no alarms and no surprises please..
-
ISC Stormcast For Wednesday, February 25th, 2026 https://isc.sans.edu/podcastdetail/9824, (Wed, Feb 25th)
ISC Stormcast For Wednesday, February 25th, 2026 https://isc.sans.edu/podcastdetail/9824, (Wed, Feb 25th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Open Redirects: A Forgotten Vulnerability?, (Tue, Feb 24th)
Open Redirects: A Forgotten Vulnerability?, (Tue, Feb 24th) In 2010, OWASP added “Unvalidated Redirects and Forwards” to its Top 10 list and merged it into “Sensitive Data Exposure” in 2013 [owasp1] [owasp2]. Open redirects are often overlooked, and their impact is not always well understood. At first, it does not look like a big deal. The…
-
Weekly Update 492
Weekly Update 492 The recurring theme this week seems to be around the gap between breaches happening and individual victims finding out about them. It’s tempting to blame this on the corporate victim of the breach (the hacked company), but they’re simultaneously dealing with a criminal intrusion, a ransom demand, and class-action lawyers knocking down…
-
Attackers Now Need Just 29 Minutes to Own a Network
Attackers Now Need Just 29 Minutes to Own a Network Credential misuse, AI tools, and security blind spots help attackers move through breached networks faster than ever, CrowdStrike finds. Jai Vijayan Go to gbhackers.com
-
Lazarus Group Picks a New Poison: Medusa Ransomware
Lazarus Group Picks a New Poison: Medusa Ransomware The North Korean threat group also leveraged Comebacker backdoor, Blindingcan RAT, and info stealer Infohook in its recent attacks. Rob Wright Go to gbhackers.com
-
As Cybersecurity Firms Chase AI, VC Market Skyrockets
As Cybersecurity Firms Chase AI, VC Market Skyrockets Investments in cybersecurity startups took off in 2025, as venture capital firms focused not just on AI-native tech, but talent as well. Robert Lemos Go to gbhackers.com
-
Malicious NuGet Packages Target ASP.NET Developers to Steal Login Credentials
Malicious NuGet Packages Target ASP.NET Developers to Steal Login Credentials Malicious NuGet packages posing as legitimate developer utilities are targeting ASP.NET projects to steal identity credentials and silently backdoor applications through a localhost proxy. All… Go to gbhackers.com
-
Chinese AI Labs Launch Massive Distillation Attacks on Anthropic Claude, Tracking 13M Exchanges
Chinese AI Labs Launch Massive Distillation Attacks on Anthropic Claude, Tracking 13M Exchanges Anthropic has identified and exposed industrial-scale data extraction campaigns orchestrated by three major Chinese AI laboratories: DeepSeek, Moonshot, and MiniMax. These organizations utilized approximately… Go to gbhackers.com
-
Romanian Cybercriminal Admits Guilt in Scheme Selling Oregon State Government Network Access
Romanian Cybercriminal Admits Guilt in Scheme Selling Oregon State Government Network Access A Romanian national has pleaded guilty to charges related to unauthorized access and sale of network credentials belonging to an Oregon state government office… Go to gbhackers.com
-
Malicious OpenClaw Tactics Deceive Users into Manual Password Entry for AMOS Infection
Malicious OpenClaw Tactics Deceive Users into Manual Password Entry for AMOS Infection Malicious OpenClaw skills are being weaponized to coerce users into manually entering their passwords, enabling a new Atomic (AMOS) Stealer infection chain that abuses… Go to gbhackers.com
-
ZeroDayRAT Targets Android and iOS Devices for Surveillance and Financial Data Theft
ZeroDayRAT Targets Android and iOS Devices for Surveillance and Financial Data Theft ZeroDayRAT targets Android and iOS devices, combining real-time surveillance with direct financial theft within a single browser panel. The Malware-as-a-Service (MaaS) ecosystem is entering a new phase, blending mobile surveillance and… Go to gbhackers.com
-
Android mental health apps with 14.7M installs filled with security flaws
Android mental health apps with 14.7M installs filled with security flaws Several mental health mobile apps with millions of downloads on Google Play contain security vulnerabilities that could expose users’ sensitive medical information. […] Ionut Ilascu Go to bleepingcomputer
-
Spain arrests suspected hacktivists for DDoSing govt sites
Spain arrests suspected hacktivists for DDoSing govt sites Spanish authorities have arrested four alleged members of a hacktivist group believed to have carried out cyberattacks targeting government ministries, political parties, and various public institutions. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft says bug in classic Outlook hides the mouse pointer
Microsoft says bug in classic Outlook hides the mouse pointer Microsoft is investigating a known issue that causes the mouse pointer to disappear in the classic Outlook desktop email client for some users. […] Sergiu Gatlan Go to bleepingcomputer
-
Ad tech firm Optimizely confirms data breach after vishing attack
Ad tech firm Optimizely confirms data breach after vishing attack New York-based ad tech company Optimizely has notified an undisclosed number of customers of a data breach after threat actors compromised some of its systems in a voice phishing attack. […] Sergiu Gatlan Go to bleepingcomputer
-
When identity isn’t the weak link, access still is
When identity isn’t the weak link, access still is Stolen tokens and compromised devices let attackers reuse trust without breaking authentication. Specops Software explains why identity alone isn’t enough and how continuous device verification strengthens Zero Trust. […] Sponsored by Specops Software Go to bleepingcomputer
-
ShinyHunters Allegedly Claim Breach of 21 Million Records from Odido
ShinyHunters Allegedly Claim Breach of 21 Million Records from Odido The notorious cybercriminal group has claimed responsibility for a massive data breach targeting the Dutch telecommunications company Odido and its brand BEN. The group ShinyHunters claims to have stolen 21 million records from 8 million customers, suggesting the incident is far more severe than previously…
-
OpenClaw Releases 2026.2.23 Released With Security Updates and New AI features
OpenClaw Releases 2026.2.23 Released With Security Updates and New AI features OpenClaw, the open-source personal AI assistant with over 215,000 GitHub stars, has released version 2026.2.23, emphasizing robust security hardening alongside advanced AI integrations. This update addresses multiple vulnerabilities and introduces features like Claude Opus 4.6 support, making it a timely boost for privacy-focused users…
-
Hackers Leverage DeepSeek and Claude to Attack FortiGate Devices Worldwide
Hackers Leverage DeepSeek and Claude to Attack FortiGate Devices Worldwide In early February 2026, a significant cybersecurity threat emerged involving the sophisticated use of Large Language Models (LLMs) in active intrusion campaigns. A misconfigured server exposed a detailed software pipeline where threat actors integrated DeepSeek and Claude into their attack workflows. This discovery highlights a…
-
WhatsApp Introduces Optional Account Password Feature to Strengthen Login Security
WhatsApp Introduces Optional Account Password Feature to Strengthen Login Security WhatsApp has released a new Android update through the Google Play Beta Program, bringing the version up to 2.26.7.8. The update reveals that WhatsApp is actively developing an optional account password feature designed to add another layer of security on top of the existing two-step…
-
$10K+ Bounty Offered to Hacker Who Can Disconnect Ring Video Doorbells from Amazon Cloud
$10K+ Bounty Offered to Hacker Who Can Disconnect Ring Video Doorbells from Amazon Cloud A newly launched bug bounty program is offering nearly $18,000 to anyone who can successfully disconnect Ring Video Doorbells from Amazon’s cloud servers while keeping the devices fully functional. This initiative aims to address ongoing privacy concerns about Ring’s data-handling practices…
-
Faking it on the phone: How to tell if a voice call is AI or not
Faking it on the phone: How to tell if a voice call is AI or not Can you believe your ears? Increasingly, the answer is no. Here’s what’s at stake for your business, and how to beat the deepfakers. Go to eset
-
APT28 Targeted European Entities Using Webhook-Based Macro Malware
APT28 Targeted European Entities Using Webhook-Based Macro Malware The Russia-linked state-sponsored threat actor tracked as APT28 has been attributed to a new campaign targeting specific entities in Western and Central Europe. The activity, per S2 Grupo’s LAB52 threat intelligence team, was active between September 2025 and January 2026. It has been codenamed Operation MacroMaze. “The…
-
Wormable XMRig Campaign Uses BYOVD Exploit and Time-Based Logic Bomb
Wormable XMRig Campaign Uses BYOVD Exploit and Time-Based Logic Bomb Cybersecurity researchers have disclosed details of a new cryptojacking campaign that uses pirated software bundles as lures to deploy a bespoke XMRig miner program on compromised hosts. “Analysis of the recovered dropper, persistence triggers, and mining payload reveals a sophisticated, multi-stage infection prioritizing maximum cryptocurrency…
-
⚡ Weekly Recap: Double-Tap Skimmers, PromptSpy AI, 30Tbps DDoS, Docker Malware & More
⚡ Weekly Recap: Double-Tap Skimmers, PromptSpy AI, 30Tbps DDoS, Docker Malware & More Security news rarely moves in a straight line. This week, it feels more like a series of sharp turns, some happening quietly in the background, others playing out in public view. The details are different, but the pressure points are familiar. Across…
-
How Exposed Endpoints Increase Risk Across LLM Infrastructure
How Exposed Endpoints Increase Risk Across LLM Infrastructure As more organizations run their own Large Language Models (LLMs), they are also deploying more internal services and Application Programming Interfaces (APIs) to support those models. Modern security risks are being introduced less from the models themselves and more from the infrastructure that serves, connects and automates…
-
Malicious npm Packages Harvest Crypto Keys, CI Secrets, and API Tokens
Malicious npm Packages Harvest Crypto Keys, CI Secrets, and API Tokens Cybersecurity researchers have disclosed what they say is an active “Shai-Hulud-like” supply chain worm campaign that has leveraged a cluster of at least 19 malicious npm packages to enable credential harvesting and cryptocurrency key theft. The campaign has been codenamed SANDWORM_MODE by supply chain…
-
On the Security of Password Managers
On the Security of Password Managers Good article on password managers that secretly have a backdoor. New research shows that these claims aren’t true in all cases, particularly when account recovery is in place or password managers are set to share vaults or organize users into groups. The researchers reverse-engineered or closely analyzed Bitwarden, Dashlane,…
-
ISC Stormcast For Tuesday, February 24th, 2026 https://isc.sans.edu/podcastdetail/9822, (Tue, Feb 24th)
ISC Stormcast For Tuesday, February 24th, 2026 https://isc.sans.edu/podcastdetail/9822, (Tue, Feb 24th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Another day, another malicious JPEG, (Mon, Feb 23rd)
Another day, another malicious JPEG, (Mon, Feb 23rd) In his last two diaries, Xavier discussed recent malware campaigns that download JPEG files with embedded malicious payload[1,2]. At that point in time, I’ve not come across the malicious “MSI image” myself, but while I was going over malware samples that were caught by one of my…
-
Spitting Cash: ATM Jackpotting Attacks Surged in 2025
Spitting Cash: ATM Jackpotting Attacks Surged in 2025 The attacks cost banks more than $20 million in losses last year, as criminals used many of the same tools and tactics they have wielded for more than a decade. Jai Vijayan Go to gbhackers.com
-
Iran’s MuddyWater Targets Orgs With Fresh Malware as Tensions Mount
Iran’s MuddyWater Targets Orgs With Fresh Malware as Tensions Mount The long-active Iranian threat group debuted various attack strains and payloads in attacks against organizations in the Middle East and Africa. Elizabeth Montalbano Go to gbhackers.com
-
Enigma Cipher Device Still Holds Secrets for Cyber Pros
Enigma Cipher Device Still Holds Secrets for Cyber Pros The Nazi relic’s history is riddled with resilience errors, and those lessons still apply to defending against modern cyber threats. Becky Bracken Go to gbhackers.com
-
Starkiller Phishing Kit Clones Real Login Pages to Evade MFA Protections
Starkiller Phishing Kit Clones Real Login Pages to Evade MFA Protections New phishing framework Starkiller is enabling more convincing, scalable credential theft by proxying real login pages and bypassing multi-factor authentication (MFA), significantly raising the… Go to gbhackers.com
-
CISA Warns of Actively Exploited Roundcube Vulnerabilities
CISA Warns of Actively Exploited Roundcube Vulnerabilities On February 20, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) updated its Known Exploited Vulnerabilities (KEV) Catalog by adding two critical flaws in… Go to gbhackers.com
-
jsPDF Flaw Exposes Millions of Developers to Object Injection
jsPDF Flaw Exposes Millions of Developers to Object Injection A serious security flaw in jsPDF, a widely used JavaScript library for generating PDFs in web browsers, puts millions of developers and their users… Go to gbhackers.com
-
HPE Telco Service Activator Vulnerability Allows Attackers to Bypass Access Controls
HPE Telco Service Activator Vulnerability Allows Attackers to Bypass Access Controls Hewlett Packard Enterprise (HPE) has issued a security bulletin warning customers of a serious vulnerability in its Telco Service Activator product that could allow attackers to… Go to gbhackers.com
-
North Korean Hackers Exploit Fake IT Worker Schemes and Malicious Interview Lures
North Korean Hackers Exploit Fake IT Worker Schemes and Malicious Interview Lures North Korean state-backed hackers are running large-scale fake IT worker and “Contagious Interview” campaigns that abuse developer hiring workflows to deliver JavaScript-based malware, steal… Go to gbhackers.com
-
Arkanix Stealer pops up as short-lived AI info-stealer experiment
Arkanix Stealer pops up as short-lived AI info-stealer experiment An information-stealing malware operation named Arkanix Stealer, promoted on multiple dark web forums towards the end of 2025, was likely developed as an AI-assisted experiment. […] Bill Toulas Go to bleepingcomputer
-
Google Suspends OpenClaw Users from Antigravity AI After OAuth Token Abuse
Google Suspends OpenClaw Users from Antigravity AI After OAuth Token Abuse Google has suspended access to its Antigravity AI platform for numerous users of the open-source tool OpenClaw, sparking backlash over aggressive enforcement of terms of service (ToS). The move targets developers leveraging OpenClaw’s OAuth plugin to tap into subsidized Gemini model tokens, which caused…
-
DPRK Linked Operators Sustain Aggressive Crypto Targeting 12 Months After Bybit Breach
DPRK Linked Operators Sustain Aggressive Crypto Targeting 12 Months After Bybit Breach February 21, 2026, marks one year since North Korea (DPRK)-linked operators stole approximately $1.46 billion in cryptoassets from Dubai-based exchange Bybit — the largest confirmed crypto theft in history. Rather than slowing down after that breach, the group has only become more active,…
-
Silver Fox APT Uses DLL Sideloading and BYOVD Techniques in Sophisticated Malware Attacks
Silver Fox APT Uses DLL Sideloading and BYOVD Techniques in Sophisticated Malware Attacks The cybersecurity community recently witnessed the emergence of targeted malware campaigns linked to the Silver Fox threat group. This operation focuses heavily on Asia, targeting local organizations with carefully localized lures. By disguising attacks as routine business communications, actors successfully distributed the…
-
Threat Actors Allegedly Selling WhatsApp Crash Exploit on Hacking Forums
Threat Actors Allegedly Selling WhatsApp Crash Exploit on Hacking Forums A recent discovery on underground hacking forums has raised alarms about a new exploit targeting the popular messaging application, WhatsApp. Threat intelligence platforms have identified a threat actor allegedly offering a script designed to crash the application across multiple operating systems. This development highlights the…
-
Google Blocked 1.75 Million Malicious Apps from Entering into the Play Store
Google Blocked 1.75 Million Malicious Apps from Entering into the Play Store AI-powered security systems blocked over 1.75 million malicious or policy-violating apps from reaching the Play Store in 2025, strengthening Android security. According to Google’s latest Android and Google Play security update, the company blocked over 1.75 million apps during the review process. The…
-
ISC Stormcast For Monday, February 23rd, 2026 https://isc.sans.edu/podcastdetail/9820, (Mon, Feb 23rd)
ISC Stormcast For Monday, February 23rd, 2026 https://isc.sans.edu/podcastdetail/9820, (Mon, Feb 23rd) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Anthropic Debuts Claude Code Security – AI Now Scan Vulnerabilities in Your Entire Codebase
Anthropic Debuts Claude Code Security – AI Now Scan Vulnerabilities in Your Entire Codebase Anthropic has quietly flipped the script on application security. On February 20, the company launched Claude Code Security, a new capability baked directly into Claude… Go to gbhackers.com
-
Predator spyware hooks iOS SpringBoard to hide mic, camera activity
Predator spyware hooks iOS SpringBoard to hide mic, camera activity Intellexa’s Predator spyware can hide iOS recording indicators while secretly streaming camera and microphone feeds to its operators. […] Bill Toulas Go to bleepingcomputer
-
Amazon: AI-assisted hacker breached 600 Fortinet firewalls in 5 weeks
Amazon: AI-assisted hacker breached 600 Fortinet firewalls in 5 weeks Amazon is warning that a Russian-speaking hacker used multiple generative AI services as part of a campaign that breached more than 600 FortiGate firewalls across 55 countries in five weeks. […] Lawrence Abrams Go to bleepingcomputer
-
Multiple Hacking Groups Exploit OpenClaw Instances to Steal API key and Deploy Malware
Multiple Hacking Groups Exploit OpenClaw Instances to Steal API key and Deploy Malware A widespread exploitation of OpenClaw, formerly known as MoltBot and ClawdBot, by multiple hacking groups to deploy malicious payloads. OpenClaw, an open-source autonomous AI framework developed by Peter Steinberger, now at OpenAI, has become a high-severity target following its viral adoption in late January 2026. Its…
-
Cloudflare Down – 6 Hour of Massive Global Service Outage Cause Customers Unreachable From the Internet
Cloudflare Down – 6 Hour of Massive Global Service Outage Cause Customers Unreachable From the Internet Cloudflare experienced a significant six-hour global service outage on February 20, 2026, causing major disruptions for customers utilizing its Bring Your Own IP (BYOIP) services. The incident, which began at 17:48 UTC and lasted for six hours and seven…
-
Hackers Leveraging Multiple AI Services to Compromise 600+ FortiGate Devices
Hackers Leveraging Multiple AI Services to Compromise 600+ FortiGate Devices A financially motivated threat actor exploited various commercial generative AI services to compromise over 600 FortiGate devices across more than 55 countries between January 11 and February 18, 2026. The campaign marks a defining demonstration of how AI is lowering the technical entry barrier to…
-
SuperClaw – Open-Source Framework to Red-Team AI Agents for Security Testing
SuperClaw – Open-Source Framework to Red-Team AI Agents for Security Testing Superagentic AI has released SuperClaw, an open-source, pre-deployment security testing framework built specifically for autonomous AI coding agents. Announced in late 2025, SuperClaw addresses a growing blind spot in enterprise AI adoption: agents are routinely deployed with broad tool access and high privileges, yet…
-
Cybersecurity Companies’ Stocks Fall Sharply as Anthropic Releases Claude Security Tool
Cybersecurity Companies’ Stocks Fall Sharply as Anthropic Releases Claude Security Tool Shares of major cybersecurity companies nosedived on Friday after AI startup Anthropic unveiled Claude Code Security, a new AI-powered tool capable of autonomously scanning codebases for software vulnerabilities and suggesting targeted patches sparking fears that artificial intelligence could begin displacing traditional enterprise security solutions.…
-
AI-Assisted Threat Actor Compromises 600+ FortiGate Devices in 55 Countries
AI-Assisted Threat Actor Compromises 600+ FortiGate Devices in 55 Countries A Russian-speaking, financially motivated threat actor has been observed taking advantage of commercial generative artificial intelligence (AI) services to compromise over 600 FortiGate devices located in 55 countries. That’s according to new findings from Amazon Threat Intelligence, which said it observed the activity between January…
-
Anthropic Launches Claude Code Security for AI-Powered Vulnerability Scanning
Anthropic Launches Claude Code Security for AI-Powered Vulnerability Scanning Artificial intelligence (AI) company Anthropic has begun to roll out a new security feature for Claude Code that can scan a user’s software codebase for vulnerabilities and suggest patches. The capability, called Claude Code Security, is currently available in a limited research preview to Enterprise and…
-
CISA Adds Two Actively Exploited Roundcube Flaws to KEV Catalog
CISA Adds Two Actively Exploited Roundcube Flaws to KEV Catalog The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Roundcube webmail software to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities in question are listed below – CVE-2025-49113 (CVSS score: 9.9) – A deserialization…
-
EC-Council Expands AI Certification Portfolio to Strengthen U.S. AI Workforce Readiness and Security
EC-Council Expands AI Certification Portfolio to Strengthen U.S. AI Workforce Readiness and Security With $5.5 trillion in global AI risk exposure and 700,000 U.S. workers needing reskilling, four new AI certifications and Certified CISO v4 help close the gap between AI adoption and workforce readiness. EC-Council, creator of the world-renowned Certified Ethical Hacker (CEH) credential…
-
Japanese-Language Phishing Emails, (Sat, Feb 21st)
Japanese-Language Phishing Emails, (Sat, Feb 21st) Introduction For at least the past year or so, I’ve been receiving Japanese-language phishing emails to my blog email addresses at @malware-traffic-analysis.net. I’m not Japanese, but I suppose my blog’s email addresses ended up on a list used by the group sending these emails. They’re all easily caught by…
-
PayPal Data Breach – 6 Months of Users’ Data Leaked Online
PayPal Data Breach – 6 Months of Users’ Data Leaked Online PayPal has begun notifying a small number of customers about a significant cybersecurity incident in which their personally identifiable information (PII) was exposed for… Go to gbhackers.com
-
Silicon Valley Engineers Indicted for Alleged Trade Secret Theft From Google and Tech Firms
Silicon Valley Engineers Indicted for Alleged Trade Secret Theft From Google and Tech Firms Federal authorities arrested three Silicon Valley engineers on Thursday, charging them with conspiring to steal trade secrets from Google and other tech giants. The… Go to gbhackers.com
-
Critical Jenkins Flaw Exposes Build Environments to XSS Attacks
Critical Jenkins Flaw Exposes Build Environments to XSS Attacks A popular open-source automation server used by developers worldwide to build, test, and deploy software faces serious security risks from recent flaws. On February… Go to gbhackers.com
-
Google Blocks 1.75 Million Malicious Apps from Entering Play Store
Google Blocks 1.75 Million Malicious Apps from Entering Play Store Google has revealed that it blocked more than 1.75 million malicious or policy‑violating Android apps from reaching users through the Play Store in 2025,… Go to gbhackers.com
-
Grandstream VoIP Phones Vulnerability Grants Attackers Root Privileges
Grandstream VoIP Phones Vulnerability Grants Attackers Root Privileges A critical unauthenticated stack-based buffer overflow vulnerability, tracked as CVE-2026-2329, affecting Grandstream GXP1600 series VoIP phones. The vulnerability, rated as critical with a CVSS score of 9.8, allows remote… Go to gbhackers.com
-
Japanese tech giant Advantest hit by ransomware attack
Japanese tech giant Advantest hit by ransomware attack Advantest Corporation disclosed that its corporate network has been targeted in a ransomware attack that may have affected customer or employee data. […] Bill Toulas Go to bleepingcomputer
-
CISA: BeyondTrust RCE flaw now exploited in ransomware attacks
CISA: BeyondTrust RCE flaw now exploited in ransomware attacks Hackers are actively exploiting the CVE-2026-1731 vulnerability in the BeyondTrust Remote Support product, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns. […] Bill Toulas Go to bleepingcomputer
-
Data breach at French bank registry impacts 1.2 million accounts
Data breach at French bank registry impacts 1.2 million accounts The French Ministry of Finance has published an announcement informing of a cybersecurity incident that has impacted 1.2 million accounts. […] Bill Toulas Go to bleepingcomputer
-
Why the shift left dream has become a nightmare for security and developers
Why the shift left dream has become a nightmare for security and developers The “shift left” approach has increased pressure on developers, as speed demands override security checks in modern CI pipelines. Qualys explains how analyzing 34,000 public container images revealed 7.3% were malicious and why security must be enforced at the infrastructure layer by…
-
PayPal discloses data breach that exposed user info for 6 months
PayPal discloses data breach that exposed user info for 6 months PayPal is notifying customers of a data breach after a software error in a loan application exposed their sensitive personal information, including Social Security numbers, for nearly 6 months last year. […] Sergiu Gatlan Go to bleepingcomputer
-
Anthropic Launches Claude Code Security to Scan Codebases for Security Vulnerabilities
Anthropic Launches Claude Code Security to Scan Codebases for Security Vulnerabilities A new feature inside Claude Code enables developers and security teams to identify and remediate vulnerabilities across their codebases, known as Claude Code Security. Currently available in a limited research preview, the tool offers AI-powered code scanning that goes beyond conventional static analysis by…
-
PayPal Data Breach Exposes SSNs and Business PII of Customers for Over Six Months
PayPal Data Breach Exposes SSNs and Business PII of Customers for Over Six Months PayPal has issued a formal data breach notification disclosing that a coding error in its PayPal Working Capital (PPWC) loan application exposed the personally identifiable information (PII) of an undisclosed number of customers for approximately six months, from July 1, 2025,…
-
Grandstream VoIP Phones Vulnerability Allows Attackers to Gain Root Privileges
Grandstream VoIP Phones Vulnerability Allows Attackers to Gain Root Privileges VoIP desk phones are trusted devices, but many are managed like office furniture. A newly disclosed flaw in Grandstream phones shows how a simple network-facing bug can turn a handset into an entry point for eavesdropping and wider access. In a typical attack, the goal…
-
CharlieKirk Grabber Stealer Attacking Windows Systems to Exfiltrate Login Credentials
CharlieKirk Grabber Stealer Attacking Windows Systems to Exfiltrate Login Credentials A new Python-based infostealer called CharlieKirk Grabber has been identified targeting Windows systems, with a focused goal of stealing stored login credentials, browser cookies, and session data. The malware is built to work as a “smash-and-grab” threat — it launches quickly, collects whatever sensitive data…
-
Critical Jenkins Vulnerability Exposes Build Environments to XSS Attacks
Critical Jenkins Vulnerability Exposes Build Environments to XSS Attacks Security Advisory has revealed multiple vulnerabilities in Jenkins Core, including a stored Cross-Site Scripting (XSS) flaw that could expose build environments to severe security risks. The issues, identified as CVE-2026-27099 and CVE-2026-27100, were responsibly disclosed under the Jenkins Bug Bounty Program sponsored by the European Commission. The most critical of the…
-
TR-26-0081 (Kolay Yazılım – Talentics Güvenlik Bildirimi)
TR-26-0081 (Kolay Yazılım – Talentics Güvenlik Bildirimi) Go to usom.gov
-
BeyondTrust Flaw Used for Web Shells, Backdoors, and Data Exfiltration
BeyondTrust Flaw Used for Web Shells, Backdoors, and Data Exfiltration Threat actors have been observed exploiting a recently disclosed critical security flaw impacting BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) products to conduct a wide range of malicious actions, including deploying VShell and The vulnerability, tracked as CVE-2026-1731 (CVSS score: 9.9), allows attackers…
-
Cline CLI 2.3.0 Supply Chain Attack Installed OpenClaw on Developer Systems
Cline CLI 2.3.0 Supply Chain Attack Installed OpenClaw on Developer Systems In yet another software supply chain attack, the open-source, artificial intelligence (AI)-powered coding assistant Cline CLI was updated to stealthily install OpenClaw, a self-hosted autonomous AI agent that has become exceedingly popular in the past few months. “On February 17, 2026, at 3:26 AM…
-
ClickFix Campaign Abuses Compromised Sites to Deploy MIMICRAT Malware
ClickFix Campaign Abuses Compromised Sites to Deploy MIMICRAT Malware Cybersecurity researchers have disclosed details of a new ClickFix campaign that abuses compromised legitimate sites to deliver a previously undocumented remote access trojan (RAT) called MIMICRAT (aka AstarionRAT). “The campaign demonstrates a high level of operational sophistication: compromised sites spanning multiple industries and geographies serve as…
-
Identity Cyber Scores: The New Metric Shaping Cyber Insurance in 2026
Identity Cyber Scores: The New Metric Shaping Cyber Insurance in 2026 With one in three cyber-attacks now involving compromised employee accounts, insurers and regulators are placing far greater emphasis on identity posture when assessing cyber risk. For many organizations, however, these assessments remain largely opaque. Elements such as password hygiene, privileged access management, and the…
-
Ukrainian National Sentenced to 5 Years in North Korea IT Worker Fraud Case
Ukrainian National Sentenced to 5 Years in North Korea IT Worker Fraud Case A 29-year-old Ukrainian national has been sentenced to five years in prison in the U.S. for his role in facilitating North Korea’s fraudulent information technology (IT) worker scheme. In November 2025, Oleksandr “Alexander” Didenko pleaded guilty to wire fraud conspiracy and aggravated…
-
Friday Squid Blogging: Squid Cartoon
Friday Squid Blogging: Squid Cartoon I like this one. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy. Bruce Schneier Go to bruce schneier
-
Ring Cancels Its Partnership with Flock
Ring Cancels Its Partnership with Flock It’s a demonstration of how toxic the surveillance-tech company Flock has become when Amazon’s Ring cancels the partnership between the two companies. As Hamilton Nolan advises, remove your Ring doorbell. Bruce Schneier Go to bruce schneier
-
Spanish police say they have arrested hacker who booked luxury hotel rooms for just one cent
Spanish police say they have arrested hacker who booked luxury hotel rooms for just one cent Spain’s police force has announced that it has arrested a 20-year-old man who they claim managed to book luxury hotel rooms worth up to €1,000 a night for just one euro cent. Read more in my article on the…
-
Attackers Use New Tool to Scan for React2Shell Exposure
Attackers Use New Tool to Scan for React2Shell Exposure Researchers say threat actors wielded the sophisticated — and unfortunately named — toolkit to target high-value networks for React2Shell exploitation. Nate Nelson Go to gbhackers.com
-
‘God-Like’ Attack Machines: AI Agents Ignore Security Policies
‘God-Like’ Attack Machines: AI Agents Ignore Security Policies Microsoft Copilot recently summarized and leaked user emails; but any AI agent will go above and beyond to complete assigned tasks, even breaking through their carefully designed guardrails. Robert Lemos Go to gbhackers.com
-
Lessons From AI Hacking: Every Model, Every Layer Is Risky
Lessons From AI Hacking: Every Model, Every Layer Is Risky After two years of finding flaws in AI infrastructure, two Wiz researchers advise security pros to worry less about prompt injection and more about vulnerabilities. Robert Lemos Go to gbhackers.com
-
Latin America’s Cyber Maturity Lags Threat Landscape
Latin America’s Cyber Maturity Lags Threat Landscape The slower pace of upgrades has the unintended impact of creating a haven for attackers, especially for initial access brokers and ransomware gangs. Alexander Culafi Go to gbhackers.com
-
Emerging Chiplet Designs Spark Fresh Cybersecurity Challenges
Emerging Chiplet Designs Spark Fresh Cybersecurity Challenges As scaled-down circuits with limited functions redefine computing for AI systems and autonomous vehicles, their flexibility demands new approaches to safeguard critical infrastructure. Agam Shah Go to gbhackers.com
-
FBI Issues Emergency Alert as Ploutus Malware Drains U.S. ATMs Without Cards or Accounts
FBI Issues Emergency Alert as Ploutus Malware Drains U.S. ATMs Without Cards or Accounts Ploutus malware is powering a new wave of “jackpotting” attacks that drain U.S. ATMs without needing a bank card, customer account, or bank authorization,… Go to gbhackers.com
-
LLM-Generated Passwords Expose Security Risks with Predictability and Weakness
LLM-Generated Passwords Expose Security Risks with Predictability and Weakness LLM-generated passwords may look complex and “high entropy,” but new research shows they are highly predictable, frequently repeated, and far weaker than traditional cryptographic… Go to gbhackers.com
-
Google Rushes Out Critical Chrome Update to Address Serious PDFium and V8 Vulnerabilities
Google Rushes Out Critical Chrome Update to Address Serious PDFium and V8 Vulnerabilities Google has rushed out a vital security patch for Chrome, fixing three flaws that could let attackers run malicious code on users’ devices. The Stable… Go to gbhackers.com
-
Hackers Exploit Critical BeyondTrust Vulnerability to Deploy VShell and SparkRAT
Hackers Exploit Critical BeyondTrust Vulnerability to Deploy VShell and SparkRAT Hackers are actively exploiting a critical vulnerability in BeyondTrust’s remote support software to deploy the VShell backdoor and SparkRAT remote access trojan, enabling full… Go to gbhackers.com
-
Ongoing Campaign Targets Microsoft 365 to Steal OAuth Tokens for Persistent Access
Ongoing Campaign Targets Microsoft 365 to Steal OAuth Tokens for Persistent Access A new phishing campaign exploiting Microsoft’s OAuth 2.0 Device Authorization Grant flow to gain unauthorized and persistent access to Microsoft 365 accounts. The sophisticated… Go to gbhackers.com
-
Ukrainian gets 5 years for helping North Koreans infiltrate US firms
Ukrainian gets 5 years for helping North Koreans infiltrate US firms A Ukrainian national was sentenced to five years in prison for providing North Korean IT workers with stolen identities that helped them infiltrate U.S. companies. […] Sergiu Gatlan Go to bleepingcomputer
-
PromptSpy is the first known Android malware to use generative AI at runtime
PromptSpy is the first known Android malware to use generative AI at runtime Researchers have discovered the first known Android malware to use generative AI in its execution flow, using Google’s Gemini model to adapt its persistence across different devices. […] Lawrence Abrams Go to bleepingcomputer
-
Flaw in Grandstream VoIP phones allows stealthy eavesdropping
Flaw in Grandstream VoIP phones allows stealthy eavesdropping A critical vulnerability in Grandstream GXP1600 series VoIP phones allows a remote, unauthenticated attacker to gain root privileges and silently eavesdrop on communications. […] Bill Toulas Go to bleepingcomputer
-
Google blocked over 1.75 million Play Store app submissions in 2025
Google blocked over 1.75 million Play Store app submissions in 2025 Google says that through 2025, it blocked more than 255,000 Android apps from obtaining excessive access to sensitive user data and rejected over 1.75 million apps from being published on Google Play due to policy violations. […] Bill Toulas Go to bleepingcomputer
-
CISA orders feds to patch actively exploited Dell flaw within 3 days
CISA orders feds to patch actively exploited Dell flaw within 3 days The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered government agencies to patch their systems within three days against a maximum-severity Dell vulnerability that has been under active exploitation since mid-2024. […] Sergiu Gatlan Go to bleepingcomputer
-
PoC Released for Windows Notepad Vulnerability that Enables Malicious Command Execution
PoC Released for Windows Notepad Vulnerability that Enables Malicious Command Execution Microsoft has patched a high-severity remote code execution (RCE) vulnerability in the modern Windows Notepad application, tracked as CVE-2026-20841, as part of its February 2026 Patch Tuesday release cycle. The flaw, rooted in command injection, was originally discovered by Cristian Papa and Alasdair Gorniak…
-
Hackers Actively Exploiting Critical BeyondTrust Vulnerability to Deploy VShell and SparkRAT
Hackers Actively Exploiting Critical BeyondTrust Vulnerability to Deploy VShell and SparkRAT A critical vulnerability in BeyondTrust’s remote support software is being actively exploited by hackers to deliver dangerous backdoors on compromised systems. The flaw, tracked as CVE-2026-1731, carries a CVSS score of 9.9 and lets attackers run system commands with no login required. BeyondTrust released…