no alarms and no surprises please..
-
Weekly Update 495
Weekly Update 495 In the beginning, it was simple. A website, a database and 150M+ email addresses to search. Time has added serverless functions (which run on servers š¤·āāļø), code on the edge, new data storage constructs and a completely different mechanism for even just querying a simple email address. HIBP is a continually evolving…
-
More Attackers Are Logging In, Not Breaking In
More Attackers Are Logging In, Not Breaking In Credential theft soared in the second half of 2025, thanks in part to the industrialization of infostealer malware and AI-enabled social engineering. Jai Vijayan Go to gbhackers.com
-
Less Lucrative Ransomware Market Makes Attackers Alter Methods
Less Lucrative Ransomware Market Makes Attackers Alter Methods Ransomware actors are ditching Cobalt Strike in favor of native Windows tools, as payment rates hit record lows and data theft surges. Alexander Culafi Go to gbhackers.com
-
Hackers Target Cybersecurity Firm Outpost24 in 7-Stage Phish
Hackers Target Cybersecurity Firm Outpost24 in 7-Stage Phish The cyberattackers leveraged trusted brands and domains in an attempt to redirect a C-suite executive at Outpost24 to give up his credentials. Jai Vijayan Go to gbhackers.com
-
Warlock Ransomware Group Augments Post-Exploitation Activities
Warlock Ransomware Group Augments Post-Exploitation Activities In a recent attack, the group showcased stealthier cross-network activity, thanks to its use of a new BYOVD technique and other tools. Elizabeth Montalbano Go to gbhackers.com
-
Microsoft Launches AI-Driven Troubleshooting for Purview Data Lifecycle Tools
Microsoft Launches AI-Driven Troubleshooting for Purview Data Lifecycle Tools Microsoft has officially released a new open-source tool designed to simplify how IT and security administrators manage data governance. Announced on March 16, 2026,… Go to gbhackers.com
-
Angular XSS Vulnerability Threatens Thousands of Web Applications
Angular XSS Vulnerability Threatens Thousands of Web Applications A high-severity Cross-Site Scripting (XSS) vulnerability, tracked as CVE-2026-32635, has been discovered in Angular, one of the world’s most widely used web application frameworks. … Go to gbhackers.com
-
Glassworm Malware Infects Popular React Native npm Packages
Glassworm Malware Infects Popular React Native npm Packages A new Glassworm-linked supply chain attack has briefly turned two popular React Native npm packages into delivery vehicles for Windows credential-stealing malware. On March… Go to gbhackers.com
-
Packagist Themes Deliver Trojanized jQuery in OphimCMS Supply Chain Attack
Packagist Themes Deliver Trojanized jQuery in OphimCMS Supply Chain Attack A new OphimCMS supply chain attack in which six Packagist themes ship trojanized jQuery and other JavaScript to compromise site visitors rather than servers.ā Researchers… Go to gbhackers.com
-
CISA Issues Alert on Wing FTP Server Vulnerability Used in Attacks
CISA Issues Alert on Wing FTP Server Vulnerability Used in Attacks The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent security alert regarding a critical vulnerability in the Wing FTP Server. On March… Go to gbhackers.com
-
Stryker attack wiped tens of thousands of devices, no malware needed
Stryker attack wiped tens of thousands of devices, no malware needed Last week’s cyberattack on medical technology giant Stryker was limited to its internal Microsoft environment and remotely wiped tens of thousands of employee devices. […] Ionut Ilascu Go to bleepingcomputer
-
CISA flags Wing FTP Server flaw as actively exploited in attacks
CISA flags Wing FTP Server flaw as actively exploited in attacks CISA warned U.S. government agencies to secure their Wing FTP Server instances against an actively exploited vulnerability that may be chained in remote code execution attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
UKās Companies House confirms security flaw exposed business data
UKās Companies House confirms security flaw exposed business data Companies House, a British government agency that operatesĀ the registry for all U.K. companies, says its WebFiling service is back online after it was closed on Friday to fix aĀ security flaw that exposed companies’ information since October 2025. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft Exchange Online outage blocks access to mailboxes
Microsoft Exchange Online outage blocks access to mailboxes Microsoft is working to address an ongoing Exchange Online outage that is preventing customers from accessing their mailboxes and calendars. […] Sergiu Gatlan Go to bleepingcomputer
-
Shadow AI is everywhere. Hereās how to find and secure it.
Shadow AI is everywhere. Hereās how to find and secure it. Shadow AI is quietly spreading across SaaS environments as employees adopt new AI tools without IT oversight. Nudge Security explains how security teams can discover AI apps, monitor usage, and govern risky AI activity. […] Sponsored by Nudge Security Go to bleepingcomputer
-
CISA Warns of Chrome 0-Day Vulnerabilities Exploited in Attacks
CISA Warns of Chrome 0-Day Vulnerabilities Exploited in Attacks An urgent warning regarding two highly critical zero-day vulnerabilities affecting Google Chrome and related products. These flaws have been officially added to CISAās Known Exploited Vulnerabilities (KEV) catalog, indicating that malicious hackers are actively exploiting them in the wild. With the deadline for federal agencies to…
-
Attackers Hijacking Legitimate Websites to Attack Microsoft Teams users
Attackers Hijacking Legitimate Websites to Attack Microsoft Teams users A multi-vector phishing campaign using compromised WordPress sites to steal login credentials from Microsoft Teams and Xfinity users. By hijacking these trusted sites, attackers can bypass security filters and trick victims into disclosing sensitive information. The threat actors are not relying on a single method to…
-
Malicious npm Packages Deliver PylangGhost RAT in New Software Supply Chain Campaign
Malicious npm Packages Deliver PylangGhost RAT in New Software Supply Chain Campaign A remote access trojan known as PylangGhost has appeared on the npm registry for the first time, concealed inside two malicious JavaScript packages. The malware, first publicly disclosed by Cisco Talos in June 2025 and attributed to the North Korean state-sponsored threat group…
-
Phishers Abuse LiveChat Support Tools to Steal Sensitive Data in New SaaS-Based Attack Tactic
Phishers Abuse LiveChat Support Tools to Steal Sensitive Data in New SaaS-Based Attack Tactic A newly identified phishing campaign is turning legitimate customer service software into a weapon for stealing sensitive user data. Attackers have been found abusing LiveChat, a widely used Software-as-a-Service (SaaS) platform that businesses rely on for real-time customer support, to carry…
-
Researchers Decrypt and Exploit Encrypted Palo Alto Cortex XDR BIOC Rules
Researchers Decrypt and Exploit Encrypted Palo Alto Cortex XDR BIOC Rules Cybersecurity researchers have uncovered a critical evasion flaw in Palo Alto Networksā Cortex XDR agent that allowed attackers to bypass behavioral detections completely. By reverse-engineering these encrypted rules, the InfoGuard Labs team discovered hardcoded global whitelists that enabled threat actors to execute malicious actions…
-
CISA Flags Actively Exploited Wing FTP Vulnerability Leaking Server Paths
CISA Flags Actively Exploited Wing FTP Vulnerability Leaking Server Paths The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a medium-severity security flaw impacting Wing FTP to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, CVE-2025-47813 (CVSS score: 4.3), is an information disclosure vulnerability that leaks the installation…
-
GlassWorm Attack Uses Stolen GitHub Tokens to Force-Push Malware Into Python Repos
GlassWorm Attack Uses Stolen GitHub Tokens to Force-Push Malware Into Python Repos The GlassWorm malware campaign is being used to fuel an ongoing attack that leverages the stolen GitHub tokens to inject malware into hundreds of Python repositories. “The attack targets Python projects ā including Django apps, ML research code, Streamlit dashboards, and PyPI packages…
-
ā” Weekly Recap: Chrome 0-Days, Router Botnets, AWS Breach, Rogue AI Agents & More
ā” Weekly Recap: Chrome 0-Days, Router Botnets, AWS Breach, Rogue AI Agents & More Some weeks in security feel normal. Then you read a few tabs and get that immediate āah, great, weāre doing this nowā feeling. This week has that energy. Fresh messes, old problems getting sharper, and research that stops feeling theoretical real…
-
Why Security Validation Is Becoming Agentic
Why Security Validation Is Becoming Agentic If you run security at any reasonably complex organization, your validation stack probably looks something like this: a BAS tool in one corner. A pentest engagement, or maybe an automated pentesting product, in another. A vulnerability scanner feeding an attack surface management platform somewhere else. Each tool gives you…
-
ClickFix Campaigns Spread MacSync macOS Infostealer via Fake AI Tool Installers
ClickFix Campaigns Spread MacSync macOS Infostealer via Fake AI Tool Installers Three different ClickFix campaigns have been found to act as a delivery vector for the deployment of a macOS information stealer called MacSync. “Unlike traditional exploit-based attacks, this method relies entirely on user interaction ā usually in the form of copying and executing commands…
-
Possible New Result in Quantum Factorization
Possible New Result in Quantum Factorization Iām skeptical aboutāand not qualified to reviewāthis new result in factorization with a quantum computer, but if itās true itās a theoretical improvement in the speed of factoring large numbers with a quantum computer. Bruce Schneier Go to bruce schneier
-
China-Nexus Hackers Skulk in Southeast Asian Military Orgs for Years
China-Nexus Hackers Skulk in Southeast Asian Military Orgs for Years Researchers uncovered an extensive cyberespionage campaign that used novel backdoors and familiar evasion techniques to maintain persistent access to regional targets. Rob Wright Go to gbhackers.com
-
GlassWorm Malware Evolves to Hide in Dependencies
GlassWorm Malware Evolves to Hide in Dependencies Researchers have identified dozens of malicious GlassWorm extensions that come with new evasion techniques. Alexander Culafi Go to gbhackers.com
-
Inside Olympic Cybersecurity: Lessons From Paris 2024 to Milan Cortina 2026
Inside Olympic Cybersecurity: Lessons From Paris 2024 to Milan Cortina 2026 Discover how Franz Regul, former CISO for the Paris 2024 Olympics, tackled unique cybersecurity challenges to protect the Olympics from evolving threats. Kristina Beek Go to gbhackers.com
-
Attackers Abuse LiveChat to Phish Credit Card, Personal Data
Attackers Abuse LiveChat to Phish Credit Card, Personal Data A social engineering campaign impersonating PayPal and Amazon uses customer support interactions to acquire sensitive info. Elizabeth Montalbano Go to gbhackers.com
-
Google Unveils Android 17 Advanced Protection Mode to Stop Malicious Services
Google Unveils Android 17 Advanced Protection Mode to Stop Malicious Services Google is preparing to launch Android 17, introducing a comprehensive suite of new features aimed at fundamentally improving device security, user privacy, and performance… Go to gbhackers.com
-
Google Looker Studio Vulnerabilities Allow Attackers to Exfiltrate Data from Google Services
Google Looker Studio Vulnerabilities Allow Attackers to Exfiltrate Data from Google Services Tenable Research recently uncovered āLeakyLooker,ā a critical set of nine novel cross-tenant vulnerabilities within Google Looker Studio that enabled attackers to silently exfiltrate or… Go to gbhackers.com
-
IBM Discovers āSlopolyā AI-Generated Malware Linked to Hive0163 Ransomware
IBM Discovers āSlopolyā AI-Generated Malware Linked to Hive0163 Ransomware Ransomware group Hive0163 is experimenting with a likely AI-generated malware framework, dubbed āSlopoly,ā marking a visible shift toward AI-assisted tooling in attacks. While the… Go to gbhackers.com
-
Fake FileZilla Downloads Spread RAT via Stealthy Multi-Stage Loader
Fake FileZilla Downloads Spread RAT via Stealthy Multi-Stage Loader Fake FileZilla downloads are being used to deliver a stealthy Remote Access Trojan (RAT) through a multiāstage loader, putting careless downloaders at high risk… Go to gbhackers.com
-
ACRStealer Variant Deploys Syscall Evasion, TLS C2, Secondary Payloads
ACRStealer Variant Deploys Syscall Evasion, TLS C2, Secondary Payloads New research reveals that a new ACRStealer variant is now being actively deployed as a final payload by HijackLoader, using lowālevel syscalls, AFD-based networking,… Go to gbhackers.com
-
OpenAI says ChatGPT ads are not rolling out globally for now
OpenAI says ChatGPT ads are not rolling out globally for now OpenAI told BleepingComputer that ChatGPT ads on Free and Go plans are not yet rolling out outside the United States, even though some users noticed references to ads in the updated privacy policy. […] Mayank Parmar Go to bleepingcomputer
-
Betterleaks, a new open-source secrets scanner to replace Gitleaks
Betterleaks, a new open-source secrets scanner to replace Gitleaks A new open-source tool called Betterleaks can scan directories, files, and git repositories and identify valid secrets using default or customized rules. […] Bill Toulas Go to bleepingcomputer
-
Google Looker Studio Vulnerabilities Allow Attackers to Exfiltrate Data from Google Services
Google Looker Studio Vulnerabilities Allow Attackers to Exfiltrate Data from Google Services A set of nine novel cross-tenant vulnerabilities in Google Looker Studio, collectively dubbed āLeakyLooker,ā that could have allowed attackers to run arbitrary SQL queries, exfiltrate sensitive data, and even modify or delete records across Google Cloud environments, all without victims granting explicit permission.…
-
Microsoft to Block Windows 11 and Server 2025 Automated Installation After Critical RCE Vulnerability
Microsoft to Block Windows 11 and Server 2025 Automated Installation After Critical RCE Vulnerability Microsoft has announced a two-phase plan to disable the hands-free deployment feature in Windows Deployment Services (WDS) following the discovery of a critical remote code execution (RCE) vulnerability tracked as CVE-2026-0386. The flaw, rooted in improper access control, allows an unauthenticated…
-
Meta to Permanently Remove End-to-End Encryption Feature in Instagram DMs
Meta to Permanently Remove End-to-End Encryption Feature in Instagram DMs Meta has confirmed it will permanently remove end-to-end encryption (E2EE) support from Instagram direct messages, with the feature officially shutting down after May 8, 2026. The announcement, quietly posted on Instagramās Help Center support page, marks a significant reversal from Metaās earlier commitment to privacy-focused…
-
Android 17 Blocks Non-Accessibility Apps from Accessibility API to Prevent Malware Abuse
Android 17 Blocks Non-Accessibility Apps from Accessibility API to Prevent Malware Abuse Google is testing a new security feature as part of Android Advanced Protection Mode (AAPM) that prevents certain kinds of apps from using the accessibility services API. The change, incorporated in Android 17 Beta 2, was first reported by Android Authority last week.…
-
ISC Stormcast For Monday, March 16th, 2026 https://isc.sans.edu/podcastdetail/9850, (Mon, Mar 16th)
ISC Stormcast For Monday, March 16th, 2026 https://isc.sans.edu/podcastdetail/9850, (Mon, Mar 16th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Microsoft releases Windows 11 OOB hotpatch to fix RRAS RCE flaw
Microsoft releases Windows 11 OOB hotpatch to fix RRAS RCE flaw Microsoft has released an out-of-band (OOB) update to fix a security vulnerabilities affecting Windows 11 Enterprise devices that receive hotpatch updates instead of the regular Patch Tuesday cumulative updates. […] Lawrence Abrams Go to bleepingcomputer
-
AppsFlyer Web SDK hijacked to spread crypto-stealing JavaScript code
AppsFlyer Web SDK hijacked to spread crypto-stealing JavaScript code The AppsFlyer Web SDK was temporarily hijacked this week with malicious code used to steal cryptocurrency in a supply-chain attack. […] Bill Toulas Go to bleepingcomputer
-
Microsoft Releases Out-of-Band Patch For Critical RRAS RCE Vulnerabilities in Windows 11
Microsoft Releases Out-of-Band Patch For Critical RRAS RCE Vulnerabilities in Windows 11 Microsoft released an out-of-band hotpatch update on March 13, 2026, addressing serious security vulnerabilities in Windows 11 versions 24H2 and 25H2. Tracked as KB5084597 and targeting OS Builds 26200.7982 and 26100.7982, this update patches three actively concerning flaws in the Windows Routing and…
-
FortiGate Firewalls Exploited in Wave of Attacks to Breach Networks and Steal Credentials
FortiGate Firewalls Exploited in Wave of Attacks to Breach Networks and Steal Credentials A series of intrusions in early 2026 in which threat actors compromised FortiGate Next-Generation Firewalls (NGFW) to establish persistent footholds within enterprise environments. Each case was intercepted during the lateral movement phase before the attackers could fully achieve their objectives. The attack…
-
OpenClaw AI Agent Flaws Could Enable Prompt Injection and Data Exfiltration
OpenClaw AI Agent Flaws Could Enable Prompt Injection and Data Exfiltration China’s National Computer Network Emergency Response Technical Team (CNCERT) has issued a warning about the security stemming from the use of OpenClaw (formerly Clawdbot and Moltbot), an open-source and self-hosted autonomous artificial intelligence (AI) agent. In a post shared on WeChat, CNCERT noted that…
-
GlassWorm Supply-Chain Attack Abuses 72 Open VSX Extensions to Target Developers
GlassWorm Supply-Chain Attack Abuses 72 Open VSX Extensions to Target Developers Cybersecurity researchers have flagged a new iteration of the GlassWorm campaign that they say represents a “significant escalation” in how it propagates through the Open VSX registry. “Instead of requiring every malicious listing to embed the loader directly, the threat actor is now abusing…
-
March Patch Tuesday visits 15 product families
March Patch Tuesday visits 15 product families Eight Critical-severity bugs ā none in Windows ā appear in 84-CVE haul Categories: Threat Research Tags: Patch Tuesday, x-ops, Microsoft, Windows, detection Go to sophos
-
Upcoming Speaking Engagements
Upcoming Speaking Engagements This is a current list of where and when I am scheduled to speak: Iām giving the Ross Anderson Lecture at the University of Cambridgeās Churchill College at 5:30 PM GMT on Thursday, March 19, 2026. Iām speaking at RSAC 2026 in San Francisco, California, USA, on Wednesday, March 25, 2026. Iām…
-
GlassWorm Spreads via 72 Malicious Open VSX Extensions Hidden in Transitive Dependencies
GlassWorm Spreads via 72 Malicious Open VSX Extensions Hidden in Transitive Dependencies The GlassWorm malware campaign has evolved, significantly escalating its attacks on software developers. Instead of embedding malware directly into initial releases, the threat actors… Go to gbhackers.com
-
Global Authorities Take Down 45,000 Malicious IPs Used in Ransomware Campaigns
Global Authorities Take Down 45,000 Malicious IPs Used in Ransomware Campaigns An unprecedented international law enforcement effort has successfully dismantled a massive cybercrime network. Coordinated by INTERPOL, the initiative targeted critical infrastructure used in phishing,… Go to gbhackers.com
-
New Critical AdGuard Home Flaw Lets Attackers Bypass Authentication
New Critical AdGuard Home Flaw Lets Attackers Bypass Authentication AdGuard Home, a highly popular network-wide ad and tracker blocking solution, has recently issued an emergency security hotfix to address a critical flaw. This… Go to gbhackers.com
-
Authorities Shut Down Proxy Service Linked to Malware Campaign Targeting Thousands of Users
Authorities Shut Down Proxy Service Linked to Malware Campaign Targeting Thousands of Users Ā A coordinated international law enforcement operation successfully dismantled SocksEscort, a massive malicious residential proxy network. Led by the U.S. Justice Department alongside several European… Go to gbhackers.com
-
Starbucks Data Breach Exposes Personal Data of Hundreds of Users
Starbucks Data Breach Exposes Personal Data of Hundreds of Users Starbucks Corporation recently disclosed a targeted cybersecurity incident that compromised the personal and financial information of 889 individuals. This internal platform is utilized by… Go to gbhackers.com
-
Microsoft: Windows 11 users can’t access C: drive on some Samsung PCs
Microsoft: Windows 11 users can’t access C: drive on some Samsung PCs Microsoft is investigating a new issue affecting some Samsung laptops running Windows 11 after installing the February 2026 security updates, in which users lose access to their C: drive and are unable to launch applications. […] Lawrence Abrams Go to bleepingcomputer
-
FBI seeks victims of Steam games used to spread malware
FBI seeks victims of Steam games used to spread malware The FBIĀ is asking gamers who installed Steam titles containing malware to provide information as part of an ongoing investigation into eight malicious games uploaded to the gaming platform. […] Lawrence Abrams Go to bleepingcomputer
-
Poland’s nuclear research centre targeted by cyberattack
Poland’s nuclear research centre targeted by cyberattack Poland’s National Centre for Nuclear Research (NCBJ) says hackers targeted its IT infrastructure, but the attack was detected and blocked before causing any impact. […] Bill Toulas Go to bleepingcomputer
-
Microsoft investigates classic Outlook sync and connection issues
Microsoft investigates classic Outlook sync and connection issues āMicrosoft is investigating several issues causing email synchronization and connection problems when using the classic Outlook desktop client. […] Sergiu Gatlan Go to bleepingcomputer
-
From VMware to whatās next: Protecting data during hypervisor migration
From VMware to whatās next: Protecting data during hypervisor migration Hypervisor migrations can introduce hidden risks that threaten data availability and recovery. Acronis explains why verified backups and cross-platform recovery are essential during VMware transitions. […] Sponsored by Acronis Go to bleepingcomputer
-
Malicious npm Packages Posing as Solara Executor Target Discord, Browsers, and Crypto Wallets
Malicious npm Packages Posing as Solara Executor Target Discord, Browsers, and Crypto Wallets JFrog security researchers Guy Korolevski and Meitar Palas uncovered a sophisticated supply chain attack on the npm ecosystem on March 12, 2026, in which threat actors disguised an information-stealing malware as a legitimate Roblox script executor. The campaign, self-named Cipher stealer, used…
-
GlassWorm Campaign Uses 72 Malicious Open VSX Extensions to Broaden Reach
GlassWorm Campaign Uses 72 Malicious Open VSX Extensions to Broaden Reach In a major escalation of supply chain attacks, the GlassWorm malware campaign has evolved to infect developer environments using transitive dependencies. On March 13, 2026, the Socket Research Team reported identifying at least 72 new malicious Open VSX extensions linked to this campaign. Instead…
-
Critical LangSmith Account Takeover Vulnerability Puts Users at Risk
Critical LangSmith Account Takeover Vulnerability Puts Users at Risk Miggo Security researchers have identified a critical vulnerability in LangSmith, tracked as CVE-2026-25750, that exposes users to potential token theft and complete account takeover. As a central hub for debugging and monitoring large language model data, LangSmith processes billions of events daily, making this a high-stakes…
-
Authorities Crack Down on 45,000 Malicious IPs Powering Ransomware Attacks
Authorities Crack Down on 45,000 Malicious IPs Powering Ransomware Attacks In a massive international crackdown on cybercrime, law enforcement agencies from 72 countries have successfully dismantled over 45,000 malicious IP addresses and servers. Coordinated by INTERPOL, āOperation Synergia IIIā targeted the critical infrastructure behind devastating ransomware, malware, and phishing campaigns worldwide. Running from July 18,…
-
Microsoft Confirms Windows 11 24H2/25H2 Bug Blocks Access to the System Drive C
Microsoft Confirms Windows 11 24H2/25H2 Bug Blocks Access to the System Drive C Microsoft has officially acknowledged a critical bug affecting Windows 11 users on certain Samsung devices, in which the system drive (C:) becomes completely inaccessible after installing the February 2026 security update. The company is now actively investigating the issue in coordination with…
-
Face value: What it takes to fool facial recognition
Face value: What it takes to fool facial recognition ESETās Jake Moore used smart glasses, deepfakes and face swaps to āhackā widely-used facial recognition systems ā and he’ll demo it all at RSAC 2026 Go to eset
-
Chinese Hackers Target Southeast Asian Militaries with AppleChris and MemFun Malware
Chinese Hackers Target Southeast Asian Militaries with AppleChris and MemFun Malware A suspected China-based cyber espionage operation has targeted Southeast Asian military organizations as part of a state-sponsored campaign that dates back to at least 2020. Palo Alto Networks Unit 42 is tracking the threat activity under the moniker CL-STA-1087, where CL refers to cluster,…
-
Meta to Shut Down Instagram End-to-End Encrypted Chat Support Starting May 2026
Meta to Shut Down Instagram End-to-End Encrypted Chat Support Starting May 2026 Meta has announced plans to discontinue support for end-to-end encryption (E2EE) for chats on Instagram after May 8, 2026. “If you have chats that are impacted by this change, you will see instructions on how you can download any media or messages you…
-
INTERPOL Dismantles 45,000 Malicious IPs, Arrests 94 in Global Cybercrime
INTERPOL Dismantles 45,000 Malicious IPs, Arrests 94 in Global Cybercrime INTERPOL on Friday announced the takedown of 45,000 malicious IP addresses and servers used in connection with phishing, malware, and ransomware campaigns, as part of the agency’s ongoing efforts to dismantle criminal networks, disrupt emerging threats, and safeguard victims from scams. The effort is part…
-
Storm-2561 Spreads Trojan VPN Clients via SEO Poisoning to Steal Credentials
Storm-2561 Spreads Trojan VPN Clients via SEO Poisoning to Steal Credentials Microsoft has disclosed details of a credential theft campaign that employs fake virtual private network (VPN) clients distributed through search engine optimization (SEO) poisoning techniques. “The campaign redirects users searching for legitimate enterprise software to malicious ZIP files on attacker-controlled websites to deploy digitally…
-
Investigating a New Click-Fix Variant
Investigating a New Click-Fix Variant Disclaimer: This report has been prepared by the Threat Research Center to enhance cybersecurity awareness and support the strengthening of defense capabilities. It is based on independent research and observations of the current threat landscape available at the time of publication. The content is intended for informational and preparedness purposes…
-
Friday Squid Blogging: Increased Squid Population in the Falklands
Friday Squid Blogging: Increased Squid Population in the Falklands Some good news: squid stocks seem to be recovering in the waters off the Falkland Islands. As usual, you can also use this squid post to talk about the security stories in the news that I havenāt covered. Blog moderation policy. Bruce Schneier Go to bruce…
-
Academia and the āAI Brain Drainā
Academia and the āAI Brain Drainā In 2025, Google, Amazon, Microsoft and Meta collectively spent US$380 billion on building artificial-intelligence tools. That number is expected to surge still higher this year, to $650 billion, to fund the building of physical infrastructure, such as data centers (see go.nature.com/3lzf79q). Moreover, these firms are spending lavishly on one…
-
SmartApeSG campaign uses ClickFix page to push Remcos RAT, (Sat, Mar 14th)
SmartApeSG campaign uses ClickFix page to push Remcos RAT, (Sat, Mar 14th) Introduction This diary describes a Remcos RAT infection that I generated in my lab on Thursday, 2026-03-11. This infection was from the SmartApeSG campaign that used a ClickFix-style fake CAPTCHA page. My previous in-depth diary about a SmartApeSG (ZPHP, HANEYMANEY)Ā was in November 2025,…
-
A React-based phishing page with credential exfiltration via EmailJS, (Fri, Mar 13th)
A React-based phishing page with credential exfiltration via EmailJS, (Fri, Mar 13th) On Wednesday, a phishing message made its way into our handler inbox that contained a fairly typical low-quality lure, but turned out to be quite interesting in the end nonetheless. That is because the accompanying credential stealing web page was dynamically constructed using…
-
Fake PoCs, Misunderstood Risks Cause Cisco SD-WAN Chaos
Fake PoCs, Misunderstood Risks Cause Cisco SD-WAN Chaos The excitement around Cisco’s latest SD-WAN bugs has inspired some light fraud, misunderstandings, and overlooked risks. Nate Nelson Go to gbhackers.com
-
Will AI Save Consumers From Smartphone-Based Phishing Attacks?
Will AI Save Consumers From Smartphone-Based Phishing Attacks? Sophisticated phishing attacks are bypassing on-device protections with troubling frequency, making it more critical than ever for users to protect themselves from potential threats, new research from Omdia shows. Hollie Hennessy, Aaron West Go to gbhackers.com
-
Real-Time Banking Trojan Strikes Brazil’s Pix Users
Real-Time Banking Trojan Strikes Brazil’s Pix Users The latest banking Trojan campaign to hit Brazil combines classic malware with a real-time human operator, waiting for the perfect moment to strike. Alexander Culafi Go to gbhackers.com
-
Iran War Bait Fuels TA453, TA473 Phishing Campaigns
Iran War Bait Fuels TA453, TA473 Phishing Campaigns TA453, TA473, and several emerging threat clusters are exploiting breaking news about the Iran war to run highly targeted phishing campaigns against governments and… Go to gbhackers.com
-
Apple Releases Emergency iOS 15.8.7 Update to Block āCorunaā Exploit Kit
Apple Releases Emergency iOS 15.8.7 Update to Block āCorunaā Exploit Kit Apple has rolled out an emergency security update, iOS 15.8.7 and iPadOS 15.8.7, to protect users of older iPhones and iPads from a sophisticated… Go to gbhackers.com
-
Two Newly Discovered Chrome Zero-Days Exploited in the Wild to Run Malicious Code
Two Newly Discovered Chrome Zero-Days Exploited in the Wild to Run Malicious Code Google has released an urgent security update for its Chrome desktop browser to address two critical zero-day vulnerabilities. Tracked as CVE-2026-3909 and CVE-2026-3910, both… Go to gbhackers.com
-
PsExec and Renamed Backup Tools Enabled Data Theft Before INC Ransomware Attack
PsExec and Renamed Backup Tools Enabled Data Theft Before INC Ransomware Attack A ransomware intrusion in which attackers used legitimate Windows tools and a renamed backup utility to quietly stage and exfiltrate sensitive data before deploying… Go to gbhackers.com
-
Critical CrackArmor Vulnerabilities Expose 12.6 Million Linux Servers to Full Root Takeover
Critical CrackArmor Vulnerabilities Expose 12.6 Million Linux Servers to Full Root Takeover A newly disclosed set of nine vulnerabilities, dubbed “CrackArmor,” has exposed a critical flaw in AppArmor, a foundational Linux security module. AppArmor serves as the… Go to gbhackers.com
-
Starbucks discloses data breach affecting hundreds of employees
Starbucks discloses data breach affecting hundreds of employees Starbucks has disclosed a data breach affecting hundreds of employees after threat actors gained access to their Starbucks Partner Central accounts. […] Sergiu Gatlan Go to bleepingcomputer
-
Google fixes two new Chrome zero-days exploited in attacks
Google fixes two new Chrome zero-days exploited in attacks Google has released emergency security updates to patch two high-severity Chrome vulnerabilities exploited in zero-day attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
Canadian retail giant Loblaw notifies customers of data breach
Canadian retail giant Loblaw notifies customers of data breach Still, out of an abundance of caution, Loblaw says it has automatically logged out all customers from their accounts. Account holders who need to access the company’s digital services will have to log in again. […] Bill Toulas Go to bleepingcomputer
-
England Hockey investigating ransomware data breach
England Hockey investigating ransomware data breach England Hockey, the governing body for field hockey in England, is investigating a potential data breach after the AiLock ransomware gang listed it as a victim on its data leak site. […] Bill Toulas Go to bleepingcomputer
-
AI-generated Slopoly malware used in Interlock ransomware attack
AI-generated Slopoly malware used in Interlock ransomware attack A new malware strain dubbed Slopoly, likely created using generative AI tools, allowed a threat actor to remain on a compromised server for more than a week and steal data in an Interlock ransomware attack. […] Bill Toulas Go to bleepingcomputer
-
Chrome Zero-Day Vulnerabilities Actively Exploited in the Wild to Execute Malicious Code
Chrome Zero-Day Vulnerabilities Actively Exploited in the Wild to Execute Malicious Code Google has released an urgent security update for its Chrome browser after confirming that two high-severity zero-day vulnerabilities are being actively exploited in the wild. The stable channel has been updated to version 146.0.7680.75/76 for Windows and macOS, and 146.0.7680.75 for Linux, with…
-
Salesforce Warns of ShinyHunters Group Exploiting Experience Cloud Sites
Salesforce Warns of ShinyHunters Group Exploiting Experience Cloud Sites A critical warning has been issued about an active threat campaign targeting misconfigured Experience Cloud sites. The notorious threat actor group ShinyHunters has claimed responsibility for a massive data theft operation exploiting overly permissive guest user configurations, reportedly impacting hundreds of high-profile organizations. According to Salesforceās…
-
Critical CrackArmor Vulnerabilities Expose 12.6 Million Linux Servers to Complete Root Takeover
Critical CrackArmor Vulnerabilities Expose 12.6 Million Linux Servers to Complete Root Takeover Nine critical vulnerabilities have been discovered in AppArmor, which is a widely used mandatory access control framework for Linux. These vulnerabilities, collectively referred to as āCrackArmor,ā enable unprivileged local users to escalate their privileges to root, break container isolation, and cause kernel operations…
-
OpenSSH GSSAPI Vulnerability Allow an Attacker to Crash SSH Child Processes
OpenSSH GSSAPI Vulnerability Allow an Attacker to Crash SSH Child Processes A significant vulnerability in the GSSAPI Key Exchange patch was applied by numerous Linux distributions on top of their OpenSSH packages. The flaw, tracked as CVE-2026-3497, was uncovered by security researcher Jeremy Brown. It allows an attacker to crash SSH child processes reliably and…
-
Meta Launches New Anti-Scam Tools on WhatsApp, Facebook and Messenger
Meta Launches New Anti-Scam Tools on WhatsApp, Facebook and Messenger Meta has launched a suite of advanced anti-scam tools across WhatsApp, Facebook, and Messenger to combat the growing industrialization of online fraud. These new defenses combine artificial intelligence, behavioral alerts, and global law enforcement partnerships to protect users proactively. To protect users from evolving social…
-
Cyber fallout from the Iran war: What to have on your radar
Cyber fallout from the Iran war: What to have on your radar The cybersecurity implications of the war in the Middle East extend far beyond the region. Hereās where to focus your defenses. Go to eset
-
Authorities Disrupt SocksEscort Proxy Botnet Exploiting 369,000 IPs Across 163 Countries
Authorities Disrupt SocksEscort Proxy Botnet Exploiting 369,000 IPs Across 163 Countries A court-authorized international law enforcement operation has dismantled a criminal proxy service named SocksEscort that enslaved thousands of residential routers worldwide into a botnet for committing large-scale fraud. “SocksEscort infected home and small business internet routers with malware,” the U.S. Department of Justice (DoJ)…
-
Veeam Patches 7 Critical Backup & Replication Flaws Allowing Remote Code Execution
Veeam Patches 7 Critical Backup & Replication Flaws Allowing Remote Code Execution Veeam has released security updates to address multiple critical vulnerabilities in its Backup & Replication software that, if successfully exploited, could result in remote code execution. The vulnerabilities are as follows – CVE-2026-21666 (CVSS score: 9.9) – A vulnerability that allows an authenticated…
-
Rust-Based VENON Malware Targets 33 Brazilian Banks with Credential-Stealing Overlays
Rust-Based VENON Malware Targets 33 Brazilian Banks with Credential-Stealing Overlays Cybersecurity researchers have disclosed details of a new banking malware targeting Brazilian users that’s written in Rust, marking a significant departure from other known Delphi-based malware families associated with the Latin American cybercrime ecosystem. The malware, which is designed to infect Windows systems and was…
-
Hive0163 Uses AI-Assisted Slopoly Malware for Persistent Access in Ransomware Attacks
Hive0163 Uses AI-Assisted Slopoly Malware for Persistent Access in Ransomware Attacks Cybersecurity researchers have disclosed details of a suspected artificial intelligence (AI)-generated malware codenamed Slopoly put to use by a financially motivated threat actor named Hive0163. “Although still relatively unspectacular, AI-generated malware such as Slopoly shows how easily threat actors can weaponize AI to develop…
-
How to Scale Phishing Detection in Your SOC: 3 Steps for CISOs
How to Scale Phishing Detection in Your SOC: 3 Steps for CISOs Phishing has quietly turned into one of the hardest enterprise threats to expose early. Instead of crude lures and obvious payloads, modern campaigns rely on trusted infrastructure, legitimate-looking authentication flows, and encrypted traffic that conceals malicious behavior from traditional detection layers. For CISOs,…
-
iPhones and iPads Approved for NATO Classified Data
iPhones and iPads Approved for NATO Classified Data Apple announcement: ā¦iPhone and iPad are the first and only consumer devices in compliance with the information assurance requirements of NATO nations. This enables iPhone and iPad to be used with classified information up to the NATO restricted level without requiring special software or settingsāa level of…