no alarms and no surprises please..
-
DPRK-Linked Hackers Use GitHub as C2 in Multi-Stage Attacks Targeting South Korea
DPRK-Linked Hackers Use GitHub as C2 in Multi-Stage Attacks Targeting South Korea Threat actors likely associated with the Democratic People’s Republic of Korea (DPRK) have been observed using GitHub as command-and-control (C2) infrastructure in multi-stage attacks targeting organizations in South Korea. The attack chain, per Fortinet FortiGuard Labs, involves obfuscated Windows shortcut (LNK) files acting as the starting point to…
-
Multi-OS Cyberattacks: How SOCs Close a Critical Risk in 3 Steps
Multi-OS Cyberattacks: How SOCs Close a Critical Risk in 3 Steps Your attack surface no longer lives on one operating system, and neither do the campaigns targeting it. In enterprise environments, attackers move across Windows endpoints, executive MacBooks, Linux infrastructure, and mobile devices, taking advantage of the fact that many SOC workflows are still fragmented by platform. For security leaders,…
-
⚡ Weekly Recap: Axios Hack, Chrome 0-Day, Fortinet Exploits, Paragon Spyware and More
⚡ Weekly Recap: Axios Hack, Chrome 0-Day, Fortinet Exploits, Paragon Spyware and More This week had real hits. The key software got tampered with. Active bugs showed up in the tools people use every day. Some attacks didn’t even need much effort because the path was already there. One weak spot now spreads wider than before. What starts small can reach…
-
Google Wants to Transition to Post-Quantum Cryptography by 2029
Google Wants to Transition to Post-Quantum Cryptography by 2029 Google says that it will fully transition to post-quantum cryptography by 2029. I think this is a good move, not because I think we will have a useful quantum computer anywhere near that year, but because crypto-agility is always a good thing. Slashdot thread. Bruce Schneier…
-
ISC Stormcast For Tuesday, April 7th, 2026 https://isc.sans.edu/podcastdetail/9882, (Tue, Apr 7th)
ISC Stormcast For Tuesday, April 7th, 2026 https://isc.sans.edu/podcastdetail/9882, (Tue, Apr 7th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
How often are redirects used in phishing in 2026?, (Mon, Apr 6th)
How often are redirects used in phishing in 2026?, (Mon, Apr 6th) In one of his recent diaries, Johannes discussed how open redirects are actively being sought out by threat actors[1], which made me wonder about how commonly these mechanisms are actually misused… Although open redirect is not generally considered a high-impact vulnerability on its…
-
ISC Stormcast For Monday, April 6th, 2026 https://isc.sans.edu/podcastdetail/9880, (Mon, Apr 6th)
ISC Stormcast For Monday, April 6th, 2026 https://isc.sans.edu/podcastdetail/9880, (Mon, Apr 6th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
AI-Assisted Supply Chain Attack Targets GitHub
AI-Assisted Supply Chain Attack Targets GitHub PRT-scan is the second in recent months where a threat actor appears to have leveraged AI for automated targeting of a widespread GitHub misconfiguration. Jai Vijayan Go to gbhackers.com
-
Axios Attack Shows Social Complex Engineering Is Industrialized
Axios Attack Shows Social Complex Engineering Is Industrialized The attack on the popular NPM package Axios is just one of many targeting maintainers and has shone a light on how threat actors can scale sophisticated social engineering campaigns. Alexander Culafi Go to gbhackers.com
-
Fortinet Issues Emergency Patch for FortiClient Zero-Day
Fortinet Issues Emergency Patch for FortiClient Zero-Day The authentication bypass flaw, tracked as CVE-2026-35616, is the latest in a series of Fortinet vulnerabilities that have been exploited in the wild. Rob Wright Go to gbhackers.com
-
Automated Credential Harvesting Campaign Exploits React2Shell Flaw
Automated Credential Harvesting Campaign Exploits React2Shell Flaw An emerging threat cluster tracked as UAT-10608 is exploiting vulnerable Web-exposed Next.js apps and using an automated tool to exfiltrate credentials, secrets, and other system data. Elizabeth Montalbano Go to gbhackers.com
-
Shadow AI in Healthcare is Here to Stay
Shadow AI in Healthcare is Here to Stay Medical professionals are not going to stop using AI tools to manage growing workloads. Organizations should prioritize bolstering security protocols to limit their blast radius. Arielle Waldman Go to gbhackers.com
-
OWASP GenAI Security Project Gets Update, New Tools Matrix
OWASP GenAI Security Project Gets Update, New Tools Matrix In recognition of 21 generative AI risks, the standards groups recommends that companies take separate but linked approaches to defending GenAI and agentic AI systems. Robert Lemos Go to gbhackers.com
-
Critical Claude Code Flaw Silently Bypasses User-Configured Security Rules
Critical Claude Code Flaw Silently Bypasses User-Configured Security Rules Anthropic’s flagship AI coding agent, Claude Code, was recently discovered to contain a critical security flaw that silently bypasses developer-configured safety rules. The… Go to gbhackers.com
-
Alleged REvil Leader ‘UNKN’ Identified by German Authorities in New Takedown Effort
Alleged REvil Leader ‘UNKN’ Identified by German Authorities in New Takedown Effort German authorities have officially put a face to one of the most notorious names in cybercrime. The German Federal Criminal Police (BKA) recently identified… Go to gbhackers.com
-
Google’s Bug Bounty Program Hits Record $17 Million in 2025 Payouts
Google’s Bug Bounty Program Hits Record $17 Million in 2025 Payouts Google has announced a record-breaking year for its Vulnerability Reward Program (VRP). In 2025, the tech giant paid out more than $17 million to… Go to gbhackers.com
-
Apache Traffic Server Flaw Allowed Attackers to Trigger Denial-of-Service Attacks
Apache Traffic Server Flaw Allowed Attackers to Trigger Denial-of-Service Attacks The Apache Software Foundation has released critical security updates to address two vulnerabilities in Apache Traffic Server (ATS). Disclosed on April 2, 2026, these… Go to gbhackers.com
-
Critical Dgraph Database Flaw Allowed Attackers to Bypass Authentication
Critical Dgraph Database Flaw Allowed Attackers to Bypass Authentication A newly discovered critical vulnerability in the open-source Dgraph database system leaves servers exposed to complete system takeovers. Tracked as CVE-2026-34976 and carrying a… Go to gbhackers.com
-
Traffic violation scams switch to QR codes in new phishing texts
Traffic violation scams switch to QR codes in new phishing texts Scammers are sending fake “Notice of Default” traffic violation text messages impersonating state courts across the U.S., pressuring recipients to scan a QR code that leads to a phishing site demanding a $6.99 payment while stealing personal and financial information. […] Lawrence Abrams Go…
-
New FortiClient EMS flaw exploited in attacks, emergency patch released
New FortiClient EMS flaw exploited in attacks, emergency patch released Fortinet has released an emergency weekend security update for a new critical FortiClient Enterprise Management Server (EMS) vulnerability that is actively exploited in attacks. […] Lawrence Abrams Go to bleepingcomputer
-
Hackers exploit React2Shell in automated credential theft campaign
Hackers exploit React2Shell in automated credential theft campaign Hackers are running a large-scale campaign to steal credentials in an automated way after exploiting React2Shell (CVE-2025-55182) in vulnerable Next.js apps. […] Bill Toulas Go to bleepingcomputer
-
Critical Claude Code Flaw Silently Bypasses Developer-Configured Security Rules
Critical Claude Code Flaw Silently Bypasses Developer-Configured Security Rules A high-severity security bypass vulnerability in Anthropic’s Claude Code AI coding agent allows malicious actors to silently evade user-configured deny rules through a simple command-padding technique, exposing hundreds of thousands of developers to credential theft and supply chain compromise. According to Adversa, the flaw was traced…
-
Hackers Using Fake “Microsoft Teams” Domains to Attack Users Via Malicious Payload
Hackers Using Fake “Microsoft Teams” Domains to Attack Users Via Malicious Payload Cybercriminals are launching a sophisticated new wave of attacks using fake Microsoft Teams domains. According to recent threat intelligence shared by SEAL Org, hackers are actively tricking corporate users into downloading malicious payloads by mimicking the widely used communication platform. As Microsoft Teams remains…
-
New ResokerRAT Uses Telegram Bot API to Control Infected Windows Systems
New ResokerRAT Uses Telegram Bot API to Control Infected Windows Systems A new Remote Access Trojan (RAT) called ResokerRAT has been found targeting Windows systems by abusing Telegram’s widely used Bot API to receive commands and send stolen data back to attackers. Unlike traditional malware that relies on custom command-and-control servers, this threat routes all…
-
METATRON – Open-Source AI Penetration Testing Assistant Brings Local LLM Analysis to Linux
METATRON – Open-Source AI Penetration Testing Assistant Brings Local LLM Analysis to Linux A new open-source penetration testing framework called METATRON is gaining attention in the security research community for its fully offline, AI-driven approach to vulnerability assessment. Built for Parrot OS and other Debian-based Linux distributions, METATRON combines automated reconnaissance tooling with a locally…
-
36 Malicious npm Strapi Packages Used to Deploy Redis RCE and Persistent C2 Malware
36 Malicious npm Strapi Packages Used to Deploy Redis RCE and Persistent C2 Malware A coordinated supply chain attack has been uncovered targeting developers who build applications on Strapi, a widely used open-source content management system. Thirty-six malicious npm packages disguised as legitimate Strapi plugins were published to the npm registry, carrying payloads designed to…
-
TR-26-0088 (Fortinet – FortiClientEMS Güvenlik Bildirimi)
TR-26-0088 (Fortinet – FortiClientEMS Güvenlik Bildirimi) Go to usom.gov
-
BKA Identifies REvil Leaders Behind 130 German Ransomware Attacks
BKA Identifies REvil Leaders Behind 130 German Ransomware Attacks Germany’s Federal Criminal Police Office (aka BKA or the Bundeskriminalamt) has unmasked the real identity of the main threat actors associated with the now-defunct REvil (aka Sodinokibi) ransomware-as-a-service (RaaS) operation. The threat actor, who went by the alias UNKN, functioned as a representative of the group,…
-
$285 Million Drift Hack Traced to Six-Month DPRK Social Engineering Operation
$285 Million Drift Hack Traced to Six-Month DPRK Social Engineering Operation Drift has revealed that the April 1, 2026, attack that led to the theft of $285 million was the culmination of a months-long targeted and meticulously planned social engineering operation undertaken by the Democratic People’s Republic of Korea (DPRK) that began in the fall of 2025. The Solana-based decentralized…
-
Germany Doxes “UNKN,” Head of RU Ransomware Gangs REvil, GandCrab
Germany Doxes “UNKN,” Head of RU Ransomware Gangs REvil, GandCrab An elusive hacker who went by the handle “UNKN” and ran the early Russian ransomware groups GandCrab and REvil now has a name and a face. Authorities in Germany say 31-year-old Russian Daniil Maksimovich Shchukin headed both cybercrime gangs and helped carry out at least…
-
Axios npm hack used fake Teams error fix to hijack maintainer account
Axios npm hack used fake Teams error fix to hijack maintainer account The maintainers of the popular Axios HTTP client have published a detailed post-mortem describing how one of its developers was targeted by a social engineering campaign believed to have been conducted by North Korean threat actors. […] Lawrence Abrams Go to bleepingcomputer
-
Device code phishing attacks surge 37x as new kits spread online
Device code phishing attacks surge 37x as new kits spread online Device code phishing attacks that abuse the OAuth 2.0 Device Authorization Grant flow to hijack accounts have surged more than 37 times this year. […] Bill Toulas Go to bleepingcomputer
-
LinkedIn secretly scans for 6,000+ Chrome extensions, collects data
LinkedIn secretly scans for 6,000+ Chrome extensions, collects data A new report dubbed “BrowserGate” warns that Microsoft’s LinkedIn is using hidden JavaScript scripts on its website to scan visitors’ browsers for installed extensions and collect device data. […] Lawrence Abrams Go to bleepingcomputer
-
Critical Fortinet FortiClient EMS 0-Day Vulnerability Actively Exploited in the Wild
Critical Fortinet FortiClient EMS 0-Day Vulnerability Actively Exploited in the Wild Fortinet has issued an emergency hotfix after security researchers disclosed a critical zero-day vulnerability in FortiClient EMS that is already being actively exploited by threat actors. Tracked as CVE-2026-35616 and carrying a CVSSv3 score of 9.1 (Critical), the flaw enables unauthenticated attackers to bypass…
-
New Progress ShareFile Bugs Let Attackers Take Over Servers Without Logging In
New Progress ShareFile Bugs Let Attackers Take Over Servers Without Logging In A dangerous attack chain in Progress ShareFile that can allow attackers to take over exposed on-premises servers without first logging in. The issues affect customer-managed ShareFile Storage Zones Controller 5.x deployments, and Progress says customers should upgrade to version 5.12.4 or move to…
-
Hackers Weaponize Claude Code Leak to Spread Vidar and GhostSocks Malware
Hackers Weaponize Claude Code Leak to Spread Vidar and GhostSocks Malware The cybersecurity community is on high alert following a massive source code leak from Anthropic. On March 31, 2026, the company accidentally exposed the complete source code for Claude Code, its flagship terminal-based coding assistant. The leak occurred due to a packaging error in…
-
Top Node.js Maintainers Targeted in Sophisticated Social Engineering Scheme
Top Node.js Maintainers Targeted in Sophisticated Social Engineering Scheme A highly coordinated social engineering campaign is actively targeting top open-source developers in the Node.js and npm ecosystem. Following the recent compromise of the popular package Axios, which sees over 100 million weekly downloads, several high-impact software maintainers have reported similar attacks. Security researchers believe this…
-
36 Malicious npm Packages Exploited Redis, PostgreSQL to Deploy Persistent Implants
36 Malicious npm Packages Exploited Redis, PostgreSQL to Deploy Persistent Implants Cybersecurity researchers have discovered 36 malicious packages in the npm registry that are disguised as Strapi CMS plugins but come with different payloads to facilitate Redis and PostgreSQL exploitation, deploy reverse shells, harvest credentials, and drop a persistent implant. “Every package contains three files (package.json,…
-
Fortinet Patches Actively Exploited CVE-2026-35616 in FortiClient EMS
Fortinet Patches Actively Exploited CVE-2026-35616 in FortiClient EMS Fortinet has released out-of-band patches for a critical security flaw impacting FortiClient EMS that it said has been exploited in the wild. The vulnerability, tracked as CVE-2026-35616 (CVSS score: 9.1), has been described as a pre-authentication API access bypass leading to privilege escalation. “An improper access control vulnerability [CWE-284] in…
-
TeamPCP Supply Chain Campaign: Update 006 – CERT-EU Confirms European Commission Cloud Breach, Sportradar Details Emerge, and Mandiant Quantifies Campaign at 1,000+ SaaS Environments, (Fri, Apr 3rd)
TeamPCP Supply Chain Campaign: Update 006 – CERT-EU Confirms European Commission Cloud Breach, Sportradar Details Emerge, and Mandiant Quantifies Campaign at 1,000+ SaaS Environments, (Fri, Apr 3rd) This is the sixth update to the TeamPCP supply chain campaign threat intelligence report, “When the Security Scanner Became the Weapon” (v3.0, March 25, 2026). Update 005 covered developments through April 1,…
-
Hackers Launch Social Engineering Offensive Against Key Node.js Maintainers
Hackers Launch Social Engineering Offensive Against Key Node.js Maintainers Following the high-profile supply chain compromise of the widely used Axios package, a highly coordinated social engineering campaign has been uncovered targeting top-tier Node.js… Go to gbhackers.com
-
Top 10 Best Privileged Access Management (PAM) Solutions 2026
Top 10 Best Privileged Access Management (PAM) Solutions 2026 In the dynamic and increasingly complex cybersecurity landscape of 2026, privileged accounts remain the most coveted targets for cybercriminals and malicious insiders alike. From system… Go to gbhackers.com
-
Top 10 Best Identity And Access Management (IAM) Companies 2026
Top 10 Best Identity And Access Management (IAM) Companies 2026 In the rapidly evolving digital landscape of 2026, Identity and Access Management (IAM) has transcended its traditional role to become the foundational pillar of… Go to gbhackers.com
-
LinkedIn Hidden Code Secretly Scans Users’ Computers for Installed Software
LinkedIn Hidden Code Secretly Scans Users’ Computers for Installed Software A new investigation by Fairlinked e.V. claims that Microsoft-owned LinkedIn is running a massive, undisclosed corporate surveillance operation. According to the “BrowserGate” report, hidden… Go to gbhackers.com
-
Anthropic Ends Claude Subscription Access for Third-Party Tools Like OpenClaw
Anthropic Ends Claude Subscription Access for Third-Party Tools Like OpenClaw Anthropic has officially shut down third-party AI agent access to its Claude subscription services, pulling the plug on unauthorized external integrations. This move marks… Go to gbhackers.com
-
LinkedIn secretely scans for 6,000+ Chrome extensions, collects data
LinkedIn secretely scans for 6,000+ Chrome extensions, collects data A new report dubbed “BrowserGate” warns that Microsoft’s LinkedIn is using hidden JavaScript scripts on its website to scan visitors’ browsers for installed extensions and collect device data. […] Lawrence Abrams Go to bleepingcomputer
-
Hims & Hers warns of data breach after Zendesk support ticket breach
Hims & Hers warns of data breach after Zendesk support ticket breach Telehealth giant Hims & Hers Health is warning that it suffered a data breach after support tickets were stolen from a third-party customer service platform. […] Bill Toulas Go to bleepingcomputer
-
Die Linke German political party confirms data stolen by Qilin ransomware
Die Linke German political party confirms data stolen by Qilin ransomware The Qilin ransomware group has claimed responsibility for an attack against Die Linke (‘The Left’), forcing an IT systems outage at the political party, and threatening sensitive data leak. […] Bill Toulas Go to bleepingcomputer
-
Evolution of Ransomware: Multi-Extortion Ransomware Attacks
Evolution of Ransomware: Multi-Extortion Ransomware Attacks Multi-extortion ransomware relies on stolen data to pressure victims with public leaks. Penta Security explains how its D.AMO platform keeps exfiltrated files encrypted and useless to attackers. […] Sponsored by Penta Security Go to bleepingcomputer
-
Microsoft still working to fix Exchange Online mailbox access issues
Microsoft still working to fix Exchange Online mailbox access issues Microsoft is investigating and working to resolve Exchange Online mailbox access issues that have intermittently affected Outlook mobile and macOS users for weeks. […] Sergiu Gatlan Go to bleepingcomputer
-
Top 10 Best User Access Management Tools in 2026
Top 10 Best User Access Management Tools in 2026 User Access Management tools centralize control over user permissions and access, providing a unified platform to enforce consistent security policies across diverse systems and applications. They enhance security by implementing role-based access controls, monitoring user activity, preventing unauthorized access, mitigating potential risks, and safeguarding sensitive information.…
-
Top 10 Best VPN For Chrome in 2026
Top 10 Best VPN For Chrome in 2026 In ever-changing technology and networks, privacy is becoming increasingly difficult to achieve. People are so used to using the Internet and IoT devices that the sensitive data they share on the web has become a prime target for hackers or malicious actors. As we all know, data…
-
LinkedIn Hidden Code Secretly Searches Your Browser for Installed Extensions
LinkedIn Hidden Code Secretly Searches Your Browser for Installed Extensions Every time you open LinkedIn in a Chrome-based browser, hidden JavaScript silently scans your computer for installed software without your knowledge, without your consent, and without a single word in LinkedIn’s privacy policy. A revealing investigation conducted by the European advocacy group Fairlinked e.V., under…
-
Anthropic Officially Ends Claude Subscriptions for Third-Party Tools Like OpenClaw
Anthropic Officially Ends Claude Subscriptions for Third-Party Tools Like OpenClaw Anthropic has officially pulled the plug on third-party AI agent access to the Claude subscription, marking a significant shift in how users can leverage its models outside the company’s native ecosystem. According to Anthropic Claude Code exec Boris Cherny, starting today, April 4, at 12…
-
14,000+ F5 BIG-IP APM Devices Exposed Online Amid Active RCE Vulnerability Exploits
14,000+ F5 BIG-IP APM Devices Exposed Online Amid Active RCE Vulnerability Exploits A critical security flaw in F5’s BIG-IP Access Policy Manager (APM) is currently under active exploitation, leaving thousands of enterprise networks at risk. The vulnerability, officially tracked as CVE-2025-53521, has sparked urgent warnings across the cybersecurity community after its impact was upgraded from…
-
China-Linked TA416 Targets European Governments with PlugX and OAuth-Based Phishing
China-Linked TA416 Targets European Governments with PlugX and OAuth-Based Phishing A China-aligned threat actor has set its sights on European government and diplomatic organizations since mid-2025, following a two-year period of minimal targeting in the region. The campaign has been attributed to TA416, a cluster of activity that overlaps with DarkPeony, RedDelta, Red Lich, SmugX, UNC6384, and Vertigo Panda. “This…
-
Microsoft Details Cookie-Controlled PHP Web Shells Persisting via Cron on Linux Servers
Microsoft Details Cookie-Controlled PHP Web Shells Persisting via Cron on Linux Servers Threat actors are increasingly using HTTP cookies as a control channel for PHP-based web shells on Linux servers and to achieve remote code execution, according to findings from the Microsoft Defender Security Research Team. “Instead of exposing command execution through URL parameters or request bodies,…
-
UNC1069 Social Engineering of Axios Maintainer Led to npm Supply Chain Attack
UNC1069 Social Engineering of Axios Maintainer Led to npm Supply Chain Attack The maintainer of the Axios npm package has confirmed that the supply chain compromise was the result of a highly-targeted social engineering campaign orchestrated by North Korean threat actors tracked as UNC1069. Maintainer Jason Saayman said the attackers tailored their social engineering efforts “specifically to…
-
Why Third-Party Risk Is the Biggest Gap in Your Clients’ Security Posture
Why Third-Party Risk Is the Biggest Gap in Your Clients’ Security Posture The next major breach hitting your clients probably won’t come from inside their walls. It’ll come through a vendor they trust, a SaaS tool their finance team signed up for, or a subcontractor nobody in IT knows about. That’s the new attack surface, and most organizations…
-
New SparkCat Variant in iOS, Android Apps Steals Crypto Wallet Recovery Phrase Images
New SparkCat Variant in iOS, Android Apps Steals Crypto Wallet Recovery Phrase Images Cybersecurity researchers have discovered a new version of the SparkCat malware on the Apple App Store and Google Play Store, more than a year after the trojan was discovered targeting both the mobile operating systems. The malware has been found to conceal itself within seemingly benign apps, such as…
-
Friday Squid Blogging: Jurassic Fish Chokes on Squid
Friday Squid Blogging: Jurassic Fish Chokes on Squid Here’s a fossil of a 150-million year old fish that choked to death on a belemnite rostrum: the hard, internal shell of an extinct, squid-like animal. Original paper. As usual, you can also use this squid post to talk about the security stories in the news that…
-
Company that Secretly Records and Publishes Zoom Meetings
Company that Secretly Records and Publishes Zoom Meetings WebinarTV searches the internet for public Zoom invites, joins the meetings, secretly records them, and publishes (alternate link) the recordings. It doesn’t use the Zoom record feature, so Zoom can’t do anything about it. Bruce Schneier Go to bruce schneier
-
Nigerian romance scammer jailed after being caught out by fellow fraudster
Nigerian romance scammer jailed after being caught out by fellow fraudster A Nigerian fraudster spent years posing as a woman online, romancing unsuspecting American men out of their savings – until he accidentally tried the same trick on a fellow scammer, who told him to “learn how to do a clean job.” The recovered chat…
-
Inconsistent Privacy Labels Don’t Tell Users What They Are Getting
Inconsistent Privacy Labels Don’t Tell Users What They Are Getting Data privacy labels are a great idea for mobile apps, but the current versions just aren’t good enough. Bree Fowler Go to gbhackers.com
-
Apple Breaks Precedent, Patches DarkSword for iOS 18
Apple Breaks Precedent, Patches DarkSword for iOS 18 Even organizations with users unwilling or unable to adopt iOS 26 can now protect themselves from a severe, OSS mobile cracking tool. Nate Nelson Go to gbhackers.com
-
Blast Radius of TeamPCP Attacks Expands Amid Hacker Infighting
Blast Radius of TeamPCP Attacks Expands Amid Hacker Infighting As organizations disclose breaches tied to TeamPCP’s supply chain attacks, ShinyHunters and Lapsus$ are getting involved, taking credit, and creating a murky situation for enterprises. Rob Wright Go to gbhackers.com
-
Picking Up ‘Skull Vibrations’? Could Be XR Headset Authentication
Picking Up ‘Skull Vibrations’? Could Be XR Headset Authentication “Skull vibration harmonics generated by vital signs” can be used to sign in to VR, AR, and MR headsets, according to emerging research. Alexander Culafi Go to gbhackers.com
-
Source Code Leaks Highlight Lack of Supply Chain Oversight
Source Code Leaks Highlight Lack of Supply Chain Oversight Or, why the software supply chain should be treated as critical infrastructure with guardrails built in at every layer. Robert Lemos Go to gbhackers.com
-
CrowdStrike Next-Gen SIEM Can Now Ingest Microsoft Defender Telemetry
CrowdStrike Next-Gen SIEM Can Now Ingest Microsoft Defender Telemetry Once CrowdStrike’s nemesis, Microsoft is now a collaborator. A shared interest in Formula 1 helped thaw the years-long fierce rivalry. Jeffrey Schwartz Go to gbhackers.com
-
Kimsuky Uses Malicious LNK Files to Drop Python Backdoor
Kimsuky Uses Malicious LNK Files to Drop Python Backdoor Kimsuky is using multi-stage malicious LNK files to deploy a Python-based backdoor, adding new intermediate scripts while keeping the final payload logic largely unchanged…. Go to gbhackers.com
-
CISA Includes TrueConf Security Flaw in KEV Catalog After Exploitation in the Wild
CISA Includes TrueConf Security Flaw in KEV Catalog After Exploitation in the Wild The Cybersecurity and Infrastructure Security Agency (CISA) has officially added a critical security flaw affecting the TrueConf Client to its Known Exploited Vulnerabilities (KEV)… Go to gbhackers.com
-
14,000+ F5 BIG-IP APM Instances Exposed Online as Attackers Exploit RCE Vulnerability
14,000+ F5 BIG-IP APM Instances Exposed Online as Attackers Exploit RCE Vulnerability Cybersecurity researchers have identified a massive attack surface involving F5 BIG-IP Access Policy Manager (APM) devices. Following a critical severity upgrade to a recently… Go to gbhackers.com
-
Axios npm compromise traced to targeted social engineering attack
Axios npm compromise traced to targeted social engineering attack The recent compromise of the widely used Axios npm package has been confirmed as the result of a targeted social engineering attack. The incident, which… Go to gbhackers.com
-
Malicious Chrome Extension “ChatGPT Ad Blocker” Targets Users, Steals Conversations
Malicious Chrome Extension “ChatGPT Ad Blocker” Targets Users, Steals Conversations Security researchers have uncovered a malicious Google Chrome extension named “ChatGPT Ad Blocker” designed to silently steal private AI conversations. The malware cleverly disguises… Go to gbhackers.com
-
Man admits to locking thousands of Windows devices in extortion plot
Man admits to locking thousands of Windows devices in extortion plot A former core infrastructure engineer has pleaded guilty to locking Windows admins out of 254 servers as part of a failed extortion plot targeting his employer, an industrial company headquartered in Somerset County, New Jersey. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft now force upgrades unmanaged Windows 11 24H2 PCs
Microsoft now force upgrades unmanaged Windows 11 24H2 PCs Starting this week, Microsoft has begun force-upgrading unmanaged devices running Windows 11 24H2 Home and Pro editions to Windows 11 25H2. […] Sergiu Gatlan Go to bleepingcomputer
-
CERT-EU: European Commission hack exposes data of 30 EU entities
CERT-EU: European Commission hack exposes data of 30 EU entities The European Union’s Cybersecurity Service (CERT-EU) has attributed the European Commission cloud hack to the TeamPCP threat group, saying the resulting breach exposed the data of at least 29 other Union entities. […] Sergiu Gatlan Go to bleepingcomputer
-
Claude Code leak used to push infostealer malware on GitHub
Claude Code leak used to push infostealer malware on GitHub Threat actors are exploiting the recent Claude Code source code leak by using fake GitHub repositories to deliver Vidar information-stealing malware. […] Bill Toulas Go to bleepingcomputer
-
Drift loses $280 million North Korean hackers seize Security Council powers
Drift loses $280 million North Korean hackers seize Security Council powers The Drift Protocol lost at least $280 million after a threat actor took control of its Security Council administrative powers in a planned, sophisticated operation. […] Bill Toulas Go to bleepingcomputer
-
Microsoft Forcing Upgrades to Unmanaged Windows 11, Version 24H2
Microsoft Forcing Upgrades to Unmanaged Windows 11, Version 24H2 Microsoft has officially begun force-upgrading unmanaged Windows 11 version 24H2 devices to version 25H2, marking the final phase of a staged rollout that relies on machine learning to determine device readiness. The move, confirmed in an updated Windows Release Health Dashboard entry, affects all Home and…
-
Multiple TP-Link Vulnerabilities Let Attackers Trigger DoS and Crash Routers
Multiple TP-Link Vulnerabilities Let Attackers Trigger DoS and Crash Routers Multiple high-severity vulnerabilities exist in TP-Link’s Tapo C520WS smart security cameras. If exploited, these vulnerabilities may allow adjacent attackers to trigger Denial-of-Service (DoS) conditions, crash the device, or completely bypass authentication. TP-Link has released urgent firmware updates to address these critical security gaps. When a…
-
Hackers Compromised 700+ Next.js Hosts by Exploiting React2Shell Vulnerability
Hackers Compromised 700+ Next.js Hosts by Exploiting React2Shell Vulnerability A massive automated credential theft campaign is actively targeting web applications worldwide. Cybersecurity researchers at Cisco Talos have uncovered an operation by a hacker group tracked as UAT-10608, which has already compromised over 700 servers. The attackers are exploiting a critical security flaw known as React2Shell…
-
CERT-EU Confirms Trivy Supply Chain Attack Led to European Commission AWS Breach
CERT-EU Confirms Trivy Supply Chain Attack Led to European Commission AWS Breach The European Commission’s primary web platform, “europa.eu,” recently suffered a severe data breach stemming from a supply-chain compromise involving the popular open-source vulnerability scanner, Trivy. On April 3, 2026, CERT-EU published an official advisory detailing how a threat actor known as TeamPCP exploited…
-
North Korea-Linked Hackers Compromise Axios npm Package in Major Supply Chain Attack
North Korea-Linked Hackers Compromise Axios npm Package in Major Supply Chain Attack A North Korea-linked threat group has successfully hijacked one of the most widely used JavaScript libraries on the internet, injecting malware into millions of potential development environments. On March 31, 2026, attackers gained access to the Axios Node Package Manager (npm) package using…
-
Hackers Exploit CVE-2025-55182 to Breach 766 Next.js Hosts, Steal Credentials
Hackers Exploit CVE-2025-55182 to Breach 766 Next.js Hosts, Steal Credentials A large-scale credential harvesting operation has been observed exploiting the React2Shell vulnerability as an initial infection vector to steal database credentials, SSH private keys, Amazon Web Services (AWS) secrets, shell command history, Stripe API keys, and GitHub tokens at scale. Cisco Talos has attributed the operation to a threat cluster…
-
Cisco Patches 9.8 CVSS IMC and SSM Flaws Allowing Remote System Compromise
Cisco Patches 9.8 CVSS IMC and SSM Flaws Allowing Remote System Compromise Cisco has released updates to address a critical security flaw in the Integrated Management Controller (IMC) that, if successfully exploited, could allow an unauthenticated, remote attacker to bypass authentication and gain access to the system with elevated privileges. The vulnerability, tracked as CVE-2026-20093, carries a…
-
ThreatsDay Bulletin: Pre-Auth Chains, Android Rootkits, CloudTrail Evasion & 10 More Stories
ThreatsDay Bulletin: Pre-Auth Chains, Android Rootkits, CloudTrail Evasion & 10 More Stories The latest ThreatsDay Bulletin is basically a cheat sheet for everything breaking on the internet right now. No corporate fluff or boring lectures here, just a quick and honest look at the messy reality of keeping systems safe this week. Things are moving fast. The list includes researchers…
-
Researchers Uncover Mining Operation Using ISO Lures to Spread RATs and Crypto Miners
Researchers Uncover Mining Operation Using ISO Lures to Spread RATs and Crypto Miners A financially motivated operation codenamed REF1695 has been observed leveraging fake installers to deploy remote access trojans (RATs) and cryptocurrency miners since November 2023. “Beyond cryptomining, the threat actor monetizes infections through CPA (Cost Per Action) fraud, directing victims to content locker pages under the guise of…
-
The State of Trusted Open Source Report
The State of Trusted Open Source Report In December 2025, we shared the first-ever The State of Trusted Open Source report, featuring insights from our product data and customer base on open source consumption across our catalog of container image projects, versions, images, language libraries, and builds. These insights shed light on what teams pull, deploy, and maintain…
-
US Bans All Foreign-Made Consumer Routers
US Bans All Foreign-Made Consumer Routers This is for new routers; you don’t have to throw away your existing ones: The Executive Branch determination noted that foreign-produced routers (1) introduce “a supply chain vulnerability that could disrupt the U.S. economy, critical infrastructure, and national defense” and (2) pose “a severe cybersecurity risk that could be…
-
Possible US Government iPhone Hacking Tool Leaked
Possible US Government iPhone Hacking Tool Leaked Wired writes (alternate source): Security researchers at Google on Tuesday released a report describing what they’re calling “Coruna,” a highly sophisticated iPhone hacking toolkit that includes five complete hacking techniques capable of bypassing all the defenses of an iPhone to silently install malware on a device when it…
-
ISC Stormcast For Friday, April 3rd, 2026 https://isc.sans.edu/podcastdetail/9878, (Fri, Apr 3rd)
ISC Stormcast For Friday, April 3rd, 2026 https://isc.sans.edu/podcastdetail/9878, (Fri, Apr 3rd) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Attempts to Exploit Exposed “Vite” Installs (CVE-2025-30208), (Thu, Apr 2nd)
Attempts to Exploit Exposed “Vite” Installs (CVE-2025-30208), (Thu, Apr 2nd) From its GitHub repo: “Vite (French word for “quick”, pronounced /vi?t/, like “veet”) is a new breed of frontend build tooling that significantly improves the frontend development experience” [https://github.com/vitejs/vite]. This environment introduces some neat and useful shortcuts to make developers’ lives simpler. But as so…
-
ISC Stormcast For Thursday, April 2nd, 2026 https://isc.sans.edu/podcastdetail/9876, (Thu, Apr 2nd)
ISC Stormcast For Thursday, April 2nd, 2026 https://isc.sans.edu/podcastdetail/9876, (Thu, Apr 2nd) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Malicious Script That Gets Rid of ADS, (Wed, Apr 1st)
Malicious Script That Gets Rid of ADS, (Wed, Apr 1st) Today, most malware are called “fileless” because they try to reduce their footprint on the infected computer filesystem to the bare minimum. But they need to write something… think about persistence. They can use the registry as an alternative storage location. But some scripts still…
-
TeamPCP Supply Chain Campaign: Update 005 – First Confirmed Victim Disclosure, Post-Compromise Cloud Enumeration Documented, and Axios Attribution Narrows, (Wed, Apr 1st)
TeamPCP Supply Chain Campaign: Update 005 – First Confirmed Victim Disclosure, Post-Compromise Cloud Enumeration Documented, and Axios Attribution Narrows, (Wed, Apr 1st) This is the fifth update to the TeamPCP supply chain campaign threat intelligence report, “When the Security Scanner Became the Weapon” (v3.0, March 25, 2026). Update 004 covered developments through March 30, including the Databricks…
-
Geopolitics, AI, and Cybersecurity: Insights From RSAC 2026
Geopolitics, AI, and Cybersecurity: Insights From RSAC 2026 AI-driven threats, global leadership shifts, and the future of cybersecurity in a rapidly evolving landscape were among the discussions at RSAC 2026 Conference. Becky Bracken, Kristina Beek Go to gbhackers.com
-
Bank Trojan ‘Casbaneiro’ Worms Through Latin America
Bank Trojan ‘Casbaneiro’ Worms Through Latin America Augmented Marauder’s multipronged banking-Trojan cyber campaigns are targeting Spanish speakers, evading detection, and replicating rapidly. Nate Nelson Go to gbhackers.com
-
Ransomware Will Hit Hospitals. Rehearsals Are Key to Defense
Ransomware Will Hit Hospitals. Rehearsals Are Key to Defense A chief medical information officer provided a peek into what hospitals face when they inevitably suffer a ransomware attack—whether it leads to short or long-term outages. Arielle Waldman Go to gbhackers.com