,370+ Microsoft SharePoint Servers Vulnerable to Spoofing Attacks Exposed Online
1,370+ Microsoft SharePoint Servers Vulnerable to Spoofing Attacks Exposed Online A critical spoofing vulnerability in Microsoft SharePoint Server, tracked as CVE-2026-32201, remains unpatched on over 1,370 internet-facing IP addresses worldwide, according to fresh scanning data from the Shadowserver Foundation, even as the flaw sits on CISA’s Known Exploited Vulnerabilities (KEV) catalog with confirmed active exploitation…
-
CrowdStrike LogScale Vulnerability Allows Remote Attackers to Read Arbitrary Files from Server
CrowdStrike LogScale Vulnerability Allows Remote Attackers to Read Arbitrary Files from Server CrowdStrike has issued an urgent security advisory for a critical unauthenticated path-traversal vulnerability (CVE-2026-40050) affecting its LogScale platform, warning that a remote attacker could exploit the flaw to read arbitrary files directly from the server’s filesystem without authentication. The vulnerability resides in a…
-
Microsoft-Signed Binary Used to Sneak LOTUSLITE Into India-Focused Espionage Campaign
Microsoft-Signed Binary Used to Sneak LOTUSLITE Into India-Focused Espionage Campaign A state-linked threat group has been caught running a quiet but carefully planned espionage operation against India’s banking sector, using a trusted Microsoft-signed file to slip malware past security defenses. The campaign delivers a new version of the LOTUSLITE backdoor through a technique known as…