no alarms and no surprises please..
-
Coast Guard’s New Cybersecurity Rules Offers Lessons for CISOs
Coast Guard’s New Cybersecurity Rules Offers Lessons for CISOs The Maritime Transportation Security Act (MTSA) requires plans to protect OT systems, audits by independent third parties, and a hybrid OT-security role. Robert Lemos Go to gbhackers.com
-
NIST Revamps CVE Framework to Focus on High-Impact Vulnerabilities
NIST Revamps CVE Framework to Focus on High-Impact Vulnerabilities The National Institute of Standards and Technology carved a new path for vulnerability remediation by changing the way it prioritizes software flaws. Arielle Waldman Go to gbhackers.com
-
Fake Zoom SDK Update Spreads Sapphire Sleet Malware in New macOS Attack Chain
Fake Zoom SDK Update Spreads Sapphire Sleet Malware in New macOS Attack Chain A sophisticated macOS-focused cyber campaign orchestrated by the North Korean threat actor Sapphire Sleet, revealing a shift toward social engineering over traditional software exploitation…. Delivered by PolitePaul service Go to gbhackers.com
-
PoC Released for FortiSandbox Flaw Enabling Arbitrary Command Execution
PoC Released for FortiSandbox Flaw Enabling Arbitrary Command Execution A proof-of-concept (PoC) exploit has been publicly released for a critical security flaw in Fortinet’s FortiSandbox. Tracked as CVE-2026-39808, this severe vulnerability allows an… Delivered by PolitePaul service Go to gbhackers.com
-
Critical Flowise Flaw Enables Remote Command Execution via MCP Adapters
Critical Flowise Flaw Enables Remote Command Execution via MCP Adapters OX Security researchers have uncovered a critical, systemic vulnerability built directly into the architecture of Anthropic’s Model Context Protocol (MCP). As the industry standard… Delivered by PolitePaul service Go to gbhackers.com
-
Weaponized CVE-2026-39987 Pushes Blockchain Backdoor Through Hugging Face
Weaponized CVE-2026-39987 Pushes Blockchain Backdoor Through Hugging Face Attackers are rapidly exploiting CVE-2026-39987 in the marimo Python notebook platform to deploy a new NKAbuse backdoor variant hosted on Hugging Face Spaces, turning… Delivered by PolitePaul service Go to gbhackers.com
-
Hackers Deploy ATHR for Scalable AI-Driven Vishing and Credential Theft
Hackers Deploy ATHR for Scalable AI-Driven Vishing and Credential Theft Hackers are increasingly turning to telephone-oriented attack delivery (TOAD) to bypass traditional email security, and a new cybercrime platform called ATHR is accelerating this… Delivered by PolitePaul service Go to gbhackers.com
-
CISA flags Apache ActiveMQ flaw as actively exploited in attacks
CISA flags Apache ActiveMQ flaw as actively exploited in attacks CISA warned that attackers are now exploiting a high-severity Apache ActiveMQ vulnerability, which was patched earlier this month after going undetected for 13 years. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft: Some Windows servers enter reboot loops after April patches
Microsoft: Some Windows servers enter reboot loops after April patches Microsoft warns that some Windows domain controllers are entering restart loops after installing the April 2026 security updates. […] Sergiu Gatlan Go to bleepingcomputer
-
Man gets 30 months for selling thousands of hacked DraftKings accounts
Man gets 30 months for selling thousands of hacked DraftKings accounts 23-year-old Kamerin Stokes of Memphis, Tennessee, was sentenced to 30 months in prison for selling access to tens of thousands of hacked DraftKings accounts. […] Sergiu Gatlan Go to bleepingcomputer
-
Recently leaked Windows zero-days now exploited in attacks
Recently leaked Windows zero-days now exploited in attacks Threat actors are exploiting three recently disclosed Windows security vulnerabilities in attacks aimed at gaining SYSTEM or elevated administrator permissions. […] Sergiu Gatlan Go to bleepingcomputer
-
Operation PowerOFF identifies 75k DDoS users, takes down 53 domains
Operation PowerOFF identifies 75k DDoS users, takes down 53 domains The latest wave of “Operation PowerOFF,” on April 13, 2026, targeted the distributed denial-of-service (DDoS) ecosystem and its users across 21 countries. […] Bill Toulas Go to bleepingcomputer
-
Microsoft Confirms Windows Servers Enter Reboot Loops Following April Patches
Microsoft Confirms Windows Servers Enter Reboot Loops Following April Patches Microsoft has confirmed a critical known issue affecting Windows Server 2025 domain controllers following the deployment of the April 2026 Patch Tuesday cumulative update, KB5082063, where affected servers are entering repeated reboot loops after installation. Released on April 14, 2026, the cumulative update KB5082063 (OS…
-
Windows Snipping Tool Vulnerability Allows Attacker to Perform Spoofing Over a Network
Windows Snipping Tool Vulnerability Allows Attacker to Perform Spoofing Over a Network Microsoft has addressed a moderate-severity security flaw in the Windows Snipping Tool that could allow malicious actors to steal user credentials. Tracked as CVE-2026-33829, this spoofing vulnerability was officially patched during the April 14, 2026, security updates. Discovered and reported by security researchers…
-
One-Click RCE in Azure Windows Admin Center Allow Attacker to Execute Arbitrary Commands
One-Click RCE in Azure Windows Admin Center Allow Attacker to Execute Arbitrary Commands Windows Admin Center is a locally deployed, browser-based management tool used by IT administrators to manage Windows servers, clients, and clusters from a centralized graphical interface. This newly discovered critical flaw, identified by Cymulate Research Labs, allows attackers to achieve unauthenticated, one-click…
-
Hackers Target Israeli Desalination Plants With ZionSiphon Sabotage Malware
Hackers Target Israeli Desalination Plants With ZionSiphon Sabotage Malware A newly discovered piece of malware called ZionSiphon has raised serious concerns about the security of critical water infrastructure in Israel. The malware was built with a clear focus: to infiltrate and potentially sabotage Israeli water treatment and desalination systems, the very facilities responsible for providing…
-
Hackers Target Trucking and Freight Firms to Steal Real-World Cargo Shipments
Hackers Target Trucking and Freight Firms to Steal Real-World Cargo Shipments A new wave of cyber attacks is hitting trucking carriers and freight brokers, and the goal is not just data theft. Criminals are breaking into logistics companies digitally to steal physical cargo shipments worth millions of dollars in the real world. Cargo theft is…
-
Supply chain dependencies: Have you checked your blind spot?
Supply chain dependencies: Have you checked your blind spot? Your biggest risk may be a vendor you trust. How can SMBs map their third-party blind spots and build operational resilience? Go to eset
-
TR-26-0108 (OAuth2 Proxy Güvenlik Zafiyeti)
TR-26-0108 (OAuth2 Proxy Güvenlik Zafiyeti) Go to usom.gov
-
TR-26-0107 (Fortinet FortiSandbox Güvenlik Bildirimi)
TR-26-0107 (Fortinet FortiSandbox Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0106 (Cisco Çoklu ürün Güvenlik Bildirimi)
TR-26-0106 (Cisco Çoklu ürün Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0105 (Adobe ColdFusion & Connect Güvenlik Bildirimi )
TR-26-0105 (Adobe ColdFusion & Connect Güvenlik Bildirimi ) Go to usom.gov
-
TR-26-0104 (Axios HTTP Client Güvenlik Bildirimi)
TR-26-0104 (Axios HTTP Client Güvenlik Bildirimi) Go to usom.gov
-
Operation PowerOFF Seizes 53 DDoS Domains, Exposes 3 Million Criminal Accounts
Operation PowerOFF Seizes 53 DDoS Domains, Exposes 3 Million Criminal Accounts An international law enforcement operation has taken down 53 domains and arrested four people in connection with commercial distributed denial-of-service (DDoS) operations that were used by more than 75,000 cybercriminals. The ongoing effort, dubbed Operation PowerOFF, disrupted access to the DDoS-for-hire services, took down…
-
Apache ActiveMQ CVE-2026-34197 Added to CISA KEV Amid Active Exploitation
Apache ActiveMQ CVE-2026-34197 Added to CISA KEV Amid Active Exploitation A recently disclosed high-severity security flaw in Apache ActiveMQ Classic has come under active exploitation in the wild, per the U.S. Cybersecurity and Infrastructure Security Agency (CISA). To that end, the agency has added the vulnerability, tracked as CVE-2026-34197 (CVSS score: 8.8), to its Known Exploited Vulnerabilities (KEV) catalog, requiring…
-
Newly Discovered PowMix Botnet Hits Czech Workers Using Randomized C2 Traffic
Newly Discovered PowMix Botnet Hits Czech Workers Using Randomized C2 Traffic Cybersecurity researchers have warned of an active malicious campaign that’s targeting the workforce in the Czech Republic with a previously undocumented botnet dubbed PowMix since at least December 2025. “PowMix employs randomized command-and-control (C2) beaconing intervals, rather than persistent connection to the C2 server, to evade…
-
ThreatsDay Bulletin: Defender 0-Day, SonicWall Brute-Force, 17-Year-Old Excel RCE and 15 More Stories
ThreatsDay Bulletin: Defender 0-Day, SonicWall Brute-Force, 17-Year-Old Excel RCE and 15 More Stories You know that feeling when you open your feed on a Thursday morning and it’s just… a lot? Yeah. This week delivered. We’ve got hackers getting creative in ways that are almost impressive if you ignore the whole “crime” part, ancient vulnerabilities somehow still ruining people’s…
-
[Webinar] Find and Eliminate Orphaned Non-Human Identities in Your Environment
[Webinar] Find and Eliminate Orphaned Non-Human Identities in Your Environment In 2024, compromised service accounts and forgotten API keys were behind 68% of cloud breaches. Not phishing. Not weak passwords. Unmanaged non-human identities that nobody was watching. For every employee in your org, there are 40 to 50 automated credentials: service accounts, API tokens, AI agent connections, andOAuth grants.…
-
QEMU abused to evade detection and enable ransomware delivery
QEMU abused to evade detection and enable ransomware delivery The use of hidden virtual machines (VMs) enables long-term access, credential harvesting, data exfiltration, and PayoutsKing ransomware deployment Categories: Threat Research Tags: virtual machine, QEMU, PayoutsKing, GOLD ENCOUNTER, CitrixBleed2 Go to sophos
-
Human Trust of AI Agents
Human Trust of AI Agents Interesting research: “Humans expect rationality and cooperation from LLM opponents in strategic games.” Abstract: As Large Language Models (LLMs) integrate into our social and economic interactions, we need to deepen our understanding of how humans respond to LLMs opponents in strategic settings. We present the results of the first controlled…
-
Here’s What Agentic AI Can Do With Have I Been Pwned’s APIs
Here’s What Agentic AI Can Do With Have I Been Pwned’s APIs I love cutting-edge tech, but I hate hyperbole, so I find AI to be a real paradox. Somewhere in that whole mess of overnight influencers, disinformation and ludicrous claims is some real “gold” – AI stuff that’s genuinely useful and makes a meaningful…
-
North Korea Uses ClickFix to Target macOS Users’ Data
North Korea Uses ClickFix to Target macOS Users’ Data Sapphire Sleet uses fake job offers and phony Zoom updates to deliver ClickFix attacks that steal credentials and sensitive data from Macs. Alexander Culafi Go to gbhackers.com
-
‘Harmless’ Global Adware Transforms Into an AV Killer
‘Harmless’ Global Adware Transforms Into an AV Killer A benign looking update Dragon Boss pushed out in March 2025 established persistence via scheduled tasks and arranged for future payloads to be excluded from Windows Defender. Nate Nelson Go to gbhackers.com
-
Two-Factor Authentication Breaks Free from the Desktop
Two-Factor Authentication Breaks Free from the Desktop Threat actors know how to bypass security systems outside of traditional IT environments. Implementing 2FA could provide a needed extra security barrier in the physical world. Arielle Waldman Go to gbhackers.com
-
Microsoft’s Original Windows Secure Boot Certificate Is Expiring
Microsoft’s Original Windows Secure Boot Certificate Is Expiring The Secure Boot refresh is one of the largest coordinated security maintenance efforts across the Windows ecosystem, Microsoft said. Update those PCs soon. Jeffrey Schwartz Go to gbhackers.com
-
Hackers Exploit n8n Webhooks to Spread Malware
Hackers Exploit n8n Webhooks to Spread Malware A new abuse campaign targeting AI-driven workflow automation platforms particularly n8n that turns legitimate automation tools into powerful malware delivery systems. Between October 2025 and March… Delivered by PolitePaul service Go to gbhackers.com
-
Two U.S. Nationals Sentenced in $5 Million DPRK Remote Worker Laptop Farm Scheme
Two U.S. Nationals Sentenced in $5 Million DPRK Remote Worker Laptop Farm Scheme The U.S. Justice Department has sentenced two New Jersey residents, Kejia Wang and Zhenxing Wang, for enabling a massive fraudulent employment operation that generated… Delivered by PolitePaul service Go to gbhackers.com
-
New PoC Exploit Published for Microsoft Defender 0-Day Flaw
New PoC Exploit Published for Microsoft Defender 0-Day Flaw A security researcher operating under the alias “Chaotic Eclipse” has publicly released a proof-of-concept (PoC) exploit for a vulnerability in Microsoft Defender. Published on… Delivered by PolitePaul service Go to gbhackers.com
-
Cisco FMC Zero-Day Among 31 High-Impact Vulnerabilities Exploited in March
Cisco FMC Zero-Day Among 31 High-Impact Vulnerabilities Exploited in March 31 high-impact vulnerabilities were actively exploited in March 2026, with a Cisco firewall zero-day abused by the Interlock ransomware group emerging as one of… Delivered by PolitePaul service Go to gbhackers.com
-
Chrome Privacy Vulnerability Exposes Users via Fingerprinting and Header Leaks
Chrome Privacy Vulnerability Exposes Users via Fingerprinting and Header Leaks A new technical review of Google Chrome’s privacy posture shows that modern tracking no longer depends only on cookies, because websites can combine browser… Delivered by PolitePaul service Go to gbhackers.com
-
US nationals behind DPRK IT worker ‘laptop farm’ sent to prison
US nationals behind DPRK IT worker ‘laptop farm’ sent to prison Two U.S. nationals have been sent to prison for helping North Korean remote information technology (IT) workers to pose as U.S. residents and get hired by over 100 companies across the country, including many Fortune 500 firms. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft: April Windows Server 2025 update may fail to install
Microsoft: April Windows Server 2025 update may fail to install Microsoft is investigating an issue causing this month’s KB5082063 security update to fail to install on some Windows Server 2025 systems. […] Sergiu Gatlan Go to bleepingcomputer
-
Critical Nginx UI auth bypass flaw now actively exploited in the wild
Critical Nginx UI auth bypass flaw now actively exploited in the wild A critical vulnerability in Nginx UI with Model Context Protocol (MCP) support is now being exploited in the wild for full server takeover without authentication. […] Bill Toulas Go to bleepingcomputer
-
New AgingFly malware used in attacks on Ukraine govt, hospitals
New AgingFly malware used in attacks on Ukraine govt, hospitals A new malware family named ‘AgingFly’ has been identified in attacks against local governments and hospitals that steal authentication data from Chromium-based browsers and WhatsApp messenger. […] Bill Toulas Go to bleepingcomputer
-
WordPress plugin suite hacked to push malware to thousands of sites
WordPress plugin suite hacked to push malware to thousands of sites More than 30 WordPress plugins in the EssentialPlugin package have been compromised with malicious code that allows unauthorized access to websites running them. […] Bill Toulas Go to bleepingcomputer
-
New Chrome Privacy Analysis Shows How Fingerprinting and Header Leaks Can Expose Users
New Chrome Privacy Analysis Shows How Fingerprinting and Header Leaks Can Expose Users Google Chrome is the most widely used browser in the world, yet a sweeping new analysis reveals it offers users almost no protection against fingerprinting and data leaks that quietly expose their identity to websites and trackers. Published April 14, 2026, the…
-
Splunk Enterprise and Cloud Platform Vulnerability Enables Remote Code Execution Attacks
Splunk Enterprise and Cloud Platform Vulnerability Enables Remote Code Execution Attacks A critical security vulnerability has been officially disclosed, affecting multiple versions of Enterprise and Cloud platforms. Tracked as CVE-2026-20204, this high-severity flaw carries a CVSS score of 7.1 and poses a significant threat to organizational networks. Discovered and reported by Splunk researcher Gabriel Nitu,…
-
Critical Chrome Vulnerabilities Let Attackers Execute Arbitrary Code – Update Now!
Critical Chrome Vulnerabilities Let Attackers Execute Arbitrary Code – Update Now! Google has rolled out a crucial security update for its Chrome browser, addressing 31 vulnerabilities that could leave systems exposed to severe cyber threats. Released on April 15, 2026, this Stable Channel update requires immediate attention from users worldwide, as the most severe flaws…
-
Fake Adobe Reader Download Delivers ScreenConnect Through Stealthy In-Memory Loader
Fake Adobe Reader Download Delivers ScreenConnect Through Stealthy In-Memory Loader A newly uncovered attack campaign is tricking users into installing remote access software on their systems by disguising malware as a legitimate Adobe Acrobat Reader download. The attack uses a sophisticated chain of techniques — including in-memory execution, process masquerading, and privilege escalation — to…
-
1,250+ C2 Servers Mapped Across Russian Hosting Across 165 Providers
1,250+ C2 Servers Mapped Across Russian Hosting Across 165 Providers Cybersecurity researchers have uncovered a large and organized network of malicious infrastructure quietly running inside Russia’s commercial hosting ecosystem. Over a three-month window from January 1 to April 1, 2026, more than 1,250 active command-and-control (C2) servers were detected across 165 Russian infrastructure providers, spanning…
-
UAC-0247 Targets Ukrainian Clinics and Government in Data-Theft Malware Campaign
UAC-0247 Targets Ukrainian Clinics and Government in Data-Theft Malware Campaign The Computer Emergencies Response Team of Ukraine (CERT-UA) has disclosed details of a new campaign that has targeted governments and municipal healthcare institutions, mainly clinics and emergency hospitals, to deliver malware capable of stealing sensitive data from Chromium-based web browsers and WhatsApp. The activity, which was observed between March and April…
-
n8n Webhooks Abused Since October 2025 to Deliver Malware via Phishing Emails
n8n Webhooks Abused Since October 2025 to Deliver Malware via Phishing Emails Threat actors have been observed weaponizing n8n, a popular artificial intelligence (AI) workflow automation platform, to facilitate sophisticated phishing campaigns and deliver malicious payloads or fingerprint devices by sending automated emails. “By leveraging trusted infrastructure, these attackers bypass traditional security filters, turning productivity tools into delivery…
-
Actively Exploited nginx-ui Flaw (CVE-2026-33032) Enables Full Nginx Server Takeover
Actively Exploited nginx-ui Flaw (CVE-2026-33032) Enables Full Nginx Server Takeover A recently disclosed critical security flaw impacting nginx-ui, an open-source, web-based Nginx management tool, has come under active exploitation in the wild. The vulnerability in question is CVE-2026-33032 (CVSS score: 9.8), an authentication bypass vulnerability that enables threat actors to seize control of the Nginx service.…
-
April Patch Tuesday Fixes Critical Flaws Across SAP, Adobe, Microsoft, Fortinet, and More
April Patch Tuesday Fixes Critical Flaws Across SAP, Adobe, Microsoft, Fortinet, and More A number of critical vulnerabilities impacting products from Adobe, Fortinet, Microsoft, and SAP have taken center stage in April’s Patch Tuesday releases. Topping the list is an SQL injection vulnerability impacting SAP Business Planning and Consolidation and SAP Business Warehouse (CVE-2026-27681, CVSS score: 9.9) that…
-
Deterministic + Agentic AI: The Architecture Exposure Validation Requires
Deterministic + Agentic AI: The Architecture Exposure Validation Requires Few technologies have moved from experimentation to boardroom mandate as quickly as AI. Across industries, leadership teams have embraced its broader potential, and boards, investors, and executives are already pushing organizations to adopt it across operational and security functions. Pentera’s AI Security and Exposure Report 2026 reflects that momentum: every…
-
6-Year Ransomware Campaign Targets Turkish Homes & SMBs
6-Year Ransomware Campaign Targets Turkish Homes & SMBs While enterprises breaches make more headlines, smaller incidents tend to be under-reported, if at all, allowing campaigns to last longer with less disruption. Nate Nelson Go to gbhackers.com
-
Defense in Depth, Medieval Style
Defense in Depth, Medieval Style This article on the walls of Constantinople is fascinating. The system comprised four defensive lines arranged in formidable layers: The brick-lined ditch, divided by bulkheads and often flooded, 15-20 meters wide and up to 7 meters deep. A low breastwork, about 2 meters high, enabling defenders to fire freely from…
-
ISC Stormcast For Thursday, April 16th, 2026 https://isc.sans.edu/podcastdetail/9894, (Thu, Apr 16th)
ISC Stormcast For Thursday, April 16th, 2026 https://isc.sans.edu/podcastdetail/9894, (Thu, Apr 16th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
[Guest Diary] Compromised DVRs and Finding Them in the Wild, (Thu, Apr 16th)
[Guest Diary] Compromised DVRs and Finding Them in the Wild, (Thu, Apr 16th) [This is a Guest Diary by Alec Jaffe, an ISC intern as part of the SANS.edu Bachelor’s Degree in Applied Cybersecurity (BACS) program [1]. Security cameras are great at monitoring physical doors, but terrible at locking their own digital ones. Across the…
-
Smashing Security podcast #463: This AI company leaked its own code. It’s also built something terrifying
Smashing Security podcast #463: This AI company leaked its own code. It’s also built something terrifying A hacking group claims to have broken into the flood defence system protecting Venice’s Piazza San Marco – and is offering to sell access to whoever wants it. The asking price? A frankly insulting $600. Meanwhile, Anthropic accidentally leaked…
-
108 malicious Chrome extensions caught stealing Google and Telegram data from 20,000 users
108 malicious Chrome extensions caught stealing Google and Telegram data from 20,000 users Cybersecurity researchers have revealed that 108 malicious Google Chrome extensions have been quietly stealing user credentials, hijacking Telegram sessions, and injecting unwanted ads and scripts into browsers – all reporting back to the same central point. Read more in my article on…
-
Critical MCP Integration Flaw Puts NGINX at Risk
Critical MCP Integration Flaw Puts NGINX at Risk Attackers can abuse the near-maximum severity flaw in nginx-ui to restart, create, modify, and delete NGINX configuration files. Jai Vijayan Go to gbhackers.com
-
Navigating the Unique Security Risks of Asia’s Digital Supply Chain
Navigating the Unique Security Risks of Asia’s Digital Supply Chain Regulatory differences, interconnected digital ecosystems, and the rise of AI have created a complex supply chain Asian organizations must wrangle. Alexander Culafi Go to gbhackers.com
-
Prepping for ‘Q-Day’: Why Quantum Risk Management Should Start Now
Prepping for ‘Q-Day’: Why Quantum Risk Management Should Start Now Quantum computers are coming and may impact systems in unexpected ways, and it will “take years to be fully quantum-safe, if ever,” cryptography expert warns. Rob Wright Go to gbhackers.com
-
Audit: Big Tech Often Ignores CA Privacy Law Opt-Out Requests
Audit: Big Tech Often Ignores CA Privacy Law Opt-Out Requests Google, Meta, and Microsoft about half the time don’t comply with requests to opt out of online tracking per a California law mandate, privacy watchdog finds. Elizabeth Montalbano Go to gbhackers.com
-
Microsoft, Salesforce Patch AI Agent Data Leak Flaws
Microsoft, Salesforce Patch AI Agent Data Leak Flaws Two recently fixed prompt injections in Salesforce Agentforce and Microsoft Copilot would have enabled an external attacker to leak sensitive data. Alexander Culafi Go to gbhackers.com
-
Trusted WordPress Plugins Hijacked in 8-Month Stealth Backdoor Campaign
Trusted WordPress Plugins Hijacked in 8-Month Stealth Backdoor Campaign Hackers secretly planted a remote code-execution backdoor in more than 30 popular WordPress plugins, leaving it dormant for about 8 months before activating malware… Delivered by PolitePaul service Go to gbhackers.com
-
Windows Active Directory Flaw Opens Door to Malicious Code Execution
Windows Active Directory Flaw Opens Door to Malicious Code Execution Microsoft disclosed a critical security vulnerability within Windows Active Directory that exposes enterprise networks to severe risks. Tracked officially as CVE-2026-33826, this vulnerability allows… Delivered by PolitePaul service Go to gbhackers.com
-
Microsoft Rolls Out KB5083769 Update for Windows 11 24H2 and 25H2
Microsoft Rolls Out KB5083769 Update for Windows 11 24H2 and 25H2 Microsoft has released KB5083769, the April 14, 2026 cumulative security update for Windows 11 versions 24H2 and 25H2, moving the operating system to builds… Delivered by PolitePaul service Go to gbhackers.com
-
Hackers Exploit Hidden Microsoft 365 Mailbox Rules to Steal Sensitive Business Emails
Hackers Exploit Hidden Microsoft 365 Mailbox Rules to Steal Sensitive Business Emails Attackers are quietly abusing Microsoft 365 mailbox rules to steal emails, hide alerts, and maintain long-term access without installing malware. These stealthy tactics are… Delivered by PolitePaul service Go to gbhackers.com
-
Agentic LLM Browsers Open New Front in Prompt Injection, Data Theft
Agentic LLM Browsers Open New Front in Prompt Injection, Data Theft Agentic LLM browsers are turning everyday browsing into automated, AI-driven workflows but they also expose a powerful new attack surface for prompt injection and… Delivered by PolitePaul service Go to gbhackers.com
-
Microsoft adds Windows protections for malicious Remote Desktop files
Microsoft adds Windows protections for malicious Remote Desktop files Microsoft has introduced new Windows protections to defend against phishing attacks that abuse Remote Desktop connection (.rdp) files, adding warnings and disabling risky shared resources by default. […] Lawrence Abrams Go to bleepingcomputer
-
Crypto-exchange Kraken extorted by hackers after insider breach
Crypto-exchange Kraken extorted by hackers after insider breach The Kraken cryptocurrency exchange announced that a cybercrime group is trying to extort the company by threatening to release videos showing internal systems that host client data. […] Bill Toulas Go to bleepingcomputer
-
Over 100 Chrome Web Store extensions steal user accounts, data
Over 100 Chrome Web Store extensions steal user accounts, data More than 100 malicious extensions in the official Chrome Web Store are attempting to steal Google OAuth2 Bearer tokens, deploy backdoors, and carry out ad fraud. […] Bill Toulas Go to bleepingcomputer
-
Microsoft releases Windows 10 KB5082200 extended security update
Microsoft releases Windows 10 KB5082200 extended security update Microsoft has released the Windows 10 KB5082200 extended security update to fix the April 2026 Patch Tuesday vulnerabilities, including 2 zero-days. […] Lawrence Abrams Go to bleepingcomputer
-
McGraw-Hill confirms data breach following extortion threat
McGraw-Hill confirms data breach following extortion threat Education company McGraw-Hill has confirmed in a statement to BleepingComputer that hackers exploited a Salesforce misconfiguration and accessed its internal data. […] Bill Toulas Go to bleepingcomputer
-
FUNNULL-Linked Triad Nexus Resurfaces With 175+ Rotating CNAME Domains and Global Scam Portals
FUNNULL-Linked Triad Nexus Resurfaces With 175+ Rotating CNAME Domains and Global Scam Portals A cybercriminal group tied to the FUNNULL Content Delivery Network has made a calculated return with a far more sophisticated and evasive infrastructure. Known as Triad Nexus, the group has rebuilt its global fraud operation following U.S. Treasury sanctions, deploying over 175…
-
Windows BitLocker Vulnerability Allows Attacker to Bypass Security Feature
Windows BitLocker Vulnerability Allows Attacker to Bypass Security Feature Microsoft officially released security updates to address a significant vulnerability in Windows BitLocker. Tracked as CVE-2026-27913, this security feature bypass vulnerability was discovered by security researcher Alon Leviev in collaboration with the Microsoft STORM team. The flaw poses a substantial risk to enterprise device security architectures.…
-
New JanaWare Ransomware Targets Turkish Users Through Customized Adwind RAT
New JanaWare Ransomware Targets Turkish Users Through Customized Adwind RAT A new ransomware family called JanaWare has begun targeting computer users in Turkey, relying on a customized version of the Adwind remote access trojan (RAT) to gain a foothold on victims’ systems. This campaign stands out because it combines a known cross‑platform RAT with fresh…
-
Microsoft Defender 0-Day Vulnerability Enables Privilege Escalation Attack
Microsoft Defender 0-Day Vulnerability Enables Privilege Escalation Attack Microsoft has released patch Tuesday security updates to address a newly discovered zero-day vulnerability in the Microsoft Defender Antimalware Platform. Disclosed on April 14, 2026, the flaw is tracked as CVE-2026-33825 and carries an “Important” severity rating. If successfully exploited, this elevation-of-privilege vulnerability allows an attacker…
-
25,000+ Endpoints Exposed by Dragon Boss Solutions Update Domain Supply Chain Attack
25,000+ Endpoints Exposed by Dragon Boss Solutions Update Domain Supply Chain Attack What started as a routine adware alert quickly turned into something far more serious. On the morning of March 22, 2026, security alerts began firing across multiple managed environments, all linked to software signed by a company called Dragon Boss Solutions LLC. The…
-
OpenAI Launches GPT-5.4-Cyber with Expanded Access for Security Teams
OpenAI Launches GPT-5.4-Cyber with Expanded Access for Security Teams OpenAI on Tuesday unveiled GPT-5.4-Cyber, a variant of its latest flagship model, GPT‑5.4, that’s specifically optimized for defensive cybersecurity use cases, days after rival Anthropic unveiled its own frontier model, Mythos. “The progressive use of AI accelerates defenders – those responsible for keeping systems, data, and users safe –…
-
New PHP Composer Flaws Enable Arbitrary Command Execution — Patches Released
New PHP Composer Flaws Enable Arbitrary Command Execution — Patches Released Two high-severity security vulnerabilities have been disclosed in Composer, a package manager for PHP, that, if successfully exploited, could result in arbitrary command execution. The vulnerabilities have been described as command injection flaws affecting the Perforce VCS (version control software) driver. Details of the two flaws are below – CVE-2026-40176…
-
Google Adds Rust-Based DNS Parser into Pixel 10 Modem to Enhance Security
Google Adds Rust-Based DNS Parser into Pixel 10 Modem to Enhance Security Google has announced the integration of a Rust-based Domain Name System (DNS) parser into the modem firmware as part of its ongoing efforts to beef up the security of Pixel devices and push memory-safe code at a more foundational level. “The new Rust-based DNS…
-
AI-Driven Pushpaganda Scam Exploits Google Discover to Spread Scareware and Ad Fraud
AI-Driven Pushpaganda Scam Exploits Google Discover to Spread Scareware and Ad Fraud Cybersecurity researchers have unmasked a novel ad fraud scheme that has been found to leverage search engine poisoning (SEO) techniques and artificial intelligence (AI)-generated content to push deceptive news stories into Google’s Discover feed and trick users into enabling persistent browser notifications that lead to…
-
Mirax Android RAT Turns Devices into SOCKS5 Proxies, Reaching 220,000 via Meta Ads
Mirax Android RAT Turns Devices into SOCKS5 Proxies, Reaching 220,000 via Meta Ads A nascent Android remote access trojan called Mirax has been observed actively targeting Spanish-speaking countries, with campaigns reaching more than 220,000 accounts on Facebook, Instagram, Messenger, and Threads through advertisements on Meta. “Mirax integrates advanced Remote Access Trojan (RAT) capabilities, allowing threat actors to…
-
Upcoming Speaking Engagements
Upcoming Speaking Engagements This is a current list of where and when I am scheduled to speak: I’m speaking at DemocracyXChange 2026 in Toronto, Ontario, Canada, on April 18, 2026. I’m speaking at the SANS AI Cybersecurity Summit 2026 in Arlington, Virginia, USA, at 9:40 AM ET on April 20, 2026. I’m speaking at the…
-
How Hackers Are Thinking About AI
How Hackers Are Thinking About AI Interesting paper: “What hackers talk about when they talk about AI: Early-stage diffusion of a cybercrime innovation.” Abstract: The rapid expansion of artificial intelligence (AI) is raising concerns about its potential to transform cybercrime. Beyond empowering novice offenders, AI stands to intensify the scale and sophistication of attacks by…
-
ISC Stormcast For Wednesday, April 15th, 2026 https://isc.sans.edu/podcastdetail/9892, (Wed, Apr 15th)
ISC Stormcast For Wednesday, April 15th, 2026 https://isc.sans.edu/podcastdetail/9892, (Wed, Apr 15th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Scanning for AI Models, (Tue, Apr 14th)
Scanning for AI Models, (Tue, Apr 14th) Starting March 10, 2026, my DShield sensor started getting probe for various AI models such as claude, openclaw, huggingface, etc. Reviewing the data already reported by other DShield sensors to ISC, the DShield database shows reporting of these probes started that day and has been active ever since.…
-
Microsoft Patch Tuesday April 2026., (Tue, Apr 14th)
Microsoft Patch Tuesday April 2026., (Tue, Apr 14th) This month’s Microsoft Patch Tuesday looks like a record one, but let’s look at it a bit closer to understand what is happening The update patches a total of 243 vulnerabilities. However, 78 of them are Chromium issues affecting Microsoft Edge. Patches for Edge were released earlier.…
-
Patch Tuesday, April 2026 Edition
Patch Tuesday, April 2026 Edition Microsoft today pushed software updates to fix a staggering 167 security vulnerabilities in its Windows operating systems and related software, including a SharePoint Server zero-day and a publicly disclosed weakness in Windows Defender dubbed “BlueHammer.” Separately, Google Chrome fixed its fourth zero-day of 2026, and an emergency update for Adobe…
-
Microsoft Bets $10 Billion to Boost Japan’s AI, Cybersecurity
Microsoft Bets $10 Billion to Boost Japan’s AI, Cybersecurity The deal aims to accelerate AI adoption, train workers, and develop cybersecurity partnerships — the latest move by a hyperscaler to compete for sovereign AI and data centers. Robert Lemos Go to gbhackers.com
-
Weekly Update 499
Weekly Update 499 I’m starting to become pretty fond of Bruce. Actually, I’ve had a bit of an epiphany: an AI assistant like Bruce isn’t just about auto-responding to tickets in an entirely autonomous manner; it’s also pretty awesome at responding with just a little bit of human assistance. Charlotte and I both replied to…
-
Privilege Elevation Dominates Massive Microsoft Patch Update
Privilege Elevation Dominates Massive Microsoft Patch Update Elevation-of-privilege bugs accounted for more than half of the 165 vulnerabilities patched, with two zero-days in that mix. Jai Vijayan Go to gbhackers.com
-
EDR-Killer Ecosystem Expansion Requires Stronger BYOVD Defenses
EDR-Killer Ecosystem Expansion Requires Stronger BYOVD Defenses Stopping EDR killers, which employ bring-your-own-vulnerable-driver (BYOVD) attack techniques, is difficult, but not impossible. Rob Wright Go to gbhackers.com
-
Wargame Exercise Demonstrates How Social Media Manipulation Works
Wargame Exercise Demonstrates How Social Media Manipulation Works In an educational game called “Capture the Narrative,” students created bots to sway a fictional election, simulating influence in real-world political scenarios. Elizabeth Montalbano Go to gbhackers.com
-
CISA Alerts on Exploited Microsoft Exchange and Windows CLFS Security Flaws
CISA Alerts on Exploited Microsoft Exchange and Windows CLFS Security Flaws The Cybersecurity and Infrastructure Security Agency (CISA) has issued a high-priority alert regarding two actively exploited security vulnerabilities in Microsoft products. Added to the… Delivered by PolitePaul service Go to gbhackers.com
-
Hackers Exploit Obsidian Plugin to Deploy Cross-Platform Malware
Hackers Exploit Obsidian Plugin to Deploy Cross-Platform Malware Hackers are abusing Obsidian’s Shell Commands plugin and shared cloud vaults to deliver a new cross‑platform malware chain that ends with the PHANTOMPULSE remote… Delivered by PolitePaul service Go to gbhackers.com
-
Hackers Exploit Critical ShowDoc RCE Flaw in Ongoing Attacks
Hackers Exploit Critical ShowDoc RCE Flaw in Ongoing Attacks Cybersecurity researchers have highlighted a critical vulnerability in ShowDoc, a widely used online document-sharing platform designed for IT teams. Tracked as CNVD-2020-26585, this severe… Delivered by PolitePaul service Go to gbhackers.com