no alarms and no surprises please..
-
Hackers Using OAuth Apps in Microsoft Entra ID to Establish Persistence
Hackers Using OAuth Apps in Microsoft Entra ID to Establish Persistence Hackers are increasingly abusing OAuth applications in Microsoft Entra ID to gain persistent access, blending in as normal “business integrations” while keeping access even after defenders reset passwords. Recent Wiz research and incident reporting show attackers using fake OAuth apps, deceptive consent prompts, and redirect URLs…
-
Ongoing Campaign Targets Microsoft 365 to Steal OAuth Tokens and Gain Persistent Access
Ongoing Campaign Targets Microsoft 365 to Steal OAuth Tokens and Gain Persistent Access An ongoing phishing campaign that targets Microsoft 365 users by abusing OAuth tokens to gain long‑term access to corporate data, which focuses on business users in North America and aims to compromise Outlook, Teams, and OneDrive without directly stealing passwords. Instead of…
-
PentAGI – Automated AI-Powered Penetration Testing Tool that Integrates 20+ Security Tools
PentAGI – Automated AI-Powered Penetration Testing Tool that Integrates 20+ Security Tools PentAGI introduces an AI-driven approach to penetration testing, automating complex workflows with tools like Nmap and Metasploit while generating detailed reports. Developed by VXControl and released on GitHub in early 2025, this open-source platform empowers security professionals to conduct autonomous assessments in isolated…
-
PromptSpy ushers in the era of Android threats using GenAI
PromptSpy ushers in the era of Android threats using GenAI ESET researchers discover PromptSpy, the first known Android malware to abuse generative AI in its execution flow Go to eset
-
Is Poshmark safe? How to buy and sell without getting scammed
Is Poshmark safe? How to buy and sell without getting scammed Like any other marketplace, the social commerce platform has its share of red flags. It pays to know what to look for so you can shop or sell without headaches. Go to eset
-
TR-26-0080 (Aida64 Engineer Güvenlik Zafiyeti)
TR-26-0080 (Aida64 Engineer Güvenlik Zafiyeti) Go to usom.gov
-
TR-26-0079 (WordPress Eklenti Güvenlik Bildirimi)
TR-26-0079 (WordPress Eklenti Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0078 (DATABASE Yazılım – Databank Akreditasyon Yazılımı Güvenlik Bildirimi)
TR-26-0078 (DATABASE Yazılım – Databank Akreditasyon Yazılımı Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0077 (Inrove Yazılım – BiEticaret CMS Güvenlik Bildirimi)
TR-26-0077 (Inrove Yazılım – BiEticaret CMS Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0076 (MeCODE Bilişim – Envanty Güvenlik Bildirimi)
TR-26-0076 (MeCODE Bilişim – Envanty Güvenlik Bildirimi) Go to usom.gov
-
Three Former Google Engineers Indicted Over Trade Secret Transfers to Iran
Three Former Google Engineers Indicted Over Trade Secret Transfers to Iran Two former Google engineers and one of their husbands have been indicted in the U.S. for allegedly committing trade secret theft from the search giant and other tech firms and transferring the information to unauthorized locations, including Iran. Samaneh Ghandali, 41, and her husband…
-
PromptSpy Android Malware Abuses Gemini AI to Automate Recent-Apps Persistence
PromptSpy Android Malware Abuses Gemini AI to Automate Recent-Apps Persistence Cybersecurity researchers have discovered what they say is the first Android malware that abuses Gemini, Google’s generative artificial intelligence (AI) chatbot, as part of its execution flow and achieves persistence. The malware has been codenamed PromptSpy by ESET. The malware is equipped to capture lockscreen…
-
INTERPOL Operation Red Card 2.0 Arrests 651 in African Cybercrime Crackdown
INTERPOL Operation Red Card 2.0 Arrests 651 in African Cybercrime Crackdown An international cybercrime operation against online scams has led to 651 arrests and recovered more than $4.3 million as part of an effort led by law enforcement agencies from 16 African countries. The initiative, codenamed Operation Red Card 2.0, took place between December 8,…
-
Microsoft Patches CVE-2026-26119 Privilege Escalation in Windows Admin Center
Microsoft Patches CVE-2026-26119 Privilege Escalation in Windows Admin Center Microsoft has disclosed a now-patched security flaw in Windows Admin Center that could allow an attacker to escalate their privileges. Windows Admin Center is a locally deployed, browser-based management tool set that lets users manage their Windows Clients, Servers, and Clusters without the need for connecting…
-
ThreatsDay Bulletin: OpenSSL RCE, Foxit 0-Days, Copilot Leak, AI Password Flaws & 20+ Stories
ThreatsDay Bulletin: OpenSSL RCE, Foxit 0-Days, Copilot Leak, AI Password Flaws & 20+ Stories The cyber threat space doesn’t pause, and this week makes that clear. New risks, new tactics, and new security gaps are showing up across platforms, tools, and industries — often all at the same time. Some developments are headline-level. Others sit…
-
February’s Patch Tuesday assumes battle stations
February’s Patch Tuesday assumes battle stations Just 58 CVEs to spar with in February, but plenty are already under attack Categories: Threat Research, X-ops Tags: Patch Tuesday, Microsoft, Windows Go to sophos
-
Malicious AI
Malicious AI Interesting: Summary: An AI agent of unknown ownership autonomously wrote and published a personalized hit piece about me after I rejected its code, attempting to damage my reputation and shame me into accepting its changes into a mainstream python library. This represents a first-of-its-kind case study of misaligned AI behavior in the wild,…
-
ISC Stormcast For Friday, February 20th, 2026 https://isc.sans.edu/podcastdetail/9818, (Fri, Feb 20th)
ISC Stormcast For Friday, February 20th, 2026 https://isc.sans.edu/podcastdetail/9818, (Fri, Feb 20th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Under the Hood of DynoWiper, (Thu, Feb 19th)
Under the Hood of DynoWiper, (Thu, Feb 19th) [This is a Guest Diary contributed by John Moutos] Overview In this post, I’m going over my analysis of DynoWiper, a wiper family that was discovered during attacks against Polish energy companies in late December of 2025. ESET Research [1] and CERT Polska [2] have linked the…
-
Supply Chain Attack Secretly Installs OpenClaw for Cline Users
Supply Chain Attack Secretly Installs OpenClaw for Cline Users The malicious version of Cline’s npm package — 2.3.0 — was downloaded more than 4,000 times before it was removed. Rob Wright Go to gbhackers.com
-
Best-in-Class ‘Starkiller’ Phishing Kit Bypasses MFA
Best-in-Class ‘Starkiller’ Phishing Kit Bypasses MFA A user-friendly PhaaS tool beats standard methods for detecting phishing attacks by live-proxying legitimate login sites. Nate Nelson Go to gbhackers.com
-
Abu Dhabi Finance Week Exposed VIP Passport Details
Abu Dhabi Finance Week Exposed VIP Passport Details Unprotected cloud data sends the wrong signal at a time when the emirate’s trying to attract investors and establish itself as a global financial center. Jai Vijayan Go to gbhackers.com
-
Connected and Compromised: When IoT Devices Turn Into Threats
Connected and Compromised: When IoT Devices Turn Into Threats Reused passwords, a lack of network segmentation, and poor sanitization processes make the Internet of Things’ attack surfaces more dangerous. Arielle Waldman Go to gbhackers.com
-
Researchers Uncover DoS Vulnerabilities in Socomec DIRIS M-70 IIoT Power Meter via Thread Emulation…
Researchers Uncover DoS Vulnerabilities in Socomec DIRIS M-70 IIoT Power Meter via Thread Emulation… Selective thread emulation and coverage-guided fuzzing have exposed six denial-of-service (DoS) vulnerabilities in the Socomec DIRIS M-70 IIoT power-monitoring gateway, all of which are… Go to gbhackers.com
-
Microsoft Defender Introduces Centralized Script Library Powered by Copilot for Live Response
Microsoft Defender Introduces Centralized Script Library Powered by Copilot for Live Response Microsoft has unveiled a significant enhancement to its Defender platform: centralized library management for live response operations, powered by Microsoft Security Copilot. This new… Go to gbhackers.com
-
CISA Alerts Organizations to Honeywell CCTV Flaw Enabling Account Takeovers
CISA Alerts Organizations to Honeywell CCTV Flaw Enabling Account Takeovers The Cybersecurity and Infrastructure Security Agency (CISA) has issued an advisory warning about a critical vulnerability affecting multiple Honeywell CCTV camera products that could… Go to gbhackers.com
-
Threat Actors Using Fake Google Forms Site to Harvest Google Logins
Threat Actors Using Fake Google Forms Site to Harvest Google Logins A new phishing campaign in which threat actors are using a convincing fake version of Google Forms to steal Google account credentials. Cybercriminals are once… Go to gbhackers.com
-
Hackers Hide Malware in Emoji-Based Code to Bypass Security Defenses
Hackers Hide Malware in Emoji-Based Code to Bypass Security Defenses Hackers are increasingly abusing emoji and other Unicode tricks to hide malicious code, bypass filters, and evade modern security controls, including AI-powered defenses. This emerging technique,… Go to gbhackers.com
-
Critical infra Honeywell CCTVs vulnerable to auth bypass flaw
Critical infra Honeywell CCTVs vulnerable to auth bypass flaw The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a critical vulnerability in multiple Honeywell CCTV products that allows unauthorized access to feeds or account hijacking. […] Bill Toulas Go to bleepingcomputer
-
AI platforms can be abused for stealthy malware communication
AI platforms can be abused for stealthy malware communication AI assistants like Grok and Microsoft Copilot with web browsing and URL-fetching capabilities can be abused to intermediate command-and-control (C2) activity. […] Bill Toulas Go to bleepingcomputer
-
Telegram channels expose rapid weaponization of SmarterMail flaws
Telegram channels expose rapid weaponization of SmarterMail flaws Underground Telegram channels shared SmarterMail exploit PoCs and stolen admin credentials within days of disclosure. Flare explains how monitoring these communities reveals rapid weaponization of CVE-2026-24423 and CVE-2026-23760 tied to ransomware activity. […] Sponsored by Flare Go to bleepingcomputer
-
Microsoft: Anti-phishing rules mistakenly blocked emails, Teams messages
Microsoft: Anti-phishing rules mistakenly blocked emails, Teams messages Microsoft says an Exchange Online issue that mistakenly quarantined legitimate emails last week was triggered by faulty heuristic detection rules designed to block credential phishing campaigns. […] Sergiu Gatlan Go to bleepingcomputer
-
Data breach at fintech firm Figure affects nearly 1 million accounts
Data breach at fintech firm Figure affects nearly 1 million accounts Hackers have stolen the personal and contact information of nearly 1 million accounts after breaching the systems of Figure Technology Solutions, a self-described blockchain-native financial technology company. […] Sergiu Gatlan Go to bleepingcomputer
-
Advanced Crypto Mining Malware Spreads Through External Drives and Air-Gapped Systems
Advanced Crypto Mining Malware Spreads Through External Drives and Air-Gapped Systems A sophisticated cryptocurrency mining campaign has emerged, targeting systems through external storage devices with the ability to compromise even air-gapped environments. The malware operates as a multi-stage infection that prioritizes mining Monero cryptocurrency while establishing persistent mechanisms to resist removal. Unlike typical cryptojacking operations,…
-
Microsoft Defender Unveils Centralized Script Library with Copilot Analysis for Enhanced Live Response
Microsoft Defender Unveils Centralized Script Library with Copilot Analysis for Enhanced Live Response Microsoft has introduced a new Library Management experience in Microsoft Defender for Endpoint, designed to fundamentally transform how security analysts manage the scripts and tools they rely on during live response investigations. Announced on February 16, 2026, the enhancement addresses a long-standing…
-
Microsoft Teams to Prompt Mobile Users for Browser Choice with Non-Office and PDF Links
Microsoft Teams to Prompt Mobile Users for Browser Choice with Non-Office and PDF Links Microsoft is rolling out a significant update to Teams Mobile on Android and iOS that changes how non-Office and PDF links are handled within the app. Beginning in late February 2026, users will be presented with a browser selection prompt when…
-
MCP Servers can be Exploited to Execute Arbitrary Code and Exfiltrate Sensitive Data
MCP Servers can be Exploited to Execute Arbitrary Code and Exfiltrate Sensitive Data The Model Context Protocol (MCP) emerged as a breakthrough standard in November 2024, designed by Anthropic to seamlessly connect AI assistants with external systems and data sources. This innovation allows Large Language Models (LLMs) to interact with tools and repositories, significantly enhancing…
-
OpenAI Launches EVMbench to Detect, Patch, and Exploit Vulnerabilities in Blockchain Environments
OpenAI Launches EVMbench to Detect, Patch, and Exploit Vulnerabilities in Blockchain Environments OpenAI, in collaboration with crypto investment firm Paradigm, has introduced EVMbench, a new benchmark designed to evaluate the ability of AI agents to detect, patch, and exploit high-severity vulnerabilities in smart contracts. The release marks a significant step in measuring AI capabilities within…
-
TR-26-0075 (Key Yazılım – INFOREX Güvenlik Bildirimi)
TR-26-0075 (Key Yazılım – INFOREX Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0074 (Dell RecoverPoint for Virtual Machines Güvenlik Bildirimi)
TR-26-0074 (Dell RecoverPoint for Virtual Machines Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0073 (Crawl4AI Güvenlik Zafiyeti)
TR-26-0073 (Crawl4AI Güvenlik Zafiyeti) Go to usom.gov
-
TR-26-0072 (WordPress Eklenti Güvenlik Bildirimi)
TR-26-0072 (WordPress Eklenti Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0071 (Tenable Security Center Güvenlik Bildirimi)
TR-26-0071 (Tenable Security Center Güvenlik Bildirimi) Go to usom.gov
-
More Than 40% of South Africans Were Scammed in 2025
More Than 40% of South Africans Were Scammed in 2025 Survey underscores the reality that scammers follow “scalable opportunities and low friction,” rather than rich targets that tend to be better protected. Nate Nelson, Contributing Writer Go to gbhackers.com
-
Citizen Lab Finds Cellebrite Tool Used on Kenyan Activist’s Phone in Police Custody
Citizen Lab Finds Cellebrite Tool Used on Kenyan Activist’s Phone in Police Custody New research from the Citizen Lab has found signs that Kenyan authorities used a commercial forensic extraction tool manufactured by Israeli company Cellebrite to break into a prominent dissident’s phone, making it the latest case of abuse of the technology targeting civil…
-
Grandstream GXP1600 VoIP Phones Exposed to Unauthenticated Remote Code Execution
Grandstream GXP1600 VoIP Phones Exposed to Unauthenticated Remote Code Execution Cybersecurity researchers have disclosed a critical security flaw in the Grandstream GXP1600 series of VoIP phones that could allow an attacker to seize control of susceptible devices. The vulnerability, tracked as CVE-2026-2329, carries a CVSS score of 9.3 out of a maximum of 10.0. It…
-
Critical Flaws Found in Four VS Code Extensions with Over 125 Million Installs
Critical Flaws Found in Four VS Code Extensions with Over 125 Million Installs Cybersecurity researchers have disclosed multiple security vulnerabilities in four popular Microsoft Visual Studio Code (VS Code) extensions that, if successfully exploited, could allow threat actors to steal local files and execute code remotely. The extensions, which have been collectively installed more than…
-
Cybersecurity Tech Predictions for 2026: Operating in a World of Permanent Instability
Cybersecurity Tech Predictions for 2026: Operating in a World of Permanent Instability In 2025, navigating the digital seas still felt like a matter of direction. Organizations charted routes, watched the horizon, and adjusted course to reach safe harbors of resilience, trust, and compliance. In 2026, the seas are no longer calm between storms. Cybersecurity now…
-
Dell RecoverPoint for VMs Zero-Day CVE-2026-22769 Exploited Since Mid-2024
Dell RecoverPoint for VMs Zero-Day CVE-2026-22769 Exploited Since Mid-2024 A maximum severity security vulnerability in Dell RecoverPoint for Virtual Machines has been exploited as a zero-day by a suspected China-nexus threat cluster dubbed UNC6201 since mid-2024, according to a new report from Google Mandiant and Google Threat Intelligence Group (GTIG). The activity involves the exploitation…
-
Threat Intelligence Executive Report – Volume 2025, Number 6
Threat Intelligence Executive Report – Volume 2025, Number 6 This issue of the Counter Threat Unit’s high-level bimonthly report discusses noteworthy updates in the threat landscape during September and October Categories: Threat Research Tags: EDR killer, infostealer, Ransomware Go to sophos
-
AI Found Twelve New Vulnerabilities in OpenSSL
AI Found Twelve New Vulnerabilities in OpenSSL The title of the post is”What AI Security Research Looks Like When It Works,” and I agree: In the latest OpenSSL security release> on January 27, 2026, twelve new zero-day vulnerabilities (meaning unknown to the maintainers at time of disclosure) were announced. Our AI system is responsible for…
-
ISC Stormcast For Thursday, February 19th, 2026 https://isc.sans.edu/podcastdetail/9816, (Thu, Feb 19th)
ISC Stormcast For Thursday, February 19th, 2026 https://isc.sans.edu/podcastdetail/9816, (Thu, Feb 19th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Tracking Malware Campaigns With Reused Material, (Wed, Feb 18th)
Tracking Malware Campaigns With Reused Material, (Wed, Feb 18th) A few days ago I wrote a diary called “Malicious Script Delivering More Maliciousness”[1]. In the malware infection chain, there was a JPEG picture that embedded the last payload delimited with “BaseStart-” and “-BaseEnd” tags. Today, I discovered anoher campaign that relies exactly on the same…
-
Dutch police arrest man for “hacking” after accidentally sending him confidential files
Dutch police arrest man for “hacking” after accidentally sending him confidential files Police in The Netherlands say they have arrested a 40-year-old man on suspicion of hacking… after police officers accidentally sent him a link granting him access to their own confidential documents Read more in my article on the Hot for Security blog. Graham…
-
Scam Abuses Gemini Chatbots to Convince People to Buy Fake Crypto
Scam Abuses Gemini Chatbots to Convince People to Buy Fake Crypto A convincing presale site for phony “Google Coin” features an AI assistant that engages victims with a slick sales pitch, funneling payment to attackers. Elizabeth Montalbano, Contributing Writer Go to gbhackers.com
-
Critical Grandstream VoIP Bug Highlights SMB Security Blind Spot
Critical Grandstream VoIP Bug Highlights SMB Security Blind Spot CVE-2026-2329 allows unauthenticated root-level access to SMB phone infrastructure, so attackers can intercept calls, commit toll fraud, and impersonate users. Jai Vijayan, Contributing Writer Go to gbhackers.com
-
Dell’s Hard-Coded Flaw: A Nation-State Goldmine
Dell’s Hard-Coded Flaw: A Nation-State Goldmine A China-related attacker has exploited the vendor flaw since mid-2024, allowing it to move laterally, maintain persistent access, and deploy malware. Alexander Culafi Go to gbhackers.com
-
A CISO’s Playbook for Defending Data Assets Against AI Scraping
A CISO’s Playbook for Defending Data Assets Against AI Scraping Discover a strategic approach to govern scraping risks, balance security with business growth, and safeguard intellectual capital from automated data harvesting. Areejit Banerjee Go to gbhackers.com
-
ClickFix Exploits Homebrew Workflow to Deploy Cuckoo Stealer for macOS Credential Theft
ClickFix Exploits Homebrew Workflow to Deploy Cuckoo Stealer for macOS Credential Theft ClickFix is being weaponized against macOS developers by turning a trusted Homebrew workflow into a stealthy delivery channel for a new infostealer dubbed Cuckoo… Go to gbhackers.com
-
Palo Alto Networks to Acquire Koi Security for Enhanced Agentic Endpoint Security
Palo Alto Networks to Acquire Koi Security for Enhanced Agentic Endpoint Security Palo Alto Networks announced on February 17, 2026, that it has entered a definitive agreement to acquire Koi Security, a pioneer in Agentic Endpoint… Go to gbhackers.com
-
Malware Campaign Targets Crypto Users with Fake MetaMask Wallet and Remote Access Backdoor
Malware Campaign Targets Crypto Users with Fake MetaMask Wallet and Remote Access Backdoor An aggressive malware campaign targeting IT professionals in cryptocurrency, Web3, and AI to steal sensitive data and live crypto funds from victim wallets. The… Go to gbhackers.com
-
New SysUpdate Variant Malware Discovered, Decryption Tool for Linux C2 Traffic Released
New SysUpdate Variant Malware Discovered, Decryption Tool for Linux C2 Traffic Released A new Linux malware sample that strongly aligns with the SysUpdate malware family used by APT27/Iron Tiger. Initially detected on a client’s system, the… Go to gbhackers.com
-
CISA Flags Actively Exploited Windows Video ActiveX Control RCE in KEV List
CISA Flags Actively Exploited Windows Video ActiveX Control RCE in KEV List The Cybersecurity and Infrastructure Security Agency (CISA) has officially added a critical vulnerability affecting Microsoft Windows to its Known Exploited Vulnerabilities (KEV) catalog. This… Go to gbhackers.com
-
Spain orders NordVPN, ProtonVPN to block LaLiga piracy sites
Spain orders NordVPN, ProtonVPN to block LaLiga piracy sites A Spanish court has granted precautionary measures against NordVPN and ProtonVPN, ordering the two popular VPN providers to block 16 websites that facilitate piracy of football matches. […] Bill Toulas Go to bleepingcomputer
-
Flaws in popular VSCode extensions expose developers to attacks
Flaws in popular VSCode extensions expose developers to attacks Vulnerabilities with high to critical severity ratings affecting popular Visual Studio Code (VSCode) extensions collectively downloaded more than 128 million times could be exploited to steal local files and execute code remotely. […] Bill Toulas Go to bleepingcomputer
-
Chinese hackers exploiting Dell zero-day flaw since mid-2024
Chinese hackers exploiting Dell zero-day flaw since mid-2024 A suspected Chinese state-backed hacking group has been quietly exploiting a critical Dell security flaw in zero-day attacks that started in mid-2024. […] Sergiu Gatlan Go to bleepingcomputer
-
Notepad++ boosts update security with ‘double-lock’ mechanism
Notepad++ boosts update security with ‘double-lock’ mechanism Notepad++ has adopted a “double-lock” design for its update mechanism to address recently exploited security gaps that resulted in a supply-chain compromise. […] Bill Toulas Go to bleepingcomputer
-
Microsoft Teams outage affects users in United States, Europe
Microsoft Teams outage affects users in United States, Europe Microsoft is working to resolve an ongoing outage affecting Microsoft Teams users, causing delays and preventing some from accessing the service. […] Sergiu Gatlan Go to bleepingcomputer
-
CISA Warns of Google Chromium 0-Day Vulnerability Actively Exploited in Attacks
CISA Warns of Google Chromium 0-Day Vulnerability Actively Exploited in Attacks An urgent warning regarding a newly discovered zero-day vulnerability in Google Chromium, which is reportedly under active exploitation in the wild. The vulnerability, tracked as CVE-2026-2441, affects Chromium’s CSS (Cascading Style Sheets) engine and can enable remote attackers to execute arbitrary code on a victim’s…
-
Microsoft VS Code Extension with 11M Downloads Expose Developers to One-Click XSS Attacks
Microsoft VS Code Extension with 11M Downloads Expose Developers to One-Click XSS Attacks A critical vulnerability discovered in Microsoft’s popular Visual Studio Code (VS Code) Live Preview extension, downloaded over 11 million times, exposes developers to one-click cross-site scripting (XSS) and local file exfiltration attacks. The flaw, now patched, was discovered by researchers Nir Zadok and Moshe Siman Tov Bustan from OX Security. The issue…
-
Notepad++ v8.9.2 Released with “Double-Lock” Update Mechanism Following Recent Hack
Notepad++ v8.9.2 Released with “Double-Lock” Update Mechanism Following Recent Hack The widely used open-source text and code editor has released version v8.9.2, introducing a major security enhancement known as the “Double-Lock” update mechanism. This update addresses vulnerabilities that were exploited in a recent state-sponsored attack targeting the application’s update infrastructure. Last month, Notepad++’s official site confirmed that attackers…
-
New ‘Foxveil’ Malware Loader Leverages Cloudflare, Netlify, and Discord to Evade Detection
New ‘Foxveil’ Malware Loader Leverages Cloudflare, Netlify, and Discord to Evade Detection A new malware loader called “Foxveil” has been discovered actively targeting systems through legitimate cloud platforms, raising concerns about how threat actors are weaponizing trusted services to bypass security measures. The malware has been operational since August 2025 and has since evolved significantly.…
-
Critical Windows Admin Center Vulnerability Allows Privilege Escalation
Critical Windows Admin Center Vulnerability Allows Privilege Escalation A critical security update addressing a high‑severity elevation of privilege vulnerability in Windows Admin Center (WAC), identified as CVE‑2026‑26119. The flaw, rated CVSS 8.8 (Critical), stems from improper authentication (CWE‑287) that could allow an authorized attacker to gain elevated network privileges. According to Microsoft, this vulnerability affects Windows Admin Center version 2.6.4, and…
-
Is it OK to let your children post selfies online?
Is it OK to let your children post selfies online? When it comes to our children’s digital lives, prohibition rarely works. It’s our responsibility to help them build a healthy relationship with tech. Go to eset
-
TR-26-0069 (TÜBİTAK BİLGEM YTE – Liderahenk Güvenlik Bildirimi)
TR-26-0069 (TÜBİTAK BİLGEM YTE – Liderahenk Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0068 (EKA Yazılım – Emlak Scripti V5 Güvenlik Bildirimi)
TR-26-0068 (EKA Yazılım – Emlak Scripti V5 Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0067 (Tumeva İnternet Teknolojileri – Tumeva Haber Yazılımı Güvenlik Bildirimi)
TR-26-0067 (Tumeva İnternet Teknolojileri – Tumeva Haber Yazılımı Güvenlik Bildirimi) Go to usom.gov
-
Webinar: How Modern SOC Teams Use AI and Context to Investigate Cloud Breaches Faster
Webinar: How Modern SOC Teams Use AI and Context to Investigate Cloud Breaches Faster Cloud attacks move fast — faster than most incident response teams. In data centers, investigations had time. Teams could collect disk images, review logs, and build timelines over days. In the cloud, infrastructure is short-lived. A compromised instance can disappear in…
-
Researchers Show Copilot and Grok Can Be Abused as Malware C2 Proxies
Researchers Show Copilot and Grok Can Be Abused as Malware C2 Proxies Cybersecurity researchers have disclosed that artificial intelligence (AI) assistants that support web browsing or URL fetching capabilities can be turned into stealthy command-and-control (C2) relays, a technique that could allow attackers to blend into legitimate enterprise communications and evade detection. The attack method,…
-
Keenadu Firmware Backdoor Infects Android Tablets via Signed OTA Updates
Keenadu Firmware Backdoor Infects Android Tablets via Signed OTA Updates A new Android backdoor that’s embedded deep into the device firmware can silently harvest data and remotely control its behavior, according to new findings from Kaspersky. The Russian cybersecurity vendor said it discovered the backdoor, dubbed Keenadu, in the firmware of devices associated with various…
-
SmartLoader Attack Uses Trojanized Oura MCP Server to Deploy StealC Infostealer
SmartLoader Attack Uses Trojanized Oura MCP Server to Deploy StealC Infostealer Cybersecurity researchers have disclosed details of a new SmartLoader campaign that involves distributing a trojanized version of a Model Context Protocol (MCP) server associated with Oura Health to deliver an information stealer known as StealC. “The threat actors cloned a legitimate Oura MCP Server…
-
My Day Getting My Hands Dirty with an NDR System
My Day Getting My Hands Dirty with an NDR System My objectiveThe role of NDR in SOC workflowsStarting up the NDR systemHow AI complements the human responseWhat else did I try out?What could I see with NDR that I wouldn’t otherwise?Am I ready to be a network security analyst now? My objective As someone relatively…
-
Side-Channel Attacks Against LLMs
Side-Channel Attacks Against LLMs Here are three papers describing different side-channel attacks against LLMs. “Remote Timing Attacks on Efficient Language Model Inference“: Abstract: Scaling up language models has significantly increased their capabilities. But larger models are slower models, and so there is now an extensive body of work (e.g., speculative sampling or parallel decoding) that…
-
ISC Stormcast For Wednesday, February 18th, 2026 https://isc.sans.edu/podcastdetail/9814, (Wed, Feb 18th)
ISC Stormcast For Wednesday, February 18th, 2026 https://isc.sans.edu/podcastdetail/9814, (Wed, Feb 18th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Fake Incident Report Used in Phishing Campaign, (Tue, Feb 17th)
Fake Incident Report Used in Phishing Campaign, (Tue, Feb 17th) This morning, I received an interesting phishing email. I’ve a “love & hate” relation with such emails because I always have the impression to lose time when reviewing them but sometimes it’s a win because you spot interesting “TTPs” (“tools, techniques & procedures”). Maybe one…
-
Singapore & Its 4 Major Telcos Fend Off Chinese Hackers
Singapore & Its 4 Major Telcos Fend Off Chinese Hackers After detecting a zero-day attack, the country’s effective response was attributed to the tight relationship between its government and private industry. Robert Lemos, Contributing Writer Go to gbhackers.com
-
Weekly Update 491
Weekly Update 491 Well, the ESP32 Bluetooth bridge experiment was a complete failure. Not the radios themselves, they’re actually pretty cool, but there’s just no way I could get the Yale locks to be reliably operated by them. At a guess, BLE is a bit too passive to detect state changes, and unless it was…
-
Supply Chain Attack Embeds Malware in Android Devices
Supply Chain Attack Embeds Malware in Android Devices Keenadu downloads payloads that hijack browser searches, commit ad fraud, and execute other actions without user knowledge. Jai Vijayan, Contributing Writer Go to gbhackers.com
-
Poland Energy Survives Attack on Wind, Solar Infrastructure
Poland Energy Survives Attack on Wind, Solar Infrastructure Russia-aligned groups are probable culprits behind the wiper attacks against renewable energy farms, a manufacturer, and a heating and power plant. Alexander Culafi Go to gbhackers.com
-
RMM Abuse Explodes as Hackers Ditch Malware
RMM Abuse Explodes as Hackers Ditch Malware It’s the path of lesser resistance, as remote monitoring and management (RMM) software offers stealth, persistence, and operational efficiency. Rob Wright Go to gbhackers.com
-
ClickFix Attacks Abuses DNS Lookup Command to Deliver ModeloRAT
ClickFix Attacks Abuses DNS Lookup Command to Deliver ModeloRAT ClickFix campaigns have adapted to the latest defenses with a new technique to trick users into infecting their own machines with malware. Elizabeth Montalbano, Contributing Writer Go to gbhackers.com
-
EU Parliament Suspends AI Integration on Corporate Devices Over Cybersecurity Fears
EU Parliament Suspends AI Integration on Corporate Devices Over Cybersecurity Fears The European Parliament has taken a precautionary step by disabling built-in artificial intelligence features on work devices issued to lawmakers and staff members, citing unresolved cybersecurity… Go to gbhackers.com
-
New Sophisticated ‘Carding-as-a-Service’ Marketplaces Fuel Surge in Credit Card Fraud
New Sophisticated ‘Carding-as-a-Service’ Marketplaces Fuel Surge in Credit Card Fraud Credit card fraud has matured into a service-based criminal economy where stolen cards, malware, and support are bundled and sold like commercial products. Underground “dump shops”… Go to gbhackers.com
-
DigitStealer Infostealer Targets macOS, Revealing Critical Infrastructure Vulnerabilities
DigitStealer Infostealer Targets macOS, Revealing Critical Infrastructure Vulnerabilities DigitStealer is an increasingly active macOS‑targeting infostealer whose predictable command‑and‑control (C2) setup exposes structural weaknesses in its operators’ infrastructure decisions. While technically sophisticated on… Go to gbhackers.com
-
Firefox v147.0.3 Released with Critical Fix for Heap Buffer Overflow Vulnerability
Firefox v147.0.3 Released with Critical Fix for Heap Buffer Overflow Vulnerability Mozilla has released an emergency security update for Firefox, addressing a critical heap buffer overflow vulnerability in the libvpx library. The update, version 147.0.4,… Go to gbhackers.com
-
Microsoft Teams Leverages AI Workflows with Microsoft 365 Copilot for Task Automation
Microsoft Teams Leverages AI Workflows with Microsoft 365 Copilot for Task Automation Microsoft is rolling out AI Workflows in the Teams Workflows app, bringing intelligent automation capabilities powered by Microsoft 365 Copilot to help users streamline… Go to gbhackers.com
-
Ireland now also investigating X over Grok-made sexual images
Ireland now also investigating X over Grok-made sexual images Ireland’s Data Protection Commission (DPC), the country’s data protection authority, has opened a formal investigation into X over the use of the platform’s Grok artificial intelligence tool to generate non-consensual sexual images of real people, including children. […] Sergiu Gatlan Go to bleepingcomputer
-
Washington Hotel in Japan discloses ransomware infection incident
Washington Hotel in Japan discloses ransomware infection incident The Washington Hotel brand in Japan has announced that that its servers were compromised in a ransomware attack, exposing various business data. […] Bill Toulas Go to bleepingcomputer
-
Eurail says stolen traveler data now up for sale on dark web
Eurail says stolen traveler data now up for sale on dark web Eurail B.V., the operator that provides access to 250,000 kilometers of European railways, confirmed that data stolen in a breach earlier this year is being offered for sale on the dark web. […] Bill Toulas Go to bleepingcomputer