no alarms and no surprises please..
-
ISC Stormcast For Friday, March 13th, 2026 https://isc.sans.edu/podcastdetail/9848, (Fri, Mar 13th)
ISC Stormcast For Friday, March 13th, 2026 https://isc.sans.edu/podcastdetail/9848, (Fri, Mar 13th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Your Signal account is safe – unless you fall for this trick
Your Signal account is safe – unless you fall for this trick Signal, the encrypted messaging app trusted by security-savvy users around the world, has confirmed that hackers have managed to takeover accounts – with government officials and journalists among those being targeted. Read more in my article on the Hot for Security blog. Graham…
-
Iran MOIS Colludes With Criminals to Boost Cyberattacks
Iran MOIS Colludes With Criminals to Boost Cyberattacks Iranian APTs have long pretended to be cybercriminal groups. Now they’re working with actual cybercriminal groups. Nate Nelson Go to gbhackers.com
-
Commercial Spyware Opponents Fear US Policy Shifting
Commercial Spyware Opponents Fear US Policy Shifting Rescinded sanctions and reactivated contracts have created confusion about the Trump administration’s spyware policy and where it draws the line. Rob Wright Go to gbhackers.com
-
Why Stryker’s Outage Is a Disaster Recovery Wake-Up Call
Why Stryker’s Outage Is a Disaster Recovery Wake-Up Call The Iranian cyberattack on Stryker is the kind of stress test that business continuity and disaster recovery programs often do not plan for. Jai Vijayan Go to gbhackers.com
-
Hackers Exploit CloudFlare Anti-Security to Steal Microsoft 365 Login Credentials
Hackers Exploit CloudFlare Anti-Security to Steal Microsoft 365 Login Credentials A recent Microsoft 365 credential harvesting campaign shows how attackers are exploiting CloudFlare’s protective features to shield malicious phishing sites from security scanners and… Go to gbhackers.com
-
Palo Alto Cortex XDR Broker Vulnerability Exposes Systems to Sensitive Information Theft and Modification
Palo Alto Cortex XDR Broker Vulnerability Exposes Systems to Sensitive Information Theft and Modification Palo Alto Networks has issued a security advisory regarding a newly discovered vulnerability in its Cortex XDR Broker Virtual Machine (VM). Tracked as CVE-2026-0231,… Go to gbhackers.com
-
Ericsson US Hit by Cyber Attack, Hackers Steal Personal Data of Employees and Customers
Ericsson US Hit by Cyber Attack, Hackers Steal Personal Data of Employees and Customers Ericsson Inc., the United States subsidiary of the Swedish telecommunications giant, has confirmed a data breach affecting 15,661 of its employees and customers. The… Go to gbhackers.com
-
CastleRAT Attack Leverages Deno JavaScript Runtime to Bypass Enterprise Defenses
CastleRAT Attack Leverages Deno JavaScript Runtime to Bypass Enterprise Defenses A sophisticated malware campaign that abuses the Deno JavaScript runtime to deliver CastleRAT, a powerful remote access trojan designed for espionage and data theft…. Go to gbhackers.com
-
Splunk RCE Vulnerability Exposes Systems to Arbitrary Shell Command Execution by Attackers
Splunk RCE Vulnerability Exposes Systems to Arbitrary Shell Command Execution by Attackers A high-severity Remote Command Execution (RCE) vulnerability has been discovered in Splunk Enterprise and Splunk Cloud Platform, exposing systems to severe security risks. Tracked… Go to gbhackers.com
-
WhatsApp introduces parent-managed accounts for pre-teens
WhatsApp introduces parent-managed accounts for pre-teens WhatsApp has begun rolling out parent-managed accounts for pre-teens, allowing parents and guardians to decide who can contact them and which groups they can join. […] Sergiu Gatlan Go to bleepingcomputer
-
SQLi flaw in Elementor Ally plugin impacts 250k+ WordPress sites
SQLi flaw in Elementor Ally plugin impacts 250k+ WordPress sites An SQL injection vulnerability in Ally, a WordPress plugin from Elementor for web accessibility and usability with more than 400,000 installations, could be exploited to steal sensitive data without authentication. […] Bill Toulas Go to bleepingcomputer
-
CISA orders feds to patch n8n RCE flaw exploited in attacks
CISA orders feds to patch n8n RCE flaw exploited in attacks The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered government agencies on Wednesday to patch their systems against an actively exploited n8n vulnerability. […] Sergiu Gatlan Go to bleepingcomputer
-
Medtech giant Stryker offline after Iran-linked wiper malware attack
Medtech giant Stryker offline after Iran-linked wiper malware attack Leading medical technology company Stryker has been hit by a wiper malware attack claimed by Handala, an Iranian-linked and pro-Palestinian hacktivist group. […] Sergiu Gatlan Go to bleepingcomputer
-
New PhantomRaven NPM attack wave steals dev data via 88 packages
New PhantomRaven NPM attack wave steals dev data via 88 packages New attack waves from the ‘PhantomRaven’ supply-chain campaign are hitting the npm registry, with dozens of malicious packages that exfiltrate sensitive data from JavaScript developers. […] Bill Toulas Go to bleepingcomputer
-
Critical Microsoft Office Vulnerability Enables Remote Code Execution Attacks
Critical Microsoft Office Vulnerability Enables Remote Code Execution Attacks On March 10, 2026, Microsoft released security updates to address a critical vulnerability in its widely used Office suite. Tracked as CVE-2026-26110, this security flaw allows an unauthorized attacker to execute malicious code on a victim’s device. With a high severity rating and a CVSS base…
-
GitLab Security Update – Patch for XSS and API DoS Vulnerabilities
GitLab Security Update – Patch for XSS and API DoS Vulnerabilities GitLab has released urgent security updates for its Community Edition (CE) and Enterprise Edition (EE) to address a wide range of vulnerabilities. The newly released versions 18.9.2, 18.8.6, and 18.7.6 fix a total of 15 security issues, including critical Cross-Site Scripting (XSS) and Denial-of-Service…
-
Hackers Leveraging Cloudflare Anti-Bot Features to Steal Microsoft 365 Credentials
Hackers Leveraging Cloudflare Anti-Bot Features to Steal Microsoft 365 Credentials A sophisticated Microsoft 365 credential harvesting campaign that weaponizes Cloudflare’s own protective features to evade detection and silently steal user login data. The campaign demonstrates a growing and troubling trend: threat actors turning the very tools designed to defend websites into shields for malicious infrastructure.…
-
Chrome Security Update – Patch for 29 Vulnerabilities that Allow Remote Code Execution
Chrome Security Update – Patch for 29 Vulnerabilities that Allow Remote Code Execution Google has officially released Chrome version 146 to the stable channel, delivering crucial security updates for Windows, Mac, and Linux users. Rolling out over the coming days, Chrome 146.0.7680.71 for Linux and 146.0.7680.71/72 for Windows and Mac addresses 29 security vulnerabilities. Many…
-
Google Completes Acquisition of Wiz in Historic $32 Billion Deal
Google Completes Acquisition of Wiz in Historic $32 Billion Deal Google has officially closed its $32 billion all-cash acquisition of Wiz, the Israeli cloud and AI security platform, marking the largest deal in Google’s history and a landmark moment for the global cybersecurity industry. The Wiz team will join Google Cloud while retaining its brand…
-
CISA Flags Actively Exploited n8n RCE Bug as 24,700 Instances Remain Exposed
CISA Flags Actively Exploited n8n RCE Bug as 24,700 Instances Remain Exposed The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical security flaw impacting n8n to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerability, tracked as CVE-2025-68613 (CVSS score: 9.9), concerns a case of expression…
-
Researchers Trick Perplexity’s Comet AI Browser Into Phishing Scam in Under Four Minutes
Researchers Trick Perplexity’s Comet AI Browser Into Phishing Scam in Under Four Minutes Agentic web browsers that leverage artificial intelligence (AI) capabilities to autonomously execute actions across multiple websites on behalf of a user could be trained and tricked into falling prey to phishing and scam traps. The attack, at its core, takes advantage of…
-
Critical n8n Flaws Allow Remote Code Execution and Exposure of Stored Credentials
Critical n8n Flaws Allow Remote Code Execution and Exposure of Stored Credentials Cybersecurity researchers have disclosed details of two now-patched security flaws in the n8n workflow automation platform, including two critical bugs that could result in arbitrary command execution. The vulnerabilities are listed below – CVE-2026-27577 (CVSS score: 9.4) – Expression sandbox escape leading to…
-
Meta Disables 150K Accounts Linked to Southeast Asia Scam Centers in Global Crackdown
Meta Disables 150K Accounts Linked to Southeast Asia Scam Centers in Global Crackdown Meta on Wednesday said it disabled over 150,000 accounts associated with scam centers in Southeast Asia as part of a coordinated effort in partnership with authorities from Thailand, the U.S., the U.K., Canada, Korea, Japan, Singapore, the Philippines, Australia, New Zealand, and…
-
Dozens of Vendors Patch Security Flaws Across Enterprise Software and Network Devices
Dozens of Vendors Patch Security Flaws Across Enterprise Software and Network Devices SAP has released security updates to address two critical security flaws that could be exploited to achieve arbitrary code execution on affected systems. The vulnerabilities in question listed below – CVE-2019-17571 (CVSS score: 9.8) – A code injection vulnerability in SAP Quotation Management…
-
Evil evolution: ClickFix and macOS infostealers
Evil evolution: ClickFix and macOS infostealers <p>Across three recent campaigns, Sophos X-Ops notes shifts in both lures and malware capabilities, as threat actors leveraging ClickFix techniques increasingly target macOS users with infostealers</p> Categories: Threat Research Tags: MacOS, infostealer, clickfix, MacSync, Social engineering Go to sophos
-
Canada Needs Nationalized, Public AI
Canada Needs Nationalized, Public AI Canada has a choice to make about its artificial intelligence future. The Carney administration is investing $2-billion over five years in its Sovereign AI Compute Strategy. Will any value generated by “sovereign AI” be captured in Canada, making a difference in the lives of Canadians, or is this just a…
-
ISC Stormcast For Thursday, March 12th, 2026 https://isc.sans.edu/podcastdetail/9846, (Thu, Mar 12th)
ISC Stormcast For Thursday, March 12th, 2026 https://isc.sans.edu/podcastdetail/9846, (Thu, Mar 12th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
When your IoT Device Logs in as Admin, It?s too Late! [Guest Diary], (Wed, Mar 11th)
When your IoT Device Logs in as Admin, It?s too Late! [Guest Diary], (Wed, Mar 11th) [This is a Guest Diary by Adam Thorman, an ISC intern as part of the SANS.edu BACS program] Introduction Have you ever installed a new device on your home or company router? Even when setup instructions are straightforward, end…
-
Analyzing “Zombie Zip” Files (CVE-2026-0866), (Wed, Mar 11th)
Analyzing “Zombie Zip” Files (CVE-2026-0866), (Wed, Mar 11th) A new vulnerability (CVE-2026-0866) has been published: Zombie Zip. It’s a method to create a malformed ZIP file that will bypass detection by most anti-virus engines. The malformed ZIP file can not be opened with a ZIP utility, a custom loader is required. The trick is to change…
-
Iran-Backed Hackers Claim Wiper Attack on Medtech Firm Stryker
Iran-Backed Hackers Claim Wiper Attack on Medtech Firm Stryker A hacktivist group with links to Iran’s intelligence agencies is claiming responsibility for a data-wiping attack against Stryker, a global medical technology company based in Michigan. News reports out of Ireland, Stryker’s largest hub outside of the United States, said the company sent home more than…
-
Smashing Security podcast #458: How not to steal $46 million from the US government
Smashing Security podcast #458: How not to steal $46 million from the US government A Wikipedia security engineer accidentally wakes a dormant JavaScript worm that hadn’t stirred since 2024 – and within minutes, giant woodpecker images are plastered across the internet’s favourite encyclopaedia. Meanwhile, a crypto contractor hired to help the US Marshals manage seized…
-
INC Ransomware Group Holds Healthcare Hostage in Oceania
INC Ransomware Group Holds Healthcare Hostage in Oceania Government agencies, emergency clinics, and others in Australia, New Zealand, and Tonga have had serious run-ins with the prolific ransomware outfit. Nate Nelson Go to gbhackers.com
-
Xygeni GitHub Action Compromised Via Tag Poison
Xygeni GitHub Action Compromised Via Tag Poison Attackers operated an active C2 implant for up to a week and compromised AppSec vendor Xygeni’s xygeni/xygeni-action in that time. Alexander Culafi Go to gbhackers.com
-
Chinese Nexus Actors Shift Focus to Qatar Amid Iranian Conflict
Chinese Nexus Actors Shift Focus to Qatar Amid Iranian Conflict Two attacks on Qatari entities signal a shift in focus for China-backed actors and demonstrate how quickly they can pivot in response to geopolitical events. Elizabeth Montalbano Go to gbhackers.com
-
Instagram Down: Global Outage Prevents Users from Posting and Messaging
Instagram Down: Global Outage Prevents Users from Posting and Messaging A widespread technical outage has struck Instagram, leaving thousands of users globally unable to access the popular social media application. The disruption, which primarily… Go to gbhackers.com
-
Google Warns of AI‑Driven Adaptive Malware Rewriting Its Own Code
Google Warns of AI‑Driven Adaptive Malware Rewriting Its Own Code The cybersecurity landscape experienced a major shift in 2025 as threat actors transitioned from experimenting with artificial intelligence to fully integrating it into real-world… Go to gbhackers.com
-
BeatBanker Trojan Spreads via Phishing, Deploys Crypto Miner and RAT on Targeted Devices
BeatBanker Trojan Spreads via Phishing, Deploys Crypto Miner and RAT on Targeted Devices BeatBanker is a new Android malware campaign targeting users in Brazil, combining banking fraud, crypto‑mining, and, in its latest wave, full device takeover via… Go to gbhackers.com
-
Microsoft Active Directory Flaw Allows Attackers to Escalate Privileges
Microsoft Active Directory Flaw Allows Attackers to Escalate Privileges Microsoft has released a critical security update addressing a high-severity elevation of privilege vulnerability in Active Directory Domain Services (AD DS). This flaw, patched… Go to gbhackers.com
-
Microsoft .NET 0-Day Flaw Opens Doors for Denial of Service Attacks
Microsoft .NET 0-Day Flaw Opens Doors for Denial of Service Attacks Microsoft’s March 2026 Patch Tuesday has addressed a zero-day vulnerability in the .NET framework, officially tracked as CVE-2026-26127. Disclosed publicly before a patch was… Go to gbhackers.com
-
New ‘BlackSanta’ EDR killer spotted targeting HR departments
New ‘BlackSanta’ EDR killer spotted targeting HR departments For more than a year, a Russian-speaking threat actor targeted human resource (HR) departments with malware that delivers a new EDR killer named BlackSanta. […] Bill Toulas Go to bleepingcomputer
-
New BeatBanker Android malware poses as Starlink app to hijack devices
New BeatBanker Android malware poses as Starlink app to hijack devices A new Android malware named BeatBanker can hijack devices and tricks users into installing it by posing as a Starlink app on websites masquerading as the official Google Play Store. […] Bill Toulas Go to bleepingcomputer
-
New ‘Zombie ZIP’ technique lets malware slip past security tools
New ‘Zombie ZIP’ technique lets malware slip past security tools A new technique dubbed “Zombie ZIP” helps conceal payloads in compressed files specially created to avoid detection from security solutions such as antivirus and endpoint detection and response (EDR) products. […] Bill Toulas Go to bleepingcomputer
-
Microsoft releases Windows 10 KB5078885 extended security update
Microsoft releases Windows 10 KB5078885 extended security update Microsoft has released the Windows 10 KB5078885 extended security update to fix the March 2026 Patch Tuesday vulnerabilities, including 2 zero-days and an issue that prevent some devices from shutting down. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft March 2026 Patch Tuesday fixes 2 zero-days, 79 flaws
Microsoft March 2026 Patch Tuesday fixes 2 zero-days, 79 flaws Today is Microsoft’s March 2026 Patch Tuesday with security updates for 79 flaws, including 2 publicly disclosed zero-day vulnerabilities. […] Lawrence Abrams Go to bleepingcomputer
-
Gogs Vulnerability Enables Attackers to Silently Overwrite Large File Storage Objects
Gogs Vulnerability Enables Attackers to Silently Overwrite Large File Storage Objects A critical security flaw has been discovered in a popular open-source, self-hosted Git service, allowing attackers to overwrite Large File Storage (LFS) objects secretly. Tracked as CVE-2026-25921, this maximum-severity vulnerability carries a CVSS 3.1 score of 10.0. It creates a severe risk for software…
-
Microsoft .NET 0-Day Vulnerability Enables Denial-of-Service Attacks
Microsoft .NET 0-Day Vulnerability Enables Denial-of-Service Attacks An emergency security update has been released to address a newly disclosed .NET Framework vulnerability, tracked as CVE-2026-26127. This security flaw allows unauthenticated, remote attackers to trigger a Denial-of-Service (DoS) condition on the network. With a CVSS score of 7.5, Microsoft has classified the vulnerability as “Important.” It…
-
Microsoft SQL Server Zero-Day Vulnerability Allows Attackers to Escalate Privileges
Microsoft SQL Server Zero-Day Vulnerability Allows Attackers to Escalate Privileges Microsoft has disclosed a critical zero-day vulnerability in SQL Server that allows authenticated attackers to escalate their privileges to the highest administrative level on affected database systems. Tracked as CVE-2026-21262, the flaw was officially released on March 10, 2026, and has already been publicly disclosed,…
-
Fortinet Security Update – Patch for Multiple Vulnerabilities That Enable Malicious Command Execution
Fortinet Security Update – Patch for Multiple Vulnerabilities That Enable Malicious Command Execution Fortinet released a sweeping security advisory on March 10, 2026, addressing eleven vulnerabilities across its core enterprise products, including FortiManager, FortiAnalyzer, FortiSwitchAXFixed, and FortiSandbox. The flaws range from authentication bypasses and buffer overflows to OS command injection and SQL injection, several of…
-
Zoom Workplace for Windows Vulnerabilities Allow Privilege Escalation
Zoom Workplace for Windows Vulnerabilities Allow Privilege Escalation Zoom has released four security bulletins on March 10, 2026, disclosing multiple vulnerabilities across its Windows-based client suite. The flaws, ranging from High to Critical severity, could allow attackers to escalate privileges on affected systems, with one critical flaw exploitable by unauthenticated remote attackers with no prior…
-
Sednit reloaded: Back in the trenches
Sednit reloaded: Back in the trenches The resurgence of one of Russia’s most notorious APT groups Go to eset
-
TR-26-0087 (TÜBİTAK BİLGEM YTE – Liderahenk Güvenlik Bildirimi)
TR-26-0087 (TÜBİTAK BİLGEM YTE – Liderahenk Güvenlik Bildirimi) Go to usom.gov
-
Five Malicious Rust Crates and AI Bot Exploit CI/CD Pipelines to Steal Developer Secrets
Five Malicious Rust Crates and AI Bot Exploit CI/CD Pipelines to Steal Developer Secrets Cybersecurity researchers have discovered five malicious Rust crates that masquerade as time-related utilities to transmit .env file data to the threat actors. The Rust packages, published to crates.io, are listed below – chrono_anchor dnp3times time_calibrator time_calibrators time-sync The crates, per Socket,…
-
FortiGate Devices Exploited to Breach Networks and Steal Service Account Credentials
FortiGate Devices Exploited to Breach Networks and Steal Service Account Credentials Cybersecurity researchers are calling attention to a new campaign where threat actors are abusing FortiGate Next-Generation Firewall (NGFW) appliances as entry points to breach victim networks. The activity involves the exploitation of recently disclosed security vulnerabilities or weak credentials to extract configuration files containing…
-
How to Stop AI Data Leaks: A Webinar Guide to Auditing Modern Agentic Workflows
How to Stop AI Data Leaks: A Webinar Guide to Auditing Modern Agentic Workflows Artificial Intelligence (AI) is no longer just a tool we talk to; it is a tool that does things for us. These are called AI Agents. They can send emails, move data, and even manage software on their own. But there…
-
KadNap Malware Infects 14,000+ Edge Devices to Power Stealth Proxy Botnet
KadNap Malware Infects 14,000+ Edge Devices to Power Stealth Proxy Botnet Cybersecurity researchers have discovered a new malware called KadNap that’s primarily targeting Asus routers to enlist them into a botnet for proxying malicious traffic. The malware, first detected in the wild in August 2025, has expanded to over 14,000 infected devices, with more than…
-
New “LeakyLooker” Flaws in Google Looker Studio Could Enable Cross-Tenant SQL Queries
New “LeakyLooker” Flaws in Google Looker Studio Could Enable Cross-Tenant SQL Queries Cybersecurity researchers have disclosed nine cross-tenant vulnerabilities in Google Looker Studio that could have permitted attackers to run arbitrary SQL queries on victims’ databases and exfiltrate sensitive data within organizations’ Google Cloud environments. The shortcomings have been collectively named LeakyLooker by Tenable. There…
-
Jailbreaking the F-35 Fighter Jet
Jailbreaking the F-35 Fighter Jet Countries around the world are becoming increasingly concerned about their dependencies on the US. If you’ve purchase US-made F-35 fighter jets, you are dependent on the US for software maintenance. The Dutch Defense Secretary recently said that he could jailbreak the planes to accept third-party software. Bruce Schneier Go to…
-
ISC Stormcast For Wednesday, March 11th, 2026 https://isc.sans.edu/podcastdetail/9844, (Wed, Mar 11th)
ISC Stormcast For Wednesday, March 11th, 2026 https://isc.sans.edu/podcastdetail/9844, (Wed, Mar 11th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Microsoft Patch Tuesday March 2026, (Tue, Mar 10th)
Microsoft Patch Tuesday March 2026, (Tue, Mar 10th) Microsoft today released patches for 93 vulnerabilities, including 9 vulnerabilities in Chromium affecting Microsoft Edge. 8 of the vulnerabilities are rated critical. 2 were disclosed prior to today but have not yet been exploited. This update addresses no already-exploited vulnerabilities. Disclose vulnerabilities: CVE-2026-26127: A denial of service…
-
ISC Stormcast For Tuesday, March 10th, 2026 https://isc.sans.edu/podcastdetail/9842, (Tue, Mar 10th)
ISC Stormcast For Tuesday, March 10th, 2026 https://isc.sans.edu/podcastdetail/9842, (Tue, Mar 10th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Encrypted Client Hello: Ready for Prime Time?, (Mon, Mar 9th)
Encrypted Client Hello: Ready for Prime Time?, (Mon, Mar 9th) Last week, two related RFCs were published: RFC 9848: Bootstrapping TLS Encrypted ClientHello with DNS Service Bindings RFC 9849: TLS Encrypted Client Hello These TLS extensions have been discussed quite a bit already, and Cloudflare, one of the early implementers and proponents, has been in use for…
-
Twitter suspended 800 million accounts last year – so why does manipulation remain so rampant?
Twitter suspended 800 million accounts last year – so why does manipulation remain so rampant? Elon Musk’s social media site says it suspended 800 million accounts in a year for spam and manipulation – but with state-backed campaigns still flooding the platform, the real question is how many fake accounts remain. Read more in my…
-
Middle East Conflict Highlights Cloud Resilience Gaps
Middle East Conflict Highlights Cloud Resilience Gaps Data centers — used by both governments and militaries for operations — are now fair game, not just for cyberattacks, but for kinetic attacks as well. Robert Lemos Go to gbhackers.com
-
Microsoft Patches 83 CVEs in March Update
Microsoft Patches 83 CVEs in March Update For a change, there’s little in this month’s Patch Tuesday that should cause panic, according to security experts. Jai Vijayan Go to gbhackers.com
-
Weekly Update 494
Weekly Update 494 Since starting HIBP a dozen and a bit years ago, I’ve loaded an average of one breach every 4.7 days. That’s 959 of them to date, but last week it was five in only two days. That’s a few weeks’ worth of breaches in only 48 and a half hours. And that’s…
-
‘Overly Permissive’ Salesforce Cloud Configs in the Crosshairs
‘Overly Permissive’ Salesforce Cloud Configs in the Crosshairs Some customers have mishandled guest user configurations otherwise intended to allow third-party access to important — and sensitive — client data. Alexander Culafi Go to gbhackers.com
-
Russian Threat Actor Sednit Resurfaces With Sophisticated Toolkit
Russian Threat Actor Sednit Resurfaces With Sophisticated Toolkit After several years of using simple implants, the Russia-affiliated actor is back with two new sophisticated malware tools. Jai Vijayan Go to gbhackers.com
-
‘BlackSanta’ EDR Killer Targets HR Workflows
‘BlackSanta’ EDR Killer Targets HR Workflows A campaign by Russian-speaking cyberattackers hijacks workflows to deliver security-busting malware, allowing attackers to steal data without detection. Elizabeth Montalbano Go to gbhackers.com
-
OpenClaw Advisory Surge Highlights Blind Spot Between GitHub and CVE Vulnerability Tracking
OpenClaw Advisory Surge Highlights Blind Spot Between GitHub and CVE Vulnerability Tracking OpenClaw’s rapid rise has accidentally exposed how far GitHub’s advisory ecosystem has drifted from traditional CVE‑centric vulnerability tracking. Within roughly three weeks, the project published… Go to gbhackers.com
-
Gogs Flaw Could Let Attackers Quietly Overwrite Large File Storage Data
Gogs Flaw Could Let Attackers Quietly Overwrite Large File Storage Data A critical security vulnerability has been identified in Gogs, a widely used open-source self-hosted Git service. / Tracked as CVE-2026-25921, this flaw allows unauthenticated attackers… Go to gbhackers.com
-
Cloudflare Pingora Flaws Enable Request Smuggling and Cache Poisoning Attacks
Cloudflare Pingora Flaws Enable Request Smuggling and Cache Poisoning Attacks In a recent security advisory, Cloudflare disclosed multiple HTTP request smuggling and cache poisoning vulnerabilities in its open-source Pingora framework. Tracked under the identifiers… Go to gbhackers.com
-
OpenAI to Acquire Promptfoo to Address Vulnerabilities in AI Systems
OpenAI to Acquire Promptfoo to Address Vulnerabilities in AI Systems OpenAI has announced the acquisition of Promptfoo, an artificial intelligence security platform designed to help enterprises identify and fix vulnerabilities in their AI systems… Go to gbhackers.com
-
SurxRAT Android Malware Uses LLMs for Phishing and Data Theft
SurxRAT Android Malware Uses LLMs for Phishing and Data Theft A new Android Remote Access Trojan (RAT) named SurxRAT, which is being sold as a commercial malware platform through a Telegram-based malware‑as‑a‑service (MaaS) ecosystem…. Go to gbhackers.com
-
Microsoft Teams phishing targets employees with A0Backdoor malware
Microsoft Teams phishing targets employees with A0Backdoor malware Hackers contacted employees at financial and healthcare organizations over Microsoft Teams to trick them into granting remote access through Quick Assist and deploy a new piece of malware called A0Backdoor. […] Bill Toulas Go to bleepingcomputer
-
Google: Cloud attacks exploit flaws more than weak credentials
Google: Cloud attacks exploit flaws more than weak credentials Hackers are increasingly exploiting newly disclosed vulnerabilities in third-party software to gain initial access to cloud environments, with the window for attacks shrinking from weeks to just days. […] Bill Toulas Go to bleepingcomputer
-
Dutch govt warns of Signal, WhatsApp account hijacking attacks
Dutch govt warns of Signal, WhatsApp account hijacking attacks Russian state-sponsored hackers have been linked to an ongoing Signal and WhatsApp phishing campaign targeting government officials, military personnel, and journalists to gain access to sensitive messages. […] Lawrence Abrams Go to bleepingcomputer
-
Ericsson US discloses data breach after service provider hack
Ericsson US discloses data breach after service provider hack Ericsson Inc., the U.S. subsidiary of Swedish networking and telecommunications giant Ericsson, says attackers have stolen data belonging to an undisclosed number of employees and customers after hacking one of its service providers. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft Teams will tag third-party bots trying to join meetings
Microsoft Teams will tag third-party bots trying to join meetings Microsoft says Teams will soon automatically tag third-party bots in lobbies, allowing organizers to control whether they can join meetings. […] Sergiu Gatlan Go to bleepingcomputer
-
Anthropic Sued the U.S. Government for Labelling Claude as ‘Supply Chain Risk’
Anthropic Sued the U.S. Government for Labelling Claude as ‘Supply Chain Risk’ Artificial intelligence leader Anthropic has filed an unprecedented lawsuit against the United States government after being designated a “supply chain risk”. The legal action, filed in a California federal court on Monday, targets the executive office of President Donald Trump, Defense Secretary Pete…
-
Apache ZooKeeper Vulnerability Allow Attackers to Access Sensitive Data
Apache ZooKeeper Vulnerability Allow Attackers to Access Sensitive Data Two “Important” severity vulnerabilities have been disclosed in Apache ZooKeeper, a widely used service for configuration management and naming in distributed applications, making timely security updates critical. These newly discovered flaws could allow attackers to access sensitive configuration data or bypass hostname verification to impersonate trusted…
-
iPhone Exploit Toolkit Used by Russian Spies Likely Originated from U.S. Contractor
iPhone Exploit Toolkit Used by Russian Spies Likely Originated from U.S. Contractor A powerful iPhone exploit kit named “Coruna,” initially created for Western intelligence by U.S. contractor L3Harris, has fallen into the hands of Russian spies and Chinese cybercriminals. The Coruna toolkit features 23 different hacking components designed to compromise Apple iPhones. Trenchant originally built…
-
Signed Malware Masquerading as Teams, Zoom Apps Drops RMM Backdoors
Signed Malware Masquerading as Teams, Zoom Apps Drops RMM Backdoors A newly uncovered phishing campaign is actively targeting enterprise users by disguising malware as widely used workplace applications, including Microsoft Teams, Zoom, and Adobe Acrobat Reader. What makes this threat stand out is that the malicious files carry legitimate-looking digital signatures, making them harder for…
-
Chinese APT Campaign Targets Qatar With PlugX Lures Tied to Middle East Conflict
Chinese APT Campaign Targets Qatar With PlugX Lures Tied to Middle East Conflict A Chinese-linked advanced persistent threat group known as Camaro Dragon launched a targeted cyberespionage campaign against entities in Qatar just one day after the outbreak of new hostilities in the Middle East on March 1, 2026. The group used war-themed lure documents…
-
Malicious npm Package Posing as OpenClaw Installer Deploys RAT, Steals macOS Credentials
Malicious npm Package Posing as OpenClaw Installer Deploys RAT, Steals macOS Credentials Cybersecurity researchers have discovered a malicious npm package that masquerades as an OpenClaw installer to deploy a remote access trojan (RAT) and steal sensitive data from compromised hosts. The package, named “@openclaw-ai/openclawai,” was uploaded to the registry by a user named “openclaw-ai” on…
-
UNC4899 Breached Crypto Firm After Developer AirDropped Trojanized File to Work Device
UNC4899 Breached Crypto Firm After Developer AirDropped Trojanized File to Work Device The North Korean threat actor known as UNC4899 is suspected to be behind a sophisticated cloud compromise campaign targeting a cryptocurrency organization in 2025 to steal millions of dollars in cryptocurrency. The activity has been attributed with moderate confidence to the state-sponsored adversary,…
-
⚡ Weekly Recap: Qualcomm 0-Day, iOS Exploit Chains, AirSnitch Attack & Vibe-Coded Malware
⚡ Weekly Recap: Qualcomm 0-Day, iOS Exploit Chains, AirSnitch Attack & Vibe-Coded Malware Another week in cybersecurity. Another week of “you’ve got to be kidding me.” Attackers were busy. Defenders were busy. And somewhere in the middle, a whole lot of people had a very bad Monday morning. That’s kind of just how it goes…
-
Can the Security Platform Finally Deliver for the Mid-Market?
Can the Security Platform Finally Deliver for the Mid-Market? Mid-market organizations are constantly striving to achieve security levels on a par with their enterprise peers. With heightened awareness of supply chain attacks, your customers and business partners are defining the security level you must meet. What if you could be the enabler for your organization…
-
Chrome Extension Turns Malicious After Ownership Transfer, Enabling Code Injection and Data Theft
Chrome Extension Turns Malicious After Ownership Transfer, Enabling Code Injection and Data Theft Two Google Chrome extensions have turned malicious after what appears to be a case of ownership transfer, offering attackers a way to push malware to downstream customers, inject arbitrary code, and harvest sensitive data. The extensions in question, both originally associated with…
-
New Attack Against Wi-Fi
New Attack Against Wi-Fi It’s called AirSnitch: Unlike previous Wi-Fi attacks, AirSnitch exploits core features in Layers 1 and 2 and the failure to bind and synchronize a client across these and higher layers, other nodes, and other network names such as SSIDs (Service Set Identifiers). This cross-layer identity desynchronization is the key driver of…
-
White House Cyber Strategy Prioritizes Offense
White House Cyber Strategy Prioritizes Offense In a seven-page strategy document, the Trump administration signaled a shift to preemption and deterrence to handling cyber threats. Jai Vijayan Go to gbhackers.com
-
‘InstallFix’ Attacks Spread Fake Claude Code Sites
‘InstallFix’ Attacks Spread Fake Claude Code Sites A fresh cyberattack campaign blends malvertising with a ClickFix-style technique that highlights risky behavior with AI coding assistants and command-line interfaces. Rob Wright Go to gbhackers.com
-
Are We Ready for Auto Remediation With Agentic AI?
Are We Ready for Auto Remediation With Agentic AI? With the rapid innovations in AI, we are entering an exciting era of automated risk remediation. Learn about security team readiness to leverage agentic AI for threat and exposure management. Melinda Marks Go to gbhackers.com
-
Chinese Cyber Threat Lurks In Critical Asian Sectors for Years
Chinese Cyber Threat Lurks In Critical Asian Sectors for Years An undefined Chinese-speaking actor wields a combo of custom malware, open source tools, and LOTL binaries against Windows and Linux, likely for spying. Elizabeth Montalbano Go to gbhackers.com
-
ClipXDaemon Malware Targets Crypto Users in Linux X11 Sessions
ClipXDaemon Malware Targets Crypto Users in Linux X11 Sessions ClipXDaemon is a new Linux malware family that hijacks cryptocurrency clipboard data in X11 sessions, operating fully offline without any command‑and‑control (C2) infrastructure. It… Go to gbhackers.com
-
Cybercrime Group in Vietnam Enables Massive Fraudulent Signups
Cybercrime Group in Vietnam Enables Massive Fraudulent Signups A wave of fraudulent account registrations to a cybercrime ecosystem operating out of Vietnam. These fake accounts are not just spam; they underpin large-scale… Go to gbhackers.com
-
1-Click ZITADEL Vulnerability Could Allow Full System Takeover
1-Click ZITADEL Vulnerability Could Allow Full System Takeover A critical Cross-Site Scripting (XSS) vulnerability has been discovered in ZITADEL, a popular open-source identity and access management platform. Tracked as CVE-2026-29191 with a… Go to gbhackers.com
-
Nginx UI Vulnerabilities Let Attackers Download Full System Backups
Nginx UI Vulnerabilities Let Attackers Download Full System Backups A critical security flaw has been discovered in Nginx UI that allows unauthenticated threat actors to download and decrypt complete system backups. Tracked as… Go to gbhackers.com
-
ExifTool Vulnerability Lets Malicious Images Trigger macOS Code Execution
ExifTool Vulnerability Lets Malicious Images Trigger macOS Code Execution ExifTool is a ubiquitous open-source solution for reading, writing, and editing image metadata. It’s the go-to tool for photographers and digital archivists, and is… Go to gbhackers.com