no alarms and no surprises please..
-
Hackers Exploit Critical ShowDoc RCE Flaw in Ongoing Attacks
Hackers Exploit Critical ShowDoc RCE Flaw in Ongoing Attacks Cybersecurity researchers have highlighted a critical vulnerability in ShowDoc, a widely used online document-sharing platform designed for IT teams. Tracked as CNVD-2020-26585, this severe… Delivered by PolitePaul service Go to gbhackers.com
-
SAP Patch Day Fixes Critical SQL Injection, DoS, and Code Injection Flaws
SAP Patch Day Fixes Critical SQL Injection, DoS, and Code Injection Flaws SAP released its monthly Security Patch Day updates, addressing 19 new security notes and one update to a previously released note. According to the… Delivered by PolitePaul service Go to gbhackers.com
-
Okta Under Attack as Hackers Skip Phishing for Identity Systems
Okta Under Attack as Hackers Skip Phishing for Identity Systems Hackers are shifting away from email phishing and are directly targeting Okta and other identity providers using voice‑based social engineering, or “Okta vishing.” This… Delivered by PolitePaul service Go to gbhackers.com
-
European Gym giant Basic-Fit data breach affects 1 million members
European Gym giant Basic-Fit data breach affects 1 million members Dutch fitness giant Basic-Fit announced that hackers breached its systems and gained access to information belonging to a million of its customers. […] Bill Toulas Go to bleepingcomputer
-
Stolen Rockstar Games analytics data leaked by extortion gang
Stolen Rockstar Games analytics data leaked by extortion gang Rockstar Games has suffered a data breach linked to a recent security incident at Anodot, with the ShinyHunters extortion gang now leaking the stolen data on its data leak site. […] Lawrence Abrams Go to bleepingcomputer
-
Critical flaw in wolfSSL library enables forged certificate use
Critical flaw in wolfSSL library enables forged certificate use A critical vulnerability in the wolfSSL SSL/TLS library can weaken security via improper verification of the hash algorithm or its size when checking Elliptic Curve Digital Signature Algorithm (ECDSA) signatures. […] Bill Toulas Go to bleepingcomputer
-
FBI takedown of W3LL phishing service leads to developer arrest
FBI takedown of W3LL phishing service leads to developer arrest The FBI Atlanta Field Office and Indonesian authorities have dismantled the “W3LL” global phishing platform, seizing infrastructure and arresting the alleged developer in what is described as the first coordinated enforcement action between the United States and Indonesia targeting a phishing kit developer. […] Lawrence Abrams…
-
OpenAI rotates macOS certs after Axios attack hit code-signing workflow
OpenAI rotates macOS certs after Axios attack hit code-signing workflow OpenAI is rotating potentially exposed macOS code-signing certificates after a GitHub Actions workflow executed a malicious Axios package during a recent supply chain attack. […] Lawrence Abrams Go to bleepingcomputer
-
Hackers Use Fake Proxifier Installer on GitHub to Spread ClipBanker Crypto-Stealing Malware
Hackers Use Fake Proxifier Installer on GitHub to Spread ClipBanker Crypto-Stealing Malware A dangerous malware campaign has been silently targeting cryptocurrency users by hiding inside a fake version of Proxifier, a popular proxy software tool. Threat actors set up a GitHub repository designed to look like a legitimate Proxifier download, but the installer bundled inside…
-
Rockstar’s GTA Game Hacked – Attackers published 78.6 Million Records Online
Rockstar’s GTA Game Hacked – Attackers published 78.6 Million Records Online Rockstar Games has confirmed a data breach after the notorious hacking group ShinyHunters exploited a third-party integration to access the company’s internal Snowflake data warehouse, ultimately leaking over 78.6 million records on April 14, 2026. The breach did not stem from a direct attack…
-
Claude AI Reportedly Down for Hundreds of Users With Intermittent 500 Errors
Claude AI Reportedly Down for Hundreds of Users With Intermittent 500 Errors Anthropic’s Claude AI is facing a fresh wave of user-reported disruptions on April 13, 2026, with hundreds of users encountering intermittent HTTP 500 internal server errors across claude.ai, the API, and Claude Code, even as Anthropic’s official status page continues to show “All…
-
Hackers Abuse GitHub and Jira Notifications to Deliver Phishing Through Trusted SaaS Channels
Hackers Abuse GitHub and Jira Notifications to Deliver Phishing Through Trusted SaaS Channels Cybercriminals are now weaponizing the very tools that developers and IT teams trust the most. By abusing the automated notification features built into GitHub and Jira, threat actors are delivering convincing phishing emails that originate directly from those platforms’ own servers. What…
-
Mozilla Criticizes Microsoft for Installing Copilot on Windows Without User Consent
Mozilla Criticizes Microsoft for Installing Copilot on Windows Without User Consent Mozilla has publicly criticized Microsoft for deploying its AI assistant, Copilot, onto Windows systems without user consent, a practice the Firefox maker describes as prioritizing corporate revenue over user rights. In a blog post titled “Old Habits Die Hard,” Mozilla accused Microsoft of using…
-
TR-26-0103 (Totolink A7100RU Güvenlik Bildirimi)
TR-26-0103 (Totolink A7100RU Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0102 (Adobe Acrobat Reader Güvenlik Bildirimi )
TR-26-0102 (Adobe Acrobat Reader Güvenlik Bildirimi ) Go to usom.gov
-
TR-26-0101 (UniFi Play Güvenlik Bildirimi)
TR-26-0101 (UniFi Play Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0100 (SAP Güvenlik Bildirimi)
TR-26-0100 (SAP Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0099 (WordPress Eklenti Güvenlik Bildirimi)
TR-26-0099 (WordPress Eklenti Güvenlik Bildirimi) Go to usom.gov
-
ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers
ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers A critical security vulnerability impacting ShowDoc, a document management and collaboration service popular in China, has come under active exploitation in the wild. The vulnerability in question is CVE-2025-0520 (aka CNVD-2020-26585), which carries a CVSS score of 9.4 out of 10.0. It relates to a case of unrestricted file upload that…
-
CISA Adds 6 Known Exploited Flaws in Fortinet, Microsoft, and Adobe Software
CISA Adds 6 Known Exploited Flaws in Fortinet, Microsoft, and Adobe Software The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added half a dozen security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The list of vulnerabilities is as follows – CVE-2026-21643 (CVSS score: 9.1) – An SQL injection vulnerability in …
-
JanelaRAT Malware Targets Latin American Banks with 14,739 Attacks in Brazil in 2025
JanelaRAT Malware Targets Latin American Banks with 14,739 Attacks in Brazil in 2025 Banks and financial institutions in Latin American countries like Brazil and Mexico have continued to be the target of a malware family called JanelaRAT. A modified version of BX RAT, JanelaRAT is known to steal financial and cryptocurrency data associated with specific…
-
FBI and Indonesian Police Dismantle W3LL Phishing Network Behind $20M Fraud Attempts
FBI and Indonesian Police Dismantle W3LL Phishing Network Behind $20M Fraud Attempts The U.S. Federal Bureau of Investigation (FBI), in partnership with the Indonesian National Police, has dismantled the infrastructure associated with a global phishing operation that leveraged an off-the-shelf toolkit called W3LL to steal thousands of victims’ account credentials and attempt more than $20 million…
-
⚡ Weekly Recap: Fiber Optic Spying, Windows Rootkit, AI Vulnerability Hunting and More
⚡ Weekly Recap: Fiber Optic Spying, Windows Rootkit, AI Vulnerability Hunting and More Monday is back, and the weekend’s backlog of chaos is officially hitting the fan. We are tracking a critical zero-day that has been quietly living in your PDFs for months, plus some aggressive state-sponsored meddling in infrastructure that is finally coming to light. It is…
-
On Anthropic’s Mythos Preview and Project Glasswing
On Anthropic’s Mythos Preview and Project Glasswing The cybersecurity industry is obsessing over Anthropic’s new model, Claude Mythos Preview, and its effects on cybersecurity. Anthropic said that it is not releasing it to the general public because of its cyberattack capabilities, and has launched Project Glasswing to run the model against a whole slew of…
-
AI Chatbots and Trust
AI Chatbots and Trust All the leading AI chatbots are sycophantic, and that’s a problem: Participants rated sycophantic AI responses as more trustworthy than balanced ones. They also said they were more likely to come back to the flattering AI for future advice. And critically they couldn’t tell the difference between sycophantic and objective…
-
ISC Stormcast For Tuesday, April 14th, 2026 https://isc.sans.edu/podcastdetail/9890, (Tue, Apr 14th)
ISC Stormcast For Tuesday, April 14th, 2026 https://isc.sans.edu/podcastdetail/9890, (Tue, Apr 14th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Scans for EncystPHP Webshell, (Mon, Apr 13th)
Scans for EncystPHP Webshell, (Mon, Apr 13th) Last week, I wrote about attackers scanning for various webshells, hoping to find some that do not require authentication or others that use well-known credentials. But some attackers are paying attention and are deploying webshells with more difficult-to-guess credentials. Today, I noticed some scans for what appears to be…
-
ISC Stormcast For Monday, April 13th, 2026 https://isc.sans.edu/podcastdetail/9888, (Mon, Apr 13th)
ISC Stormcast For Monday, April 13th, 2026 https://isc.sans.edu/podcastdetail/9888, (Mon, Apr 13th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Obfuscated JavaScript or Nothing, (Thu, Apr 9th)
Obfuscated JavaScript or Nothing, (Thu, Apr 9th) I spotted an interesting piece of JavaScript code that was delivered via a phishing email in a RAR archive. The file was called “cbmjlzan.JS” (SHA256:a8ba9ba93b4509a86e3d7dd40fd0652c2743e32277760c5f7942b788b74c5285) and is only identified as malicious by 15 AV’s on VirusTotal[1]. The file is pretty big (10MB) and contains a copy of the…
-
CSA: CISOs Should Prepare for Post-Mythos Exploit Storm
CSA: CISOs Should Prepare for Post-Mythos Exploit Storm Security experts warn of an “AI vulnerability storm” triggered by the introduction of Anthropic’s Claude Mythos in a new paper from the Cloud Security Alliance (CSA). Alexander Culafi Go to gbhackers.com
-
Adobe Patches Actively Exploited Zero-Day That Lingered for Months
Adobe Patches Actively Exploited Zero-Day That Lingered for Months An attacker has been using maliciously crafted PDF files to exploit a zero-day in Adobe Acrobat and Reader for at least four months. Jai Vijayan Go to gbhackers.com
-
Empty Attestations: OT Lacks the Tools for Cryptographic Readiness
Empty Attestations: OT Lacks the Tools for Cryptographic Readiness OT asset owners are being asked by regulators to attest to their post-quantum cryptographic readiness without the appropriate tooling, resulting in paperwork dressed up to look like genuine security. Brad McInnis Go to gbhackers.com
-
APT41 Delivers ‘Zero-Detection’ Backdoor to Harvest Cloud Credentials
APT41 Delivers ‘Zero-Detection’ Backdoor to Harvest Cloud Credentials The prolific China-backed threat group is targeting AWS, Google, Azure, and Alibaba cloud environments and using typosquatting to obscure C2 communication. Elizabeth Montalbano Go to gbhackers.com
-
Iran-Linked CyberAv3ngers Target Water Utilities, Industrial Controllers
Iran-Linked CyberAv3ngers Target Water Utilities, Industrial Controllers Iran-linked threat group CyberAv3ngers is intensifying attacks on U.S. water utilities and industrial control systems, shifting from noisy hacktivism to sustained disruption of operational technology (OT)… Delivered by PolitePaul service Go to gbhackers.com
-
Basic-Fit Suffers Data Breach Affecting Millions Across Multiple Nations
Basic-Fit Suffers Data Breach Affecting Millions Across Multiple Nations European fitness operator Basic-Fit has confirmed a significant data breach affecting approximately one million members across its network. The incident heavily impacted users in… Delivered by PolitePaul service Go to gbhackers.com
-
Critical Axios Vulnerability Enables Remote Code Execution, PoC Released
Critical Axios Vulnerability Enables Remote Code Execution, PoC Released A critical security vulnerability has been discovered in Axios, one of the most widely used HTTP client libraries, exposing applications to Remote Code Execution… Delivered by PolitePaul service Go to gbhackers.com
-
VIPERTUNNEL Python Backdoor Hidden in Fake DLL, Obfuscated Loader Chain
VIPERTUNNEL Python Backdoor Hidden in Fake DLL, Obfuscated Loader Chain Hackers are abusing a stealthy Python backdoor called VIPERTUNNEL, hiding it behind a fake DLL file and a multi‑stage obfuscated loader to quietly tunnel traffic… Delivered by PolitePaul service Go to gbhackers.com
-
Marimo RCE Vulnerability Exploited Within 10 Hours of Public Disclosure
Marimo RCE Vulnerability Exploited Within 10 Hours of Public Disclosure A critical remote code execution (RCE) vulnerability in the open-source Python notebook platform Marimo was actively exploited less than 10 hours after its public… Delivered by PolitePaul service Go to gbhackers.com
-
Critical Marimo pre-auth RCE flaw now under active exploitation
Critical Marimo pre-auth RCE flaw now under active exploitation A critical pre-authentication remote code execution (RCE) vulnerability in Marimo is now under active exploitation, leveraged for credential theft. […] Bill Toulas Go to bleepingcomputer
-
Microsoft Confirms Recent Windows 11 Updates Break Push Button Reset
Microsoft Confirms Recent Windows 11 Updates Break Push Button Reset Microsoft has officially acknowledged that recent security updates for Windows 11 are causing the “Reset this PC” (Push-button reset) recovery feature to fail. The issue was confirmed in the release notes for the March 2026 hotpatch updates, affecting systems running the latest operating system version.…
-
Critical WordPress Plugin Flaw Lets Attackers Bypass Authentication and Gain Admin Access
Critical WordPress Plugin Flaw Lets Attackers Bypass Authentication and Gain Admin Access A critical security flaw found in a widely used WordPress plugin is putting thousands of websites at serious risk worldwide. Tracked as CVE-2026-1492, this vulnerability affects the User Registration & Membership plugin for WordPress and lets attackers completely bypass the login process to…
-
WhatsApp’s ‘End-to-End Encryption by Default’ Claim Called Major Consumer Fraud by Pavel Durov
WhatsApp’s ‘End-to-End Encryption by Default’ Claim Called Major Consumer Fraud by Pavel Durov Telegram founder Pavel Durov has accused WhatsApp of perpetrating what he calls “the biggest consumer fraud in history,” alleging that the platform’s widely marketed end-to-end encryption (E2EE) claims are fundamentally misleading, leaving the private messages of billions of users exposed on unencrypted…
-
Over 20,000 crypto fraud victims identified in international crackdown
Over 20,000 crypto fraud victims identified in international crackdown An international law enforcement action led by the U.K.’s National Crime Agency (NCA) has identified over 20,000 victims of cryptocurrency fraud across Canada, the United Kingdom, and the United States. […] Sergiu Gatlan Go to bleepingcomputer
-
OpenAI Warns macOS Users to Update ChatGPT and Codex Immediately
OpenAI Warns macOS Users to Update ChatGPT and Codex Immediately OpenAI has disclosed a security incident tied to the compromise of Axios, a widely used third-party JavaScript developer library, as part of a broader software supply chain attack detected on March 31, 2026. While the company confirmed no user data, API keys, or systems were…
-
CPUID Breach Distributes STX RAT via Trojanized CPU-Z and HWMonitor Downloads
CPUID Breach Distributes STX RAT via Trojanized CPU-Z and HWMonitor Downloads Unknown threat actors compromised CPUID (“cpuid[.]com”), a website that hosts popular hardware monitoring tools like CPU-Z, HWMonitor, HWMonitor Pro, and PerfMonitor, for less than 24 hours to serve malicious executables for the software and deploy a remote access trojan called STX RAT. The incident lasted from…
-
Adobe Patches Actively Exploited Acrobat Reader Flaw CVE-2026-34621
Adobe Patches Actively Exploited Acrobat Reader Flaw CVE-2026-34621 Adobe has released emergency updates to fix a critical security flaw in Acrobat Reader that has come under active exploitation in the wild. The vulnerability, assigned the CVE identifier CVE-2026-34621, carries a CVSS score of 8.6 out of 10.0. Successful exploitation of the flaw could allow an attacker to…
-
Citizen Lab: Law Enforcement Used Webloc to Track 500 Million Devices via Ad Data
Citizen Lab: Law Enforcement Used Webloc to Track 500 Million Devices via Ad Data Hungarian domestic intelligence, the national police in El Salvador, and several U.S. law enforcement and police departments have been attributed to the use of an advertising-based global geolocation surveillance system called Webloc. The tool was developed by Israeli company Cobwebs Technologies and is…
-
AI and cryptocurrency scams are costing Americans billions, FBI reports
AI and cryptocurrency scams are costing Americans billions, FBI reports The fraud landscape has been changed by AI and cryptocurrency in a way that should concern organisations and individuals alike. Read more in my article on the Fortra blog. Graham Cluley Go to grahamcluley
-
Google Locks Chrome Sessions to Devices to Stop Cookie Theft
Google Locks Chrome Sessions to Devices to Stop Cookie Theft Google has officially launched a major security upgrade to protect users from session hijacking. Starting with Chrome version 146 for Windows users, Device Bound… Delivered by PolitePaul service Go to gbhackers.com
-
Claude and ChatGPT Exploited in Sweeping Cyber Campaign Against Government Agencies
Claude and ChatGPT Exploited in Sweeping Cyber Campaign Against Government Agencies In a groundbreaking technical report released by Gambit Security researcher Eyal Sela, new details have emerged about a massive cyberattack targeting government infrastructure. A… Delivered by PolitePaul service Go to gbhackers.com
-
Storm-2755 Uses AiTM Hijacking to Divert Employee Salaries
Storm-2755 Uses AiTM Hijacking to Divert Employee Salaries Hackers are abusing adversary-in-the-middle (AiTM) session hijacking to steal employee salaries in a new “payroll pirate” campaign tracked by Microsoft as Storm-2755 and targeting… Delivered by PolitePaul service Go to gbhackers.com
-
EngageSDK Vulnerability puts millions of crypto wallets at risk
EngageSDK Vulnerability puts millions of crypto wallets at risk A newly disclosed vulnerability in the widely used Android library EngageSDK has raised serious concerns across the cryptocurrency ecosystem, potentially exposing millions of users… Delivered by PolitePaul service Go to gbhackers.com
-
Hackers Exploit GitHub Copilot Flaw to Exfiltrate Sensitive Data
Hackers Exploit GitHub Copilot Flaw to Exfiltrate Sensitive Data A high-severity flaw in GitHub Copilot Chat recently allowed attackers to silently steal sensitive data like API keys and private source code. Tracked as… Delivered by PolitePaul service Go to gbhackers.com
-
ChatGPT rolls out new $100 Pro subscription to challenge Claude
ChatGPT rolls out new $100 Pro subscription to challenge Claude OpenAI has rolled out a new Pro subscription that costs $100 and is in line with Claude’s pricing, which also has a $100 subscription, in addition to the $200 Max monthly plan. […] Mayank Parmar Go to bleepingcomputer
-
Nearly 4,000 US industrial devices exposed to Iranian cyberattacks
Nearly 4,000 US industrial devices exposed to Iranian cyberattacks The attack surface targeted by Iranian-linked hackers in cyberattacks against U.S. critical infrastructure networks includes thousands of Internet-exposed programmable logic controllers (PLCs) manufactured by Rockwell Automation. […] Sergiu Gatlan Go to bleepingcomputer
-
Analysis of one billion CISA KEV remediation records exposes limits of human-scale security
Analysis of one billion CISA KEV remediation records exposes limits of human-scale security Analysis of 1 billion CISA KEV remediation records reveal a breaking point for human-scale security. Qualys shows most critical flaws are exploited before defenders can patch them. […] Sponsored by Qualys Go to bleepingcomputer
-
CPUID hacked to deliver malware via CPU-Z, HWMonitor downloads
CPUID hacked to deliver malware via CPU-Z, HWMonitor downloads Hackers gained access to an API for the CPUID project and changed the download links on the official website to serve malicious executables for the popular CPU-Z and HWMonitor tools. […] Bill Toulas Go to bleepingcomputer
-
Microsoft: Canadian employees targeted in payroll pirate attacks
Microsoft: Canadian employees targeted in payroll pirate attacks A financially motivated threat actor tracked as Storm-2755 is stealing Canadian employees’ salary payments after hijacking their accounts in payroll pirate attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
Google Launches Gmail End-to-End Encryption for Android and iOS
Google Launches Gmail End-to-End Encryption for Android and iOS Google has officially rolled out End-to-End Encryption (E2EE) for the Gmail application on Android and iOS devices. This major update targets users utilizing Gmail client-side encryption. It allows organisations to handle sensitive data confidentially directly from their smartphones or tablets. The feature ensures compliance with strict…
-
Google Unveils Device-Bound Chrome Sessions in Anti-Cookie-Theft Move
Google Unveils Device-Bound Chrome Sessions in Anti-Cookie-Theft Move Google officially announced the public rollout of Device Bound Session Credentials (DBSC) for Windows users on Chrome 146. According to the Google Account Security and Chrome teams, this major security update aims to eliminate session hijacking, a primary method for attackers to compromise user accounts. The feature…
-
Ransomware Gangs Expand Use of EDR Killers Beyond Vulnerable Drivers, ESET Warns
Ransomware Gangs Expand Use of EDR Killers Beyond Vulnerable Drivers, ESET Warns In recent years, Endpoint Detection and Response (EDR) killers have become a standard, highly effective weapon in modern ransomware intrusions. Before launching their file-encrypting malware, cybercriminals routinely deploy specialized tools to bypass security software. According to a comprehensive new report by ESET Research,…
-
Hacker Uses Claude and ChatGPT to Breach Multiple Government Agencies
Hacker Uses Claude and ChatGPT to Breach Multiple Government Agencies A single threat actor compromised nine Mexican government agencies and stole hundreds of millions of citizen records in a highly sophisticated cyberattack. The campaign, which ran from late December 2025 through mid-February 2026, highlights a dangerous shift in the modern threat landscape. Researchers at Gambit…
-
Anthropic Launches Claude Beta for Word, Bringing AI-Powered Editing to Microsoft Docs
Anthropic Launches Claude Beta for Word, Bringing AI-Powered Editing to Microsoft Docs Anthropic has officially launched Claude for Word in public beta, bringing its AI assistant directly into Microsoft Word as a native sidebar add-in for Team and Enterprise users on both Mac and Windows platforms. The integration marks a significant step in Anthropic’s push…
-
Recovery scammers hit you when you’re down: Here’s how to avoid a second strike
Recovery scammers hit you when you’re down: Here’s how to avoid a second strike If you’ve been the victim of fraud, you’re likely already a lead on a ‘sucker list’ – and if you’re not careful, your ordeal may be about to get worse. Go to eset
-
TR-26-0097 (Totolink A7100RU Güvenlik Bildirimi)
TR-26-0097 (Totolink A7100RU Güvenlik Bildirimi) Go to usom.gov
-
GlassWorm Campaign Uses Zig Dropper to Infect Multiple Developer IDEs
GlassWorm Campaign Uses Zig Dropper to Infect Multiple Developer IDEs Cybersecurity researchers have flagged yet another evolution of the ongoing GlassWorm campaign, which employs a new Zig dropper that’s designed to stealthily infect all integrated development environments (IDEs) on a developer’s machine. The technique has been discovered in an Open VSX extension named “specstudio.code-wakatime-activity-tracker,” which masquerades as WakaTime,…
-
Browser Extensions Are the New AI Consumption Channel That No One Is Talking About
Browser Extensions Are the New AI Consumption Channel That No One Is Talking About While much of the discussion on AI security centers around protecting ‘shadow’ AI and GenAI consumption, there’s a wide-open window nobody’s guarding: AI browser extensions. A new report from LayerX exposes just how deep this blind spot goes, and why AI extensions may be the most…
-
Google Rolls Out DBSC in Chrome 146 to Block Session Theft on Windows
Google Rolls Out DBSC in Chrome 146 to Block Session Theft on Windows Google has made Device Bound Session Credentials (DBSC) generally available to all Windows users of its Chrome web browser, months after it began testing the security feature in open beta. The public availability is currently limited to Windows users on Chrome 146, with macOS expansion planned in…
-
Marimo RCE Flaw CVE-2026-39987 Exploited Within 10 Hours of Disclosure
Marimo RCE Flaw CVE-2026-39987 Exploited Within 10 Hours of Disclosure A critical security vulnerability in Marimo, an open-source Python notebook for data science and analysis, has been exploited within 10 hours of public disclosure, according to findings from Sysdig. The vulnerability in question is CVE-2026-39987 (CVSS score: 9.3), a pre-authenticated remote code execution vulnerability impacting all versions of Marimo…
-
Backdoored Smart Slider 3 Pro Update Distributed via Compromised Nextend Servers
Backdoored Smart Slider 3 Pro Update Distributed via Compromised Nextend Servers Unknown threat actors have hijacked the update system for the Smart Slider 3 Pro plugin for WordPress and Joomla to push a poisoned version containing a backdoor. The incident impacts Smart Slider 3 Pro version 3.5.1.35 for WordPress, per WordPress security company Patchstack. Smart Slider 3 is a…
-
Friday Squid Blogging: Squid Overfishing in the South Pacific
Friday Squid Blogging: Squid Overfishing in the South Pacific Regulation is hard: The South Pacific Regional Fisheries Management Organization (SPRFMO) oversees fishing across roughly 59 million square kilometers (22 million square miles) of the South Pacific high seas, trying to impose order on a region double the size of Africa, where distant-water fleets pursue species…
-
Sen. Sanders Talks to Claude About AI and Privacy
Sen. Sanders Talks to Claude About AI and Privacy Claude is actually pretty good on the issues. Bruce Schneier Go to bruce schneier
-
Hims Breach Exposes the Most Sensitive Kinds of PHI
Hims Breach Exposes the Most Sensitive Kinds of PHI Threat actors breached the telehealth brand, and now they may know who’s bald, overweight, and impotent. What could they do with that information? Nate Nelson Go to gbhackers.com
-
Your Next Breach Will Look Like Business as Usual
Your Next Breach Will Look Like Business as Usual These are the fundamental detection model shifts cybersecurity teams need to make to keep up with the rising number of credential-based attacks. Jeanette Miller-Osborn Go to gbhackers.com
-
FINRA Launches Financial Intelligence Fusion Center to Combat Cybersecurity and Fraud Threats
FINRA Launches Financial Intelligence Fusion Center to Combat Cybersecurity and Fraud Threats Go to gbhackers.com
-
Orange Business Reimagines Enterprise Voice Communications With Trust and AI
Orange Business Reimagines Enterprise Voice Communications With Trust and AI Go to gbhackers.com
-
Industrial Controllers Still Vulnerable As Conflicts Move to Cyber
Industrial Controllers Still Vulnerable As Conflicts Move to Cyber The US government warns programmable logic controllers are being targeted, and research turns up 179 vulnerable operational technology (OT) devices. Robert Lemos Go to gbhackers.com
-
Iranian APT alert: 5,219 Rockwell PLCs exposed online
Iranian APT alert: 5,219 Rockwell PLCs exposed online Censys has warned that more than 5,000 Rockwell Automation/Allen-Bradley PLCs are currently exposed to the internet as Iranian-affiliated APT actors actively target these devices… Go to gbhackers.com
-
Middle East Espionage Attack Uses Fake Secure Messaging Apps to Deliver ProSpy
Middle East Espionage Attack Uses Fake Secure Messaging Apps to Deliver ProSpy Hackers are impersonating popular secure messaging apps to deploy a sophisticated Android spyware tool called ProSpy against journalists, activists, and political figures across the Middle East,… Go to gbhackers.com
-
HPE Aruba Private 5G Vulnerability Opens Door to Credential Theft Attacks
HPE Aruba Private 5G Vulnerability Opens Door to Credential Theft Attacks A newly disclosed security flaw in HPE Aruba Networking Private 5G Core On-Prem is putting enterprise networks at severe risk of credential theft. Documented… Go to gbhackers.com
-
TP-Link Devices at Risk as Multiple Security Flaws Enable Takeover
TP-Link Devices at Risk as Multiple Security Flaws Enable Takeover Cybersecurity researchers have uncovered five significant security vulnerabilities in the TP-Link Archer AX53 v1.0 router. If left unpatched, these critical flaws could allow attackers… Go to gbhackers.com
-
New React Server Components Flaw Could Let Attackers Trigger DoS
New React Server Components Flaw Could Let Attackers Trigger DoS A newly disclosed high-severity vulnerability in React Server Components could allow unauthenticated attackers to trigger a Denial of Service (DoS) condition. Tracked as CVE-2026-23869,… Go to gbhackers.com
-
New ‘LucidRook’ malware used in targeted attacks on NGOs, universities
New ‘LucidRook’ malware used in targeted attacks on NGOs, universities A new Lua-based malware, called LucidRook, is being used in spear-phishing campaigns targeting non-governmental organizations and universities in Taiwan. […] Bill Toulas Go to bleepingcomputer
-
New VENOM phishing attacks steal senior executives’ Microsoft logins
New VENOM phishing attacks steal senior executives’ Microsoft logins Threat actors using a previously undocumented phishing-as-a-service (PhaaS) platform called “VENOM” are targeting credentials of C-suite executives across multiple industries. […] Bill Toulas Go to bleepingcomputer
-
Healthcare IT solutions provider ChipSoft hit by ransomware attack
Healthcare IT solutions provider ChipSoft hit by ransomware attack Dutch healthcare software vendor ChipSoft has been impacted by a ransomware attack that forced the company to take offline its website and digital services for patients and healthcare providers. […] Bill Toulas Go to bleepingcomputer
-
Google Chrome adds infostealer protection against session cookie theft
Google Chrome adds infostealer protection against session cookie theft Google has rolled out Device Bound Session Credentials (DBSC) protection in Chrome 146 for Windows, designed to block info-stealing malware from harvesting session cookies. […] Ionut Ilascu Go to bleepingcomputer
-
Smart Slider updates hijacked to push malicious WordPress, Joomla versions
Smart Slider updates hijacked to push malicious WordPress, Joomla versions Hackers hijacked the update system for the Smart Slider 3 Pro plugin for WordPress and Joomla, and pushed a malicious version with multiple backdoors. […] Bill Toulas Go to bleepingcomputer
-
CPUID Website Compromised to Deliver Weaponized HWMonitor and CPU-Z Tools
CPUID Website Compromised to Deliver Weaponized HWMonitor and CPU-Z Tools The cpuid-dot-com website, home to widely used system utilities CPU-Z and HWMonitor, is at the center of an active supply chain security incident. Users downloading HWMonitor 1.63 or CPU-Z ZIPs since early April have reportedly received trojanized installers capable of dropping malicious DLLs, evading antivirus…
-
Trojanized OpenVSX Extension Spreads GlassWorm Across VS Code, Cursor, and Windsurf
Trojanized OpenVSX Extension Spreads GlassWorm Across VS Code, Cursor, and Windsurf A fake developer extension published on the OpenVSX marketplace is silently spreading a known malware strain called GlassWorm to every code editor installed on a developer’s machine. The malicious package disguises itself as a legitimate productivity tool and uses a compiled native binary to…
-
Mallory Launches AI-Native Threat Intelligence Platform, Turning Global Threat Data Into Prioritized Action
Mallory Launches AI-Native Threat Intelligence Platform, Turning Global Threat Data Into Prioritized Action Austin, Texas, United States, April 9th, 2026, CyberNewswire Built by a veteran security team and led by a former Google and Mandiant executive, Mallory delivers intelligence that drives action for enterprise security teams. Mallory is launching a AI-native threat intelligence platform, purpose-built…
-
Juniper Networks Default Password Vulnerability Let Attacker Take Full Control of the Device
Juniper Networks Default Password Vulnerability Let Attacker Take Full Control of the Device A critical security alert warns of a severe default password vulnerability affecting Support Insights Virtual Lightweight Collector (vLWC) appliances. This flaw enables unauthenticated network-based attackers to gain full administrative control of exposed network devices easily. Formally tracked as CVE-2026-33784, this vulnerability has…
-
DesckVB RAT Uses Obfuscated JavaScript and Fileless .NET Loader to Evade Detection
DesckVB RAT Uses Obfuscated JavaScript and Fileless .NET Loader to Evade Detection A new Remote Access Trojan known as DesckVB has been targeting systems in 2026, using obfuscated JavaScript and a fileless .NET loader to stay hidden from traditional security tools. The malware gives attackers full remote control over a victim’s machine, making it a…
-
TR-26-0096 (Canonical LXD Güvenlik Bildirimi)
TR-26-0096 (Canonical LXD Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0095 (IBM Çoklu Ürün Güvenlik Bildirimi)
TR-26-0095 (IBM Çoklu Ürün Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0094 (Samsung Çoklu Ürün Güvenlik Bildirimi)
TR-26-0094 (Samsung Çoklu Ürün Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0093 (Mozilla Firefox/Thunderbird Güvenlik Bildirimi)
TR-26-0093 (Mozilla Firefox/Thunderbird Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0092 (Totolink A7100RU Güvenlik Bildirimi)
TR-26-0092 (Totolink A7100RU Güvenlik Bildirimi) Go to usom.gov
-
EngageLab SDK Flaw Exposed 50M Android Users, Including 30M Crypto Wallet Installs
EngageLab SDK Flaw Exposed 50M Android Users, Including 30M Crypto Wallet Installs Details have emerged about a now-patched security vulnerability in a widely used third-party Android software development kit (SDK) called EngageLab SDK that could have put millions of cryptocurrency wallet users at risk. “This flaw allows apps on the same device to bypass Android security sandbox and gain…
-
UAT-10362 Targets Taiwanese NGOs with LucidRook Malware in Spear-Phishing Campaigns
UAT-10362 Targets Taiwanese NGOs with LucidRook Malware in Spear-Phishing Campaigns A previously undocumented threat cluster dubbed UAT-10362 has been attributed to spear-phishing campaigns targeting Taiwanese non-governmental organizations (NGOs) and suspected universities to deploy a new Lua-based malware called LucidRook. “LucidRook is a sophisticated stager that embeds a Lua interpreter and Rust-compiled libraries within a dynamic-link library…
-
ThreatsDay Bulletin: Hybrid P2P Botnet, 13-Year-Old Apache RCE and 18 More Stories
ThreatsDay Bulletin: Hybrid P2P Botnet, 13-Year-Old Apache RCE and 18 More Stories Thursday. Another week, another batch of things that probably should’ve been caught sooner but weren’t. This one’s got some range — old vulnerabilities getting new life, a few “why was that even possible” moments, attackers leaning on platforms and tools you’d normally trust without thinking…