no alarms and no surprises please..
-
Man arrested for demanding reward after accidental police data leak
Man arrested for demanding reward after accidental police data leak Dutch authorities arrested a 40-year-old man after he downloaded confidential documents that had been mistakenly shared by the police and refused to delete them unless he received “something in return.” […] Sergiu Gatlan Go to bleepingcomputer
-
Infostealer malware found stealing OpenClaw secrets for first time
Infostealer malware found stealing OpenClaw secrets for first time With the massive adoption of the OpenClaw agentic AI assistant, information-stealing malware has been spotted stealing files associated with the framework that contain API keys, authentication tokens, and other secrets. […] Bill Toulas Go to bleepingcomputer
-
Apache NiFi Vulnerability Enables Authorization Bypass
Apache NiFi Vulnerability Enables Authorization Bypass A newly disclosed high-severity vulnerability in Apache NiFi exposes systems to an authorization bypass that could allow lower-privileged users to modify restricted components. Tracked as CVE-2026-25903, the flaw impacts Apache NiFi versions 1.1.0 through 2.7.2 and has been fixed in version 2.8.0. According to the Apache NiFi security advisory, the issue arises from missing…
-
Malicious Chrome Extension Steals Facebook Business Manage 2FA Codes and Analytics Data
Malicious Chrome Extension Steals Facebook Business Manage 2FA Codes and Analytics Data A malicious Chrome extension that claims to help Meta Business users quietly steals Facebook Business Manager 2FA codes and analytics data, putting high‑value ad accounts at risk of takeover. The extension, “CL Suite by @CLMasters” (ID: jkphinfhmfkckkcnifhjiplhfoiefffl), is still available in the Chrome Web…
-
Langchain Community SSRF Bypass Vulnerability Enables Access to Internal Services
Langchain Community SSRF Bypass Vulnerability Enables Access to Internal Services A Server‑Side Request Forgery (SSRF) vulnerability has been identified in the langchain/community package, affecting versions up to 1.1.13. The flaw, tracked as CVE‑2026‑26019, has a moderate severity rating, with a CVSS 3.1 score, due on its potential to expose sensitive cloud metadata and internal infrastructure. The vulnerability originates from the RecursiveUrlLoader class, which…
-
25 Vulnerabilities in Cloud Password Managers Allow Unauthorized Access and Modifications
25 Vulnerabilities in Cloud Password Managers Allow Unauthorized Access and Modifications Researchers from ETH Zurich have uncovered 25 serious vulnerabilities in three leading cloud-based password managers: Bitwarden, LastPass, and Dashlane. These flaws enable a malicious server to bypass zero-knowledge encryption claims, allowing unauthorized access, modification, and recovery of users’ stored passwords and vault data. Bitwarden,…
-
Noodlophile Malware Creators Evolve Tactics with Fake Job Postings and Phishing Lures
Noodlophile Malware Creators Evolve Tactics with Fake Job Postings and Phishing Lures The Noodlophile information stealer, originally uncovered in May 2025, has significantly evolved its attack strategies to bypass security measures. Initially, this malware hid behind deceptive advertisements for fake AI video generation platforms on social media, tricking users into downloading malicious ZIP files. These…
-
TR-26-0066 (TR7 Siber Savunma – Web Application Firewall Güvenlik Bildirimi)
TR-26-0066 (TR7 Siber Savunma – Web Application Firewall Güvenlik Bildirimi) Go to usom.gov
-
Infostealer Steals OpenClaw AI Agent Configuration Files and Gateway Tokens
Infostealer Steals OpenClaw AI Agent Configuration Files and Gateway Tokens Cybersecurity researchers disclosed they have detected a case of an information stealer infection successfully exfiltrating a victim’s OpenClaw (formerly Clawdbot and Moltbot) configuration environment. “This finding marks a significant milestone in the evolution of infostealer behavior: the transition from stealing browser credentials to harvesting the…
-
Study Uncovers 25 Password Recovery Attacks in Major Cloud Password Managers
Study Uncovers 25 Password Recovery Attacks in Major Cloud Password Managers A new study has found that multiple cloud-based password managers, including Bitwarden, Dashlane, and LastPass, are susceptible to password recovery attacks under certain conditions. “The attacks range in severity from integrity violations to the complete compromise of all vaults in an organization,” researchers Matteo…
-
Weekly Recap: Outlook Add-Ins Hijack, 0-Day Patches, Wormable Botnet & AI Malware
Weekly Recap: Outlook Add-Ins Hijack, 0-Day Patches, Wormable Botnet & AI Malware This week’s recap shows how small gaps are turning into big entry points. Not always through new exploits, often through tools, add-ons, cloud setups, or workflows that people already trust and rarely question. Another signal: attackers are mixing old and new methods. Legacy…
-
Safe and Inclusive E‑Society: How Lithuania Is Bracing for AI‑Driven Cyber Fraud
Safe and Inclusive E‑Society: How Lithuania Is Bracing for AI‑Driven Cyber Fraud Presentation of the KTU Consortium Mission ‘A Safe and Inclusive Digital Society’ at the Innovation Agency event ‘Innovation Breakfast: How Mission-Oriented Science and Innovation Programmes Will Address Societal Challenges’. Technologies are evolving fast, reshaping economies, governance, and daily life. Yet, as innovation accelerates,…
-
New ZeroDayRAT Mobile Spyware Enables Real-Time Surveillance and Data Theft
New ZeroDayRAT Mobile Spyware Enables Real-Time Surveillance and Data Theft Cybersecurity researchers have disclosed details of a new mobile spyware platform dubbed ZeroDayRAT that’s being advertised on Telegram as a way to grab sensitive data and facilitate real-time surveillance on Android and iOS devices. “The developer runs dedicated channels for sales, customer support, and regular…
-
The Promptware Kill Chain
The Promptware Kill Chain Attacks against modern generative artificial intelligence (AI) large language models (LLMs) pose a real threat. Yet discussions around these attacks and their potential defenses are dangerously myopic. The dominant narrative focuses on “prompt injection,” a set of techniques to embed instructions into inputs to LLM intended to perform malicious activity. This…
-
ISC Stormcast For Tuesday, February 17th, 2026 https://isc.sans.edu/podcastdetail/9812, (Tue, Feb 17th)
ISC Stormcast For Tuesday, February 17th, 2026 https://isc.sans.edu/podcastdetail/9812, (Tue, Feb 17th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
2026 64-Bits Malware Trend, (Mon, Feb 16th)
2026 64-Bits Malware Trend, (Mon, Feb 16th) In 2022 (time flies!), I wrote a diary about the 32-bits VS. 64-bits malware landscape[1]. It demonstrated that, despite the growing number of 64-bits computers, the “old-architecture” remained the standard. In the SANS malware reversing training (FOR610[2]), we quickly cover the main differences between the two architectures. One of…
-
Operation DoppelBrand: Weaponizing Fortune 500 Brands
Operation DoppelBrand: Weaponizing Fortune 500 Brands The GS7 cyberthreat group targets US financial institutions with near-perfect imitations of corporate portals to steal credentials and gain remote access. Elizabeth Montalbano, Contributing Writer Go to gbhackers.com
-
260K+ Chrome Users Duped by Fake AI Browser Extensions
260K+ Chrome Users Duped by Fake AI Browser Extensions 30 copycat apps tricked users, and Google itself, into thinking they’re legitimate AI tools. Nate Nelson, Contributing Writer Go to gbhackers.com
-
Hackers Exploit ‘Summarize with AI’ Feature to Inject Malicious Prompts into AI Recommendations
Hackers Exploit ‘Summarize with AI’ Feature to Inject Malicious Prompts into AI Recommendations Hackers and marketers are increasingly abusing “Summarize with AI” buttons and AI-share links to quietly plant persistent instructions in AI assistants’ memory, a growing… Go to gbhackers.com
-
OpenClaw Founder Peter Steinberger Joins OpenAI to Strengthen AI Research
OpenClaw Founder Peter Steinberger Joins OpenAI to Strengthen AI Research OpenClaw founder Peter Steinberger says he is joining OpenAI to help “bring agents to everyone,” positioning the move as a way to accelerate development… Go to gbhackers.com
-
Critical Airleader Vulnerability Exposes Systems to Exploitable Remote Attacks
Critical Airleader Vulnerability Exposes Systems to Exploitable Remote Attacks A critical security vulnerability in Airleader Master software has been disclosed by CISA, exposing industrial control systems across multiple critical infrastructure sectors to potential… Go to gbhackers.com
-
Matryoshka Clickfix Variant Targets macOS Users, Deploys New Stealer Malware
Matryoshka Clickfix Variant Targets macOS Users, Deploys New Stealer Malware A new variant of the “ClickFix” social engineering campaign specifically targeting macOS users. Codenamed Matryoshka a reference to its multiple nested obfuscation layers this evolution… Go to gbhackers.com
-
FileZen Flaw Allows Attackers to Execute Commands Remotely
FileZen Flaw Allows Attackers to Execute Commands Remotely A high-severity vulnerability in FileZen, a file transfer solution developed by Soliton Systems K.K., enables authenticated attackers to remotely execute arbitrary operating system commands… Go to gbhackers.com
-
Google patches first Chrome zero-day exploited in attacks this year
Google patches first Chrome zero-day exploited in attacks this year Google has released emergency updates to fix a high-severity Chrome vulnerability exploited in zero-day attacks, marking the first such security flaw patched since the start of the year. […] Sergiu Gatlan Go to bleepingcomputer
-
Canada Goose investigating as hackers leak 600K customer records
Canada Goose investigating as hackers leak 600K customer records ShinyHunters, a well-known data extortion group, claims to have stolen more than 600,000 Canada Goose customer records containing personal and payment-related data. Canada Goose told BleepingComputer the dataset appears to relate to past customer transactions and that it has not found evidence of a breach of…
-
New ClickFix attack abuses nslookup to retrieve PowerShell payload via DNS
New ClickFix attack abuses nslookup to retrieve PowerShell payload via DNS Threat actors are now abusing DNS queries as part of ClickFix social engineering attacks to deliver malware, making this the first known use of DNS as a channel in these campaigns. […] Lawrence Abrams Go to bleepingcomputer
-
Windows 11 KB5077181 fixes boot failures linked to failed updates
Windows 11 KB5077181 fixes boot failures linked to failed updates Microsoft says it has resolved a Windows 11 bug that caused some commercial systems to fail to boot with an “UNMOUNTABLE_BOOT_VOLUME” error after installing recent security updates, with the fix delivered in the February 2026 Patch Tuesday update. […] Lawrence Abrams Go to bleepingcomputer
-
CTM360: Lumma Stealer and Ninja Browser malware campaign abusing Google Groups
CTM360: Lumma Stealer and Ninja Browser malware campaign abusing Google Groups CTM360 reports 4,000+ malicious Google Groups and 3,500+ Google-hosted URLs used to spread the Lumma Stealer infostealing malware and a trojanized “Ninja Browser.” The report details how attackers abuse trusted Google services to steal credentials and maintain persistence across Windows and Linux systems. […]…
-
Critical BeyondTrust Vulnerability Exploited in the Wild to Gain Full Domain Control
Critical BeyondTrust Vulnerability Exploited in the Wild to Gain Full Domain Control A critical vulnerability tracked as CVE-2026-1731 is being actively exploited in the wild, enabling attackers to gain full domain control over affected systems. Threat actors are leveraging this flaw to execute operating system commands remotely without authentication. The flaw, discovered in self-hosted BeyondTrust deployments, allows unauthenticated…
-
Chrome 0-Day Vulnerability Actively Exploited by Attackers in the Wild
Chrome 0-Day Vulnerability Actively Exploited by Attackers in the Wild Google has urgently patched a high-severity zero-day vulnerability in Chrome, confirming active exploitation in the wild. Tracked as CVE-2026-2441, the flaw is a use-after-free bug in the browser’s CSS handling, reported by independent researcher Shaheen Fazim just five days ago on February 11, 2026. The…
-
Windows 11 KB5077181 Security Update Causing Some Devices to Restart in an Infinite Loop
Windows 11 KB5077181 Security Update Causing Some Devices to Restart in an Infinite Loop Microsoft’s February 10, 2026, security update KB5077181 for Windows 11 versions 24H2 (build 26200.7840) and 25H2 (build 26100.7840) has triggered widespread reports of critical boot failures just days after deployment. Users describe devices entering infinite restart loops, often exceeding 15 cycles,…
-
Microsoft Discloses DNS-Based ClickFix Attack Using Nslookup for Malware Staging
Microsoft Discloses DNS-Based ClickFix Attack Using Nslookup for Malware Staging Microsoft has disclosed details of a new version of the ClickFix social engineering tactic in which the attackers trick unsuspecting users into running commands that carry out a Domain Name System (DNS) lookup to retrieve the next-stage payload. Specifically, the attack relies on using the…
-
ISC Stormcast For Monday, February 16th, 2026 https://isc.sans.edu/podcastdetail/9810, (Mon, Feb 16th)
ISC Stormcast For Monday, February 16th, 2026 https://isc.sans.edu/podcastdetail/9810, (Mon, Feb 16th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
One threat actor responsible for 83% of recent Ivanti RCE attacks
One threat actor responsible for 83% of recent Ivanti RCE attacks Threat intelligence observations show that a single threat actor is responsible for most of the active exploitation of two critical vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM), tracked as CVE-2026-21962 and CVE-2026-24061. […] Bill Toulas Go to bleepingcomputer
-
Snail mail letters target Trezor and Ledger users in crypto-theft attacks
Snail mail letters target Trezor and Ledger users in crypto-theft attacks Threat actors are sending physical letters pretending to be from Trezor and Ledger, makers of cryptocurrency hardware wallets, to trick users into submitting recovery phrases in crypto theft attacks. […] Lawrence Abrams Go to bleepingcomputer
-
PentestAgent – AI Penetration Testing Tool With Prebuilt Attack Playbooks and HexStrike Integration
PentestAgent – AI Penetration Testing Tool With Prebuilt Attack Playbooks and HexStrike Integration PentestAgent, an open-source AI agent framework from developer Masic (GH05TCREW), has introduced enhanced capabilities, including prebuilt attack playbooks and seamless HexStrike integration. Released on GitHub by a researcher with the alias GH05TCREW, this tool leverages large language models (LLMs) like Claude Sonnet…
-
New Clickfix Exploit Tricks Users into Changing DNS Settings for Malware Installation
New Clickfix Exploit Tricks Users into Changing DNS Settings for Malware Installation A new evolution in the ClickFix social engineering campaign, which now employs a custom DNS hijacking technique to deliver malware. This attack method tricks users into executing malicious commands that utilize DNS lookups to fetch the next stage of the infection, allowing attackers…
-
Threat Actors Exploit Claude Artifacts and Google Ads to Target macOS Users
Threat Actors Exploit Claude Artifacts and Google Ads to Target macOS Users A sophisticated malware campaign targeting macOS users through Google-sponsored search results and legitimate platforms, including Anthropic’s Claude AI and Medium. The campaign has already reached over 15,000 potential victims through two distinct attack variants that exploit users’ trust in established online services. 15,000…
-
Upcoming Speaking Engagements
Upcoming Speaking Engagements This is a current list of where and when I am scheduled to speak: I’m speaking at Ontario Tech University in Oshawa, Ontario, Canada, at 2 PM ET on Thursday, February 26, 2026. I’m speaking at the Personal AI Summit in Los Angeles, California, USA, on Thursday, March 5, 2026. I’m speaking…
-
Zscaler-SquareX Deal Boosts Zero Trust, Secure Browsing Capabilities
Zscaler-SquareX Deal Boosts Zero Trust, Secure Browsing Capabilities Zscaler’s acquisition of SquareX comes as competitors like CrowdStrike and Palo Alto Networks are also investing in secure browser technologies. Jeffrey Schwartz Go to gbhackers.com
-
REMnux v8 Linux Toolkit Released With AI-Powered Malware Analysis Capabilities
REMnux v8 Linux Toolkit Released With AI-Powered Malware Analysis Capabilities The landscape of malware analysis has taken a significant leap forward with the official release of REMnux v8. This popular Linux toolkit, which has… Go to gbhackers.com
-
Phishing Campaigns Target Users with Fake Meeting Invites and Update Alerts via Zoom, Teams,…
Phishing Campaigns Target Users with Fake Meeting Invites and Update Alerts via Zoom, Teams,… An ongoing wave of phishing campaigns exploiting fake meeting invites from popular video conferencing platforms, including Zoom, Microsoft Teams, and Google Meet. The attacks… Go to gbhackers.com
-
CVE-2025-64712 in Unstructured.io Puts Amazon, Google, and Tech Giants at Risk of Remote Code…
CVE-2025-64712 in Unstructured.io Puts Amazon, Google, and Tech Giants at Risk of Remote Code… A newly disclosed critical flaw, CVE-2025-64712 (CVSS 9.8), in Unstructured.io’s “unstructured” ETL library could let attackers perform arbitrary file writes and potentially achieve remote code execution… Go to gbhackers.com
-
Fake job recruiters hide malware in developer coding challenges
Fake job recruiters hide malware in developer coding challenges A new variation of the fake recruiter campaign from North Korean threat actors is targeting JavaScript and Python developers with cryptocurrency-related tasks. […] Bill Toulas Go to bleepingcomputer
-
Claude LLM artifacts abused to push Mac infostealers in ClickFix attack
Claude LLM artifacts abused to push Mac infostealers in ClickFix attack Threat actors are abusing Claude artifacts and Google Ads in ClickFix campaigns that deliver infostealer malware to macOS users searching for specific queries. […] Bill Toulas Go to bleepingcomputer
-
Louis Vuitton, Dior, and Tiffany fined $25 million over data breaches
Louis Vuitton, Dior, and Tiffany fined $25 million over data breaches South Korea has fined luxury fashion brands Louis Vuitton, Christian Dior Couture, and Tiffany $25 million for failing to implement adequate security measures, which facilitated unauthorized access and the exposure of data belonging to more than 5.5 million customers. […] Bill Toulas Go to…
-
Turning IBM QRadar Alerts into Action with Criminal IP
Turning IBM QRadar Alerts into Action with Criminal IP Criminal IP now integrates with IBM QRadar SIEM and SOAR to bring external IP-based threat intelligence directly into detection and response workflows. See how risk scoring and automated enrichment help SOC teams prioritize high-risk IPs and accelerate investigations without leaving QRadar. […] Sponsored by Criminal IP…
-
CISA flags critical Microsoft SCCM flaw as exploited in attacks
CISA flags critical Microsoft SCCM flaw as exploited in attacks CISA ordered federal agencies on Thursday to secure their systems against a critical Microsoft Configuration Manager vulnerability patched in October 2024 and now exploited in attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
Threat Actor Allegedly Selling Critical Severity OpenSea 0-day Exploit Chain on Hacking Forums
Threat Actor Allegedly Selling Critical Severity OpenSea 0-day Exploit Chain on Hacking Forums A threat actor is reportedly selling a purported critical severity zero-day exploit chain targeting OpenSea for $100,000 USD in Bitcoin or Monero. The listing claims the vulnerability remains unpatched and undisclosed, raising alarms in the NFT community. The exploit allegedly targets flaws…
-
CISA Warns of Microsoft Configuration Manager SQL Injection Vulnerability Exploited in Attacks
CISA Warns of Microsoft Configuration Manager SQL Injection Vulnerability Exploited in Attacks CISA has issued an urgent alert about a critical SQL injection vulnerability in Microsoft Configuration Manager (SCCM). Tracked as CVE-2024-43468, this flaw lets unauthenticated attackers run malicious commands on servers and databases. Added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on February 12,…
-
Malicious Chrome AI Extensions Attacking 260,000 Users via Injected IFrames
Malicious Chrome AI Extensions Attacking 260,000 Users via Injected IFrames A coordinated campaign is using malicious Chrome extensions that impersonate popular AI tools like ChatGPT, Claude, Gemini, and Grok. These fake “AI assistants” spy on users through injected, remote-controlled iframes, turning helpful browser add-ons into surveillance tools. More than 260,000 users have installed these extensions.…
-
Chrome Extensions Infected 500K Users to Hijack VKontakte Accounts
Chrome Extensions Infected 500K Users to Hijack VKontakte Accounts Over half a million VKontakte users have fallen victim to a sophisticated malware campaign that silently hijacks accounts through seemingly harmless Chrome extensions. The malicious extensions, disguised as VK customization tools, automatically subscribe users to attacker-controlled groups, reset account settings every 30 days, and manipulate security…
-
New ClickFix Attack Wave Targeting Windows Systems to Deploy StealC Stealer
New ClickFix Attack Wave Targeting Windows Systems to Deploy StealC Stealer A sophisticated social engineering campaign is targeting Windows users through fake CAPTCHA verification pages to deliver the StealC information stealer malware. The attack begins when victims visit compromised websites that display fraudulent Cloudflare security checks, tricking them into executing malicious PowerShell commands. The compromised…
-
TR-26-0065 (Universal Yazılım – FlexCity/Kiosk Güvenlik Bildirimi)
TR-26-0065 (Universal Yazılım – FlexCity/Kiosk Güvenlik Bildirimi) Go to usom.gov
-
Google Ties Suspected Russian Actor to CANFAIL Malware Attacks on Ukrainian Orgs
Google Ties Suspected Russian Actor to CANFAIL Malware Attacks on Ukrainian Orgs A previously undocumented threat actor has been attributed to attacks targeting Ukrainian organizations with malware known as CANFAIL. Google Threat Intelligence Group (GTIG) described the hack group as possibly affiliated with Russian intelligence services. The threat actor is assessed to have targeted defense,…
-
Google Links China, Iran, Russia, North Korea to Coordinated Defense Sector Cyber Operations
Google Links China, Iran, Russia, North Korea to Coordinated Defense Sector Cyber Operations Several state-sponsored actors, hacktivist entities, and criminal groups from China, Iran, North Korea, and Russia have trained their sights on the defense industrial base (DIB) sector, according to findings from Google Threat Intelligence Group (GTIG). The tech giant’s threat intelligence division said…
-
UAT-9921 Deploys VoidLink Malware to Target Technology and Financial Sectors
UAT-9921 Deploys VoidLink Malware to Target Technology and Financial Sectors A previously unknown threat actor tracked as UAT-9921 has been observed leveraging a new modular framework called VoidLink in its campaigns targeting the technology and financial services sectors, according to findings from Cisco Talos. “This threat actor seems to have been active since 2019, although…
-
Malicious Chrome Extensions Caught Stealing Business Data, Emails, and Browsing History
Malicious Chrome Extensions Caught Stealing Business Data, Emails, and Browsing History Cybersecurity researchers have discovered a malicious Google Chrome extension that’s designed to steal data associated with Meta Business Suite and Facebook Business Manager. The extension, named CL Suite by @CLMasters (ID: jkphinfhmfkckkcnifhjiplhfoiefffl), is marketed as a way to scrape Meta Business Suite data, remove…
-
npm’s Update to Harden Their Supply Chain, and Points to Consider
npm’s Update to Harden Their Supply Chain, and Points to Consider In December 2025, in response to the Sha1-Hulud incident, npm completed a major authentication overhaul intended to reduce supply-chain attacks. While the overhaul is a solid step forward, the changes don’t make npm projects immune from supply-chain attacks. npm is still susceptible to malware…
-
The OpenClaw experiment is a warning shot for enterprise AI security
The OpenClaw experiment is a warning shot for enterprise AI security Go to sophos
-
Friday Squid Blogging: Do Squid Dream?
Friday Squid Blogging: Do Squid Dream? An exploration of the interesting question. Bruce Schneier Go to bruce schneier
-
Urgent warnings from UK and US cyber agencies after Polish energy grid attack
Urgent warnings from UK and US cyber agencies after Polish energy grid attack A coordinated cyberattack that targeted Poland’s energy infrastructure in late December 2025 has prompted cybersecurity agencies to issue urgent warnings to critical national infrastructure operators on both sides of the Atlantic. Read more in my article on the Fortra blog. Graham Cluley…
-
Microsoft Under Pressure to Bolster Defenses for BYOVD Attacks
Microsoft Under Pressure to Bolster Defenses for BYOVD Attacks Threat actors are exploiting security gaps to weaponize Windows drivers and terminate security processes in targeted networks, and there may be no easy fixes in sight. Rob Wright Go to gbhackers.com
-
Nation-State Hackers Put Defense Industrial Base Under Siege
Nation-State Hackers Put Defense Industrial Base Under Siege Espionage groups from China, Russia and other nations burned at least two dozen zero-days in edge devices in attempts to infiltrate defense contractors’ networks. Robert Lemos, Contributing Writer Go to gbhackers.com
-
AI Agents ‘Swarm,’ Security Complexity Follows Suit
AI Agents ‘Swarm,’ Security Complexity Follows Suit As AI deployments scale and start to include packs of agents autonomously working in concert, organizations face a naturally amplified attack surface. Alexander Culafi Go to gbhackers.com
-
Chrome Extensions Infect 500K Users to Hijack VKontakte Accounts
Chrome Extensions Infect 500K Users to Hijack VKontakte Accounts A long-running Chrome extension malware campaign has silently hijacked more than 500,000 VKontakte (VK) accounts, forcing users into attacker-controlled groups, resetting their settings every… Go to gbhackers.com
-
Malicious Chrome AI Extensions Target 260,000 Users with Injected Iframes
Malicious Chrome AI Extensions Target 260,000 Users with Injected Iframes As AI tools like ChatGPT, Claude, Gemini, and Grok gain mainstream adoption, cybercriminals are weaponizing their popularity to distribute malicious browser extensions. Security researchers… Go to gbhackers.com
-
CISA Alerts Users to Notepad++ Flaw Allowing Code Execution
CISA Alerts Users to Notepad++ Flaw Allowing Code Execution The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in the popular Notepad++ text editor to its Known Exploited Vulnerabilities catalog,… Go to gbhackers.com
-
New XWorm RAT Campaign Leverages Phishing and CVE-2018-0802 Excel Exploit to Bypass Detection
New XWorm RAT Campaign Leverages Phishing and CVE-2018-0802 Excel Exploit to Bypass Detection XWorm, a multi-functional .NET‑based RAT first observed in 2022, remains actively traded across cybercrime marketplaces and continues to attract both low-skilled and advanced operators… Go to gbhackers.com
-
OpenClaw 2026.2.12 Released to Patch Over 40 Security Vulnerabilities
OpenClaw 2026.2.12 Released to Patch Over 40 Security Vulnerabilities The OpenClaw team has officially released version 2026.2.12, a comprehensive update focused heavily on security hardening and architectural stability. This release addresses over 40… Go to gbhackers.com
-
Microsoft fixes bug that blocked Google Chrome from launching
Microsoft fixes bug that blocked Google Chrome from launching Microsoft has fixed a known issue causing its Family Safety parental control service to block Windows users from launching Google Chrome and other web browsers. […] Sergiu Gatlan Go to bleepingcomputer
-
Russia tries to block WhatsApp, Telegram in communication blockade
Russia tries to block WhatsApp, Telegram in communication blockade The Russian government is attempting to block WhatsApp in the country as its crackdown on communication platforms not under its control intensifies. […] Bill Toulas Go to bleepingcomputer
-
Bitwarden introduces ‘Cupid Vault’ for secure password sharing
Bitwarden introduces ‘Cupid Vault’ for secure password sharing Bitwarden has launched a new system called ‘Cupid Vault’ that allows users to safely share passwords with trusted email addresses. […] Bill Toulas Go to bleepingcomputer
-
Critical BeyondTrust RCE flaw now exploited in attacks, patch now
Critical BeyondTrust RCE flaw now exploited in attacks, patch now A critical pre-authentication remote code execution vulnerability in BeyondTrust Remote Support and Privileged Remote Access appliances is now being exploited in attacks after a PoC was published online. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft: New Windows LNK spoofing issues aren’t vulnerabilities
Microsoft: New Windows LNK spoofing issues aren’t vulnerabilities Today, at Wild West Hackin’ Fest, security researcher Wietze Beukema disclosed multiple vulnerabilities in Windows LK shortcut files that allow attackers to deploy malicious payloads. […] Sergiu Gatlan Go to bleepingcomputer
-
Critical Vulnerability in Next-Mdx-Remote Allows Arbitrary Code Execution in React Server-Side Rendering
Critical Vulnerability in Next-Mdx-Remote Allows Arbitrary Code Execution in React Server-Side Rendering Security advisory HCSEC-2026-01 revealed a critical vulnerability in the next-mdx-remote library that allows attackers to execute arbitrary code on servers rendering untrusted MDX content. Tracked as CVE-2026-0969, the issue affects versions 4.3.0 through 5.0.0 and is fixed in 6.0.0. Next-mdx-remote is a popular…
-
Over 1,800 Windows Servers Compromised by BADIIS Malware in Large-Scale SEO Poisoning Campaign
Over 1,800 Windows Servers Compromised by BADIIS Malware in Large-Scale SEO Poisoning Campaign A sophisticated cyber campaign has compromised over 1,800 Windows servers globally, using a potent malware strain known as BADIIS. This operation targets Internet Information Services (IIS) environments, transforming legitimate infrastructure into a massive network for SEO poisoning. By hijacking these servers, threat…
-
CISA Warns of Notepad++ Code Execution Vulnerability Exploited in Attacks
CISA Warns of Notepad++ Code Execution Vulnerability Exploited in Attacks CISA has added CVE-2025-15556 to its Known Exploited Vulnerabilities (KEV) catalog, highlighting active exploitation of a critical code execution flaw in Notepad++, a widely used open-source text editor popular among developers and IT professionals. Added on February 12, 2026, with a federal civilian executive branch…
-
Odido Telecom Suffers Cyberattack – 6.2 Million Customer Accounts Affected
Odido Telecom Suffers Cyberattack – 6.2 Million Customer Accounts Affected Odido Telecom, a leading Dutch telecommunications provider, confirmed on February 12, 2026, that hackers accessed personal data from 6.2 million customer accounts in a major cyberattack. The breach, detected over the February 7-8 weekend, has raised alarms about phishing risks despite no disruption to services.…
-
287 Chrome Extensions Exfiltrate Browsing History From 37.4 Million Users
287 Chrome Extensions Exfiltrate Browsing History From 37.4 Million Users A massive data exfiltration operation involving 287 Chrome extensions that secretly steal browsing history from approximately 37.4 million users worldwide. According to research with alias qcontinuum1, the discovery represents roughly one percent of the global Chrome user base, highlighting a significant privacy breach affecting millions of…
-
Naming and shaming: How ransomware groups tighten the screws on victims
Naming and shaming: How ransomware groups tighten the screws on victims When corporate data is exposed on a dedicated leak site, the consequences linger long after the attack fades from the news cycle Go to eset
-
TR-26-0064 (NTN Bilgi İşlem Hizmetleri – Smart Panel Güvenlik Bildirimi)
TR-26-0064 (NTN Bilgi İşlem Hizmetleri – Smart Panel Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0063 (Farktör Yazılım – E-Ticaret Paketi Güvenlik Bildirimi)
TR-26-0063 (Farktör Yazılım – E-Ticaret Paketi Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0062 (WordPress Eklenti Güvenlik Bildirimi)
TR-26-0062 (WordPress Eklenti Güvenlik Bildirimi) Go to usom.gov
-
Google Reports State-Backed Hackers Using Gemini AI for Recon and Attack Support
Google Reports State-Backed Hackers Using Gemini AI for Recon and Attack Support Google on Thursday said it observed the North Korea-linked threat actor known as UNC2970 using its generative artificial intelligence (AI) model Gemini to conduct reconnaissance on its targets, as various hacking groups continue to weaponize the tool for accelerating various phases of the…
-
Lazarus Campaign Plants Malicious Packages in npm and PyPI Ecosystems
Lazarus Campaign Plants Malicious Packages in npm and PyPI Ecosystems Cybersecurity researchers have discovered a fresh set of malicious packages across npm and the Python Package Index (PyPI) repository linked to a fake recruitment-themed campaign orchestrated by the North Korea-linked Lazarus Group. The coordinated campaign has been codenamed graphalgo in reference to the first package…
-
ThreatsDay Bulletin: AI Prompt RCE, Claude 0-Click, RenEngine Loader, Auto 0-Days & 25+ Stories
ThreatsDay Bulletin: AI Prompt RCE, Claude 0-Click, RenEngine Loader, Auto 0-Days & 25+ Stories Threat activity this week shows one consistent signal — attackers are leaning harder on what already works. Instead of flashy new exploits, many operations are built around quiet misuse of trusted tools, familiar workflows, and overlooked exposures that sit in plain…
-
The CTEM Divide: Why 84% of Security Programs Are Falling Behind
The CTEM Divide: Why 84% of Security Programs Are Falling Behind A new 2026 market intelligence study of 128 enterprise security decision-makers (available here) reveals a stark divide forming between organizations – one that has nothing to do with budget size or industry and everything to do with a single framework decision. Organizations implementing Continuous…
-
83% of Ivanti EPMM Exploits Linked to Single IP on Bulletproof Hosting Infrastructure
83% of Ivanti EPMM Exploits Linked to Single IP on Bulletproof Hosting Infrastructure A significant chunk of the exploitation attempts targeting a newly disclosed security flaw in Ivanti Endpoint Manager Mobile (EPMM) can be traced back to a single IP address on bulletproof hosting infrastructure offered by PROSPERO. Threat intelligence firm GreyNoise said it recorded…
-
3D Printer Surveillance
3D Printer Surveillance New York is contemplating a bill that adds surveillance to 3D printers: New York’s 20262027 executive budget bill (S.9005 / A.10005) includes language that should alarm every maker, educator, and small manufacturer in the state. Buried in Part C is a provision requiring all 3D printers sold or delivered in New York…
-
AI-Powered Knowledge Graph Generator & APTs, (Thu, Feb 12th)
AI-Powered Knowledge Graph Generator & APTs, (Thu, Feb 12th) Unstructured text to interactive knowledge graph via LLM & SPO triplet extraction Courtesy of TLDR InfoSec Launches & Tools again, another fine discovery in Robert McDermott’s AI Powered Knowledge Graph Generator. Robert’s system takes unstructured text, uses your preferred LLM and extracts knowledge in the form of Subject-Predicate-Object (SPO) triplets,…
-
ISC Stormcast For Friday, February 13th, 2026 https://isc.sans.edu/podcastdetail/9808, (Fri, Feb 13th)
ISC Stormcast For Friday, February 13th, 2026 https://isc.sans.edu/podcastdetail/9808, (Fri, Feb 13th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Polish hacker charged seven years after massive Morele.net data breach
Polish hacker charged seven years after massive Morele.net data breach A 29-year-old Polish man has been charged in connection with a data breach that exposed the personal details of around 2.5 million customers of the popular Polish e-commerce website Morele.net. Read more in my article on the Hot for Security blog. Graham Cluley Go to…
-
Ivanti EPMM Zero-Day Bugs Spark Exploit Frenzy — Again
Ivanti EPMM Zero-Day Bugs Spark Exploit Frenzy — Again It’s time to phase out the “patch and pray” approach, eliminate needless public interfaces, and enforce authentication controls, one expert says. Nate Nelson, Contributing Writer Go to gbhackers.com
-
Booz Allen Announces General Availability of Vellox Reverser to Automate Malware Defense
Booz Allen Announces General Availability of Vellox Reverser to Automate Malware Defense The AI-powered product delivers expert-grade malware analysis and reverse engineering in minutes. Go to gbhackers.com
-
SpecterOps Launches BloodHound Scentry to Accelerate the Practice of Identity Attack Path Management
SpecterOps Launches BloodHound Scentry to Accelerate the Practice of Identity Attack Path Management Drawing on years of adversary tradecraft, SpecterOps experts work alongside customers to analyze and eliminate attack paths, protect critical assets, and stay ahead of emerging threats. Go to gbhackers.com
-
Gone With the Shame: One in Two Americans Are Reluctant to Talk About Romance Scam Incidents
Gone With the Shame: One in Two Americans Are Reluctant to Talk About Romance Scam Incidents Men should take extra care on Valentine’s Day because they are nearly twice as likely as women to fall victim to romance scams. Go to gbhackers.com
-
Chrome Security Update Released to Address Code Execution Vulnerabilities
Chrome Security Update Released to Address Code Execution Vulnerabilities Google has released Chrome 145 to the stable channel for Windows, Mac, and Linux systems, addressing 11 security vulnerabilities that could allow attackers to… Go to gbhackers.com
-
WordPress Backup Plugin Vulnerability Exposes 800,000 Sites to Remote Code Execution Attacks
WordPress Backup Plugin Vulnerability Exposes 800,000 Sites to Remote Code Execution Attacks A critical vulnerability in the popular WPvivid Backup & Migration plugin is putting more than 800,000 WordPress websites at risk of complete takeover through… Go to gbhackers.com
-
Palo Alto Networks Firewall Vulnerability Lets Attackers Trigger Reboot Loops
Palo Alto Networks Firewall Vulnerability Lets Attackers Trigger Reboot Loops Palo Alto Networks has disclosed a PAN-OS firewall vulnerability that can let remote attackers force repeated reboots, potentially pushing a device into a “reboot… Go to gbhackers.com