no alarms and no surprises please..
-
File read flaw in Smart Slider plugin impacts 500K WordPress sites
File read flaw in Smart Slider plugin impacts 500K WordPress sites A vulnerability in the Smart Slider 3 WordPress plugin, active on more than 800,000 websites, can be exploited to allow subscriber-level users access to arbitrary files on the server. […] Bill Toulas Go to bleepingcomputer
-
India Set to Ban Sale of Hikvision, TP-Link, CCTV Products From April
India Set to Ban Sale of Hikvision, TP-Link, CCTV Products From April Starting April 1, 2026, the Indian government will effectively ban Chinese video surveillance giants, including Hikvision, Dahua, and TP-Link, from selling internet-connected CCTV cameras in the country. This decisive market restriction stems from new mandatory certification rules driven by national security concerns regarding…
-
New “Prompt Poaching” Attack Steals Users’ AI Conversations via Malicious Browser Extensions
New “Prompt Poaching” Attack Steals Users’ AI Conversations via Malicious Browser Extensions For many users, engaging with an AI assistant requires opening a dedicated browser tab, which inherently isolates the AI from other browsing activities. While this separation improves privacy, it reduces usefulness and context. To bridge this gap, AI-powered browser extensions have surged in…
-
VoidLink Malware Framework Shows that AI-assisted Malware is Not Experimental Anymore
VoidLink Malware Framework Shows that AI-assisted Malware is Not Experimental Anymore For years, cybersecurity professionals debated whether AI could truly be weaponized to build dangerous malware at scale. That debate is now settled. VoidLink, a Linux-based malware framework discovered in early 2026, has crossed a threshold the security community long feared — AI-assisted malware has…
-
10 Best Spam Filter Tools 2026
10 Best Spam Filter Tools 2026 Spam filter tools use advanced algorithms and machine learning techniques to detect and block unwanted email messages. They analyze email content, sender reputation, and patterns to effectively identify and filter out spam, ensuring inboxes remain clutter-free. These tools offer customizable filtering rules, allowing users to set specific criteria for…
-
10 Best Log Monitoring Tools in 2026
10 Best Log Monitoring Tools in 2026 As enterprises adopt more cloud-native technologies, containers, and microservices-based architectures, log monitoring and management are now critical. According to many market research assessments, the global log management industry is anticipated to increase from $1.9 billion in 2020 to $4.1 billion in 2026. This expansion is driven by the increased…
-
ISC Stormcast For Monday, March 30th, 2026 https://isc.sans.edu/podcastdetail/9870, (Mon, Mar 30th)
ISC Stormcast For Monday, March 30th, 2026 https://isc.sans.edu/podcastdetail/9870, (Mon, Mar 30th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
DShield (Cowrie) Honeypot Stats and When Sessions Disconnect, (Mon, Mar 30th)
DShield (Cowrie) Honeypot Stats and When Sessions Disconnect, (Mon, Mar 30th) A lot of the information seen on DShield honeypots [1] is repeated bot traffic, especially when looking at the Cowrie [2] telnet and SSH sessions. However, how long a session lasts, how many commands are run per session and what the last commands run before…
-
TeamPCP Supply Chain Campaign: Update 003 – Operational Tempo Shift as Campaign Enters Monetization Phase With No New Compromises in 48 Hours, (Sat, Mar 28th)
TeamPCP Supply Chain Campaign: Update 003 – Operational Tempo Shift as Campaign Enters Monetization Phase With No New Compromises in 48 Hours, (Sat, Mar 28th) This is the third update to the TeamPCP supply chain campaign threat intelligence report, “When the Security Scanner Became the Weapon” (v3.0, March 25, 2026). Update 002 covered developments through March 27,…
-
New Infinity Stealer malware grabs macOS data via ClickFix lures
New Infinity Stealer malware grabs macOS data via ClickFix lures A new info-stealing malware named Infinity Stealer is targeting macOS systems with a Python payload packaged as an executable using the open-source Nuitka compiler. […] Bill Toulas Go to bleepingcomputer
-
Hackers Probe Citrix NetScaler Instances Ahead of Likely CVE-2026-3055 Exploitation
Hackers Probe Citrix NetScaler Instances Ahead of Likely CVE-2026-3055 Exploitation Cybersecurity researchers are sounding the alarm over imminent in-the-wild exploitation of a recently disclosed critical vulnerability in Citrix NetScaler ADC and Gateway appliances. Threat intelligence firm watchTowr and Defused Cyber have detected active reconnaissance campaigns specifically targeting CVE-2026-3055, a high-severity memory overread flaw that could…
-
Cybersecurity Companies’ Stocks Fall as Anthropic Tests Powerful New Model
Cybersecurity Companies’ Stocks Fall as Anthropic Tests Powerful New Model Cybersecurity stocks declined sharply on Friday following revelations that Anthropic has begun testing “Mythos,” an extraordinarily powerful new AI model with advanced vulnerability-discovery capabilities. Anthropic is actively trialing a new tier of artificial intelligence models codenamed “Capybara,” with the flagship model operating under the moniker…
-
CISA Warns of F5 BIG-IP Vulnerability Actively Exploited in Attacks
CISA Warns of F5 BIG-IP Vulnerability Actively Exploited in Attacks The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a newly disclosed vulnerability affecting F5 BIG-IP systems to its Known Exploited Vulnerabilities (KEV) catalog, warning that the flaw is being actively leveraged in real-world attacks. The vulnerability, tracked as CVE-2025-53521, was officially listed on…
-
Iran-Linked Hackers Breach FBI Director’s Personal Email, Hit Stryker With Wiper Attack
Iran-Linked Hackers Breach FBI Director’s Personal Email, Hit Stryker With Wiper Attack Threat actors with ties to Iran successfully broke into the personal email account of Kash Patel, the director of the U.S. Federal Bureau of Investigation (FBI), and leaked a cache of photos and other documents to the internet. Handala Hack Team, which carried…
-
Citrix NetScaler Under Active Recon for CVE-2026-3055 (CVSS 9.3) Memory Overread Bug
Citrix NetScaler Under Active Recon for CVE-2026-3055 (CVSS 9.3) Memory Overread Bug A recently disclosed critical security flaw impacting Citrix NetScaler ADC and NetScaler Gateway is witnessing active reconnaissance activity, according to Defused Cyber and watchTowr. The vulnerability, CVE-2026-3055 (CVSS score: 9.3), refers to a case of insufficient input validation leading to memory overread, which…
-
CISA Adds CVE-2025-53521 to KEV After Active F5 BIG-IP APM Exploitation
CISA Adds CVE-2025-53521 to KEV After Active F5 BIG-IP APM Exploitation The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical security flaw impacting F5 BIG-IP Access Policy Manager (APM) to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability in question is CVE-2025-53521 (CVSS v4 score: 9.3),…
-
TA446 Deploys DarkSword iOS Exploit Kit in Targeted Spear-Phishing Campaign
TA446 Deploys DarkSword iOS Exploit Kit in Targeted Spear-Phishing Campaign Proofpoint has disclosed details of a targeted email campaign in which threat actors with ties to Russia are leveraging the recently disclosed DarkSword exploit kit to target iOS devices. The activity has been attributed with high confidence to the Russian state-sponsored threat group known as…
-
Malicious Browser Extensions Hijack Users’ AI Chats in New “Prompt Poaching” Attack
Malicious Browser Extensions Hijack Users’ AI Chats in New “Prompt Poaching” Attack A new wave of malicious browser extensions is quietly harvesting sensitive user interactions with AI tools, in a growing threat now dubbed “prompt poaching.”… Go to gbhackers.com
-
Fake Certificate Loader Hides BlankGrabber Malware Chain
Fake Certificate Loader Hides BlankGrabber Malware Chain BlankGrabber’s operators are now abusing a fake “certificate” loader to hide a multi‑stage Rust and Python infection chain, making this commodity stealer significantly harder… Go to gbhackers.com
-
Open VSX Scanner Vulnerability Lets Malicious Extensions Go Live
Open VSX Scanner Vulnerability Lets Malicious Extensions Go Live Open VSX, the extension marketplace used by VS Code forks such as Cursor and Windsurf, recently fixed a critical vulnerability in its newly introduced… Go to gbhackers.com
-
European Commission Confirms Cyberattack After AWS Account Breach
European Commission Confirms Cyberattack After AWS Account Breach The European Commission has confirmed a cybersecurity incident affecting its cloud-based infrastructure after attackers gained access to an Amazon Web Services (AWS) account hosting… Go to gbhackers.com
-
BIND 9 Security Flaws Allow Attackers to Bypass Security Controls and Crash Servers
BIND 9 Security Flaws Allow Attackers to Bypass Security Controls and Crash Servers The Internet Systems Consortium (ISC) has released critical security advisories addressing three new vulnerabilities in the widely used BIND 9 Domain Name System (DNS)… Go to gbhackers.com
-
Backdoored Telnyx PyPI package pushes malware hidden in WAV audio
Backdoored Telnyx PyPI package pushes malware hidden in WAV audio TeamPCP hackers compromised the Telnyx package on the Python Package Index today, uploading malicious versions that deliver credential-stealing malware hidden inside a WAV file. […] Bill Toulas Go to bleepingcomputer
-
Fake VS Code alerts on GitHub spread malware to developers
Fake VS Code alerts on GitHub spread malware to developers A large-scale campaign is targeting developers on GitHub with fake Visual Studio Code (VS Code) security alerts posted in the Discussions section of various projects, to trick users into downloading malware. […] Bill Toulas Go to bleepingcomputer
-
Agentic GRC: Teams Get the Tech. The Mindset Shift Is What’s Missing.
Agentic GRC: Teams Get the Tech. The Mindset Shift Is What’s Missing. Agentic GRC automates workflows, forcing teams to rethink their role beyond operations. Anecdotes explains why the biggest challenge is shifting from execution to risk leadership. […] Sponsored by Anecdotes Go to bleepingcomputer
-
European Commission investigating breach after Amazon cloud account hack
European Commission investigating breach after Amazon cloud account hack The European Commission, the European Union’s main executive body, is investigating a security breach after a threat actor gained access to the Commission’s Amazon cloud environment. […] Sergiu Gatlan Go to bleepingcomputer
-
Anti-piracy coalition takes down AnimePlay app with 5 million users
Anti-piracy coalition takes down AnimePlay app with 5 million users The Alliance for Creativity and Entertainment (ACE) announced the shutdown of AnimePlay, a major anime streaming platform with over 5 million users. […] Sergiu Gatlan Go to bleepingcomputer
-
European Commission Confirms Cyberattack Following AWS Account Hack
European Commission Confirms Cyberattack Following AWS Account Hack The European Commission has officially confirmed a cyberattack following a targeted cyberattack that compromised its Amazon Web Services (AWS) account. Discovered on March 24, the intrusion specifically affected the external cloud environment that hosts the Commission’s public web presence on the Europa.eu platform. Despite the severity of…
-
Windows 11 and Server 2025 Update to Block Untrusted Cross-Signed Kernel Drivers by Default
Windows 11 and Server 2025 Update to Block Untrusted Cross-Signed Kernel Drivers by Default Microsoft is taking a major step to harden the Windows operating system against kernel-level threats by removing trust for drivers signed by the deprecated cross-signed root program. Starting with the April 2026 update, Windows 11 and Windows Server 2025 will block…
-
CISA Adds Aquasecurity Trivy Scanner Vulnerability to KEV Catalog
CISA Adds Aquasecurity Trivy Scanner Vulnerability to KEV Catalog CISA has officially added a critical vulnerability affecting Aquasecurity’s Trivy scanner to its Known Exploited Vulnerabilities (KEV) catalog. Tracked as CVE-2026-33634, this alarming security flaw poses a severe risk to software development pipelines. By exploiting this vulnerability, threat actors can gain unauthorized access to highly sensitive…
-
FBI Chief Kash Patel’s Gmail Account was Hacked by Iranian Hackers
FBI Chief Kash Patel’s Gmail Account was Hacked by Iranian Hackers Iran-linked hackers have claimed responsibility for breaching FBI Director Kash Patel’s personal Gmail inbox, leaking photographs, documents, and email correspondence online. The hacker group Handala Hack Team announced the breach on their website, declaring that Patel “will now find his name among the list…
-
New Silver Fox Campaign Hits Japanese Businesses With Tax-Themed Phishing Lures
New Silver Fox Campaign Hits Japanese Businesses With Tax-Themed Phishing Lures Japan’s tax season has become a hunting ground for a well-organized threat actor known as Silver Fox. As Japanese companies enter their annual cycle of tax filing, salary reviews, and personnel changes, this group is taking full advantage of the moment — sending highly…
-
RSAC 2026 wrap-up – Week in security with Tony Anscombe
RSAC 2026 wrap-up – Week in security with Tony Anscombe This year, AI agents took the center stage – as a defensive capability, but more pressingly as a risk many organizations haven’t caught up with Go to eset
-
A cunning predator: How Silver Fox preys on Japanese firms this tax season
A cunning predator: How Silver Fox preys on Japanese firms this tax season Silver Fox is back in Japan, spoofing tax and HR emails timed to the one season when no one thinks twice about opening them Go to eset
-
Apple Sends Lock Screen Alerts to Outdated iPhones Over Active Web-Based Exploits
Apple Sends Lock Screen Alerts to Outdated iPhones Over Active Web-Based Exploits Apple is now sending Lock Screen notifications to iPhones and iPads running older versions of iOS and iPadOS to alert users of web-based attacks and urge them to install the update. The development was first reported by MacRumors. “Apple is aware of attacks…
-
TeamPCP Pushes Malicious Telnyx Versions to PyPI, Hides Stealer in WAV Files
TeamPCP Pushes Malicious Telnyx Versions to PyPI, Hides Stealer in WAV Files TeamPCP, the threat actor behind the supply chain attack targeting Trivy, KICS, and litellm, has now compromised the telnyx Python package by pushing two malicious versions to steal sensitive data. The two versions, 4.87.1 and 4.87.2, published to the Python Package Index (PyPI)…
-
Open VSX Bug Let Malicious VS Code Extensions Bypass Pre-Publish Security Checks
Open VSX Bug Let Malicious VS Code Extensions Bypass Pre-Publish Security Checks Cybersecurity researchers have disclosed details of a now-patched bug impacting Open VSX’s pre-publish scanning pipeline to cause the tool to allow a malicious Microsoft Visual Studio Code (VS Code) extension to pass the vetting process and go live in the registry. “The pipeline…
-
AitM Phishing Targets TikTok Business Accounts Using Cloudflare Turnstile Evasion
AitM Phishing Targets TikTok Business Accounts Using Cloudflare Turnstile Evasion Threat actors are using adversary-in-the-middle (AitM) phishing pages to seize control of TikTok for Business accounts in a new campaign, according to a report from Push Security. Business accounts associated with social media platforms are a lucrative target, as they can be weaponized by bad…
-
We Are At War
We Are At War Rising geopolitical tensions are reflected (or in some cases preceded) by cyber operations, while technology itself has become politicized. Let’s admit it: we are in the middle of it. Introduction: One tech power to rule them all is a thing of the past The relative safety, peace and prosperity that much…
-
Friday Squid Blogging: Bioluminescent Bacteria in Squid
Friday Squid Blogging: Bioluminescent Bacteria in Squid The Hawaiian bobtail squid has bioluminescent bacteria. Bruce Schneier Go to bruce schneier
-
TeamPCP Supply Chain Campaign: Update 002 – Telnyx PyPI Compromise, Vect Ransomware Mass Affiliate Program, and First Named Victim Claim, (Fri, Mar 27th)
TeamPCP Supply Chain Campaign: Update 002 – Telnyx PyPI Compromise, Vect Ransomware Mass Affiliate Program, and First Named Victim Claim, (Fri, Mar 27th) This is the second update to the TeamPCP supply chain campaign threat intelligence report, “When the Security Scanner Became the Weapon” (v3.0, March 25, 2026). Update 001 covered developments through March 26. This update…
-
World Leaks data extortion: What you need to know
World Leaks data extortion: What you need to know World Leaks is a cyber extortion operation that steals sensitive data from organizations and threatens to leak it via the dark web if a ransom is not paid. Read more in my article on the Fortra blog. Graham Cluley Go to grahamcluley
-
China Upgrades the Backdoor It Uses to Spy on Telcos Globally
China Upgrades the Backdoor It Uses to Spy on Telcos Globally Chinese APT Red Menshen’s super-advanced BPFdoor malware defeats traditional cybersecurity protections. All telcos can do, really, is try hunting it down. Nate Nelson Go to gbhackers.com
-
Wartime Usage of Compromised IP Cameras Highlight Their Danger
Wartime Usage of Compromised IP Cameras Highlight Their Danger The list of countries exploiting internet-connected cameras to give them eye’s inside their adversaries’ borders continues to expand, with Russia, Iran, Israel, Ukraine, and the United States all using the tactic. What should companies look out for? Robert Lemos Go to gbhackers.com
-
Infrastructure Attacks With Physical Consequences Down 25%
Infrastructure Attacks With Physical Consequences Down 25% Operational technology (OT) at industrial and critical infrastructure sites seem to have been benefitting from a lull in ransomware, and hackers’ relative ignorance of OT systems. Nate Nelson Go to gbhackers.com
-
Google Sets 2029 Deadline for Quantum-Safe Cryptography
Google Sets 2029 Deadline for Quantum-Safe Cryptography The post-quantum future may be coming sooner than you think, as Google plans to have PQC migration in place by 2029. Alexander Culafi Go to gbhackers.com
-
CISA Adds Critical Aquasecurity Trivy Scanner Vulnerability to KEV Catalog
CISA Adds Critical Aquasecurity Trivy Scanner Vulnerability to KEV Catalog The Cybersecurity and Infrastructure Security Agency (CISA) has urgently added a critical flaw affecting Aquasecurity’s Trivy scanner to its Known Exploited Vulnerabilities (KEV) catalog…. Go to gbhackers.com
-
Silver Fox Cyberattack Targets Japanese Businesses with Tax-Themed Phishing Scams
Silver Fox Cyberattack Targets Japanese Businesses with Tax-Themed Phishing Scams A threat actor known as Silver Fox is targeting Japanese organizations with a new wave of spearphishing attacks timed to coincide with the country’s… Go to gbhackers.com
-
TeamPCP Hackers Focus on AI Developers, Planting Malicious Code to Disrupt Projects
TeamPCP Hackers Focus on AI Developers, Planting Malicious Code to Disrupt Projects The FBI Cyber Division has issued a critical alert following a massive supply chain attack orchestrated by the threat actor group TeamPCP. The hackers… Go to gbhackers.com
-
Hackers Target South Asian Financial Firm with BRUSHWORM and BRUSHLOGGER Attacks
Hackers Target South Asian Financial Firm with BRUSHWORM and BRUSHLOGGER Attacks A South Asian financial institution has been hit by a custom malware toolkit combining a modular backdoor, dubbed BRUSHWORM, and a DLL side‑loaded keylogger known… Go to gbhackers.com
-
Red Hat Warns of Malware Embedded in Popular Linux Tool, Opening Doors for Unauthorized…
Red Hat Warns of Malware Embedded in Popular Linux Tool, Opening Doors for Unauthorized… Red Hat has issued an urgent security alert regarding a highly sophisticated supply chain attack targeting the popular xz compression utility. Cybersecurity researchers discovered malicious code embedded… Go to gbhackers.com
-
Windows 11 KB5079391 update rolls out Smart App Control improvements
Windows 11 KB5079391 update rolls out Smart App Control improvements Microsoft has released the KB5079391 preview cumulative update for Windows 11 24H2 and 25H2, which includes 29 changes, such as Smart App Control and Display improvements. […] Sergiu Gatlan Go to bleepingcomputer
-
Dutch Police discloses security breach after phishing attack
Dutch Police discloses security breach after phishing attack The Dutch National Police (Politie) says a security breach resulting from a successful phishing attack has had a limited impact and hasn’t affected citizens’ data. […] Sergiu Gatlan Go to bleepingcomputer
-
Ajax football club hack exposed fan data, enabled ticket hijack
Ajax football club hack exposed fan data, enabled ticket hijack Dutch professional football club Ajax Amsterdam (AFC Ajax) disclosed that a hacker exploited vulnerabilities in its IT systems and accessed data belonging to a few hundred people. […] Bill Toulas Go to bleepingcomputer
-
CISA: New Langflow flaw actively exploited to hijack AI workflows
CISA: New Langflow flaw actively exploited to hijack AI workflows The Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are actively exploiting a critical vulnerability identified as CVE-2026-33017, which affects the Langflow framework for building AI agents. […] Bill Toulas Go to bleepingcomputer
-
UK sanctions Xinbi marketplace linked to Asian scam centers
UK sanctions Xinbi marketplace linked to Asian scam centers The United Kingdom’s Foreign, Commonwealth and Development Office (FCDO) has sanctioned Xinbi, a Chinese-language cryptocurrency-based online marketplace that sells stolen data and satellite internet equipment to scam networks in Southeast Asia. […] Sergiu Gatlan Go to bleepingcomputer
-
Critical Citrix NetScaler and Gateway Vulnerabilities Let Remote Attackers Leak Sensitive Information
Critical Citrix NetScaler and Gateway Vulnerabilities Let Remote Attackers Leak Sensitive Information Cloud Software Group has issued a critical security bulletin detailing two newly discovered vulnerabilities affecting customer-managed NetScaler ADC and NetScaler Gateway appliances. These flaws, tracked as CVE-2026-3055 and CVE-2026-4368, could allow remote attackers to leak sensitive information or cause user session mixups. Network…
-
Fake Cloudflare CAPTCHA Pages Spread Infiniti Stealer Malware on macOS Systems
Fake Cloudflare CAPTCHA Pages Spread Infiniti Stealer Malware on macOS Systems A new macOS malware that was undocumented previously, is quietly tricking users through fake Cloudflare human verification pages. Called Infiniti Stealer, this threat uses a well-known social engineering trick called ClickFix to convince Mac users into running dangerous commands directly on their own machines,…
-
New Windows Error Reporting Vulnerability Lets Attackers Escalate to Gain SYSTEM Access
New Windows Error Reporting Vulnerability Lets Attackers Escalate to Gain SYSTEM Access A newly analyzed local privilege escalation vulnerability in the Windows Error Reporting (WER) service allows attackers to easily gain full SYSTEM access. The flaw, tracked as CVE-2026-20817, was considered so structurally dangerous that Microsoft completely removed the vulnerable feature rather than attempting a…
-
ISC Warns of High-Severity Kea DHCP Flaw That Can Crash Services Remotely
ISC Warns of High-Severity Kea DHCP Flaw That Can Crash Services Remotely The Internet Systems Consortium (ISC) has released a critical security advisory warning network administrators of a high-severity vulnerability affecting the Kea DHCP server. Tracked as CVE-2026-3608, this flaw allows unauthenticated remote attackers to trigger a stack overflow error. When successfully exploited, the vulnerability…
-
Anthropic’s Leaked Drafts Expose Powerful New AI Model “Claude Mythos”
Anthropic’s Leaked Drafts Expose Powerful New AI Model “Claude Mythos” Anthropic has inadvertently exposed highly sensitive internal documents, revealing the existence of a powerful, unreleased AI model dubbed “Claude Mythos.” The leak, which stems from an unsecured and publicly searchable data cache, has raised immediate alarms within the cybersecurity community, particularly due to internal assessments…
-
China-Linked Red Menshen Uses Stealthy BPFDoor Implants to Spy via Telecom Networks
China-Linked Red Menshen Uses Stealthy BPFDoor Implants to Spy via Telecom Networks A long-term and ongoing campaign attributed to a China-nexus threat actor has embedded itself in telecom networks to conduct espionage against government networks. The strategic positioning activity, which involves implanting and maintaining stealthy access mechanisms within critical environments, has been attributed to Red…
-
[Webinar] Stop Guessing. Learn to Validate Your Defenses Against Real Attacks
[Webinar] Stop Guessing. Learn to Validate Your Defenses Against Real Attacks Most teams have security tools in place. Alerts are firing, dashboards look clean, threat intel is flowing in. On the surface, everything feels under control. But one question usually stays unanswered: Would your defenses actually stop a real attack? That’s where things get shaky.…
-
Claude Extension Flaw Enabled Zero-Click XSS Prompt Injection via Any Website
Claude Extension Flaw Enabled Zero-Click XSS Prompt Injection via Any Website Cybersecurity researchers have disclosed a vulnerability in Anthropic’s Claude Google Chrome Extension that could have been exploited to trigger malicious prompts simply by visiting a web page. The flaw “allowed any website to silently inject prompts into that assistant as if the user wrote…
-
Masters of Imitation: How Hackers and Art Forgers Perfect the Art of Deception
Masters of Imitation: How Hackers and Art Forgers Perfect the Art of Deception Unmasking impostors is something the art world has faced for decades, and there are valuable lessons from the works of Elmyr de Hory that can apply to the world of defensive cybersecurity. During the 1960s, de Hory gained infamy as a premier…
-
ThreatsDay Bulletin: PQC Push, AI Vuln Hunting, Pirated Traps, Phishing Kits & 20 More Stories
ThreatsDay Bulletin: PQC Push, AI Vuln Hunting, Pirated Traps, Phishing Kits & 20 More Stories Some weeks in security feel loud. This one feels sneaky. Less big dramatic fireworks, more of that slow creeping sense that too many people are getting way too comfortable abusing things they probably shouldn’t even be touching. There’s a little…
-
As the US Midterms Approach, AI Is Going to Emerge as a Key Issue Concerning Voters
As the US Midterms Approach, AI Is Going to Emerge as a Key Issue Concerning Voters In December, the Trump administration signed an executive order that neutered states’ ability to regulate AI by ordering his administration to both sue and withhold funds from states that try to do so. This action pointedly supported industry lobbyists…
-
ISC Stormcast For Friday, March 27th, 2026 https://isc.sans.edu/podcastdetail/9868, (Fri, Mar 27th)
ISC Stormcast For Friday, March 27th, 2026 https://isc.sans.edu/podcastdetail/9868, (Fri, Mar 27th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
TeamPCP Supply Chain Campaign: Update 001 – Checkmarx Scope Wider Than Reported, CISA KEV Entry, and Detection Tools Available, (Thu, Mar 26th)
TeamPCP Supply Chain Campaign: Update 001 – Checkmarx Scope Wider Than Reported, CISA KEV Entry, and Detection Tools Available, (Thu, Mar 26th) This is the first update to the TeamPCP supply chain campaign threat intelligence report, “When the Security Scanner Became the Weapon” (v3.0, March 25, 2026). That report covers the full campaign from the February 28…
-
Smashing Security podcast #460: Never knock on the door of a nuclear submarine base and ask for a selfie
Smashing Security podcast #460: Never knock on the door of a nuclear submarine base and ask for a selfie A disgruntled data analyst decides that the best response to losing his contract is to steal the entire company payroll database and demand $2.5 million in Bitcoin – signing his extortion emails from a company called…
-
Is the FCC’s Router Ban the Wrong Fix?
Is the FCC’s Router Ban the Wrong Fix? The agency put foreign-made consumer routers on its list of prohibited communications devices, but the ban could create more problems down the road. Jai Vijayan Go to gbhackers.com
-
Critical Flaw in Langflow AI Platform Under Attack
Critical Flaw in Langflow AI Platform Under Attack Threats actors pounced on the code injection vulnerability within hours of its disclosure, demonstrating that organizations have little time to address critical bugs. Rob Wright Go to gbhackers.com
-
How Organizations Can Use Blunders to Level Up Their Security Programs
How Organizations Can Use Blunders to Level Up Their Security Programs The industry highlights how organizations repeatedly make common security mistakes but one session during RSAC detailed ways to avoid them. Arielle Waldman Go to gbhackers.com
-
AI-Powered Dependency Decisions Introduce, Ignore Security Bugs
AI-Powered Dependency Decisions Introduce, Ignore Security Bugs AI models often hallucinate or make costly mistakes when tasked with recommending software versions, upgrade paths, and security fixes — leading to significant technical debt. Rob Wright Go to gbhackers.com
-
Intermediaries Driving Global Spyware Market Expansion
Intermediaries Driving Global Spyware Market Expansion Third-party resellers and brokers foil transparency efforts and allow spyware to spread despite government restrictions, a study finds. Robert Lemos Go to gbhackers.com
-
Torg Grabber Malware Shifts from Telegram Exfiltration to Encrypted REST API for C2
Torg Grabber Malware Shifts from Telegram Exfiltration to Encrypted REST API for C2 A fast-evolving information‑stealing malware dubbed “Torg Grabber” that has shifted from simple Telegram‑based exfiltration to a hardened, encrypted REST API command‑and‑control (C2) channel fronted… Go to gbhackers.com
-
Fake Screenshot Lures Target Web3 Support Staff with Multi-Stage Malware Attack
Fake Screenshot Lures Target Web3 Support Staff with Multi-Stage Malware Attack Fake screenshot links are being used to quietly deploy a multi‑stage backdoor against Web3 customer support teams, in a campaign assessed to be linked… Go to gbhackers.com
-
IDrive for Windows Vulnerability Allows Attackers to Escalate Privileges and Gain Unauthorized Access
IDrive for Windows Vulnerability Allows Attackers to Escalate Privileges and Gain Unauthorized Access A critical security flaw has been identified in the IDrive Cloud Backup Client for Windows, exposing users to local privilege escalation attacks. Tracked as… Go to gbhackers.com
-
Kiss Loader Malware Targets with Early Bird APC Injection in New Attack Campaign
Kiss Loader Malware Targets with Early Bird APC Injection in New Attack Campaign A newly identified malware loader dubbed “Kiss Loader” is emerging as a potential threat, leveraging advanced process injection techniques and dynamic delivery infrastructure. The… Go to gbhackers.com
-
Preventing Account Takeovers: A Practical Guide to Detection and Response
Preventing Account Takeovers: A Practical Guide to Detection and Response Yesterday’s password leak can become tomorrow’s identity crisis. According to research firm Gitnux, account-takeover attacks jumped 354 percent in 2023, driven by bots that… Go to gbhackers.com
-
GitHub adds AI-powered bug detection to expand security coverage
GitHub adds AI-powered bug detection to expand security coverage GitHub is adopting AI-based scanning for its Code Security tool to expand vulnerability detections beyond the CodeQL static analysis and cover more languages and frameworks. […] Bill Toulas Go to bleepingcomputer
-
PolyShell attacks target 56% of all vulnerable Magento stores
PolyShell attacks target 56% of all vulnerable Magento stores Attacks leveraging the ‘PolyShell’ vulnerability in version 2 of Magento Open Source and Adobe Commerce installations are underway, targeting more than half of all vulnerable stores. […] Bill Toulas Go to bleepingcomputer
-
Bubble AI app builder abused to steal Microsoft account credentials
Bubble AI app builder abused to steal Microsoft account credentials Threat actors are evading phishing detection in campaigns targeting Microsoft accounts by abusing the no-code app-building platform Bubble to generate and host malicious web apps. […] Bill Toulas Go to bleepingcomputer
-
New Torg Grabber infostealer malware targets 728 crypto wallets
New Torg Grabber infostealer malware targets 728 crypto wallets A new info-stealing malware called Torg Grabber is stealing sensitive data from 850 browser extensions, more than 700 of them for cryptocurrency wallets. […] Bill Toulas Go to bleepingcomputer
-
Citrix urges admins to patch NetScaler flaws as soon as possible
Citrix urges admins to patch NetScaler flaws as soon as possible Citrix has patched two NetScaler ADC and NetScaler Gateway vulnerabilities, one of which is very similar to the CitrixBleed and CitrixBleed2 flaws exploited in zero-day attacks in recent years. […] Sergiu Gatlan Go to bleepingcomputer
-
Fake npm Install Messages Hide RAT Malware in New Open Source Supply Chain Campaign
Fake npm Install Messages Hide RAT Malware in New Open Source Supply Chain Campaign A new and carefully crafted software supply chain campaign is targeting developers through the npm package registry, using fake installation messages to hide malicious activity. The campaign, which security researchers have named the “Ghost campaign,” began in early February 2026 and…
-
Fake VS Code Security Alerts on GitHub Used to Push Malware in Widespread Phishing Campaign
Fake VS Code Security Alerts on GitHub Used to Push Malware in Widespread Phishing Campaign A large-scale phishing campaign is targeting software developers on GitHub, using fake Visual Studio Code security alerts posted in GitHub Discussions to trick users into downloading malicious software. The attacks are designed to look like legitimate security advisories, warning developers…
-
Ghost SPN Attack Lets Hackers Conduct Stealthy Kerberoasting Under the Radar
Ghost SPN Attack Lets Hackers Conduct Stealthy Kerberoasting Under the Radar A sophisticated evolution of Kerberoasting dubbed the “Ghost SPN” attack that allows adversaries to extract Active Directory credentials while erasing all traces of their activity, rendering traditional detection models effectively blind to the intrusion. The attack revealed by Trellix security researchers utilizes delegated administrative…
-
China-Linked Hackers Breach Southeast Asian Military Systems in Long-Running Spy Campaign
China-Linked Hackers Breach Southeast Asian Military Systems in Long-Running Spy Campaign A sophisticated and long-running cyber espionage campaign, tracked as CL-STA-1087, has been quietly targeting military organizations across Southeast Asia since at least 2020. The operation, assessed with moderate confidence to be linked to a China-aligned threat actor, focuses on collecting strategic and operational intelligence rather…
-
Open Directory Malware Campaign Uses Obfuscated VBS, PNG Loaders and RAT Payloads
Open Directory Malware Campaign Uses Obfuscated VBS, PNG Loaders and RAT Payloads A sophisticated multi-stage malware campaign has surfaced, deploying obfuscated Visual Basic Script (VBS) files, PNG-embedded loaders, and remote access trojans (RATs) to target systems without leaving a trace on disk. What began as a routine endpoint detection in early 2026 quickly revealed itself…
-
Virtual machines, virtually everywhere – and with real security gaps
Virtual machines, virtually everywhere – and with real security gaps Cloud VMs offer unmatched speed, scale and flexibility – all of which could eventually count for little if they’re left to fend for themselves Go to eset
-
LeakBase Admin Arrested in Russia Over Massive Stolen Credential Marketplace
LeakBase Admin Arrested in Russia Over Massive Stolen Credential Marketplace The alleged administrator of the LeakBase cybercrime forum has been arrested by Russian law enforcement authorities, state media reported Thursday. According to TASS and MVD Media, a news website linked to the Russian Interior Ministry, the suspect is a resident of the city of Taganrog.…
-
GlassWorm Malware Uses Solana Dead Drops to Deliver RAT and Steal Browser, Crypto Data
GlassWorm Malware Uses Solana Dead Drops to Deliver RAT and Steal Browser, Crypto Data Cybersecurity researchers have flagged a new evolution of the GlassWorm campaign that delivers a multi-stage framework capable of comprehensive data theft and installing a remote access trojan (RAT), which deploys an information-stealing Google Chrome extension masquerading as an offline version of…
-
The Kill Chain Is Obsolete When Your AI Agent Is the Threat
The Kill Chain Is Obsolete When Your AI Agent Is the Threat In September 2025, Anthropic disclosed that a state-sponsored threat actor used an AI coding agent to execute an autonomous cyber espionage campaign against 30 global targets. The AI handled 80-90% of tactical operations on its own, performing reconnaissance, writing exploit code, and attempting…
-
Russian Hacker Sentenced to 2 Years for TA551 Botnet-Driven Ransomware Attacks
Russian Hacker Sentenced to 2 Years for TA551 Botnet-Driven Ransomware Attacks The U.S. Department of Justice (DoJ) said a Russian national has been sentenced to two years in prison for managing a botnet that was used to launch ransomware attacks against U.S. companies. Ilya Angelov, 40, of Tolyatti, Russia, was also fined $100,000. Angelov, who…
-
Device Code Phishing Hits 340+ Microsoft 365 Orgs Across Five Countries via OAuth Abuse
Device Code Phishing Hits 340+ Microsoft 365 Orgs Across Five Countries via OAuth Abuse Cybersecurity researchers are calling attention to an active device code phishing campaign that’s targeting Microsoft 365 identities across more than 340 organizations in the U.S., Canada, Australia, New Zealand, and Germany. The activity, per Huntress, was first spotted on February 19,…
-
Sen. Wyden Warns of Another Section 702 Abuse
Sen. Wyden Warns of Another Section 702 Abuse Sen. Ron Wyden is warning us of an abuse of Section 702: Wyden took to the Senate floor to deliver a lengthy speech, ostensibly about the since approved (with support of many Democrats) nomination of Joshua Rudd to lead the NSA. Wyden was protesting that nomination, but…
-
ISC Stormcast For Thursday, March 26th, 2026 https://isc.sans.edu/podcastdetail/9866, (Thu, Mar 26th)
ISC Stormcast For Thursday, March 26th, 2026 https://isc.sans.edu/podcastdetail/9866, (Thu, Mar 26th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Apple Patches (almost) everything again. March 2026 edition., (Wed, Mar 25th)
Apple Patches (almost) everything again. March 2026 edition., (Wed, Mar 25th) Apple released the next version of its operating system, patching 85 different vulnerabilities across all of them. None of the vulnerabilities are currently being exploited. The last three macOS “generations” are covered, as are the last two versions of iOS/iPadOS. For tvOS, watchOS, and visionOS,…
-
How one man used 10,000 bots to steal $8,000,000 from music artists
How one man used 10,000 bots to steal $8,000,000 from music artists A man has pleaded guilty to defrauding online music streaming platforms out of more than US $8 million, after creating hundreds of thousands of songs with AI, and then using bots to play them billions of times. Read more in my article on…