no alarms and no surprises please..
-
The Hidden Security Risks of Shadow AI in Enterprises
The Hidden Security Risks of Shadow AI in Enterprises As AI tools become more accessible, employees are adopting them without formal approval from IT and security teams. While these tools may boost productivity, automate tasks, or fill gaps in existing workflows, they also operate outside the visibility of security teams, bypassing controls and creating new blind spots…
-
Adobe Reader Zero-Day Exploited via Malicious PDFs Since December 2025
Adobe Reader Zero-Day Exploited via Malicious PDFs Since December 2025 Threat actors have been exploiting a previously unknown zero-day vulnerability in Adobe Reader using maliciously crafted PDF documents since at least December 2025. The finding, detailed by EXPMON’s Haifei Li, has been described as a highly-sophisticated PDF exploit. The artifact (“Invoice540.pdf”) first appeared on the VirusTotal platform on…
-
We let OpenClaw loose on an internal network. Here’s what it found
We let OpenClaw loose on an internal network. Here’s what it found <p>Following our article on the challenges posed by agentic AI, we gave OpenClaw access to one of our legacy networks</p> Categories: Threat Research Tags: OpenClaw, LLM, AI, penetration testing, Red Team, CISO, Sophos X-Ops Go to sophos
-
On Microsoft’s Lousy Cloud Security
On Microsoft’s Lousy Cloud Security ProPublica has a scoop: In late 2024, the federal government’s cybersecurity evaluators rendered a troubling verdict on one of Microsoft’s biggest cloud computing offerings. The tech giant’s “lack of proper detailed security documentation” left reviewers with a “lack of confidence in assessing the system’s overall security posture,” according to an…
-
Russia’s ‘Fancy Bear’ APT Continues Its Global Onslaught
Russia’s ‘Fancy Bear’ APT Continues Its Global Onslaught Victims don’t need to match the cybercrime group’s technical sophistication, experts say. But patching and some form of zero trust are now non-negotiable. Alexander Culafi Go to gbhackers.com
-
‘BlueHammer’ Windows Zero-Day Exploit Signals Microsoft Bug Disclosure Issues
‘BlueHammer’ Windows Zero-Day Exploit Signals Microsoft Bug Disclosure Issues Under the alias ‘Chaotic Eclipse,’ a researcher released a PoC exploit for a zero-day flaw that allows for system takeover by a local user, citing an undisclosed beef with Microsoft. Elizabeth Montalbano Go to gbhackers.com
-
Do Ceasefires Slow Cyberattacks? History Suggests Not
Do Ceasefires Slow Cyberattacks? History Suggests Not The cybersecurity community is waiting with bated breath to see if Iranian hackers will honor a ceasefire that doesn’t actually name or directly involve them. Nate Nelson Go to gbhackers.com
-
STX RAT Hides Remote Desktop, Steals Data to Dodge Detection
STX RAT Hides Remote Desktop, Steals Data to Dodge Detection A stealthy new remote access trojan, dubbed STX RAT, that blends hidden remote desktop control with powerful infostealer capabilities while using advanced evasion and encryption techniques… Go to gbhackers.com
-
Microsoft Details How Defender Protects High-Value Assets in Real-World Attacks
Microsoft Details How Defender Protects High-Value Assets in Real-World Attacks Microsoft has significantly upgraded its Defender platform to automatically detect and block sophisticated cyberattacks targeting High-Value Assets (HVAs) like domain controllers and web servers…. Go to gbhackers.com
-
Fake Security Tool Spreads LucidRook in Taiwan Cyberattacks
Fake Security Tool Spreads LucidRook in Taiwan Cyberattacks Hackers are using fake security tools and cleverly crafted phishing emails to secretly deploy a new malware family, LucidRook, against organizations in Taiwan. The campaign, tracked… Go to gbhackers.com
-
China’s Tianjin Supercomputer Center Allegedly Hit in 10-Petabyte Data Theft
China’s Tianjin Supercomputer Center Allegedly Hit in 10-Petabyte Data Theft A threat actor has allegedly executed one of the largest data heists in China’s history, siphoning an astounding 10 petabytes of highly classified information… Go to gbhackers.com
-
CISA Issues Warning on Critical Ivanti EPMM Flaw Exploited in Ongoing Attacks
CISA Issues Warning on Critical Ivanti EPMM Flaw Exploited in Ongoing Attacks The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert regarding a critical security flaw in Ivanti Endpoint Manager Mobile (EPMM). The… Go to gbhackers.com
-
Hackers exploiting Acrobat Reader zero-day flaw since December
Hackers exploiting Acrobat Reader zero-day flaw since December Attackers have been exploiting a zero-day vulnerability in Adobe Reader using maliciously crafted PDF documents since at least December. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers steal $3.6 million from crypto ATM giant Bitcoin Depot
Hackers steal $3.6 million from crypto ATM giant Bitcoin Depot Bitcoin Depot, which operates one of the largest Bitcoin ATM networks, says attackers stole $3.665 million worth of Bitcoin from its crypto wallets after breaching its systems last month. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft suspends dev accounts for high-profile open source projects
Microsoft suspends dev accounts for high-profile open source projects Microsoft has suspended developer accounts used to maintain multiple high-profile open-source projects without proper notification and no way to quickly reinstate them, effectively blocking them from publishing new software builds and security patches for Windows users. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers use pixel-large SVG trick to hide credit card stealer
Hackers use pixel-large SVG trick to hide credit card stealer A massive campaign impacting nearly 100 online stores using the Magento e-commerce platform hides credit card-stealing code in a pixel-sized Scalable Vector Graphics (SVG) image. […] Bill Toulas Go to bleepingcomputer
-
Google: New UNC6783 hackers steal corporate Zendesk support tickets
Google: New UNC6783 hackers steal corporate Zendesk support tickets A threat actor tracked as UNC6783 is compromising business process outsourcing (BPO) providers to gain access to high-value companies across multiple sectors. […] Bill Toulas Go to bleepingcomputer
-
Hackers Claim to Have Stolen 10 Petabytes of Data from China’s Tianjin Supercomputer Center
Hackers Claim to Have Stolen 10 Petabytes of Data from China’s Tianjin Supercomputer Center Hackers are claiming that one of China’s most strategically important computing facilities suffered a massive cyber intrusion, with more than 10 petabytes of sensitive information allegedly taken from a state-run supercomputing environment that experts suspect is the National Supercomputing Center in…
-
Microsoft Suspends Developer Accounts of High-Profile Open-Source Projects
Microsoft Suspends Developer Accounts of High-Profile Open-Source Projects Microsoft has suspended the Windows Hardware Program developer accounts of two critical open-source security projects, VeraCrypt and WireGuard, blocking their ability to sign drivers and push updates to millions of Windows users, with no prior warning or explanation provided to the developers. Mounir Idrassi, the lead developer…
-
New RoningLoader Campaign Uses DLL Side-Loading and Code Injection to Evade Detection
New RoningLoader Campaign Uses DLL Side-Loading and Code Injection to Evade Detection A threat actor known as DragonBreath has launched a stealthy campaign using a multi-stage malware loader called RoningLoader. The malware targets Chinese-speaking users by disguising itself as trusted software such as Google Chrome and Microsoft Teams. Its core strength lies in a layered…
-
Critical Chrome Vulnerabilities Let Attackers to Execute Arbitrary Code
Critical Chrome Vulnerabilities Let Attackers to Execute Arbitrary Code Google has released Chrome 147 to the stable channel for Windows, Mac, and Linux, patching a sweeping set of security vulnerabilities — including two critical-severity flaws that could allow remote attackers to execute arbitrary code on targeted systems. The most severe vulnerabilities in this release are…
-
New Silver Fox Campaign Hides ValleyRAT Inside Fake Telegram Chinese Language Pack Installer
New Silver Fox Campaign Hides ValleyRAT Inside Fake Telegram Chinese Language Pack Installer A new malware campaign linked to the Silver Fox APT group has been discovered, using a fake Telegram Chinese language pack installer to secretly deliver ValleyRAT — a powerful remote access trojan — onto targeted machines. The malicious file, disguised as a…
-
TR-26-0089 (Apache HTTP Server Güvenlik Bildirimi)
TR-26-0089 (Apache HTTP Server Güvenlik Bildirimi) Go to usom.gov
-
New Chaos Variant Targets Misconfigured Cloud Deployments, Adds SOCKS Proxy
New Chaos Variant Targets Misconfigured Cloud Deployments, Adds SOCKS Proxy Cybersecurity researchers have flagged a new variant ofmalware called Chaosthat’scapable of hitting misconfigured cloud deployments, marking an expansion of the botnet’s targeting infrastructure. “Chaos malware is increasingly targeting misconfigured cloud deployments, expanding beyond its traditional focus on routers and edge devices,” Darktrace said in a new report. Go to TheHackersNews
-
Masjesu Botnet Emerges as DDoS-for-Hire Service Targeting Global IoT Devices
Masjesu Botnet Emerges as DDoS-for-Hire Service Targeting Global IoT Devices Cybersecurity researchers have lifted the curtain on a stealthy botnet that’s designed for distributed denial-of-service (DDoS) attacks. Called Masjesu, the botnet has been advertised via Telegram as a DDoS-for-hire service since it first surfaced in 2023. It’s capable of targeting a wide range of IoT devices,…
-
APT28 Deploys PRISMEX Malware in Campaign Targeting Ukraine and NATO Allies
APT28 Deploys PRISMEX Malware in Campaign Targeting Ukraine and NATO Allies The Russian threat actor known as APT28 (aka Forest Blizzard and Pawn Storm) has been linked to a fresh spear-phishing campaign targeting Ukraine and its allies to deploy a previously undocumented malware suite codenamed PRISMEX. “PRISMEX combines advanced steganography, component object model (COM) hijacking, and legitimate…
-
Shrinking the IAM Attack Surface through Identity Visibility and Intelligence Platforms (IVIP)
Shrinking the IAM Attack Surface through Identity Visibility and Intelligence Platforms (IVIP) The Fragmented State of Modern Enterprise Identity Enterprise IAM is approaching a breaking point. As organizations scale, identity becomes increasingly fragmented across thousands of applications, decentralized teams, machine identities, and autonomous systems. The result is Identity Dark Matter: identity activity that sits outside the visibility of…
-
Anthropic’s Claude Mythos Finds Thousands of Zero-Day Flaws Across Major Systems
Anthropic’s Claude Mythos Finds Thousands of Zero-Day Flaws Across Major Systems Artificial Intelligence (AI) company Anthropic announced a new cybersecurity initiative called Project Glasswing that will use a preview version of its new frontier model, Claude Mythos, to find and address security vulnerabilities. The model will be used by a small set of organizations, including Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike,& Go…
-
Python Supply-Chain Compromise
Python Supply-Chain Compromise This is news: A malicious supply chain compromise has been identified in the Python Package Index package litellm version 1.82.8. The published wheel contains a malicious .pth file (litellm_init.pth, 34,628 bytes) which is automatically executed by the Python interpreter on every startup, without requiring any explicit import of the litellm module. There…
-
ISC Stormcast For Thursday, April 9th, 2026 https://isc.sans.edu/podcastdetail/9886, (Thu, Apr 9th)
ISC Stormcast For Thursday, April 9th, 2026 https://isc.sans.edu/podcastdetail/9886, (Thu, Apr 9th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Number Usage in Passwords: Take Two, (Thu, Apr 9th)
Number Usage in Passwords: Take Two, (Thu, Apr 9th) In a previous diary [1], we looked to see how numbers were used within passwords submitted to honeypots. One of the items of interest was how dates, and more specifically years, were represented within the data and how that changed over time. It is often seen…
-
TeamPCP Supply Chain Campaign: Update 007 – Cisco Source Code Stolen via Trivy-Linked Breach, Google GTIG Tracks TeamPCP as UNC6780, and CISA KEV Deadline Arrives with No Standalone Advisory, (Wed, Apr 8th)
TeamPCP Supply Chain Campaign: Update 007 – Cisco Source Code Stolen via Trivy-Linked Breach, Google GTIG Tracks TeamPCP as UNC6780, and CISA KEV Deadline Arrives with No Standalone Advisory, (Wed, Apr 8th) This is the seventh update to the TeamPCP supply chain campaign threat intelligence report, “When the Security Scanner Became the Weapon” (v3.0, March 25, 2026). Update…
-
More Honeypot Fingerprinting Scans, (Wed, Apr 8th)
More Honeypot Fingerprinting Scans, (Wed, Apr 8th) One question that often comes up when I talk about honeypots: Are attackers able to figure out if they are connected to a honeypot? The answer is pretty simple: Yes! Most “medium interaction” honeypots, like the one we are using, are just simulating various systems. These simulations are…
-
Smashing Security podcast #462: LinkedIn is spying on you, and you agreed to nothing
Smashing Security podcast #462: LinkedIn is spying on you, and you agreed to nothing LinkedIn has been secretly scanning your browser for over 6,000 installed extensions — on every single click you make. It can tell if you’re job hunting, what religion you are, and whether you have ADHD. And none of this is mentioned…
-
Russia’s Forest Blizzard Nabs Rafts of Logins Via SOHO Routers
Russia’s Forest Blizzard Nabs Rafts of Logins Via SOHO Routers Heard of fileless malware? How about malwareless cyber espionage? Russia’s APT28 is spying on global organizations by modifying just one DNS setting in vulnerable routers. Nate Nelson Go to gbhackers.com
-
Threat Actors Get Crafty With Emojis to Escape Detection
Threat Actors Get Crafty With Emojis to Escape Detection When 🤖 means “bot available,” 🧰 signifies “toolkit,” or 💰💰💰 translates to “big ransom,” bad actors can evade filters and keep it all on the down-low. Jai Vijayan Go to gbhackers.com
-
AI-Led Remediation Crisis Prompts HackerOne to Pause Bug Bounties
AI-Led Remediation Crisis Prompts HackerOne to Pause Bug Bounties Discovery used to be the bottleneck for open source bugs, but with automated discovery, remediation’s the bottleneck, which bounties don’t fund. Jai Vijayan Go to gbhackers.com
-
Fraud Rockets Higher in Mobile-First Latin America
Fraud Rockets Higher in Mobile-First Latin America Cyber-fraudsters move quickly from compromised devices to account takeover to funds transfer, shifting money before many financial institutions can react. Robert Lemos Go to gbhackers.com
-
Full Sail University to Open IBM Cyber Defense Range Powered by AWS and Cloud Range on Campus
Full Sail University to Open IBM Cyber Defense Range Powered by AWS and Cloud Range on Campus Go to gbhackers.com
-
Niobium Introduces The Fog
Niobium Introduces The Fog Go to gbhackers.com
-
Pluralsight Launches SecureReady to Help Organizations Build Job-Ready Cybersecurity Teams
Pluralsight Launches SecureReady to Help Organizations Build Job-Ready Cybersecurity Teams Go to gbhackers.com
-
IBM Security Verify Access Flaws Let Remote Attackers Access Sensitive Data
IBM Security Verify Access Flaws Let Remote Attackers Access Sensitive Data IBM has issued an urgent security bulletin addressing a slew of vulnerabilities impacting IBM Verify Identity Access and IBM Security Verify Access. These flaws… Go to gbhackers.com
-
Masjesu Botnet Targets Routers in Commercial DDoS Attacks
Masjesu Botnet Targets Routers in Commercial DDoS Attacks Hackers are abusing the Masjesu botnet to run high-volume DDoS-for-hire attacks against routers, gateways, and other exposed IoT infrastructure, turning everyday network hardware into commercial attack… Go to gbhackers.com
-
GreyNoise Launches C2 Detection for Exploited Edge Devices
GreyNoise Launches C2 Detection for Exploited Edge Devices GreyNoise has introduced a new capability, C2 Detection, to identify compromised edge devices such as firewalls, routers, and VPN systems assets that are increasingly targeted… Go to gbhackers.com
-
Top 10 Best Multi-Factor Authentication (MFA) Providers in 2026
Top 10 Best Multi-Factor Authentication (MFA) Providers in 2026 In the digital realm of 2026, the traditional password stands as a flimsy barrier against an onslaught of sophisticated cyber threats. From phishing campaigns and… Go to gbhackers.com
-
Multiple OpenSSL Flaws Expose Sensitive Data in RSA KEM Handling
Multiple OpenSSL Flaws Expose Sensitive Data in RSA KEM Handling A newly disclosed flaw in OpenSSL could allow attackers to access sensitive data stored in application memory. Tracked as CVE-2026-31790, this moderate-severity vulnerability affects… Go to gbhackers.com
-
Microsoft rolls out fix for broken Windows Start Menu search
Microsoft rolls out fix for broken Windows Start Menu search Microsoft has pushed a server-side fix for a known issue that broke the Windows Start Menu search feature on some Windows 11 23H2 devices. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers exploit critical flaw in Ninja Forms WordPress plugin
Hackers exploit critical flaw in Ninja Forms WordPress plugin A critical vulnerability in the Ninja Forms File Uploads premium add-on for WordPress allows uploading arbitrary files without authentication, which can lead to remote code execution. […] Bill Toulas Go to bleepingcomputer
-
FBI: Americans lost a record $21 billion to cybercrime last year
FBI: Americans lost a record $21 billion to cybercrime last year U.S. victims lost nearly $21 billion to cyber-enabled crimes last year, driven primarily by investment scams, business email compromise, tech support fraud, and data breaches, the Federal Bureau of Investigation says. […] Bill Toulas Go to bleepingcomputer
-
Snowflake customers hit in data theft attacks after SaaS integrator breach
Snowflake customers hit in data theft attacks after SaaS integrator breach Over a dozen companies have suffered data theft attacks after a SaaS integration provider was breached and authentication tokens stolen. […] Lawrence Abrams Go to bleepingcomputer
-
US warns of Iranian hackers targeting critical infrastructure
US warns of Iranian hackers targeting critical infrastructure Iranian-linked hackers are targeting Internet-exposed Rockwell/Allen-Bradley programmable logic controllers (PLCs) on the networks of U.S. critical infrastructure organizations. […] Sergiu Gatlan Go to bleepingcomputer
-
Indian Bank Warns Users of Fake LPG Payment and KYC Update Scams to Steal Banking Info
Indian Bank Warns Users of Fake LPG Payment and KYC Update Scams to Steal Banking Info Indian Bank has issued an urgent cybersecurity advisory warning its customers about a rapidly spreading wave of fraudulent LPG payment and KYC update messages that are being used to steal banking credentials and drain accounts. Cybercriminals are exploiting growing…
-
Multiple OpenSSL Vulnerabilities Exposes Sensitive Data in RSA KEM Handling
Multiple OpenSSL Vulnerabilities Exposes Sensitive Data in RSA KEM Handling OpenSSL has released a broad April 2026 security update that fixes seven vulnerabilities across supported branches, led by CVE-2026-31790, a moderate-severity flaw in RSA KEM RSASVE encapsulation that can expose uninitialized memory to a malicious peer. The advisory directs users of vulnerable 3.x releases to…
-
FBI Disrupts Russian Router Hijacking Operation Compromised Thousands of Users
FBI Disrupts Russian Router Hijacking Operation Compromised Thousands of Users The U.S. Justice Department and the FBI have successfully dismantled a massive cyberespionage network in a court-authorized takedown dubbed “Operation Masquerade.” Announced on April 7, 2026, the technical operation neutralized thousands of compromised small office/home office (SOHO) routers that were hijacked by Russian military intelligence…
-
Claude Finds 13-Year-Old 0-Day RCE Vulnerability in Apache ActiveMQ in 10 Minutes
Claude Finds 13-Year-Old 0-Day RCE Vulnerability in Apache ActiveMQ in 10 Minutes A critical remote code execution (RCE) vulnerability has been disclosed in Apache ActiveMQ Classic, a flaw that sat undetected for over a decade and was ultimately discovered not by a human researcher manually combing through code, but by Anthropic’s Claude AI model in…
-
CUPS Vulnerability Chain Enables Remote Attacker to Execute Malicious Code as Root User
CUPS Vulnerability Chain Enables Remote Attacker to Execute Malicious Code as Root User A critical vulnerability chain in the Common Unix Printing System (CUPS) that allows unauthenticated remote attackers to execute arbitrary malicious code with root system privileges. Security researcher Asim Viladi Oglu Manizada and his team discovered two zero-day flaws, officially tracked as CVE-2026-34980…
-
As breakout time accelerates, prevention-first cybersecurity takes center stage
As breakout time accelerates, prevention-first cybersecurity takes center stage Threat actors are using AI to supercharge tried-and-tested TTPs. When attacks move this fast, cyber-defenders need to rethink their own strategy. Go to eset
-
Iran-Linked Hackers Disrupt U.S. Critical Infrastructure by Targeting Internet-Exposed PLCs
Iran-Linked Hackers Disrupt U.S. Critical Infrastructure by Targeting Internet-Exposed PLCs Iran-affiliated cyber actors are targeting internet-facing operational technology (OT) devices across critical infrastructures in the U.S., including programmable logic controllers (PLCs), cybersecurity and intelligence agencies warned Tuesday. “These attacks have led to diminished PLC functionality, manipulation of display data and, in some cases, operational disruption and financial…
-
Russian State-Linked APT28 Exploits SOHO Routers in Global DNS Hijacking Campaign
Russian State-Linked APT28 Exploits SOHO Routers in Global DNS Hijacking Campaign The Russia-linked threat actor known as APT28 (aka Forest Blizzard) has been linked to a new campaign that has compromised insecure MikroTik and TP-Link routers and modified their settings to turn them into malicious infrastructure under their control as part of a cyber espionage campaign…
-
[Webinar] How to Close Identity Gaps in 2026 Before AI Exploits Enterprise Risk
[Webinar] How to Close Identity Gaps in 2026 Before AI Exploits Enterprise Risk In the rapid evolution of the 2026 threat landscape, a frustrating paradox has emerged for CISOs and security leaders: Identity programs are maturing, yet the risk is actually increasing. According to new research from the Ponemon Institute, hundreds of applications within the typical enterprise remain disconnected from…
-
Docker CVE-2026-34040 Lets Attackers Bypass Authorization and Gain Host Access
Docker CVE-2026-34040 Lets Attackers Bypass Authorization and Gain Host Access A high-severity security vulnerability has been disclosed in Docker Engine that could permit an attacker to bypass authorization plugins (AuthZ) under specific circumstances. The vulnerability, tracked as CVE-2026-34040 (CVSS score: 8.8), stems from an incomplete fix for CVE-2024-41110, a maximum-severity vulnerability in the same component that came to…
-
Over 1,000 Exposed ComfyUI Instances Targeted in Cryptomining Botnet Campaign
Over 1,000 Exposed ComfyUI Instances Targeted in Cryptomining Botnet Campaign An active campaign has been observed targeting internet-exposed instances running ComfyUI, a popular stable diffusion platform, to enlist them into a cryptocurrency mining and proxy botnet. “A purpose-built Python scanner continuously sweeps major cloud IP ranges for vulnerable targets, automatically installing malicious nodes via ComfyUI-Manager if no…
-
Cybersecurity in the Age of Instant Software
Cybersecurity in the Age of Instant Software AI is rapidly changing how software is written, deployed, and used. Trends point to a future where AIs can write custom software quickly and easily: “instant software.” Taken to an extreme, it might become easier for a user to have an AI write an application on demand—a spreadsheet,…
-
Hong Kong Police Can Force You to Reveal Your Encryption Keys
Hong Kong Police Can Force You to Reveal Your Encryption Keys According to a new law, the Hong Kong police can demand that you reveal the encryption keys protecting your computer, phone, hard drives, etc.—even if you are just transiting the airport. In a security alert dated March 26, the U.S. Consulate General said that,…
-
ISC Stormcast For Wednesday, April 8th, 2026 https://isc.sans.edu/podcastdetail/9884, (Wed, Apr 8th)
ISC Stormcast For Wednesday, April 8th, 2026 https://isc.sans.edu/podcastdetail/9884, (Wed, Apr 8th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
A Little Bit Pivoting: What Web Shells are Attackers Looking for?, (Tue, Apr 7th)
A Little Bit Pivoting: What Web Shells are Attackers Looking for?, (Tue, Apr 7th) Webshells remain a popular method for attackers to maintain persistence on a compromised web server. Many “arbitrary file write” and “remote code execution” vulnerabilities are used to drop small files on systems for later execution of additional payloads. The names of these…
-
Russia Hacked Routers to Steal Microsoft Office Tokens
Russia Hacked Routers to Steal Microsoft Office Tokens Hackers linked to Russia’s military intelligence units are using known flaws in older Internet routers to mass harvest authentication tokens from Microsoft Office users, security experts warned today. The spying campaign allowed state-backed Russian hackers to quietly siphon authentication tokens from users on more than 18,000 networks…
-
Life imprisonment for Cambodian scam compound operators – but will it make a difference?
Life imprisonment for Cambodian scam compound operators – but will it make a difference? Cambodia has taken a dramatic step in its fight against scam compounds that have imprisoned innocent people, and forced them to work as virtual slaves defrauding victims via the internet around the world with romance scams and dodgy investment schemes. Read…
-
172: SuperBox
172: SuperBox What if there was a device which gave you endless movies and TV shows without ads? Ok great sign me up! In this episode we interview “D3ada55”, who found such a device, but as she gazed into it, she discovered it gazing back at her. Sponsors Support for this show comes from ThreatLocker®.…
-
Weekly Update 498
Weekly Update 498 This week, more time than I’d have liked to spend went on talking about the trials of chasing invoices. This is off the back of a customer (who, for now, will remain unnamed), who had invoices stacking back more than 6 months overdue and despite payment terms of 30 days, paid on…
-
Storm-1175 Deploys Medusa Ransomware at ‘High Velocity’
Storm-1175 Deploys Medusa Ransomware at ‘High Velocity’ Microsoft says the financially motivated cybercrime group has exploited N-day and zero-day vulnerabilities in campaigns predicated on speed. Rob Wright Go to gbhackers.com
-
Grafana Patches AI Bug That Could Have Leaked User Data
Grafana Patches AI Bug That Could Have Leaked User Data By hiding malicious instructions on an attacker-controlled Web page, AI could ingest orders as benign and return sensitive data to the attacker’s server. Alexander Culafi Go to gbhackers.com
-
RSAC 2026: How AI Is Reshaping Cybersecurity Faster Than Ever
RSAC 2026: How AI Is Reshaping Cybersecurity Faster Than Ever Dark Reading’s Kelly Jackson Higgins shares insights on the past, present, and future of cybersecurity after attending RSAC 2026 Conference. Kristina Beek, Kelly Jackson Higgins Go to gbhackers.com
-
Human vs AI: Debates Shape RSAC 2026 Cybersecurity Trends
Human vs AI: Debates Shape RSAC 2026 Cybersecurity Trends As AI dominated RSAC 2026, CISOs and industry leaders debated its role in security, from agentic applications to the challenges of scaling human involvement in decision-making. Alexander Culafi, Kristina Beek Go to gbhackers.com
-
Lies, Damned Lies, and Cybersecurity Metrics
Lies, Damned Lies, and Cybersecurity Metrics A panel of five C-suite leaders discuss how cybersecurity success is measured and why it isn’t improving results. Joan Goodchild Go to gbhackers.com
-
Focusing on the People in Cybersecurity at RSAC 2026 Conference
Focusing on the People in Cybersecurity at RSAC 2026 Conference AI dominated the RSAC 2026 Conference and showed it’s still humans in cybersecurity who matter most. Melinda Marks Go to gbhackers.com
-
Hackers Exploit Next.js React2Shell Vulnerability, Breach 766 Hosts in 24 Hours
Hackers Exploit Next.js React2Shell Vulnerability, Breach 766 Hosts in 24 Hours Hackers are abusing a critical React2Shell vulnerability in Next.js applications to run an automated credential‑theft operation that has already compromised at least 766 servers… Go to gbhackers.com
-
Tor-Backed ClickFix Campaign Drops Node.js RAT on Windows
Tor-Backed ClickFix Campaign Drops Node.js RAT on Windows Hackers are using a deceptive technique known as “ClickFix” to deliver a sophisticated Node. js-based remote access Trojan (RAT) targeting Windows users. ClickFix, which gained… Go to gbhackers.com
-
Critical Android Flaw Allows Zero-Interaction Denial-of-Service Attacks
Critical Android Flaw Allows Zero-Interaction Denial-of-Service Attacks Google has rolled out its April 2026 Android Security Bulletin, addressing multiple vulnerabilities across the mobile operating system. The most alarming discovery this month… Go to gbhackers.com
-
Attackers Exploit Flowise Injection Vulnerability as 15,000+ Instances Remain Exposed
Attackers Exploit Flowise Injection Vulnerability as 15,000+ Instances Remain Exposed A critical security flaw in Flowise, a popular open-source AI development platform, is currently being exploited in the wild. Tracked as CVE-2025-59528, this code… Go to gbhackers.com
-
Fake Installers Spread RATs, Monero Miners in Ongoing Malware Campaign
Fake Installers Spread RATs, Monero Miners in Ongoing Malware Campaign Fake software installers are being used in a long-running malware operation to drop remote access trojans (RATs), Monero cryptominers, and a new .NET implant… Go to gbhackers.com
-
German authorities identify REvil and GandCrab ransomware bosses
German authorities identify REvil and GandCrab ransomware bosses The Federal Police in Germany (BKA) has identified two Russian nationals as the leaders of GandCrab and REvil ransomware operations between 2019 and 2021. […] Bill Toulas Go to bleepingcomputer
-
New GPUBreach attack enables system takeover via GPU rowhammer
New GPUBreach attack enables system takeover via GPU rowhammer A new attack, dubbed GPUBreach, can induce Rowhammer bit-flips on GPU GDDR6 memories to escalate privileges and lead to a full system compromise. […] Bill Toulas Go to bleepingcomputer
-
Disgruntled researcher leaks “BlueHammer” Windows zero-day exploit
Disgruntled researcher leaks “BlueHammer” Windows zero-day exploit Exploit code has been released for an unpatched Windows privilege escalation flaw reported privately to Microsoft, allowing attackers to gain SYSTEM or elevated administrator permissions. […] Bill Toulas Go to bleepingcomputer
-
Microsoft fixes Classic Outlook bug causing email delivery issues
Microsoft fixes Classic Outlook bug causing email delivery issues Microsoft has resolved a known issue that was preventing some Classic Outlook users from sending emails via Outlook.com. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft removes Support and Recovery Assistant from Windows
Microsoft removes Support and Recovery Assistant from Windows Microsoft has deprecated and removed the Support and Recovery Assistant (SaRA) command-line utility from all in-support versions of Windows updates starting March 10. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft Releases New Defender Update for Windows 11, 10, and Server Installation Images
Microsoft Releases New Defender Update for Windows 11, 10, and Server Installation Images Microsoft has officially rolled out its latest security intelligence update for Microsoft Defender Antivirus, delivering crucial protections for Windows 11, Windows 10, and Windows Server installation images. This vital release ensures that Microsoft’s built-in antimalware solutions are fully equipped to identify and neutralize…
-
Microsoft Warns Storm-1175 Exploits Web-Facing Assets 0-Day Flaws in Medusa Ransomware Attacks
Microsoft Warns Storm-1175 Exploits Web-Facing Assets 0-Day Flaws in Medusa Ransomware Attacks A new ransomware campaign is putting organizations on high alert. A financially motivated threat group known as Storm-1175 has been running fast-paced attacks targeting vulnerable, internet-facing systems — and deploying the Medusa ransomware as the final blow. What makes this group especially dangerous…
-
50,000 WordPress Sites Exposed to Critical Ninja Forms File Upload RCE Vulnerability
50,000 WordPress Sites Exposed to Critical Ninja Forms File Upload RCE Vulnerability A critical security flaw in the popular WordPress plugin “Ninja Forms – File Upload” has left approximately 50,000 websites vulnerable to complete takeover. Tracked as CVE-2026-0740, this flaw boasts a maximum CVSS severity score of 9.8, making it a severe threat that requires…
-
OpenAI Codex Vulnerability Allows Attackers to Steal GitHub Access Tokens
OpenAI Codex Vulnerability Allows Attackers to Steal GitHub Access Tokens The integration of AI coding agents has introduced new, high-impact attack surfaces for development teams. Phantom Labs at BeyondTrust recently discovered a critical command-injection vulnerability in OpenAI Codex. This flaw allowed attackers to steal sensitive GitHub User Access Tokens. By exploiting how Codex handles task…
-
Hackers Use Fake TradingView Premium Posts on Reddit to Deliver Vidar and AMOS Stealers
Hackers Use Fake TradingView Premium Posts on Reddit to Deliver Vidar and AMOS Stealers A threat actor has been running an active campaign on Reddit, using fake posts that promise free TradingView Premium access to deliver two malware families — Vidar on Windows and AMOS on macOS. The operation is still live, with new posts…
-
Flowise AI Agent Builder Under Active CVSS 10.0 RCE Exploitation; 12,000+ Instances Exposed
Flowise AI Agent Builder Under Active CVSS 10.0 RCE Exploitation; 12,000+ Instances Exposed Threat actors are exploiting a maximum-severity security flaw in Flowise, an open-source artificial intelligence (AI) platform, according to new findings from VulnCheck. The vulnerability in question is CVE-2025-59528 (CVSS score: 10.0), a code injection vulnerability that could result in remote code execution. “The…
-
Iran-Linked Password-Spraying Campaign Targets 300+ Israeli Microsoft 365 Organizations
Iran-Linked Password-Spraying Campaign Targets 300+ Israeli Microsoft 365 Organizations An Iran-nexus threat actor is suspected to be behind a password-spraying campaign targeting Microsoft 365 environments in Israel and the U.A.E. amid ongoing conflict in the Middle East. The activity, assessed to be ongoing, was carried out in three distinct attack waves that took place on March 3, March 13,…
-
DPRK-Linked Hackers Use GitHub as C2 in Multi-Stage Attacks Targeting South Korea
DPRK-Linked Hackers Use GitHub as C2 in Multi-Stage Attacks Targeting South Korea Threat actors likely associated with the Democratic People’s Republic of Korea (DPRK) have been observed using GitHub as command-and-control (C2) infrastructure in multi-stage attacks targeting organizations in South Korea. The attack chain, per Fortinet FortiGuard Labs, involves obfuscated Windows shortcut (LNK) files acting as the starting point to…
-
Multi-OS Cyberattacks: How SOCs Close a Critical Risk in 3 Steps
Multi-OS Cyberattacks: How SOCs Close a Critical Risk in 3 Steps Your attack surface no longer lives on one operating system, and neither do the campaigns targeting it. In enterprise environments, attackers move across Windows endpoints, executive MacBooks, Linux infrastructure, and mobile devices, taking advantage of the fact that many SOC workflows are still fragmented by platform. For security leaders,…
-
⚡ Weekly Recap: Axios Hack, Chrome 0-Day, Fortinet Exploits, Paragon Spyware and More
⚡ Weekly Recap: Axios Hack, Chrome 0-Day, Fortinet Exploits, Paragon Spyware and More This week had real hits. The key software got tampered with. Active bugs showed up in the tools people use every day. Some attacks didn’t even need much effort because the path was already there. One weak spot now spreads wider than before. What starts small can reach…
-
Google Wants to Transition to Post-Quantum Cryptography by 2029
Google Wants to Transition to Post-Quantum Cryptography by 2029 Google says that it will fully transition to post-quantum cryptography by 2029. I think this is a good move, not because I think we will have a useful quantum computer anywhere near that year, but because crypto-agility is always a good thing. Slashdot thread. Bruce Schneier…
-
ISC Stormcast For Tuesday, April 7th, 2026 https://isc.sans.edu/podcastdetail/9882, (Tue, Apr 7th)
ISC Stormcast For Tuesday, April 7th, 2026 https://isc.sans.edu/podcastdetail/9882, (Tue, Apr 7th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
How often are redirects used in phishing in 2026?, (Mon, Apr 6th)
How often are redirects used in phishing in 2026?, (Mon, Apr 6th) In one of his recent diaries, Johannes discussed how open redirects are actively being sought out by threat actors[1], which made me wonder about how commonly these mechanisms are actually misused… Although open redirect is not generally considered a high-impact vulnerability on its…