no alarms and no surprises please..
-
Microsoft Emergency .NET 10.0.7 Update to Patch Elevation of Privilege Vulnerability
Microsoft Emergency .NET 10.0.7 Update to Patch Elevation of Privilege Vulnerability Microsoft has issued an emergency out-of-band (OOB) security update for .NET 10, releasing version 10.0.7 on April 21, 2026, to address a critical elevation of privilege vulnerability discovered in the Microsoft.AspNetCore.DataProtection NuGet package. The out-of-band release was prompted after customers began reporting decryption failures…
-
New NGate variant hides in a trojanized NFC payment app
New NGate variant hides in a trojanized NFC payment app ESET researchers discover another iteration of NGate malware, this time possibly developed with the assistance of AI Go to eset
-
SystemBC C2 Server Reveals 1,570+ Victims in The Gentlemen Ransomware Operation
SystemBC C2 Server Reveals 1,570+ Victims in The Gentlemen Ransomware Operation Threat actors associated with The Gentlemen ransomware‑as‑a‑service (RaaS) operation have been observed attempting to deploy a known proxy malware called SystemBC. According to new research published by Check Point, the command-and-control (C2 or C&C) server linked to SystemBC has led to the discovery of…
-
22 BRIDGE:BREAK Flaws Expose Thousands of Lantronix and Silex Serial-to-IP Converters
22 BRIDGE:BREAK Flaws Expose Thousands of Lantronix and Silex Serial-to-IP Converters Cybersecurity researchers have identified 22 new vulnerabilities in popular models of serial-to-IP converters from Lantronix and Silex that could be exploited to hijack susceptible devices and tamper with data exchanged by them. The vulnerabilities have been collectively codenamed BRIDGE:BREAK by Forescout Research Vedere Labs,…
-
Ransomware Negotiator Pleads Guilty to Aiding BlackCat Attacks in 2023
Ransomware Negotiator Pleads Guilty to Aiding BlackCat Attacks in 2023 A third individual who was employed as a ransomware negotiator has pleaded guilty to conducting ransomware attacks against U.S. companies in 2023. Angelo Martino, 41, of Land O’Lakes, Florida, teamed up with the operators of the BlackCat ransomware starting in April 2023 to assist the…
-
5 Places where Mature SOCs Keep MTTR Fast and Others Waste Time
5 Places where Mature SOCs Keep MTTR Fast and Others Waste Time Security teams often present MTTR as an internal KPI. Leadership sees it differently: every hour a threat dwells inside the environment is an hour of potential data exfiltration, service disruption, regulatory exposure, and brand damage. The root cause of slow MTTR is almost…
-
NGate Campaign Targets Brazil, Trojanizes HandyPay to Steal NFC Data and PINs
NGate Campaign Targets Brazil, Trojanizes HandyPay to Steal NFC Data and PINs Cybersecurity researchers have discovered a new iteration of an Android malware family called NGate that has been found to abuse a legitimate application called HandyPay instead of NFCGate. “The threat actors took the app, which is used to relay NFC data, and patched it with malicious…
-
Mexican Surveillance Company
Mexican Surveillance Company Grupo Seguritech is a Mexican surveillance company that is expanding into the US. Bruce Schneier Go to bruce schneier
-
ISC Stormcast For Wednesday, April 22nd, 2026 https://isc.sans.edu/podcastdetail/9902, (Wed, Apr 22nd)
ISC Stormcast For Wednesday, April 22nd, 2026 https://isc.sans.edu/podcastdetail/9902, (Wed, Apr 22nd) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
[Guest Diary] Beyond Cryptojacking: Telegram tdata as a Credential Harvesting Vector, Lessons from a Honeypot Incident, (Wed, Apr 22nd)
[Guest Diary] Beyond Cryptojacking: Telegram tdata as a Credential Harvesting Vector, Lessons from a Honeypot Incident, (Wed, Apr 22nd) [This is a Guest Diary by L. Carty, an ISC intern as part of the SANS.edu Bachelor’s Degree in Applied Cybersecurity (BACS) program [1].] Introduction A few weeks ago, my honeypot logged an incident that changed…
-
A .WAV With A Payload, (Tue, Apr 21st)
A .WAV With A Payload, (Tue, Apr 21st) There have been reports of threat actors using a .wav file as a vector for malware. It’s a proper .wav file, but they didn’t use staganography. The .wav file will play, but you’ll just hear noise: That’s because the TAs have just replaced the bytes that encode…
-
ISC Stormcast For Tuesday, April 21st, 2026 https://isc.sans.edu/podcastdetail/9900, (Tue, Apr 21st)
ISC Stormcast For Tuesday, April 21st, 2026 https://isc.sans.edu/podcastdetail/9900, (Tue, Apr 21st) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Handling the CVE Flood With EPSS, (Mon, Apr 20th)
Handling the CVE Flood With EPSS, (Mon, Apr 20th) Every morning, security people around the world face the same ritual: opening their vulnerability feed to find a lot of new CVE entries that appeared overnight. Over the past decade, this flood has become a defining challenge of modern defensive security. Some numbers[1]: CVEs published in…
-
‘Scattered Spider’ Member ‘Tylerb’ Pleads Guilty
‘Scattered Spider’ Member ‘Tylerb’ Pleads Guilty A 24-year-old British national and senior member of the cybercrime group “Scattered Spider” has pleaded guilty to wire fraud conspiracy and aggravated identity theft. Tyler Robert Buchanan admitted his role in a series of text-message phishing attacks in the summer of 2022 that allowed the group to hack into…
-
173: Tarjeteros
173: Tarjeteros In the streets of the Dominican Republic, a new economy thrives in the shadows. It’s built not on tourism or sugar, but on stolen data. They call them tarjeteros. And they are making a lot of money from stolen credit cards. This is a story about one group of tarjeteros who came to…
-
Weekly Update 500
Weekly Update 500 Looking back at this milestone video, it’s the audience question towards the end I liked most: “are you happy”? Charlotte and I have chosen a path that’s non-traditional, intense and at times, pretty stressful. There’s no clear delineation of when work starts and ends, no holidays where we don’t work, nor weekends,…
-
Ransomware Negotiator Pleads Guilty to BlackCat Scheme
Ransomware Negotiator Pleads Guilty to BlackCat Scheme A cautionary tale illustrates why the person negotiating should never be involved with any part of the ransom payment process, experts noted. Alexander Culafi Go to gbhackers.com
-
Exploits Turn Windows Defender into Attacker Tool
Exploits Turn Windows Defender into Attacker Tool Three proof-of-concept exploits are being used in active attacks against Microsoft’s built-in security platform; two are unpatched. Jai Vijayan Go to gbhackers.com
-
Surge in Bomgar RMM Exploitation Demonstrates Supply Chain Risk
Surge in Bomgar RMM Exploitation Demonstrates Supply Chain Risk The critical remote code execution flaw (CVE-2026-1731) in the remote monitoring and management tool can be exploited to spread ransomware and compromise supply chains. Elizabeth Montalbano Go to gbhackers.com
-
Google Fixes Critical RCE Flaw in AI-Based Antigravity Tool
Google Fixes Critical RCE Flaw in AI-Based Antigravity Tool The prompt injection vulnerability in the agentic AI product for filesystem operations was a sanitization issue that allowed for sandbox escape and arbitrary code execution. Elizabeth Montalbano Go to gbhackers.com
-
Chinese APT Targets Indian Banks, Korean Policy Circles
Chinese APT Targets Indian Banks, Korean Policy Circles China is spying on India’s financial sector, for some reason, and it’s not putting much effort into it, judging by some stale TTPs. Nate Nelson Go to gbhackers.com
-
Apache Syncope RCE Vulnerability Detailed After Public Exploit Code Release
Apache Syncope RCE Vulnerability Detailed After Public Exploit Code Release Security researchers have released full technical details and a working proof-of-concept (PoC) exploit for CVE-2025-57738, a high-severity remote code execution (RCE) vulnerability in Apache… Delivered by PolitePaul service Go to gbhackers.com
-
Microsoft spots Sapphire Sleet macOS attack using AppleScript and social engineering
Microsoft spots Sapphire Sleet macOS attack using AppleScript and social engineering A new macOS-focused cyber campaign linked to the North Korean threat actor Sapphire Sleet, highlighting how attackers are increasingly relying on social engineering rather… Delivered by PolitePaul service Go to gbhackers.com
-
PureRAT Hides PE Payloads in PNGs for Fileless Execution
PureRAT Hides PE Payloads in PNGs for Fileless Execution A multi-stage PureRAT campaign that hides portable executable (PE) payloads inside PNG images and executes them almost entirely in memory, making detection and forensics… Delivered by PolitePaul service Go to gbhackers.com
-
GitHub Issue Alerts Exploited in OAuth Phishing Scam Targeting Developers
GitHub Issue Alerts Exploited in OAuth Phishing Scam Targeting Developers Hackers are abusing GitHub’s own issue-notification emails to phish developers and silently take over their repositories using malicious OAuth applications, effectively turning trusted DevOps… Delivered by PolitePaul service Go to gbhackers.com
-
CISA Alerts Defenders to Exploited Cisco Catalyst SD-WAN Manager Security Flaws
CISA Alerts Defenders to Exploited Cisco Catalyst SD-WAN Manager Security Flaws The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning to network defenders regarding the active exploitation of Cisco Catalyst SD-WAN Manager…. Delivered by PolitePaul service Go to gbhackers.com
-
NGate Android malware uses HandyPay NFC app to steal card data
NGate Android malware uses HandyPay NFC app to steal card data A new variant of the NGate malware that steals NFC payment data is targeting Android users by hiding in a trojanized version of HandyPay, a legitimate mobile payments processing tool. […] Bill Toulas Go to bleepingcomputer
-
KelpDAO suffers $290 million heist tied to Lazarus hackers
KelpDAO suffers $290 million heist tied to Lazarus hackers State-sponsored North Korean hackers are likely behind the $290 million crypto-heist that impacted the KelpDAO DeFi project on Saturday. […] Bill Toulas Go to bleepingcomputer
-
China’s Apple App Store infiltrated by crypto-stealing wallet apps
China’s Apple App Store infiltrated by crypto-stealing wallet apps A set of 26 malicious apps on Apple App Store impersonate popular wallets, such as Metamask, Coinbase, Trust Wallet, and OneKey, to steal recovery or seed phrases and drain them of cryptocurrency assets. […] Bill Toulas Go to bleepingcomputer
-
The Gentlemen ransomware now uses SystemBC for bot-powered attacks
The Gentlemen ransomware now uses SystemBC for bot-powered attacks A SystemBC proxy malware botnet of more than 1,570 hosts, believed to be corporate victims, has been discovered following an investigation into a Gentlemen ransomware attack carried out by a gang affiliate. […] Bill Toulas Go to bleepingcomputer
-
Seiko USA website defaced as hacker claims customer data theft
Seiko USA website defaced as hacker claims customer data theft The Seiko USA website was defaced over the weekend, displaying a message from attackers claiming they stole its Shopify customer database and threatening to leak it unless a ransom is paid. […] Lawrence Abrams Go to bleepingcomputer
-
Claude Code, Gemini CLI, and GitHub Copilot Vulnerable to Prompt Injection via GitHub Comments
Claude Code, Gemini CLI, and GitHub Copilot Vulnerable to Prompt Injection via GitHub Comments A critical cross-vendor vulnerability class dubbed “Comment and Control” is a new category of prompt injection attacks that weaponizes GitHub pull request titles, issue bodies, and issue comments to hijack AI coding agents and steal API keys and access tokens directly from CI/CD…
-
SideWinder Uses Fake Chrome PDF Viewer and Zimbra Clone to Steal Government Webmail Credentials
SideWinder Uses Fake Chrome PDF Viewer and Zimbra Clone to Steal Government Webmail Credentials A well-known advanced persistent threat group called SideWinder has launched a highly targeted phishing campaign against South Asian government organizations, using a fake Chrome PDF viewer and a pixel-perfect clone of the Zimbra email login portal to steal employee credentials. The…
-
PoC Exploit Released for Windows Snipping Tool NTLM Hash Leak Vulnerability
PoC Exploit Released for Windows Snipping Tool NTLM Hash Leak Vulnerability A proof-of-concept (PoC) exploit has been publicly released for a newly disclosed vulnerability in Microsoft’s Snipping Tool that allows attackers to silently steal users’ Net-NTLM credential hashes by luring them to a malicious webpage. Tracked as CVE-2026-33829, the flaw resides in how Windows Snipping…
-
iTerm2 Flaw Abuses SSH Integration Escape Sequences to Turn Text Into Code Execution
iTerm2 Flaw Abuses SSH Integration Escape Sequences to Turn Text Into Code Execution Cybersecurity researchers, working in partnership with OpenAI, have uncovered a fascinating and severe vulnerability in iTerm2, a widely used macOS terminal emulator. According to Califio, the flaw abuses the application’s SSH integration feature, allowing attackers to turn seemingly harmless text output into…
-
British National Admits Hacking Companies and Stealing Millions in Virtual Currency
British National Admits Hacking Companies and Stealing Millions in Virtual Currency A British man has pleaded guilty in the United States to his role in a large cybercrime scheme that used SMS phishing, company network intrusions, and SIM swapping to steal at least $1 million in virtual currency from victims across the country. Tyler Robert…
-
What the ransom note won’t say
What the ransom note won’t say An attack is what you see, but a business operation is what you’re up against Go to eset
-
CISA Adds 8 Exploited Flaws to KEV, Sets April-May 2026 Federal Deadlines
CISA Adds 8 Exploited Flaws to KEV, Sets April-May 2026 Federal Deadlines The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added eight new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including three flaws impacting Cisco Catalyst SD-WAN Manager, citing evidence of active exploitation. The list of vulnerabilities is as follows – CVE-2023-27351…
-
SGLang CVE-2026-5760 (CVSS 9.8) Enables RCE via Malicious GGUF Model Files
SGLang CVE-2026-5760 (CVSS 9.8) Enables RCE via Malicious GGUF Model Files A critical security vulnerability has been disclosed in SGLang that, if successfully exploited, could result in remote code execution on susceptible systems. The vulnerability, tracked as CVE-2026-5760, carries a CVSS score of 9.8 out of 10.0. It has been described as a case of…
-
⚡ Weekly Recap: Vercel Hack, Push Fraud, QEMU Abused, New Android RATs Emerge & More
⚡ Weekly Recap: Vercel Hack, Push Fraud, QEMU Abused, New Android RATs Emerge & More Monday’s recap shows the same pattern in different places. A third-party tool becomes a way in, then leads to internal access. A trusted download path is briefly swapped to deliver malware. Browser extensions act normally while pulling data and running…
-
Why Most AI Deployments Stall After the Demo
Why Most AI Deployments Stall After the Demo The fastest way to fall in love with an AI tool is to watch the demo. Everything moves quickly. Prompts land cleanly. The system produces impressive outputs in seconds. It feels like the beginning of a new era for your team. But most AI initiatives don’t fail…
-
Anthropic MCP Design Vulnerability Enables RCE, Threatening AI Supply Chain
Anthropic MCP Design Vulnerability Enables RCE, Threatening AI Supply Chain Cybersecurity researchers have discovered a critical “by design” weakness in the Model Context Protocol’s (MCP) architecture that could pave the way for remote code execution and have a cascading effect on the artificial intelligence (AI) supply chain. “This flaw enables Arbitrary Command Execution (RCE) on…
-
Is “Satoshi Nakamoto” Really Adam Back?
Is “Satoshi Nakamoto” Really Adam Back? The New York Times has a long article where the author lays out an impressive array of circumstantial evidence that the inventor of Bitcoin is the cypherpunk Adam Back. I don’t know. The article is convincing, but it’s written to be convincing. I can’t remember if I ever met…
-
Vercel Employee’s AI Tool Access Led to Data Breach
Vercel Employee’s AI Tool Access Led to Data Breach Stolen OAuth tokens, which are at the root of these breaches, “are the new attack surface, the new lateral movement,” a researcher noted. Alexander Culafi Go to gbhackers.com
-
Serial-to-IP Devices Hide Thousands of Old and New Bugs
Serial-to-IP Devices Hide Thousands of Old and New Bugs The OT devices that translate machine talk into Internet-speak are riddled with vulnerabilities and more frequently targeted for attacks, researchers say. Nate Nelson Go to gbhackers.com
-
WhatsApp Leaks User Metadata to Attackers
WhatsApp Leaks User Metadata to Attackers Strangers can infer limited info about you without knowing or messaging you, which could theoretically aid certain kinds of malicious activity. Nate Nelson Go to gbhackers.com
-
Iran’s MOIS Tied to Coordinated Cyber Campaign Using Multiple Hacker Personas
Iran’s MOIS Tied to Coordinated Cyber Campaign Using Multiple Hacker Personas A single Iranian state-directed operation is hiding behind several so‑called “hacktivist” brands, using different online identities to run one coordinated global cyber campaign. New analysis… Delivered by PolitePaul service Go to gbhackers.com
-
TBK DVR Vulnerability CVE-2024-3721 Exploited to Spread Nexcorium DDoS Malware
TBK DVR Vulnerability CVE-2024-3721 Exploited to Spread Nexcorium DDoS Malware Hackers are actively exploiting a critical vulnerability in TBK digital video recorder (DVR) devices to deploy a new Mirai-based botnet called Nexcorium. The campaign leverages… Delivered by PolitePaul service Go to gbhackers.com
-
iTerm2 Flaw Turns SSH Escape Sequences Into Arbitrary Code Execution
iTerm2 Flaw Turns SSH Escape Sequences Into Arbitrary Code Execution In the cybersecurity community, we often assume that simply reading a text file using a command like cat is a perfectly safe operation. However, security researchers… Delivered by PolitePaul service Go to gbhackers.com
-
Microsoft-Signed Malware Built With FUD Crypt Packs Persistence and C2
Microsoft-Signed Malware Built With FUD Crypt Packs Persistence and C2 Hackers are abusing a service called FUD Crypt to generate fully undetected, Microsoft‑signed malware that installs persistence and connects to a dedicated command‑and‑control (C2)… Delivered by PolitePaul service Go to gbhackers.com
-
MiningDropper Spreads Infostealers, RATs, Banking Malware on Android
MiningDropper Spreads Infostealers, RATs, Banking Malware on Android Hackers are abusing a modular Android framework called MiningDropper to mine cryptocurrency and silently install infostealers, remote access trojans (RATs), and banking malware on infected devices. MiningDropper… Delivered by PolitePaul service Go to gbhackers.com
-
Microsoft pulls service update causing Teams launch failures
Microsoft pulls service update causing Teams launch failures Microsoft has reverted a recent service update that was preventing some customers from launching the Microsoft Teams desktop client. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft releases emergency updates to fix Windows Server issues
Microsoft releases emergency updates to fix Windows Server issues Microsoft has released out-of-band (OOB) updates to fix issues affecting Windows Server systems after installing the April 2026 security updates. […] Sergiu Gatlan Go to bleepingcomputer
-
Vercel confirms breach as hackers claim to be selling stolen data
Vercel confirms breach as hackers claim to be selling stolen data Cloud development platform Vercel has disclosed a security incident after threat actors claimed to have breached its systems and are attempting to sell stolen data. […] Lawrence Abrams Go to bleepingcomputer
-
Apple account change alerts abused to send phishing emails
Apple account change alerts abused to send phishing emails Apple account change notifications are being abused to send fake iPhone purchase phishing scams within legitimate emails sent from Apple’s servers, increasing legitimacy and potentially allowing them to bypass spam filters. […] Lawrence Abrams Go to bleepingcomputer
-
NIST to stop rating non-priority flaws due to volume increase
NIST to stop rating non-priority flaws due to volume increase The National Institute of Standards and Technology will stop assigning severity scores to lower-priority vulnerabilities due to the growing workload from rising submission volumes. […] Bill Toulas Go to bleepingcomputer
-
Public Notion Pages Leaks Profile Photos and Email address of Editors
Public Notion Pages Leaks Profile Photos and Email address of Editors Notion, a popular productivity and collaboration platform, is under significant scrutiny from the cybersecurity community. Security researchers have revealed that public Notion pages silently expose the personally identifiable information (PII) of anyone who has ever edited them. This data leak includes full names, email…
-
NIST Shifts to Risk-Based NVD Model as CVE Submissions Surge 263% Since 2020
NIST Shifts to Risk-Based NVD Model as CVE Submissions Surge 263% Since 2020 The National Institute of Standards and Technology (NIST) has officially updated how it processes vulnerabilities in the National Vulnerability Database (NVD). According to an April 15, 2026 announcement, NIST is abandoning its comprehensive analysis approach in favor of a targeted, risk-based model.…
-
Google Uses Gemini AI to Stop Malicious Ads From Threat Actors – 8.3 billion ads Blocked
Google Uses Gemini AI to Stop Malicious Ads From Threat Actors – 8.3 billion ads Blocked Threat actors are increasingly leveraging generative AI to launch sophisticated advertising scams at an unprecedented scale. In response, Google has integrated its advanced Gemini AI models into its security infrastructure to neutralize these threats actively. According to Google’s newly…
-
Hackers Use CVE-2024-3721 to Infect TBK DVRs With Nexcorium DDoS Malware
Hackers Use CVE-2024-3721 to Infect TBK DVRs With Nexcorium DDoS Malware A newly identified botnet campaign is actively exploiting a critical flaw in TBK digital video recorders to deploy a dangerous piece of malware known as Nexcorium, a Mirai-based threat built to launch large-scale distributed denial-of-service attacks. The vulnerability at the center of this campaign,…
-
Critical Vulnerability In Flowise Allows Remote Command Execution Via MCP Adapters
Critical Vulnerability In Flowise Allows Remote Command Execution Via MCP Adapters A critical vulnerability in Flowise and multiple AI frameworks has been discovered by OX Security, exposing millions of users to remote code execution (RCE). The flaw stems from the Model Context Protocol (MCP), a widely used communication standard for AI agents developed by Anthropic.…
-
Vercel Breach Tied to Context AI Hack Exposes Limited Customer Credentials
Vercel Breach Tied to Context AI Hack Exposes Limited Customer Credentials Web infrastructure provider Vercel has disclosed a security breach that allows bad actors to gain unauthorized access to “certain” internal Vercel systems. The incident stemmed from the compromise of Context.ai, a third-party artificial intelligence (AI) tool, that was used by an employee at the…
-
Researcher Claims Claude Opus Enabled Creation of Working Chrome Exploit
Researcher Claims Claude Opus Enabled Creation of Working Chrome Exploit A security researcher has shown that Anthropic’s Claude Opus can help build a working browser exploit chain against Google Chrome’s V8 engine, raising fresh… Delivered by PolitePaul service Go to gbhackers.com
-
Critical flaw in Protobuf library enables JavaScript code execution
Critical flaw in Protobuf library enables JavaScript code execution Proof-of-concept exploit code has been published for a critical remote code execution flaw in protobuf.js, a widely used JavaScript implementation of Google’s Protocol Buffers. […] Bill Toulas Go to bleepingcomputer
-
Microsoft Teams right-click paste broken by Edge update bug
Microsoft Teams right-click paste broken by Edge update bug Microsoft is warning that a recent Microsoft Edge browser update introduced a bug that breaks right-click paste in chats in the Microsoft Teams desktop client. […] Lawrence Abrams Go to bleepingcomputer
-
NAKIVO v11.2: Ransomware Defense, Faster Replication, vSphere 9, and Proxmox VE 9.0 Support
NAKIVO v11.2: Ransomware Defense, Faster Replication, vSphere 9, and Proxmox VE 9.0 Support NAKIVO Inc. announced the general availability of NAKIVO Backup & Replication v11.2, focused on fast, reliable, and proactive data protection. […] Sponsored by NAKIVO Go to bleepingcomputer
-
Microsoft Teams Right-Click Paste Broken Following Edge Browser Update
Microsoft Teams Right-Click Paste Broken Following Edge Browser Update A confirmed bug in Microsoft Teams desktop client version 26072.519.4556.7438 is disabling the right-click paste option for users on Windows and macOS, with Microsoft attributing the root cause to a code regression introduced in a recent Microsoft Edge browser update. Users across organizations began reporting on…
-
OpenAI Expands Cyber Defense Program With GPT-5.4-Cyber Access for Trusted Organizations
OpenAI Expands Cyber Defense Program With GPT-5.4-Cyber Access for Trusted Organizations OpenAI has officially launched the expanded phase of its Trusted Access for Cyber program. Granting select organizations access to its specialized GPT-5.4-Cyber model to strengthen digital defenses across critical infrastructure, financial services, and open-source security communities. The program operates on a tiered trust model advanced AI cyber capabilities…
-
Apple Works on Fix for iPhone Passcode Bug Linked to Missing Czech Keyboard Character
Apple Works on Fix for iPhone Passcode Bug Linked to Missing Czech Keyboard Character Apple is reportedly developing a software fix for a frustrating iOS 26 bug that has left some users entirely locked out of their iPhones for months. According to a recent report by The Register, Cupertino’s software engineers are scrambling to patch…
-
Researcher Uses Claude Opus to Build a Working Chrome Exploit Chain
Researcher Uses Claude Opus to Build a Working Chrome Exploit Chain Amidst the heated debate surrounding Anthropic’s recent announcement of its Mythos and Project Glasswing models, a security researcher has demonstrated the tangible cybersecurity implications of frontier AI. Moving beyond theoretical warnings, the researcher successfully utilized Claude Opus to construct a fully functional exploit chain…
-
[Webinar] Eliminate Ghost Identities Before They Expose Your Enterprise Data
[Webinar] Eliminate Ghost Identities Before They Expose Your Enterprise Data In 2024, compromised service accounts and forgotten API keys were behind 68% of cloud breaches. Not phishing. Not weak passwords. Unmanaged non-human identities that nobody was watching. For every employee in your org, there are 40 to 50 automated credentials: service accounts, API tokens, AI agent connections, and OAuth…
-
$13.74M Hack Shuts Down Sanctioned Grinex Exchange After Intelligence Claims
$13.74M Hack Shuts Down Sanctioned Grinex Exchange After Intelligence Claims Grinex, a Kyrgyzstan-incorporated cryptocurrency exchange sanctioned by the U.K. and the U.S. last year, said it’s suspending operations after it blamed Western intelligence agencies for a $13.74 million hack. The exchange said it fell victim to what it described as a large-scale cyber attack that…
-
Nexcorium Mirai Variant Weaponises TBK DVR Vulnerability in Fresh IoT Botnet Push
Nexcorium Mirai Variant Weaponises TBK DVR Vulnerability in Fresh IoT Botnet Push A newly discovered Mirai malware variant named Nexcorium is actively targeting unpatched Internet of Things (IoT) devices. According to recent threat research from FortiGuard… Delivered by PolitePaul service Go to gbhackers.com
-
TP-Link Routers Hit by Mirai in CVE-2023-33538 Attacks
TP-Link Routers Hit by Mirai in CVE-2023-33538 Attacks Hackers are actively scanning for vulnerable TP-Link home routers to push Mirai-style malware, abusing CVE-2023-33538 in a new wave of automated attacks. While the… Delivered by PolitePaul service Go to gbhackers.com
-
SEO Poisoning Attack Uses Microsoft Binary to Install RMM Tool
SEO Poisoning Attack Uses Microsoft Binary to Install RMM Tool New research has exposed a search engine poisoning campaign that delivers a trojanized TestDisk installer, abuses a Microsoft-signed binary for DLL sideloading, and silently… Delivered by PolitePaul service Go to gbhackers.com
-
Operation PowerOFF Knocks Out 75,000 DDoS Attackers and Over 50 Service Domains
Operation PowerOFF Knocks Out 75,000 DDoS Attackers and Over 50 Service Domains A major international law enforcement campaign has hit the DDoS-for-hire ecosystem, warning more than 75,000 suspected users and disrupting the infrastructure that helped power… Delivered by PolitePaul service Go to gbhackers.com
-
Industrial Systems Hit by New Email-Worm Threat Wave
Industrial Systems Hit by New Email-Worm Threat Wave Email-borne worms are driving a fresh wave of incidents against industrial control systems (ICS), even as overall malware activity on these networks appears to… Delivered by PolitePaul service Go to gbhackers.com
-
Payouts King ransomware uses QEMU VMs to bypass endpoint security
Payouts King ransomware uses QEMU VMs to bypass endpoint security The Payouts King ransomware is using the QEMU emulator as a reverse SSH backdoor to run hidden virtual machines on compromised systems and bypass endpoint security. […] Bill Toulas Go to bleepingcomputer
-
Grinex exchange blames “Western intelligence” for $13.7M crypto hack
Grinex exchange blames “Western intelligence” for $13.7M crypto hack Kyrgyzstan-based cryptocurrency exchange Grinex has suspended its operations after suffering a $13.7 million hack attributed to Western intelligence agencies. […] Bill Toulas Go to bleepingcomputer
-
Inside an Underground Guide: How Threat Actors Vet Stolen Credit Card Shops
Inside an Underground Guide: How Threat Actors Vet Stolen Credit Card Shops In cybercrime markets, trust isn’t assumed, it’s verified. Flare reveals how underground guides teach actors to evaluate carding shops based on data quality, reputation, and survivability. […] Sponsored by Flare Go to bleepingcomputer
-
Webinar: From phishing to fallout — Why MSPs must rethink both security and recovery
Webinar: From phishing to fallout — Why MSPs must rethink both security and recovery Cyberattacks are evolving faster than many MSP and corporate defenses can keep up, with phishing driving much of today’s cybercrime. Join our upcoming webinar to learn how to combine security and recovery strategies to reduce risk and maintain business continuity. […]…
-
Fiverr Allegedly Leaks User Information to Google Indexing, Researchers Say
Fiverr Allegedly Leaks User Information to Google Indexing, Researchers Say Freelance service platform Fiverr is facing a significant privacy incident after researchers discovered that sensitive customer files are publicly accessible and indexed by Google search. According to a recent disclosure on Hacker News, an insecure file-hosting configuration has exposed personal identifiable information (PII), including completed…
-
Nexcorium-Associated Mirai Variant Uses TBK DVR Exploit to Scale Botnet Operations
Nexcorium-Associated Mirai Variant Uses TBK DVR Exploit to Scale Botnet Operations A new iteration of the notorious Mirai botnet, dubbed Nexcorium, has emerged in the wild, aggressively targeting internet-connected video recording devices. According to recent threat research published by Fortinet’s FortiGuard Labs, threat actors are exploiting a known command injection vulnerability to hijack TBK DVR…
-
Nearly 6 Million Internet-Facing FTP Servers Still Exposed in 2026, Censys Warns
Nearly 6 Million Internet-Facing FTP Servers Still Exposed in 2026, Censys Warns According to a recent April 2026 report by security researcher Himaja Motheram at Censys, just under 6 million internet-facing hosts are still running the File Transfer Protocol (FTP). While this marks a significant 40% decline from the 10.1 million servers observed in 2024,…
-
PoC Exploit Released for FortiSandbox Vulnerability that Allows Attacker to Execute Commands
PoC Exploit Released for FortiSandbox Vulnerability that Allows Attacker to Execute Commands A proof-of-concept (PoC) exploit has been publicly released for a critical vulnerability in Fortinet’s FortiSandbox product, tracked as CVE-2026-39808. The flaw allows an unauthenticated attacker to execute arbitrary operating system commands as root, the highest privilege level, without requiring any login credentials. The vulnerability…
-
Hackers Target TP-Link Routers With Mirai Malware in CVE-2023-33538 Exploitation Attempts
Hackers Target TP-Link Routers With Mirai Malware in CVE-2023-33538 Exploitation Attempts A known security flaw in several end-of-life TP-Link Wi-Fi routers is being actively targeted by hackers trying to install Mirai-based botnet malware on vulnerable devices. The vulnerability, tracked as CVE-2023-33538, affects multiple TP-Link models that no longer receive vendor updates, leaving users with no…
-
That data breach alert might be a trap
That data breach alert might be a trap Ignoring a real breach notification invites risk, but falling for a bogus one could be even worse. Stop reacting on autopilot. Go to eset
-
Mirai Variant Nexcorium Exploits CVE-2024-3721 to Hijack TBK DVRs for DDoS Botnet
Mirai Variant Nexcorium Exploits CVE-2024-3721 to Hijack TBK DVRs for DDoS Botnet Threat actors are exploiting security flaws in TBK DVR and end‑of‑life (EoL) TP-Link Wi-Fi routers to deploy Mirai-botnet variants on compromised devices, according to findings from Fortinet FortiGuard Labs and Palo Alto Networks Unit 42. The attack targeting TBK DVR devices has been…
-
Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched
Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched Huntress is warning that threat actors are exploiting three recently disclosed security flaws in Microsoft Defender to gain elevated privileges in compromised systems. The activity involves the exploitation of three vulnerabilities that are codenamed BlueHammer (requires GitHub sign-in), RedSun, and UnDefend, all of which were released as…
-
Google Blocks 8.3B Policy-Violating Ads in 2025, Launches Android 17 Privacy Overhaul
Google Blocks 8.3B Policy-Violating Ads in 2025, Launches Android 17 Privacy Overhaul Google this week announced a new set of Play policy updates to strengthen user privacy and protect businesses against fraud, even as it revealed it blocked or removed over 8.3 billion ads globally and suspended 24.9 million accounts in 2025. The new policy…
-
NIST Limits CVE Enrichment After 263% Surge in Vulnerability Submissions
NIST Limits CVE Enrichment After 263% Surge in Vulnerability Submissions The National Institute of Standards and Technology (NIST) has announced changes to the way it handles cybersecurity vulnerabilities and exposures (CVEs) listed in its National Vulnerability Database (NVD), stating it will only enrich those that fulfil certain conditions owing to an explosion in CVE submissions.…
-
Microsoft addresses 163 CVEs, 88 advisories for April Patch Tuesday
Microsoft addresses 163 CVEs, 88 advisories for April Patch Tuesday Following a long-established pattern, the fourth month of the year is one of the cruelest Categories: X-ops, Threat Research Tags: Patch Tuesday Go to sophos
-
Friday Squid Blogging: New Giant Squid Video
Friday Squid Blogging: New Giant Squid Video Pretty fantastic video from Japan of a giant squid eating another squid. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy. Bruce Schneier Go to bruce schneier
-
Mythos and Cybersecurity
Mythos and Cybersecurity Last week, Anthropic pulled back the curtain on Claude Mythos Preview, an AI model so capable at finding and exploiting software vulnerabilities that the company decided it was too dangerous to release to the public. Instead, access has been restricted to roughly 50 organizations—Microsoft, Apple, Amazon Web Services, CrowdStrike and other vendors…
-
ISC Stormcast For Friday, April 17th, 2026 https://isc.sans.edu/podcastdetail/9896, (Fri, Apr 17th)
ISC Stormcast For Friday, April 17th, 2026 https://isc.sans.edu/podcastdetail/9896, (Fri, Apr 17th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Lumma Stealer infection with Sectop RAT (ArechClient2), (Fri, Apr 17th)
Lumma Stealer infection with Sectop RAT (ArechClient2), (Fri, Apr 17th) Introduction This diary provides indicators from a Lumma Stealer infection that was followed by Sectop RAT (ArechClient2). I searched for cracked versions of popular copyright-protected software, and I downloaded the initial malware after following the results of one such search. This is a common distribution…
-
Singer loses life savings to fake wallet downloaded from the Apple App Store
Singer loses life savings to fake wallet downloaded from the Apple App Store If you hold cryptocurrency, there’s a very simple golden rule that you should always follow. Never hand over your seed phrase. Garrett Dutton, better known as G. Love – the front man of blues-hip-hop outfit G. Love & Special Sauce – has…
-
Sometimes changing the password on your email mailbox isn’t enough
Sometimes changing the password on your email mailbox isn’t enough Have you ever taken a look at your Microsoft 365 mailbox rules? If not, it might be worth a few minutes of your time. Because newly released research reveals that hackers may already have beaten you to it. Read more in my article on the…
-
How NIST’s Cutback of CVE Handling Impacts Cyber Teams
How NIST’s Cutback of CVE Handling Impacts Cyber Teams Industry and ad hoc coalitions appear poised to help fill the gap created by NIST’s decision to cut back on CVE data enrichment. Becky Bracken Go to gbhackers.com
-
Every Old Vulnerability Is Now an AI Vulnerability
Every Old Vulnerability Is Now an AI Vulnerability AI’s danger isn’t that it’s creating new bugs, it’s that it’s amplifying old ones. Nik Kale Go to gbhackers.com