no alarms and no surprises please..
-
Chrome Security Update Fixes 26 Vulnerabilities Allowing Remote Code Execution
Chrome Security Update Fixes 26 Vulnerabilities Allowing Remote Code Execution Google has released a substantial security update for its Chrome web browser, addressing 26 distinct vulnerabilities that could allow unauthenticated attackers to execute malicious code remotely. The latest Stable channel update rolls out versions 146.0.7680.153 and 146.0.7680.154 for Windows and macOS, while Linux users will…
-
Oracle Issues Urgent Security Update for Critical RCE Flaw in Identity Manager and Web Services Manager
Oracle Issues Urgent Security Update for Critical RCE Flaw in Identity Manager and Web Services Manager Oracle has issued an out-of-band Security Alert addressing a critical remote code execution (RCE) vulnerability, CVE-2026-21992, affecting two widely deployed Fusion Middleware components, Oracle Identity Manager and Oracle Web Services Manager. The vulnerability carries a CVSS 3.1 base score…
-
Anthropic Launches Projects Feature for Claude Cowork Desktop
Anthropic Launches Projects Feature for Claude Cowork Desktop Anthropic is expanding Claude Cowork Desktop with a new Projects feature designed to keep files, instructions, and task context organized inside a single workspace. For paid users, the update makes it easier to start from scratch, import an existing chat, or connect a local folder so Claude…
-
Windows 11 March Update Breaks Microsoft Teams and OneDrive Sign-Ins
Windows 11 March Update Breaks Microsoft Teams and OneDrive Sign-Ins Microsoft has acknowledged a significant bug introduced by its March 2026 cumulative update that is preventing users from signing into Microsoft Teams Free, OneDrive, and several other Microsoft applications on Windows 11 devices. The issue, tied to the KB5079473 update released on March 10, 2026,…
-
Move fast and save things: A quick guide to recovering a hacked account
Move fast and save things: A quick guide to recovering a hacked account What you do – and how fast – after an account is compromised often matters more than it may seem Go to eset
-
Trivy Security Scanner GitHub Actions Breached, 75 Tags Hijacked to Steal CI/CD Secrets
Trivy Security Scanner GitHub Actions Breached, 75 Tags Hijacked to Steal CI/CD Secrets Trivy, a popular open-source vulnerability scanner maintained by Aqua Security, was compromised a second time within the span of a month to deliver malware that stole sensitive CI/CD secrets. The latest incident impacted GitHub Actions “aquasecurity/trivy-action” and “aquasecurity/setup-trivy,” which are used to…
-
Critical Langflow Flaw CVE-2026-33017 Triggers Attacks within 20 Hours of Disclosure
Critical Langflow Flaw CVE-2026-33017 Triggers Attacks within 20 Hours of Disclosure A critical security flaw impacting Langflow has come under active exploitation within 20 hours of public disclosure, highlighting the speed at which threat actors weaponize newly published vulnerabilities. The security defect, tracked as CVE-2026-33017 (CVSS score: 9.3), is a case of missing authentication combined…
-
Google Adds 24-Hour Wait for Unverified App Sideloading to Reduce Malware and Scams
Google Adds 24-Hour Wait for Unverified App Sideloading to Reduce Malware and Scams Google on Thursday announced a new “advanced flow” for Android sideloading that requires a mandatory 24-hour wait period to install apps from unverified developers in an attempt to balance openness with safety. The new changes come against the backdrop of a developer…
-
The Importance of Behavioral Analytics in AI-Enabled Cyber Attacks
The Importance of Behavioral Analytics in AI-Enabled Cyber Attacks Artificial Intelligence (AI) is changing how individuals and organizations conduct many activities, including how cybercriminals carry out phishing attacks and iterate on malware. Now, cybercriminals are using AI to generate personalized phishing emails, deepfakes and malware that evade traditional detection by impersonating normal user activity and…
-
Magento PolyShell Flaw Enables Unauthenticated Uploads, RCE and Account Takeover
Magento PolyShell Flaw Enables Unauthenticated Uploads, RCE and Account Takeover Sansec is warning of a critical security flaw in Magento’s REST API that could allow unauthenticated attackers to upload arbitrary executables and achieve code execution and account takeover. The vulnerability has been codenamed PolyShell by Sansec owing to the fact that the attack hinges on…
-
Friday Squid Blogging: Jumbo Flying Squid in the South Pacific
Friday Squid Blogging: Jumbo Flying Squid in the South Pacific The population needs better conservation. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy. Bruce Schneier Go to bruce schneier
-
Proton Mail Shared User Information with the Police
Proton Mail Shared User Information with the Police 404 Media has a story about Proton Mail giving subscriber data to the Swiss government, who passed the information to the FBI. It’s metadata—payment information related to a particular account—but still important knowledge. This sort of thing happens, even to privacy-centric companies like Proton Mail. Bruce Schneier…
-
Denver’s crosswalks hacked to broadcast anti-Trump messages
Denver’s crosswalks hacked to broadcast anti-Trump messages Pedestrians crossing a street in Denver, Colorado, got rather more than they bargained for last weekend, when the audio signals at two crosswalks began broadcasting a political message alongside their usual walking instructions. Read more in my article on the Hot for Security blog. Graham Cluley Go to…
-
LeakNet ransomware: what you need to know
LeakNet ransomware: what you need to know A ransomware gang that claims to be a group of “investigative journalists”? Meet LeakNet – the group using fake CAPTCHA pages to trick employees into hacking themselves. Read more in my article on the Fortra blog. Graham Cluley Go to grahamcluley
-
Patch Now: Oracle’s Fusion Middleware Has Critical RCE Flaw
Patch Now: Oracle’s Fusion Middleware Has Critical RCE Flaw Attackers can execute arbitrary code without authentication if Oracle’s Identity or Web Services Managers are exposed to the Web. Nate Nelson Go to gbhackers.com
-
Cyber OpSec Fail: Beast Gang Exposes Ransomware Server
Cyber OpSec Fail: Beast Gang Exposes Ransomware Server Files on a central cloud server used by the ransomware group highlight a systematic, aggressive attack on network backups as a key TTP. Robert Lemos Go to gbhackers.com
-
Interlock Ransomware Targets Cisco Enterprise Firewalls
Interlock Ransomware Targets Cisco Enterprise Firewalls The ransomware gang, known for double-extortion attacks, had access to a critical Cisco firewall vulnerability weeks before it was publicly disclosed. Alexander Culafi Go to gbhackers.com
-
CISA Warns Cisco Secure Firewall Management Center 0-Day Is Being Exploited in Ransomware Attacks
CISA Warns Cisco Secure Firewall Management Center 0-Day Is Being Exploited in Ransomware Attacks The Cybersecurity and Infrastructure Security Agency has issued an urgent warning regarding a critical zero-day vulnerability affecting heavily relied-upon Cisco security products. Tracked officially… Go to gbhackers.com
-
Bamboo Data Center and Server Vulnerability Enables Remote Code Execution
Bamboo Data Center and Server Vulnerability Enables Remote Code Execution Atlassian has officially resolved a high-severity Remote Code Execution (RCE) vulnerability within its Bamboo Data Centre application. Officially tracked as CVE-2026-21570, this critical security… Go to gbhackers.com
-
New Critical Jenkins Vulnerabilities Put CI/CD Servers at Risk of RCE Exploits
New Critical Jenkins Vulnerabilities Put CI/CD Servers at Risk of RCE Exploits The Jenkins project released a critical security advisory addressing multiple vulnerabilities in its core automation server and the LoadNinja plugin. These flaws expose continuous… Go to gbhackers.com
-
Navia Confirms Data Breach Exposing Sensitive Information of 2.7 Million Users
Navia Confirms Data Breach Exposing Sensitive Information of 2.7 Million Users Navia Benefit Solutions has confirmed a significant data breach impacting nearly 2.7 million individuals. The incident resulted from unauthorised access to the company’s systems,… Go to gbhackers.com
-
Microsoft Introduces Teams Upgrades to Improve Windows App Performance on ioS and Android
Microsoft Introduces Teams Upgrades to Improve Windows App Performance on ioS and Android Microsoft has officially announced the general availability of new Microsoft Teams optimizations designed specifically for the Windows App on both iOS and Android operating… Go to gbhackers.com
-
Musician admits to $10M streaming royalty fraud using AI bots
Musician admits to $10M streaming royalty fraud using AI bots North Carolina musician Michael Smith has pleaded guilty to collecting over $10 million in royalty payments through a massive streaming royalty fraud scheme on Spotify, Apple Music, Amazon Music, and YouTube Music. […] Sergiu Gatlan Go to bleepingcomputer
-
International joint action disrupts world’s largest DDoS botnets
International joint action disrupts world’s largest DDoS botnets Authorities from the United States, Germany, and Canada have taken down Command and Control (C2) infrastructure used by the Aisuru, KimWolf, JackSkid, and Mossad botnets to infect Internet of Things (IoT) devices. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft: March Windows updates break Teams, OneDrive sign-ins
Microsoft: March Windows updates break Teams, OneDrive sign-ins Microsoft says the March Windows 11 update breaks sign-ins with Microsoft accounts across multiple Microsoft apps, including Teams and OneDrive. […] Sergiu Gatlan Go to bleepingcomputer
-
Ex-data analyst stole company data in $2.5M extortion scheme
Ex-data analyst stole company data in $2.5M extortion scheme A North Carolina man was found guilty of extorting a D.C.-based technology company while still being employed as a data analyst contractor. […] Sergiu Gatlan Go to bleepingcomputer
-
Navia discloses data breach impacting 2.7 million people
Navia discloses data breach impacting 2.7 million people Navia Benefit Solutions, Inc. (Navia) is informing nearly 2.7 million individuals of a data breach that exposed their sensitive information to attackers. […] Bill Toulas Go to bleepingcomputer
-
Apex – AI-Powered Pentester Attacks Apps in Black-Box Mode to Find Vulnerabilities
Apex – AI-Powered Pentester Attacks Apps in Black-Box Mode to Find Vulnerabilities Apex is an autonomous, AI-powered penetration testing agent designed to operate in black-box mode against live applications. It does not require access to source code, hints, or predefined attack paths. This enables it to discover, chain, and verify real-world vulnerabilities at the speed…
-
SILENTCONNECT Uses VBScript, PowerShell and PEB Masquerading to Deploy ScreenConnect
SILENTCONNECT Uses VBScript, PowerShell and PEB Masquerading to Deploy ScreenConnect SILENTCONNECT is a newly discovered multi-stage malware loader that has been silently targeting Windows machines since at least March 2025. It uses VBScript, in-memory PowerShell execution, and PEB masquerading to install the ConnectWise ScreenConnect remote monitoring and management tool on victim systems. Once deployed, ScreenConnect…
-
Russian APT Exploits Zimbra XSS to Target Ukrainian Government in ‘Operation GhostMail’
Russian APT Exploits Zimbra XSS to Target Ukrainian Government in ‘Operation GhostMail’ A Russian state-linked threat actor has launched a targeted cyberattack against a Ukrainian government agency, exploiting a cross-site scripting (XSS) vulnerability in Zimbra Collaboration Suite to steal credentials and sensitive email data. Dubbed “Operation GhostMail,” the campaign stands out for its complete absence…
-
Authorities Disrupt IoT Botnet Infrastructure Behind Record-Breaking 30 Tbps DDoS Attacks
Authorities Disrupt IoT Botnet Infrastructure Behind Record-Breaking 30 Tbps DDoS Attacks Authorities have successfully dismantled the command-and-control (C2) infrastructure powering four massive Internet of Things (IoT) botnets. The U.S. Justice Department, collaborating closely with Canadian and German agencies, targeted the administrators and architecture behind the Aisuru, KimWolf, JackSkid, and Mossad botnets. Together, these malicious networks…
-
CISA Warns of Zimbra Collaboration Suite Vulnerability Exploited in Attacks
CISA Warns of Zimbra Collaboration Suite Vulnerability Exploited in Attacks CISA has added a high-severity vulnerability affecting the Zimbra Collaboration Suite (ZCS) to its Known Exploited Vulnerabilities (KEV) catalog. Tracked as CVE-2025-66376, this security flaw is currently facing active exploitation in the wild. Organizations utilizing Zimbra must urgently prioritize remediation to prevent unauthorized access and…
-
EDR killers explained: Beyond the drivers
EDR killers explained: Beyond the drivers ESET researchers dive deeper into the EDR killer ecosystem, disclosing how attackers abuse vulnerable drivers Go to eset
-
DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks
DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks The U.S. Department of Justice (DoJ) on Thursday announced the disruption of command-and-control (C2) infrastructure used by several Internet of Things (IoT) botnets like AISURU, Kimwolf, JackSkid, and Mossad as part of a court-authorized law enforcement operation. The effort also saw authorities…
-
Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks
Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks Apple is urging users who are still running an outdated version of iOS to update their iPhones to secure against web-based attacks carried out via powerful exploit kits like Coruna and DarkSword. These attacks employ malicious web content to target out-of-date versions of iOS,…
-
Speagle Malware Hijacks Cobra DocGuard to Steal Data via Compromised Servers
Speagle Malware Hijacks Cobra DocGuard to Steal Data via Compromised Servers Cybersecurity researchers have flagged a new malware dubbed Speagle that hijacks the functionality and infrastructure of a legitimate program called Cobra DocGuard. “Speagle is designed to surreptitiously harvest sensitive information from infected computers and transmit it to a Cobra DocGuard server that has been…
-
54 EDR Killers Use BYOVD to Exploit 35 Signed Vulnerable Drivers and Disable Security
54 EDR Killers Use BYOVD to Exploit 35 Signed Vulnerable Drivers and Disable Security A new analysis of endpoint detection and response (EDR) killers has revealed that 54 of them leverage a technique known as bring your own vulnerable driver (BYOVD) by abusing a total of 35 vulnerable drivers. EDR killer programs have been a…
-
ThreatsDay Bulletin: FortiGate RaaS, Citrix Exploits, MCP Abuse, LiveChat Phish & More
ThreatsDay Bulletin: FortiGate RaaS, Citrix Exploits, MCP Abuse, LiveChat Phish & More ThreatsDay Bulletin is back on The Hacker News, and this week feels off in a familiar way. Nothing loud, nothing breaking everything at once. Just a lot of small things that shouldn’t work anymore but still do. Some of it looks simple, almost…
-
Android devices ship with firmware-level malware
Android devices ship with firmware-level malware Keenadu malware gives an attacker control over a device but appears to be used primarily to facilitate ad fraud Categories: Threat Research Tags: Android, Keenadu Go to sophos
-
Hacking a Robot Vacuum
Hacking a Robot Vacuum Someone tries to remote control his own DJI Romo vacuum, and ends up controlling 7,000 of them from all around the world. The IoT is horribly insecure, but we already knew that. Bruce Schneier Go to bruce schneier
-
ISC Stormcast For Friday, March 20th, 2026 https://isc.sans.edu/podcastdetail/9858, (Fri, Mar 20th)
ISC Stormcast For Friday, March 20th, 2026 https://isc.sans.edu/podcastdetail/9858, (Fri, Mar 20th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Feds Disrupt IoT Botnets Behind Huge DDoS Attacks
Feds Disrupt IoT Botnets Behind Huge DDoS Attacks The U.S. Justice Department joined authorities in Canada and Germany in dismantling the online infrastructure behind four highly disruptive botnets that compromised more than three million Internet of Things (IoT) devices, such as routers and web cameras. The feds say the four botnets — named Aisuru, Kimwolf,…
-
AI Conundrum: Why MCP Security Can’t Be Patched Away
AI Conundrum: Why MCP Security Can’t Be Patched Away MCP introduces security risks into LLM environments that are architectural and not easily fixable, researcher says at RSAC 2026 Conference. Jai Vijayan Go to gbhackers.com
-
Pyronut Package Backdoors Telegram Bots With RCE
Pyronut Package Backdoors Telegram Bots With RCE Malicious ‘Pyronut’ is a trojanized Python package that backdoors Telegram bots and userbots, giving attackers remote code execution over both the Telegram session and… Go to gbhackers.com
-
OpenWebUI Servers Targeted in Attacks Using AI Payloads to Steal Data
OpenWebUI Servers Targeted in Attacks Using AI Payloads to Steal Data A recent campaign has targeted improperly secured Open WebUI systems, allowing threat actors to deploy malicious artificial intelligence payloads. Open WebUI is a highly popular… Go to gbhackers.com
-
Horabot Returns in Mexico, Spreading via Phishing and Email Worm Attacks
Horabot Returns in Mexico, Spreading via Phishing and Email Worm Attacks Horabot has resurfaced in Mexico with a more complex, multi‑stage kill chain that blends fake CAPTCHA lures, living-off-the-land scripting, and an email worm‑style spreader… Go to gbhackers.com
-
CISA Adds Exploited Zimbra Collaboration Suite Flaw to Warning List
CISA Adds Exploited Zimbra Collaboration Suite Flaw to Warning List The Cybersecurity and Infrastructure Security Agency (CISA) has officially added a critical vulnerability affecting the Zimbra Collaboration Suite (ZCS) to its Known Exploited Vulnerabilities… Go to gbhackers.com
-
Open VSX Extension Delivers RAT and Stealer via GitHub Downloader
Open VSX Extension Delivers RAT and Stealer via GitHub Downloader An Open VSX extension used by thousands of developers has been caught silently pulling a full-featured remote access trojan and infostealer from GitHub. The… Go to gbhackers.com
-
Aura confirms data breach exposing 900,000 marketing contacts
Aura confirms data breach exposing 900,000 marketing contacts Identity protection company Aura has confirmed that an unauthorized party gained access to nearly 900,000 customer records containing names and email addresses. […] Bill Toulas Go to bleepingcomputer
-
CISA orders feds to patch Zimbra XSS flaw exploited in attacks
CISA orders feds to patch Zimbra XSS flaw exploited in attacks CISA has ordered U.S. government agencies to secure their servers against an actively exploited vulnerability in the Zimbra Collaboration Suite (ZCS). […] Sergiu Gatlan Go to bleepingcomputer
-
ConnectWise patches new flaw allowing ScreenConnect hijacking
ConnectWise patches new flaw allowing ScreenConnect hijacking ConnectWise is warning ScreenConnect customers of a cryptographic signature verification vulnerability that could lead to unauthorized access and privilege escalation. […] Bill Toulas Go to bleepingcomputer
-
Ransomware gang exploits Cisco flaw in zero-day attacks since January
Ransomware gang exploits Cisco flaw in zero-day attacks since January The Interlock ransomware gang has been exploiting a maximum severity remote code execution (RCE) vulnerability in Cisco’s Secure Firewall Management Center (FMC) software in zero-day attacks since late January. […] Sergiu Gatlan Go to bleepingcomputer
-
Marquis: Ransomware gang stole data of 672K people in cyberattack
Marquis: Ransomware gang stole data of 672K people in cyberattack Marquis, a Texas-based financial services provider, revealed this week that a ransomware gang stole the data of over 670,000 individuals in an August 2025 cyberattack that also disrupted operations at 74 banks across the United States. […] Sergiu Gatlan Go to bleepingcomputer
-
WaterPlum Deploys New ‘StoatWaffle’ Malware in VSCode-Based Supply Chain Campaign
WaterPlum Deploys New ‘StoatWaffle’ Malware in VSCode-Based Supply Chain Campaign A North Korea-linked hacking group known as WaterPlum has introduced a dangerous new malware called StoatWaffle, deploying it through compromised Visual Studio Code (VSCode) repositories disguised as legitimate blockchain development projects to silently infiltrate developer machines. WaterPlum has been running a campaign known as “Contagious…
-
CISA Warns of Microsoft SharePoint Vulnerability Exploited in Attacks
CISA Warns of Microsoft SharePoint Vulnerability Exploited in Attacks A critical security flaw in Microsoft SharePoint has been identified as actively exploited, and on March 18, 2026, the vulnerability was officially added to the Known Exploited Vulnerabilities (KEV) catalog. This addition confirms that threat actors are actively exploiting the flaw in real-world network attacks, prompting…
-
New SnappyClient Implant Combines Remote Access, Data Theft and Advanced Evasion
New SnappyClient Implant Combines Remote Access, Data Theft and Advanced Evasion A dangerous new malware implant called SnappyClient has quietly emerged as a serious threat to Windows users, combining remote access, data theft, and sophisticated evasion techniques in one compact C++ package. First spotted in December 2025, this command-and-control (C2) framework implant can log keystrokes,…
-
Cisco Firewall 0-day Vulnerability Exploited in the Wild to Deploy Interlock Ransomware
Cisco Firewall 0-day Vulnerability Exploited in the Wild to Deploy Interlock Ransomware An active campaign by the Interlock ransomware group is exploiting a critical zero-day vulnerability (CVE-2026-20131) in Cisco Secure Firewall Management Center (FMC) Software. The vulnerability may allow an unauthenticated remote attacker to execute arbitrary Java code with root privileges on an affected device.…
-
New iOS Exploit With Advanced iPhone Hacking Tools Attacking Users to Steal Personal Data
New iOS Exploit With Advanced iPhone Hacking Tools Attacking Users to Steal Personal Data A sophisticated full-chain iOS exploit kit dubbed DarkSword, actively deployed by multiple commercial surveillance vendors and state-sponsored threat actors since at least November 2025 to steal sensitive personal data from iPhone users across four countries. DarkSword is a full-chain iOS exploit that…
-
EU Sanctions Companies in China, Iran for Cyberattacks
EU Sanctions Companies in China, Iran for Cyberattacks Already sanctioned in the US and the UK, these rulings prohibit companies and a couple of principals from entering or doing business in the European Union. Nate Nelson Go to gbhackers.com
-
CISA Warns of Zimbra, SharePoint Flaw Exploits; Cisco Zero-Day Hit in Ransomware Attacks
CISA Warns of Zimbra, SharePoint Flaw Exploits; Cisco Zero-Day Hit in Ransomware Attacks The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has urged government agencies to apply patches for two security flaws impacting Synacor Zimbra Collaboration Suite (ZCS) and Microsoft Office SharePoint, stating they have been actively exploited in the wild. The vulnerabilities in question…
-
OFAC Sanctions DPRK IT Worker Network Funding WMD Programs Through Fake Remote Jobs
OFAC Sanctions DPRK IT Worker Network Funding WMD Programs Through Fake Remote Jobs The U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) has sanctioned six individuals and two entities for their involvement in the Democratic People’s Republic of Korea (DPRK) information technology (IT) worker scheme with an aim to defraud U.S. businesses…
-
Interlock Ransomware Exploits Cisco FMC Zero-Day CVE-2026-20131 for Root Access
Interlock Ransomware Exploits Cisco FMC Zero-Day CVE-2026-20131 for Root Access Amazon Threat Intelligence is warning of an active Interlock ransomware campaign that’s exploiting a recently disclosed critical security flaw in Cisco Secure Firewall Management Center (FMC) Software. The vulnerability in question is CVE-2026-20131 (CVSS score: 10.0), a case of insecure deserialization of user-supplied Java byte…
-
ISC Stormcast For Thursday, March 19th, 2026 https://isc.sans.edu/podcastdetail/9856, (Thu, Mar 19th)
ISC Stormcast For Thursday, March 19th, 2026 https://isc.sans.edu/podcastdetail/9856, (Thu, Mar 19th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Interesting Message Stored in Cowrie Logs, (Wed, Mar 18th)
Interesting Message Stored in Cowrie Logs, (Wed, Mar 18th) This activity was found and reported by BACS student Adam Thorman as part of one of his assignments which I posted his final paper [1] last week. This activity appeared to only have occurred on the 19 Feb 2026 where at least 2 sensors detected on the…
-
Scans for “adminer”, (Wed, Mar 18th)
Scans for “adminer”, (Wed, Mar 18th) A very popular target of attackers scanning our honeypots is “phpmyadmin”. phpMyAdmin is a script first released in the late 90s, before many security concepts had been discovered. It’s rich history of vulnerabilities made it a favorite target. Its alternative, “adminer”, began appearing about a decade later (https://www.adminer.org). One of…
-
ISC Stormcast For Wednesday, March 18th, 2026 https://isc.sans.edu/podcastdetail/9854, (Wed, Mar 18th)
ISC Stormcast For Wednesday, March 18th, 2026 https://isc.sans.edu/podcastdetail/9854, (Wed, Mar 18th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Smashing Security podcast #459: This clever scam nearly hijacked a tech CEO’s Apple ID
Smashing Security podcast #459: This clever scam nearly hijacked a tech CEO’s Apple ID In episode 459 of Smashing Security, we dive into a chillingly clever account takeover attempt targeting WordPress co-founder Matt Mullenweg – involving MFA fatigue, real Apple alerts, a convincing support call, and a phishing page that oh-so-nearly worked. If a famous…
-
C2 Implant ‘SnappyClient’ Targets Crypto Wallets
C2 Implant ‘SnappyClient’ Targets Crypto Wallets In addition to enabling remote access, the malware supports a wide range of capabilities, including data theft and spying. Jai Vijayan Go to gbhackers.com
-
DarkSword: iPhone Exploit Kit Serves Spies & Thieves Alike
DarkSword: iPhone Exploit Kit Serves Spies & Thieves Alike A sophisticated iOS exploit chain leverages multiple zero-day vulnerabilities and is targeting users in Saudi Arabia, Turkey, Malaysia, and Ukraine. Alexander Culafi Go to gbhackers.com
-
‘Claudy Day’ Trio of Flaws Exposes Claude Users to Data Theft
‘Claudy Day’ Trio of Flaws Exposes Claude Users to Data Theft A prompt injection vulnerability paired with other flaws can turn a Google search into a full attack chain that could threaten enterprise networks. Elizabeth Montalbano Go to gbhackers.com
-
Meta, TikTok Steal Users’ Sensitive PII When They Click on Ads
Meta, TikTok Steal Users’ Sensitive PII When They Click on Ads Tracking pixels let social media companies spy on their own customers when they click over to advertiser sites, gleaning credit card info, currency type, and more. Nate Nelson Go to gbhackers.com
-
SideWinder Espionage Campaign Expands Across Southeast Asia
SideWinder Espionage Campaign Expands Across Southeast Asia The suspected India-linked threat group targets governments, telecom, and critical infrastructure using spear-phishing, old vulnerabilities, and rapidly rotating infrastructure to maintain persistent access. Robert Lemos Go to gbhackers.com
-
ForceMemo Hijacks GitHub Accounts, Backdoors Python Repos
ForceMemo Hijacks GitHub Accounts, Backdoors Python Repos ForceMemo is an active software supply‑chain campaign hijacking GitHub accounts and silently backdooring Python repositories via force‑pushed commits that look legitimate in the web… Go to gbhackers.com
-
Critical Telnetd Vulnerability Enables Remote Code Execution Attacks
Critical Telnetd Vulnerability Enables Remote Code Execution Attacks A critical buffer overflow vulnerability has been discovered in the GNU InetUtils telnetd daemon. Tracked as CVE-2026-32746, the flaw carries a maximum CVSS 3.1… Go to gbhackers.com
-
OpenAI Introduces GPT-5.4 Mini and Nano for Faster, Lightweight AI Performance
OpenAI Introduces GPT-5.4 Mini and Nano for Faster, Lightweight AI Performance OpenAI has officially launched GPT-5.4 mini and GPT-5.4 nano, introducing high-efficiency models optimized for automated workflows, coding subagents, and latency-sensitive deployments. These models are… Go to gbhackers.com
-
Iran Cyber Ops Merge With PsyOps and EW Amid Escalating Conflict
Iran Cyber Ops Merge With PsyOps and EW Amid Escalating Conflict A new phase of the Iran war is unfolding in which ballistic missiles, drones, electronic warfare, and cyber operations are being deployed in parallel,… Go to gbhackers.com
-
Ubuntu Desktop Vulnerability Lets Attackers Escalate Privileges to Full Root Access
Ubuntu Desktop Vulnerability Lets Attackers Escalate Privileges to Full Root Access The Qualys Threat Research Unit (TRU) has disclosed a critical Local Privilege Escalation (LPE) vulnerability affecting default installations of Ubuntu Desktop version 24.04 and… Go to gbhackers.com
-
Apple pushes first Background Security Improvements update to fix WebKit flaw
Apple pushes first Background Security Improvements update to fix WebKit flaw Apple has released its first Background Security Improvements update to fix a WebKit flaw tracked as CVE-2026-20643 on iPhones, iPads, and Macs without requiring a full operating system upgrade. […] Lawrence Abrams Go to bleepingcomputer
-
GlassWorm malware hits 400+ code repos on GitHub, npm, VSCode, OpenVSX
GlassWorm malware hits 400+ code repos on GitHub, npm, VSCode, OpenVSX The GlassWorm supply-chain campaign has returned with a new, coordinated attack that targeted hundreds of packages, repositories, and extensions on GitHub, npm, and VSCode/OpenVSX extensions. […] Bill Toulas Go to bleepingcomputer
-
Europe sanctions Chinese and Iranian firms for cyberattacks
Europe sanctions Chinese and Iranian firms for cyberattacks The European Union Council has announced sanctions against three entities and two individuals for their involvement in cyberattacks targeting critical infrastructure in the region. […] Bill Toulas Go to bleepingcomputer
-
Top 5 Things CISOs Need to Do Today to Secure AI Agents
Top 5 Things CISOs Need to Do Today to Secure AI Agents AI agents are autonomous actors with real access to data and systems, not just copilots. Token Security explains why identity-based access control is critical to prevent misuse and data exposure. […] Sponsored by Token Security Go to bleepingcomputer
-
New font-rendering trick hides malicious commands from AI tools
New font-rendering trick hides malicious commands from AI tools A new font-rendering attack causes AI assistants to miss malicious commands shown on webpages by hiding them in seemingly harmless HTML. […] Bill Toulas Go to bleepingcomputer
-
Boggy Serpens Targets Diplomats and Critical Infrastructure in Multi-Wave Espionage Campaign
Boggy Serpens Targets Diplomats and Critical Infrastructure in Multi-Wave Espionage Campaign A well-resourced Iranian nation-state group known as Boggy Serpens — also tracked as MuddyWater — has sharply escalated its cyberespionage operations, running sustained and targeted campaigns against diplomatic missions, energy companies, maritime operators, and financial institutions. Attributed to Iran’s Ministry of Intelligence and Security…
-
Attackers Abuse Court Documents, GitHub Payloads to Infect Judicial Targets With COVERT RAT
Attackers Abuse Court Documents, GitHub Payloads to Infect Judicial Targets With COVERT RAT A new wave of targeted attacks is quietly hitting Argentina’s judicial system, using fake court documents to lure legal professionals into installing a dangerous piece of malware. The campaign, formally called Operation Covert Access, deploys a Rust-built Remote Access Trojan known as…
-
Microsoft to Stop Force Installation of 365 Copilot App on Windows Devices
Microsoft to Stop Force Installation of 365 Copilot App on Windows Devices Microsoft has temporarily halted the automatic installation of the Microsoft 365 Copilot app on Windows devices. According to a recent update in the Microsoft 365 Message Center on March 16, 2026, the company paused the mandatory rollout, originally scheduled to be completed late…
-
‘RegPwn’ Windows Registry Vulnerability Enables Full System Access to Attackers
‘RegPwn’ Windows Registry Vulnerability Enables Full System Access to Attackers A high-severity Windows vulnerability dubbed “RegPwn” (CVE-2026-24291) is an elevation-of-privilege flaw that allows low-privileged users to gain full SYSTEM access. The MDSec red team discovered the vulnerability and successfully used it in internal engagements since January 2025, before it was addressed in a recent Microsoft…
-
Critical FortiClient SQL Injection Vulnerability Enables Arbitrary Database Access
Critical FortiClient SQL Injection Vulnerability Enables Arbitrary Database Access A critical SQL injection vulnerability in Fortinet’s FortiClient Endpoint Management Server (EMS). Tracked as CVE-2026-21643, this severe flaw carries a CVSS score of 9.1. It allows unauthenticated attackers to execute arbitrary SQL commands and access sensitive database information. The issue specifically affects FortiClient EMS version 7.4.4…
-
Critical Unpatched Telnetd Flaw (CVE-2026-32746) Enables Unauthenticated Root RCE via Port 23
Critical Unpatched Telnetd Flaw (CVE-2026-32746) Enables Unauthenticated Root RCE via Port 23 Cybersecurity researchers have disclosed a critical security flaw impacting the GNU InetUtils telnet daemon (telnetd) that could be exploited by an unauthenticated remote attacker to execute arbitrary code with elevated privileges. The vulnerability, tracked as CVE-2026-32746, carries a CVSS score of 9.8 out…
-
AI Flaws in Amazon Bedrock, LangSmith, and SGLang Enable Data Exfiltration and RCE
AI Flaws in Amazon Bedrock, LangSmith, and SGLang Enable Data Exfiltration and RCE Cybersecurity researchers have disclosed details of a new method for exfiltrating sensitive data from artificial intelligence (AI) code execution environments using domain name system (DNS) queries. In a report published Monday, BeyondTrust revealed that Amazon Bedrock AgentCore Code Interpreter’s sandbox mode permits…
-
LeakNet Ransomware Uses ClickFix via Hacked Sites, Deploys Deno In-Memory Loader
LeakNet Ransomware Uses ClickFix via Hacked Sites, Deploys Deno In-Memory Loader The ransomware operation known as LeakNet has adopted the ClickFix social engineering tactic delivered through compromised websites as an initial access method. The use of ClickFix, where users are tricked into manually running malicious commands to address non-existent errors, is a departure from relying…
-
AI is Everywhere, But CISOs are Still Securing It with Yesterday’s Skills and Tools, Study Finds
AI is Everywhere, But CISOs are Still Securing It with Yesterday’s Skills and Tools, Study Finds A majority of security leaders are struggling to defend AI systems with tools and skills that are not fit for the challenge, according to the AI and Adversarial Testing Benchmark Report 2026 from Pentera. The report, based on a…
-
Konni Deploys EndRAT Through Phishing, Uses KakaoTalk to Propagate Malware
Konni Deploys EndRAT Through Phishing, Uses KakaoTalk to Propagate Malware North Korean threat actors have been observed sending phishing to compromise targets and obtain access to a victim’s KakaoTalk desktop application to distribute malicious payloads to certain contacts. The activity has been attributed by South Korean threat intelligence firm Genians to a hacking group referred…
-
Initial access techniques used by Iran-based threat actors
Initial access techniques used by Iran-based threat actors Analysis of attacks originating from Iran-linked threat groups reveals a preference for certain techniques Categories: Threat Research Tags: Iran, initial access Go to sophos
-
South Korean Police Accidentally Post Cryptocurrency Wallet Password
South Korean Police Accidentally Post Cryptocurrency Wallet Password An expensive mistake: Someone jumped at the opportunity to steal $4.4 million in crypto assets after South Korea’s National Tax Service exposed publicly the mnemonic recovery phrase of a seized cryptocurrency wallet. The funds were stored in a Ledger cold wallet seized in law enforcement raids at…
-
IPv4 Mapped IPv6 Addresses, (Tue, Mar 17th)
IPv4 Mapped IPv6 Addresses, (Tue, Mar 17th) Yesterday, in my diary about the scans for “/proxy/” URLs, I noted how attackers are using IPv4-mapped IPv6 addresses to possibly obfuscate their attack. These addresses are defined in RFC 4038. These addresses are one of the many transition mechanisms used to retain some backward compatibility as IPv6 is…
-
ISC Stormcast For Tuesday, March 17th, 2026 https://isc.sans.edu/podcastdetail/9852, (Tue, Mar 17th)
ISC Stormcast For Tuesday, March 17th, 2026 https://isc.sans.edu/podcastdetail/9852, (Tue, Mar 17th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
/proxy/ URL scans with IP addresses, (Mon, Mar 16th)
/proxy/ URL scans with IP addresses, (Mon, Mar 16th) Attempts to find proxy servers are among the most common scans our honeypots detect. Most of the time, the attacker attempts to use a host header or include the hostname in the URL to trigger the proxy server forwarding the request. In some cases, common URL prefixes like…
-
Free parking in Russia after Distributed Denial-of-Service attack knocks city’s parking system offline
Free parking in Russia after Distributed Denial-of-Service attack knocks city’s parking system offline Drivers in the Russian city of Perm have been enjoying an unexpected bonus this week: free parking. Not because the city council suddenly decided to embrace generosity – but rather because hackers succeeded in knocking the city’s payment system offline. Read more…
-
Fraudsters are using public planning records to target permit applicants
Fraudsters are using public planning records to target permit applicants If you’re in the middle of applying for a planning or zoning permit, there is some unwelcome news: cyber-criminals have found a way to exploit the bureaucratic tedium of the process against you. Read more in my article on the Fortra blog. Graham Cluley Go…