no alarms and no surprises please..
-
RFQ Malware Campaign Uses DOCX, RTF, JS, and Python
RFQ Malware Campaign Uses DOCX, RTF, JS, and Python Hackers are abusing DOCX, RTF, JavaScript, PowerShell, and Python to deliver an in‑memory Cobalt Strike beacon in a stealthy spear‑phishing campaign that impersonates Boeing… Go to gbhackers.com
-
NoVoice on Google Play Exploits 22 Flaws to Hit Millions of Android Users
NoVoice on Google Play Exploits 22 Flaws to Hit Millions of Android Users NoVoice is a new Android rootkit campaign that hid in more than 50 apps on Google Play, exploiting 22 vulnerabilities to hijack millions of… Go to gbhackers.com
-
CISA Issues Alert on Chrome Zero-Day Under Active Exploitation
CISA Issues Alert on Chrome Zero-Day Under Active Exploitation The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning regarding a critical zero-day vulnerability affecting Google Chrome and other Chromium-based… Go to gbhackers.com
-
Apple Releases iOS 18.7.7 Update to Defend Against DarkSword Exploit
Apple Releases iOS 18.7.7 Update to Defend Against DarkSword Exploit Apple has officially expanded the rollout of iOS 18.7.7 and iPadOS 18.7.7 to defend users against a critical web-based threat known as the DarkSword… Go to gbhackers.com
-
Axios npm Supply Chain Breach: Microsoft Shares Mitigation Steps
Axios npm Supply Chain Breach: Microsoft Shares Mitigation Steps Microsoft has detailed how organizations can detect and mitigate a recent supply chain compromise involving malicious Axios npm releases and infrastructure attributed to the… Go to gbhackers.com
-
Microsoft links Classic Outlook issue to email delivery problems
Microsoft links Classic Outlook issue to email delivery problems Microsoft is investigating a known issue that prevents some Classic Outlook users from sending emails via Outlook.com. […] Sergiu Gatlan Go to bleepingcomputer
-
Over 14,000 F5 BIG-IP APM instances still exposed to RCE attacks
Over 14,000 F5 BIG-IP APM instances still exposed to RCE attacks Internet security watchdog Shadowserver has found over 14,000 BIG-IP APM instances exposed online amid ongoing attacks exploiting a critical-severity remote code execution (RCE) vulnerability. […] Sergiu Gatlan Go to bleepingcomputer
-
New CrystalRAT malware adds RAT, stealer and prankware features
New CrystalRAT malware adds RAT, stealer and prankware features A new malware-as-a-service called CrystalRAT is being promoted on Telegram, offering remote access, data theft, keylogging, and clipboard hijacking capabilities. […] Bill Toulas Go to bleepingcomputer
-
Apple expands iOS 18 updates to more iPhones to block DarkSword attacks
Apple expands iOS 18 updates to more iPhones to block DarkSword attacks Apple has now made it possible for more iPhones still running iOS 18 to receive security updates that protect against the actively exploited DarkSword exploit kit. […] Lawrence Abrams Go to bleepingcomputer
-
Hackers exploit TrueConf zero-day to push malicious software updates
Hackers exploit TrueConf zero-day to push malicious software updates Hackers have targeted TrueConf conference servers in attacks that exploit a zero-day vulnerability, allowing them to execute arbitrary files on all connected endpoints. […] Bill Toulas Go to bleepingcomputer
-
Microsoft Copilot Terms of Service Label Copilot is for Entertainment Purposes Only
Microsoft Copilot Terms of Service Label Copilot is for Entertainment Purposes Only Microsoft’s terms of service for its Copilot AI assistant include a notable disclaimer that has sparked renewed scrutiny from security and enterprise communities: the product is intended solely for entertainment purposes. According to the official Copilot terms of use, Microsoft explicitly states that…
-
New WhatsApp Attack Chain Uses VBS Scripts, Cloud Downloads, and MSI Backdoors
New WhatsApp Attack Chain Uses VBS Scripts, Cloud Downloads, and MSI Backdoors A new malware campaign is actively using WhatsApp to deliver harmful files directly to Windows users, exploiting the widespread trust placed in everyday messaging apps. The threat actors send malicious Visual Basic Script (VBS) files through WhatsApp messages, knowing that users rarely question…
-
Critical Cisco IMC Vulnerability Let Attackers Bypass Authentication
Critical Cisco IMC Vulnerability Let Attackers Bypass Authentication Cisco has recently disclosed a critical security flaw affecting its Integrated Management Controller (IMC), prompting the release of urgent software updates. The vulnerability, officially tracked as CVE-2026-20093, has been assigned a critical Base CVSS score of 9.8, indicating the highest level of severity. This security weakness is…
-
Remcos RAT Infection Chain Hides Behind Obfuscated Scripts and Trusted Windows Binaries
Remcos RAT Infection Chain Hides Behind Obfuscated Scripts and Trusted Windows Binaries Cybercriminals are getting better at hiding their tracks, and a recently uncovered Remcos RAT campaign is proof of that. This attack does not rely on a single malicious file dropped onto a system. Instead, it uses a carefully built, multi-stage chain that starts…
-
Symantec DLP Agent Vulnerability Let Attackers Escalate Privileges
Symantec DLP Agent Vulnerability Let Attackers Escalate Privileges A high-severity security flaw has been identified in the Symantec Data Loss Prevention (DLP) Agent for Windows. Tracked as CVE-2026-3991, this vulnerability allows a low-privileged local attacker to escalate their system privileges to the highest level. Security researcher Manuel Feifel discovered the flaw, and Broadcom has recently…
-
Digital assets after death: Managing risks to your loved one’s digital estate
Digital assets after death: Managing risks to your loved one’s digital estate Fraudsters often target the accounts of the deceased or their grieving relatives. Here’s how to keep the scammers at bay. Go to eset
-
CERT-UA Impersonation Campaign Spread AGEWHEEZE Malware to 1 Million Emails
CERT-UA Impersonation Campaign Spread AGEWHEEZE Malware to 1 Million Emails The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of a new phishing campaign in which the cybersecurity agency itself was impersonated to distribute a remote administration tool known as AGEWHEEZE. As part of the attacks, the threat actors, tracked as UAC-0255, sent…
-
Microsoft Warns of WhatsApp-Delivered VBS Malware Hijacking Windows via UAC Bypass
Microsoft Warns of WhatsApp-Delivered VBS Malware Hijacking Windows via UAC Bypass Microsoft is calling attention to a new campaign that has leveraged WhatsApp messages to distribute malicious Visual Basic Script (VBS) files. The activity, beginning in late February 2026, leverages these scripts to initiate a multi-stage infection chain for establishing persistence and enabling remote access.…
-
Block the Prompt, Not the Work: The End of “Doctor No”
Block the Prompt, Not the Work: The End of “Doctor No” There is a character that keeps appearing in enterprise security departments, and most CISOs know exactly who that is. It doesn’t build. It doesn’t enable. Its entire function is to say “No.” No to ChatGPT. No to DeepSeek. No to the file-sharing tool the…
-
Casbaneiro Phishing Targets Latin America and Europe Using Dynamic PDF Lures
Casbaneiro Phishing Targets Latin America and Europe Using Dynamic PDF Lures A multi-pronged phishing campaign is targeting Spanish-speaking users in organizations across Latin America and Europe to deliver Windows banking trojans like Casbaneiro (aka Metamorfo) via another malware called Horabot. The activity has been attributed to a Brazilian cybercrime threat actor tracked as Augmented Marauder…
-
New Chrome Zero-Day CVE-2026-5281 Under Active Exploitation — Patch Released
New Chrome Zero-Day CVE-2026-5281 Under Active Exploitation — Patch Released Google on Thursday released security updates for its Chrome web browser to address 21 vulnerabilities, including a zero-day flaw that it said has been exploited in the wild. The high-severity vulnerability, CVE-2026-5281 (CVSS score: N/A), concerns a use-after-free bug in Dawn, an open-source and cross-platform…
-
Is “Hackback” Official US Cybersecurity Strategy?
Is “Hackback” Official US Cybersecurity Strategy? The 2026 US “Cyber Strategy for America” document is mostly the same thing we’ve seen out of the White House for over a decade, but with a more aggressive tone. But one sentence stood out: “We will unleash the private sector by creating incentives to identify and disrupt adversary…
-
Smashing Security podcast #461: This man hid $400 million in a fishing rod. Then it vanished
Smashing Security podcast #461: This man hid $400 million in a fishing rod. Then it vanished A cannabis-growing, beekeeping, gyrocopter-flying Irishman invested his drug money in Bitcoin back in 2011 – and now sits on a fortune worth $400 million. There’s just one small problem: the access codes were tucked inside his fishing rod case,…
-
Alleged RedLine malware developer extradited to United States
Alleged RedLine malware developer extradited to United States A man has appeared in federal court in Austin, Texas, after being extradited to the United States to face charges related to his alleged role as a key developer of the notorious RedLine malware. Read more in my article on the Hot for Security blog. Graham Cluley…
-
LatAm’s Self-Taught Cyber Talent Overlooked Amid Cyberattack Glut
LatAm’s Self-Taught Cyber Talent Overlooked Amid Cyberattack Glut A newly released study exclusively shared with Dark Reading details the unique circumstances that make up Latin America’s labor pool, and why organizations may want to expand their talent search. Alexander Culafi Go to gbhackers.com
-
Cyberattacks Intensify Pressure on Latin American Governments
Cyberattacks Intensify Pressure on Latin American Governments Cyber threats across Latin America are increasingly targeting government systems, from disruptive attacks in Puerto Rico to a surge of probes against Colombia’s health sector. Robert Lemos Go to gbhackers.com
-
Venom Stealer MaaS Platform Commoditizes ClickFix Attacks
Venom Stealer MaaS Platform Commoditizes ClickFix Attacks A new service on the cybercrime market provides automated capabilities to create persistent information-stealing social engineering attacks. Elizabeth Montalbano Go to gbhackers.com
-
Are We Training AI Too Late?
Are We Training AI Too Late? Ask the Expert: Cybersecurity teams need to expand their field of view to include new, unique threat sources, rather than relying on past, proven threat actors. Nishawn Smagh Go to gbhackers.com
-
CrystalX Malware-as-a-Service Spreads via Telegram With Stealer, RAT Tools
CrystalX Malware-as-a-Service Spreads via Telegram With Stealer, RAT Tools Hackers are actively promoting a new malware-as-a-service (MaaS) platform called CrystalX RAT through private Telegram channels, offering cybercriminals a powerful toolkit that combines remote… Go to gbhackers.com
-
Hackers Exploit Hotel Booking Systems to Send Fake Payment Requests to Guests
Hackers Exploit Hotel Booking Systems to Send Fake Payment Requests to Guests Hackers are increasingly targeting hotel booking workflows to trick travelers into handing over payment details, using a technique that blends real reservation data with… Go to gbhackers.com
-
PoC Exploit Code Published for nginx-ui Backup Restore Security Flaw
PoC Exploit Code Published for nginx-ui Backup Restore Security Flaw A critical security flaw in the nginx-ui backup restore mechanism, tracked as CVE-2026-33026, allows attackers to manipulate encrypted backups and execute arbitrary commands. Proof-of-Concept (PoC)… Go to gbhackers.com
-
North Korean Hackers Breach Axios Package, Target Windows, macOS, and Linux Systems
North Korean Hackers Breach Axios Package, Target Windows, macOS, and Linux Systems A North Korea–nexus threat actor has hijacked the popular Axios NPM package in a high‑impact software supply chain attack that can silently backdoor Windows,… Go to gbhackers.com
-
CrewAI Hit by Critical Vulnerabilities Enabling Sandbox Escape and Host Compromise
CrewAI Hit by Critical Vulnerabilities Enabling Sandbox Escape and Host Compromise CrewAI, a prominent tool used by developers to orchestrate multi-agent AI systems, is currently vulnerable to a chain of critical security flaws. By using… Go to gbhackers.com
-
Google Drive ransomware detection now on by default for paying users
Google Drive ransomware detection now on by default for paying users Google announced that the AI-powered Google Drive ransomware detection feature has reached general availability and is now enabled by default for all paying users. […] Sergiu Gatlan Go to bleepingcomputer
-
New Windows 11 emergency update fixes preview update install issues
New Windows 11 emergency update fixes preview update install issues Microsoft released an emergency update to fix the March 2026 KB5079391 non-security preview update, which was pulled over the weekend due to installation issues. […] Sergiu Gatlan Go to bleepingcomputer
-
Claude Code source code accidentally leaked in NPM package
Claude Code source code accidentally leaked in NPM package Anthropic says it accidentally leaked the source code for Claude Code, which is closed source, but the company says no customer data or credentials were exposed. […] Mayank Parmar Go to bleepingcomputer
-
Google now allows you to change your @gmail.com address
Google now allows you to change your @gmail.com address Google is rolling out a new feature in the U.S. that allows users to change their @gmail address or create a new alias. […] Mayank Parmar Go to bleepingcomputer
-
Proton launches new “Meet” privacy-focused conferencing platform
Proton launches new “Meet” privacy-focused conferencing platform Proton has announced a new video conferencing service named Meet and positioned it as a privacy-focused alternative to mainstream services like Google Meet, Zoom, and Microsoft Teams. […] Bill Toulas Go to bleepingcomputer
-
Hackers Backdoor Telnyx Python SDK on PyPI to Steal Credentials Across Windows, macOS, and Linux
Hackers Backdoor Telnyx Python SDK on PyPI to Steal Credentials Across Windows, macOS, and Linux A threat actor group known as TeamPCP has been caught backdooring the Telnyx Python SDK on PyPI — a popular cloud communications library with over 700,000 downloads in February alone. On March 27, 2026, two malicious versions of the package,…
-
New npm Supply Chain Attack Uses undicy-http to Deploy Screen-Streaming RAT and Browser Injector
New npm Supply Chain Attack Uses undicy-http to Deploy Screen-Streaming RAT and Browser Injector A malicious npm package named undicy-http has surfaced inside the Node.js developer ecosystem, quietly compromising machines of developers who mistakenly install it. The package impersonates undici, the official HTTP client library bundled with Node.js that handles millions of weekly downloads. Despite sharing a near-identical…
-
PNG Vulnerabilities Allow Attackers to Trigger Process Crashes, Leak Sensitive Information
PNG Vulnerabilities Allow Attackers to Trigger Process Crashes, Leak Sensitive Information Two high-severity vulnerabilities have been discovered in libpng, the widely used reference library for reading and writing PNG images. These flaws allow attackers to trigger process crashes, leak sensitive information, and potentially execute arbitrary code by convincing a system to process a crafted PNG…
-
XLoader Malware Upgrades Obfuscation Tactics and Hides C2 Traffic Behind Decoy Servers
XLoader Malware Upgrades Obfuscation Tactics and Hides C2 Traffic Behind Decoy Servers A well-known information-stealing malware called XLoader has received significant upgrades in its latest versions, making it considerably harder to detect and analyze than before. Originally derived from a malware family known as FormBook, which first surfaced in 2016, XLoader was rebranded and relaunched…
-
Mercor AI Confirms Data Breach Following Lapsus$ Claims of 4TB Data Theft
Mercor AI Confirms Data Breach Following Lapsus$ Claims of 4TB Data Theft Mercor AI has officially confirmed a severe data breach following claims by the notorious Lapsus$ hacking group that they stole 4 terabytes of sensitive company data. The incident, stemming from a recent supply chain attack on the open-source LiteLLM project, has exposed proprietary…
-
This month in security with Tony Anscombe – March 2026 edition
This month in security with Tony Anscombe – March 2026 edition The past four weeks have seen a slew of new cybersecurity wake-up calls that showed why every organization needs a well-thought-out cyber-resilience plan Go to eset
-
Claude Code Source Leaked via npm Packaging Error, Anthropic Confirms
Claude Code Source Leaked via npm Packaging Error, Anthropic Confirms Anthropic on Tuesday confirmed that internal code for its popular artificial intelligence (AI) coding assistant, Claude Code, had been inadvertently released due to a human error. “No sensitive customer data or credentials were involved or exposed,” an Anthropic spokesperson said in a statement shared with…
-
Android Developer Verification Rollout Begins Ahead of September Enforcement
Android Developer Verification Rollout Begins Ahead of September Enforcement Google on Monday said it’s officially rolling out Android developer verification to all developers to combat the problem of bad actors distributing harmful apps while “hiding behind anonymity.” The development comes ahead of a planned verification mandate that goes into effect in Brazil, Indonesia, Singapore, and…
-
TrueConf Zero-Day Exploited in Attacks on Southeast Asian Government Networks
TrueConf Zero-Day Exploited in Attacks on Southeast Asian Government Networks A high-severity security flaw in the TrueConf client video conferencing software has been exploited in the wild as a zero-day as part of a campaign targeting government entities in Southeast Asia dubbed TrueChaos. The vulnerability in question is CVE-2026-3502 (CVSS score: 7.8), a lack of…
-
Vertex AI Vulnerability Exposes Google Cloud Data and Private Artifacts
Vertex AI Vulnerability Exposes Google Cloud Data and Private Artifacts Cybersecurity researchers have disclosed a security “blind spot” in Google Cloud’s Vertex AI platform that could allow artificial intelligence (AI) agents to be weaponized by an attacker to gain unauthorized access to sensitive data and compromise an organization’s cloud environment. According to Palo Alto Networks…
-
The AI Arms Race – Why Unified Exposure Management Is Becoming a Boardroom Priority
The AI Arms Race – Why Unified Exposure Management Is Becoming a Boardroom Priority The cybersecurity landscape is accelerating at an unprecedented rate. What is emerging is not simply a rise in the number of vulnerabilities or tools, but a dramatic increase in speed. Speed of attack, speed of exploitation, and speed of change across…
-
Axios npm package compromised to deploy malware
Axios npm package compromised to deploy malware Categories: Threat Research Tags: advisory, NPM, Axios Go to sophos
-
Inventors of Quantum Cryptography Win Turing Award
Inventors of Quantum Cryptography Win Turing Award Charles Bennett and Gilles Brassard have won the 2026 Turing Award for inventing quantum cryptography. I am incredibly pleased to see them get this recognition. I have always thought the technology to be fantastic, even though I think it’s largely unnecessary. I wrote up my thoughts back in…
-
ISC Stormcast For Wednesday, April 1st, 2026 https://isc.sans.edu/podcastdetail/9874, (Wed, Apr 1st)
ISC Stormcast For Wednesday, April 1st, 2026 https://isc.sans.edu/podcastdetail/9874, (Wed, Apr 1st) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Application Control Bypass for Data Exfiltration, (Tue, Mar 31st)
Application Control Bypass for Data Exfiltration, (Tue, Mar 31st) In case of a cyber incident, most organizations fear more of data loss (via exfiltration) than regular data encryption because they have a good backup policy in place. If exfiltration happened, it means a total loss of control of the stolen data with all the consequences (PII, CC…
-
Iranian hackers breach FBI director’s personal email, and post his CV and photos online
Iranian hackers breach FBI director’s personal email, and post his CV and photos online It’s not every day that you read that the head of America’s top law enforcement agency has been hacked, but then – these aren’t ordinary times. Read more in my article on the Hot for Security blog. Graham Cluley Go to…
-
Weekly Update 497
Weekly Update 497 Day by day, I find we’re eeking more goodness out of OpenClaw and finding the sweet spot between what the humans do well and the agent can run off and do on its own. Significantly, we’re shifting more and more of the workload to the latter as all 3 of us at…
-
Axios NPM Package Compromised in Precision Attack
Axios NPM Package Compromised in Precision Attack The NPM package for Axios, a popular JavaScript HTTP client library, was briefly compromised this week, possibly by North Korean threat actors. Alexander Culafi Go to gbhackers.com
-
Google’s Vertex AI Has an Over-Privileged Problem
Google’s Vertex AI Has an Over-Privileged Problem Palo Alto researchers show how attackers could exploit AI agents on Google’s Vertex AI to steal data and break into restricted cloud infrastructure. Jai Vijayan Go to gbhackers.com
-
TeamPCP Breaches Cloud, SaaS Instances With Stolen Credentials
TeamPCP Breaches Cloud, SaaS Instances With Stolen Credentials The threat group’s shift to speedy attacks on AWS, Azure, and SaaS instances shows organizations need to respond quickly to compromised credentials. Rob Wright Go to gbhackers.com
-
Rethinking Vulnerability Management Strategies for Mid-Market Security
Rethinking Vulnerability Management Strategies for Mid-Market Security Intruder’s Chris Wallis argues mid-market teams should prioritize CVE remediation speed over vulnerability counts, while expanding defenses beyond CVEs to include attack surface management. Terry Sweeney Go to gbhackers.com
-
AI and Quantum Are Forcing a Rethink of Digital Trust
AI and Quantum Are Forcing a Rethink of Digital Trust In a conversation with Dark Reading’s Terry Sweeney, DigiCert CEO Amit Sinha explains how AI-driven identities and quantum threats are reshaping the foundations of digital trust. Terry Sweeney Go to gbhackers.com
-
Black Hat USA
Black Hat USA Go to gbhackers.com
-
Dutch Finance Ministry Responds to Cyberattack by Taking Systems Offline
Dutch Finance Ministry Responds to Cyberattack by Taking Systems Offline The Dutch Ministry of Finance is actively managing a significant cybersecurity incident after discovering unauthorized access to its internal Information and Communication Technology (ICT)… Go to gbhackers.com
-
Telegram-Based ResokerRAT Adds Screenshot Capture and Persistence
Telegram-Based ResokerRAT Adds Screenshot Capture and Persistence Hackers are deploying a new Windows malware called ResokerRAT, a Telegram‑based Remote Access Trojan (RAT) that gives attackers stealthy remote control over infected systems. Instead… Go to gbhackers.com
-
PNG Vulnerabilities Allow Attackers to Trigger Crashes and Leak Sensitive Data
PNG Vulnerabilities Allow Attackers to Trigger Crashes and Leak Sensitive Data Security researchers have disclosed two high-severity vulnerabilities in libpng, the widely deployed reference library used for processing Portable Network Graphics (PNG) image files. These critical… Go to gbhackers.com
-
EvilTokens Launches New Phishing Service Targeting Microsoft Accounts
EvilTokens Launches New Phishing Service Targeting Microsoft Accounts EvilTokens is a new Phishing-as-a-Service (PhaaS) platform that industrialises Microsoft account takeover by abusing the OAuth device code flow rather than traditional credential phishing. The… Go to gbhackers.com
-
Google Introduces Advanced Ransomware Defense and Recovery Features in Drive
Google Introduces Advanced Ransomware Defense and Recovery Features in Drive Google has officially moved its advanced ransomware detection and file restoration features for Google Drive out of beta, making them generally available to organizations… Go to gbhackers.com
-
Hacker charged with stealing $53 million from Uranium crypto exchange
Hacker charged with stealing $53 million from Uranium crypto exchange U.S. prosecutors have charged a Maryland man with stealing more than $53 million after hacking the Uranium Finance crypto exchange twice and laundering the proceeds through a cryptocurrency mixer. […] Sergiu Gatlan Go to bleepingcomputer
-
Dutch Finance Ministry takes treasury banking portal offline after breach
Dutch Finance Ministry takes treasury banking portal offline after breach The Dutch Ministry of Finance took some of its systems offline, including the digital portal for treasury banking, while investigating a cyberattack detected two weeks ago. […] Sergiu Gatlan Go to bleepingcomputer
-
CISA orders feds to patch actively exploited Citrix flaw by Thursday
CISA orders feds to patch actively exploited Citrix flaw by Thursday The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered government agencies to patch their Citrix NetScaler appliances against an actively exploited vulnerability by Thursday. […] Sergiu Gatlan Go to bleepingcomputer
-
Healthcare tech firm CareCloud says hackers stole patient data
Healthcare tech firm CareCloud says hackers stole patient data Healthcare IT firm CareCloud has disclosed a data breach incident that exposed sensitive data and caused a network disruption lasting approximately eight hours. […] Bill Toulas Go to bleepingcomputer
-
New RoadK1ll WebSocket implant used to pivot on breached networks
New RoadK1ll WebSocket implant used to pivot on breached networks A newly identified malicious implant named RoadK1ll is enabling threat actors to quietly move from a compromised host to other systems on the network. […] Bill Toulas Go to bleepingcomputer
-
New DeepLoad Malware Uses ClickFix and AI-Generated Evasion to Breach Enterprise Networks
New DeepLoad Malware Uses ClickFix and AI-Generated Evasion to Breach Enterprise Networks A newly discovered malware named DeepLoad is targeting enterprise environments, turning a single user action into persistent, credential-stealing access that survives reboots and outlasts standard cleanup efforts. What sets this campaign apart is how every stage of the attack was deliberately built to…
-
Hackers Deploy RoadK1ll Pivoting Malware to Turn Compromised Hosts Into Network Relays
Hackers Deploy RoadK1ll Pivoting Malware to Turn Compromised Hosts Into Network Relays A new piece of malware called RoadK1ll has been found silently converting compromised machines into controllable network relay points. Unlike most malware that arrives loaded with commands and attack tools, RoadK1ll is deliberately lean, built around one goal: giving attackers a reliable and…
-
GhostSocks Turns Victim Systems Into Residential Proxies for Evasive Cyberattacks
GhostSocks Turns Victim Systems Into Residential Proxies for Evasive Cyberattacks A new malware called GhostSocks has been quietly spreading through compromised systems, turning home and office devices into residential proxies that threat actors use to conceal their malicious traffic. Unlike traditional malware that simply steals data or locks files, GhostSocks hijacks the victim’s internet connection…
-
Notepad++ v8.9.3 Released Addressing cURL Security Vulnerability and Crash Issues
Notepad++ v8.9.3 Released Addressing cURL Security Vulnerability and Crash Issues Notepad++ has officially released version 8.9.3, delivering critical security patches, structural performance enhancements, and resolutions for persistent crash issues. This update finalizes the text editor’s transition to a highly optimized XML parser, addressing multiple recent regressions while fortifying the application’s auto-update mechanism against documented vulnerabilities.…
-
Axios NPM Packages Compromised to Inject Malicious Codes in an Active Supply Chain Attack
Axios NPM Packages Compromised to Inject Malicious Codes in an Active Supply Chain Attack A sophisticated supply chain attack has targeted Axios, one of the most heavily adopted HTTP clients within the JavaScript ecosystem, by introducing a malicious transitive dependency into the official npm registry. Serving as a critical component across frontend frameworks, backend microservices,…
-
Axios Supply Chain Attack Pushes Cross-Platform RAT via Compromised npm Account
Axios Supply Chain Attack Pushes Cross-Platform RAT via Compromised npm Account The popular HTTP client known as Axios has suffered a supply chain attack after two newly published versions of the npm package introduced a malicious dependency. Versions 1.14.1 and 0.30.4 of Axios have been found to inject “plain-crypto-js” version 4.2.1 as a fake dependency.…
-
OpenAI Patches ChatGPT Data Exfiltration Flaw and Codex GitHub Token Vulnerability
OpenAI Patches ChatGPT Data Exfiltration Flaw and Codex GitHub Token Vulnerability A previously unknown vulnerability in OpenAI ChatGPT allowed sensitive conversation data to be exfiltrated without user knowledge or consent, according to new findings from Check Point. “A single malicious prompt could turn an otherwise ordinary conversation into a covert exfiltration channel, leaking user messages,…
-
DeepLoad Malware Uses ClickFix and WMI Persistence to Steal Browser Credentials
DeepLoad Malware Uses ClickFix and WMI Persistence to Steal Browser Credentials A new campaign has leveraged the ClickFix social engineering tactic as a way to distribute a previously undocumented malware loader referred to as DeepLoad. “It likely uses AI-assisted obfuscation and process injection to evade static scanning, while credential theft starts immediately and captures passwords…
-
⚡ Weekly Recap: Telecom Sleeper Cells, LLM Jailbreaks, Apple Forces U.K. Age Checks and More
⚡ Weekly Recap: Telecom Sleeper Cells, LLM Jailbreaks, Apple Forces U.K. Age Checks and More Some weeks are loud. This one was quieter but not in a good way. Long-running operations are finally hitting courtrooms, old attack methods are showing up in new places, and research that stopped being theoretical right around the time defenders…
-
3 SOC Process Fixes That Unlock Tier 1 Productivity
3 SOC Process Fixes That Unlock Tier 1 Productivity What is really slowing Tier 1 down: the threat itself or the process around it? In many SOCs, the biggest delays do not come from the threat alone. They come from fragmented workflows, manual triage steps, and limited visibility early in the investigation. Fixing those process…
-
Incident responders, s’il vous plait: Invites lead to odd malware events
Incident responders, s’il vous plait: Invites lead to odd malware events <p>A phishing campaign targeting multiple organizations led to RMM installations – but not much else (yet). A threat actor experimenting, or an access-as-a-service attack underway?</p> Categories: Threat Research Tags: STAC6405, infostealer, RMM, Phishing Go to sophos
-
Apple’s Camera Indicator Lights
Apple’s Camera Indicator Lights A thoughtful review of Apple’s system to alert users that the camera is on. It’s really well-designed, and important in a world where malware could surreptitiously start recording. The reason it’s tempting to think that a dedicated camera indicator light is more secure than an on-display indicator is the fact that…
-
ISC Stormcast For Tuesday, March 31st, 2026 https://isc.sans.edu/podcastdetail/9872, (Tue, Mar 31st)
ISC Stormcast For Tuesday, March 31st, 2026 https://isc.sans.edu/podcastdetail/9872, (Tue, Mar 31st) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
TeamPCP Supply Chain Campaign: Update 004 – Databricks Investigating Alleged Compromise, TeamPCP Runs Dual Ransomware Operations, and AstraZeneca Data Released, (Mon, Mar 30th)
TeamPCP Supply Chain Campaign: Update 004 – Databricks Investigating Alleged Compromise, TeamPCP Runs Dual Ransomware Operations, and AstraZeneca Data Released, (Mon, Mar 30th) This is the fourth update to the TeamPCP supply chain campaign threat intelligence report, “When the Security Scanner Became the Weapon” (v3.0, March 25, 2026). Update 003 covered developments through March 28, including the…
-
HIBP Mega Update: Passkeys, k-Anonymity Searches, Massive Speed Enhancements and a Bulk Domain Verification API
HIBP Mega Update: Passkeys, k-Anonymity Searches, Massive Speed Enhancements and a Bulk Domain Verification API For a hobby project built in my spare time to provide a simple community service, Have I Been Pwned sure has, well, “escalated”. Today, we support hundreds of thousands of website visitors each day, tens of millions of API queries,…
-
AI-Powered ‘DeepLoad’ Malware Steals Credentials, Evades Detection
AI-Powered ‘DeepLoad’ Malware Steals Credentials, Evades Detection The massive amount of junk code that hides the malware’s logic from security scans was almost certainly generated by AI, researchers say. Jai Vijayan Go to gbhackers.com
-
Fortinet BIG-IP Vulnerability Reclassified as RCE, Under Exploitation
Fortinet BIG-IP Vulnerability Reclassified as RCE, Under Exploitation CVE-2025-53521 was initially disclosed in October as a high-severity denial-of-service (DoS) flaw, but new information has revealed the bug is actually much more dangerous. Rob Wright Go to gbhackers.com
-
Manufacturing and Healthcare Share Struggles with Passwords
Manufacturing and Healthcare Share Struggles with Passwords The two key economic sectors struggle with security for a reason: Many insiders view access management as a roadblock, while attackers see it as a way in. Arielle Waldman Go to gbhackers.com
-
Storm Brews Over Critical, No-Click Telegram Flaw
Storm Brews Over Critical, No-Click Telegram Flaw The vulnerability, which is allegedly triggered by a corrupted sticker in the messaging app, received a 9.8 CVSS score, but Telegram denies it exists. Elizabeth Montalbano Go to gbhackers.com
-
New Homoglyph Tricks Let Cybercriminals Mimic Trusted Domains
New Homoglyph Tricks Let Cybercriminals Mimic Trusted Domains New homoglyph attack techniques are turning tiny visual differences in text into a reliable way to spoof trusted domains, steal credentials, and bypass weak… Go to gbhackers.com
-
Telnyx Python SDK Backdoored on PyPI to Steal Cloud Credentials
Telnyx Python SDK Backdoored on PyPI to Steal Cloud Credentials The popular Telnyx Python SDK on PyPI to deploy a multi‑stage credential‑stealing operation that targets cloud infrastructure, Kubernetes clusters, and developer environments at scale…. Go to gbhackers.com
-
Critical Fortinet FortiClient EMS Vulnerability Actively Exploited in Attacks
Critical Fortinet FortiClient EMS Vulnerability Actively Exploited in Attacks Threat intelligence researchers have detected active exploitation of a critical vulnerability in Fortinet’s FortiClient Enterprise Management Server (EMS). The security flaw, identified as CVE-2026-21643,… Go to gbhackers.com
-
Stored XSS Vulnerability in Jira Work Management Could Enable Full Organization Takeover
Stored XSS Vulnerability in Jira Work Management Could Enable Full Organization Takeover Security researchers recently uncovered a critical stored Cross-Site Scripting (XSS) vulnerability within Atlassian’s Jira Work Management platform. This flaw allows an attacker with limited… Go to gbhackers.com
-
10 Best Data Loss Prevention Software in 2026
10 Best Data Loss Prevention Software in 2026 Data loss prevention (DLP) refers to technology and techniques for detecting and preventing unauthorized access, use, disclosure, or destruction of sensitive data. DLP solutions… Go to gbhackers.com
-
Microsoft pulls KB5079391 Windows update over install issues
Microsoft pulls KB5079391 Windows update over install issues Microsoft has pulled a buggy Windows 11 non-security preview update to investigate a known issue that triggers 0x80073712 errors during installation. […] Sergiu Gatlan Go to bleepingcomputer
-
Critical Fortinet Forticlient EMS flaw now exploited in attacks
Critical Fortinet Forticlient EMS flaw now exploited in attacks Attackers are now actively exploiting a critical vulnerability in Fortinet’s FortiClient EMS platform, according to threat intelligence company Defused. […] Sergiu Gatlan Go to bleepingcomputer
-
European Commission confirms data breach after Europa.eu hack
European Commission confirms data breach after Europa.eu hack The European Commission has confirmed a data breach after its Europa.eu web platform was hacked in a cyberattack claimed by the ShinyHunters extortion gang. […] Sergiu Gatlan Go to bleepingcomputer
-
FBI confirms hack of Director Patel’s personal email inbox
FBI confirms hack of Director Patel’s personal email inbox The Handala hackers associated with Iran have breached the personal email account of FBI Director Kash Patel and published photos and documents. […] Ionut Ilascu Go to bleepingcomputer