no alarms and no surprises please..
-
Palo Alto Networks Firewall Vulnerability Lets Attackers Trigger Reboot Loops
Palo Alto Networks Firewall Vulnerability Lets Attackers Trigger Reboot Loops Palo Alto Networks has disclosed a PAN-OS firewall vulnerability that can let remote attackers force repeated reboots, potentially pushing a device into a “reboot… Go to gbhackers.com
-
Malicious ‘duer-js’ NPM Package Distributes ‘Bada Stealer’ Malware Targeting Windows and Discord Users
Malicious ‘duer-js’ NPM Package Distributes ‘Bada Stealer’ Malware Targeting Windows and Discord Users A newly discovered malicious NPM package, dubbed duer-js , is being used to distribute an advanced information‑stealing malware that primarily targets Windows systems and Discord users…. Go to gbhackers.com
-
Adblock Filters Expose User Location Even With VPN Protection
Adblock Filters Expose User Location Even With VPN Protection A new fingerprinting technique called “Adbleed” reveals that VPN users aren’t as anonymous as they think. While VPNs hide your IP address and encrypt… Go to gbhackers.com
-
Google says hackers are abusing Gemini AI for all attacks stages
Google says hackers are abusing Gemini AI for all attacks stages Google Threat Intelligence Group (GTIG) has published a new report warning about AI model extraction/distillation attacks, in which private-sector firms and researchers use legitimate API access to systematically probe models and replicate their logic and reasoning. […] Bill Toulas Go to bleepingcomputer
-
Apple fixes zero-day flaw used in ‘extremely sophisticated’ attacks
Apple fixes zero-day flaw used in ‘extremely sophisticated’ attacks Apple has released security updates to fix a zero-day vulnerability that was exploited in an “extremely sophisticated attack” targeting specific individuals. […] Lawrence Abrams Go to bleepingcomputer
-
Windows 11 Notepad flaw let files execute silently via Markdown links
Windows 11 Notepad flaw let files execute silently via Markdown links Microsoft has fixed a “remote code execution” vulnerability in Windows 11 Notepad that allowed attackers to execute local or remote programs by tricking users into clicking specially crafted Markdown links, without displaying any Windows security warnings. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft Store Outlook add-in hijacked to steal 4,000 Microsoft accounts
Microsoft Store Outlook add-in hijacked to steal 4,000 Microsoft accounts The AgreeTo add-in for Outlook has been hijacked and turned into a phishing kit that stole more than 4,000 Microsoft account credentials. […] Bill Toulas Go to bleepingcomputer
-
Crazy ransomware gang abuses employee monitoring tool in attacks
Crazy ransomware gang abuses employee monitoring tool in attacks A member of the Crazy ransomware gang is abusing legitimate employee monitoring software and the SimpleHelp remote support tool to maintain persistence in corporate networks, evade detection, and prepare for ransomware deployment. […] Lawrence Abrams Go to bleepingcomputer
-
Fake CAPTCHA Attacks Emerge as Key Entry Point for LummaStealer Malware Campaigns
Fake CAPTCHA Attacks Emerge as Key Entry Point for LummaStealer Malware Campaigns LummaStealer, a notorious information-stealing malware, has made a significant comeback following a major law enforcement disruption in 2025. This resurgence is characterized by a shift in distribution tactics, moving away from traditional exploit kits towards aggressive social engineering campaigns. Cybercriminals are now leveraging…
-
Microsoft Outlook Add-in Stolen 4,000 Microsoft account Credentials and Credit Card Numbers
Microsoft Outlook Add-in Stolen 4,000 Microsoft account Credentials and Credit Card Numbers Security researchers have identified the first documented instance of a malicious Microsoft Outlook add-in being used against users in real-world scenarios. A compromised meeting scheduler named AgreeTo was used to steal over 4,000 Microsoft account credentials, credit card numbers, and answers to banking security questions.…
-
Promptware – Hackers Can Use Google Calendar Invites to Stream Victims’ Cameras via Zoom
Promptware – Hackers Can Use Google Calendar Invites to Stream Victims’ Cameras via Zoom A new and dangerous class of cyberattack called “Promptware” has been discovered, capable of turning your personal AI assistant into a sleeper agent that spies on you. Security researchers from Ben-Gurion University, Tel Aviv University, and Harvard have demonstrated a terrifying…
-
$44 Evilmouse Autonomously Executes Commands and Compromises Systems Once Connected
$44 Evilmouse Autonomously Executes Commands and Compromises Systems Once Connected A $44 hardware implant disguised as an ordinary computer mouse. This device acts as a covert keystroke injector, akin to the Hak5 Rubber Ducky, but leverages the innocuous form factor of a mouse to bypass basic user awareness training. Plug it in, and it autonomously…
-
Palo Alto Networks Firewall Vulnerability Allows an Attacker to Force Firewalls into a Reboot Loop
Palo Alto Networks Firewall Vulnerability Allows an Attacker to Force Firewalls into a Reboot Loop A critical denial-of-service (DoS) flaw in Palo Alto Networks’ PAN-OS software could let unauthenticated attackers crash firewalls into endless reboot cycles, potentially crippling enterprise networks. Dubbed CVE-2026-0229, the vulnerability lurks in the Advanced DNS Security (ADNS) feature. An attacker sends…
-
Senegalese Data Breaches Expose Lack of ‘Security Maturity’
Senegalese Data Breaches Expose Lack of ‘Security Maturity’ Green Blood Group steals personal records and biometric data of the West African nation’s nearly 20 million residents. Nate Nelson, Contributing Writer Go to gbhackers.com
-
TR-26-0061 (Logo Yazılım – Logo j-Platform Güvenlik Bildirimi)
TR-26-0061 (Logo Yazılım – Logo j-Platform Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0060 (E-Kalite Yazılım – Turboard Güvenlik Bildirimi)
TR-26-0060 (E-Kalite Yazılım – Turboard Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0059 (Dinosoft Business Solutions – Dinosoft ERP Güvenlik Bildirimi)
TR-26-0059 (Dinosoft Business Solutions – Dinosoft ERP Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0058 (Pan Yazılım & Bilişim Teknolojileri – PanCafe Pro Güvenlik Bildirimi)
TR-26-0058 (Pan Yazılım & Bilişim Teknolojileri – PanCafe Pro Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0057 (Microsoft Windows Güvenlik Bildirimi)
TR-26-0057 (Microsoft Windows Güvenlik Bildirimi) Go to usom.gov
-
Apple Fixes Exploited Zero-Day Affecting iOS, macOS, and Apple Devices
Apple Fixes Exploited Zero-Day Affecting iOS, macOS, and Apple Devices Apple on Wednesday released iOS, iPadOS, macOS Tahoe, tvOS, watchOS, and visionOS updates to address a zero-day flaw that it said has been exploited in sophisticated cyber attacks. The vulnerability, tracked as CVE-2026-20700 (CVSS score: N/A), has been described as a memory corruption issue in…
-
First Malicious Outlook Add-In Found Stealing 4,000+ Microsoft Credentials
First Malicious Outlook Add-In Found Stealing 4,000+ Microsoft Credentials Cybersecurity researchers have discovered what they said is the first known malicious Microsoft Outlook add-in detected in the wild. In this unusual supply chain attack detailed by Koi Security, an unknown attacker claimed the domain associated with a now-abandoned legitimate add-in to serve a fake Microsoft…
-
APT36 and SideCopy Launch Cross-Platform RAT Campaigns Against Indian Entities
APT36 and SideCopy Launch Cross-Platform RAT Campaigns Against Indian Entities Indian defense sector and government-aligned organizations have been targeted by multiple campaigns that are designed to compromise Windows and Linux environments with remote access trojans capable of stealing sensitive data and ensuring continued access to infected machines. The campaigns are characterized by the use of…
-
Over 60 Software Vendors Issue Security Fixes Across OS, Cloud, and Network Platforms
Over 60 Software Vendors Issue Security Fixes Across OS, Cloud, and Network Platforms It’s Patch Tuesday, which means a number of software vendors have released patches for various security vulnerabilities impacting their products and services. Microsoft issued fixes for 59 flaws, including six actively exploited zero-days in various Windows components that could be abused to…
-
Exposed Training Open the Door for Crypto-Mining in Fortune 500 Cloud Environments
Exposed Training Open the Door for Crypto-Mining in Fortune 500 Cloud Environments Intentionally vulnerable training applications are widely used for security education, internal testing, and product demonstrations. Tools such as OWASP Juice Shop, DVWA, Hackazon, and bWAPP are designed to be insecure by default, making them useful for learning how common attack techniques work in…
-
Rewiring Democracy Ebook is on Sale
Rewiring Democracy Ebook is on Sale I just noticed that the ebook version of Rewriring Democracy is on sale for $5 on Amazon, Apple Books, Barnes & Noble, Books A Million, Google Play, Kobo, and presumably everywhere else in the US. I have no idea how long this will last. Also, Amazon has a coupon…
-
Prompt Injection Via Road Signs
Prompt Injection Via Road Signs Interesting research: “CHAI: Command Hijacking Against Embodied AI.” Abstract: Embodied Artificial Intelligence (AI) promises to handle edge cases in robotic vehicle systems where data is scarce by using common-sense reasoning grounded in perception and action to generalize beyond training distributions and adapt to novel real-world situations. These capabilities, however, also…
-
ISC Stormcast For Thursday, February 12th, 2026 https://isc.sans.edu/podcastdetail/9806, (Thu, Feb 12th)
ISC Stormcast For Thursday, February 12th, 2026 https://isc.sans.edu/podcastdetail/9806, (Thu, Feb 12th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Four Seconds to Botnet – Analyzing a Self Propagating SSH Worm with Cryptographically Signed C2 [Guest Diary], (Wed, Feb 11th)
Four Seconds to Botnet – Analyzing a Self Propagating SSH Worm with Cryptographically Signed C2 [Guest Diary], (Wed, Feb 11th) [This is a Guest Diary by Johnathan Husch, an ISC intern as part of the SANS.edu BACS program] Weak SSH passwords remain one of the most consistently exploited attack surfaces on the Internet. Even today,…
-
Apple Patches Everything: February 2026, (Wed, Feb 11th)
Apple Patches Everything: February 2026, (Wed, Feb 11th) Today, Apple released updates for all of its operating systems (iOS, iPadOS, macOS, tvOS, watchOS, and visionOS). The update fixes 71 distinct vulnerabilities, many of which affect multiple operating systems. Older versions of iOS, iPadOS, and macOS are also updated. OF special note is CVE-2026-20700. This vulnerability has…
-
WSL in the Malware Ecosystem, (Wed, Feb 11th)
WSL in the Malware Ecosystem, (Wed, Feb 11th) WSL or “Windows Subsystem Linux”[1] is a feature in the Microsoft Windows ecosystem that allows users to run a real Linux environment directly inside Windows without needing a traditional virtual machine or dual boot setup. The latest version, WSL2, runs a lightweight virtualized Linux kernel for better…
-
Kimwolf Botnet Swamps Anonymity Network I2P
Kimwolf Botnet Swamps Anonymity Network I2P For the past week, the massive “Internet of Things” (IoT) botnet known as Kimwolf has been disrupting The Invisible Internet Project (I2P), a decentralized, encrypted communications network designed to anonymize and secure online communications. I2P users started reporting disruptions in the network around the same time the Kimwolf botmasters…
-
Smashing Security podcast #454: AI was not plotting humanity’s demise. Humans were
Smashing Security podcast #454: AI was not plotting humanity’s demise. Humans were AI bots are having existential crises, inventing religions, and allegedly plotting against humanity… or so the internet would have you believe. We dig into Moltbook, the “AI-only” social network that sent Twitter into a meltdown, attracted breathless talk of the singularity, and turned…
-
North Korea’s UNC1069 Hammers Crypto Firms With AI
North Korea’s UNC1069 Hammers Crypto Firms With AI In moving away from traditional banks to focus on Web3 companies, the threat actor is leveraging LLMs, deepfakes, legitimate platforms, and ClickFix. Alexander Culafi Go to gbhackers.com
-
AI Rising: Do We Know Enough About the Data Populating It?
AI Rising: Do We Know Enough About the Data Populating It? Organizations remain reluctant to address the fact that AI can dangerously expose business operations as well as personal data. Adam Strange Go to gbhackers.com
-
Top Cyber Industry Defenses Spike CO2 Emissions
Top Cyber Industry Defenses Spike CO2 Emissions Organizations can improve their climate footprints by optimizing two specific cybersecurity protections, without incurring added risks. Nate Nelson, Contributing Writer Go to gbhackers.com
-
RU-APT-ChainReaver-L Hijacks Trusted Sites and GitHub in Sweeping Cross-Platform Supply Chain Attack
RU-APT-ChainReaver-L Hijacks Trusted Sites and GitHub in Sweeping Cross-Platform Supply Chain Attack A newly exposed advanced persistent threat (APT) campaign, tracked as RU-APT-ChainReaver-L, is hijacking trusted file-hosting sites and long-standing GitHub accounts to deliver stealthy malware… Go to gbhackers.com
-
Ivanti Endpoint Manager Flaw Enables Remote Data Exposure
Ivanti Endpoint Manager Flaw Enables Remote Data Exposure Ivanti has issued a high-security update for its Endpoint Manager (EPM) solution to address two significant vulnerabilities that could put organisational data at risk…. Go to gbhackers.com
-
Windows Shell Zero-Day Vulnerability Allows Attackers to Bypass Authentication
Windows Shell Zero-Day Vulnerability Allows Attackers to Bypass Authentication Microsoft has issued an urgent security warning following the discovery of a zero-day vulnerability in the Windows Shell, now tracked as CVE-2026-21510. This critical flaw,… Go to gbhackers.com
-
Hackers Exploit ChatGPT, Grok and Google Ads to Spread macOS AMOS Stealer
Hackers Exploit ChatGPT, Grok and Google Ads to Spread macOS AMOS Stealer Threat actors are abusing shareable ChatGPT and Grok conversations and pushing them with Google Search ads to trick macOS users into running Terminal commands… Go to gbhackers.com
-
Windows Remote Access Connection Manager Zero-Day Enables DoS Attacks
Windows Remote Access Connection Manager Zero-Day Enables DoS Attacks Microsoft has released urgent security updates to address a zero-day vulnerability in the Windows Remote Access Connection Manager (RasMan). Assigned the identifier CVE-2026-21525, this flaw… Go to gbhackers.com
-
Microsoft releases Windows 11 26H1 for select and upcoming CPUs
Microsoft releases Windows 11 26H1 for select and upcoming CPUs Microsoft has announced Windows 11 26H1, but it’s not for existing PCs. Instead, it will ship on devices with Snapdragon X2 processors and possibly other rumored ARM chips.w […] Mayank Parmar Go to bleepingcomputer
-
New Linux botnet SSHStalker uses old-school IRC for C2 comms
New Linux botnet SSHStalker uses old-school IRC for C2 comms A newly documented Linux botnet named SSHStalker is using the IRC (Internet Relay Chat) communication protocol for command-and-control (C2) operations. […] Bill Toulas Go to bleepingcomputer
-
North Korean hackers use new macOS malware in crypto-theft attacks
North Korean hackers use new macOS malware in crypto-theft attacks North Korean hackers are running tailored campaigns using AI-generated video and the ClickFix technique to deliver malware for macOS and Windows to targets in the cryptocurrency sector. […] Bill Toulas Go to bleepingcomputer
-
Malicious 7-Zip site distributes installer laced with proxy tool
Malicious 7-Zip site distributes installer laced with proxy tool A fake 7-Zip website is distributing a trojanized installer of the popular archiving tool that turns the user’s computer into a residential proxy node. […] Bill Toulas Go to bleepingcomputer
-
Microsoft releases Windows 10 KB5075912 extended security update
Microsoft releases Windows 10 KB5075912 extended security update Microsoft has released the Windows 10 KB5075912 extended security update to fix February 2026 Patch Tuesday vulnerabilities, including six zero-days, and continue rolling out replacements for expiring Secure Boot certificates. […] Lawrence Abrams Go to bleepingcomputer
-
Socelars Malware Attacking Windows Systems to Steal Sensitive Business Data
Socelars Malware Attacking Windows Systems to Steal Sensitive Business Data A dangerous information-stealing malware called Socelars is actively targeting Windows systems to collect sensitive authentication data, with particular focus on Facebook Ads Manager accounts and session cookies. Unlike traditional malware that causes immediate system damage, Socelars operates silently in the background, turning infected machines into…
-
Windows Shell Security Feature 0-Day Vulnerability Let Attackers Bypass Authentication
Windows Shell Security Feature 0-Day Vulnerability Let Attackers Bypass Authentication Microsoft released Microsoft Patch Tuesday updates to address a critical zero-day vulnerability in Windows Shell that is currently being actively exploited in the wild. Tracked as CVE-2026-21510, this security flaw allows remote attackers to bypass essential protection mechanisms, putting millions of Windows users at risk. The…
-
GitLab Patches Multiple Vulnerabilities That Enables DoS and Cross-site Scripting Attacks
GitLab Patches Multiple Vulnerabilities That Enables DoS and Cross-site Scripting Attacks A critical security update has been released for both the Community Edition (CE) and Enterprise Edition (EE) to address multiple high-severity vulnerabilities. The patches, available in versions 18.8.4, 18.7.4, and 18.6.6, fix flaws that could allow attackers to crash servers, steal data, or hijack…
-
Windows Notepad Vulnerability Allows Attackers to Execute Malicious Code Remotely
Windows Notepad Vulnerability Allows Attackers to Execute Malicious Code Remotely Microsoft has patched a critical remote code execution (RCE) flaw in the Windows Notepad app, tracked as CVE-2026-20841, which could let attackers run malicious code on victims’ machines. Disclosed on February 10, 2026, Microsoft Patch Tuesday updates, the vulnerability stems from improper neutralization of special…
-
Windows Remote Desktop Services 0-Day Vulnerability Exploited in the Wild to Escalate Privileges
Windows Remote Desktop Services 0-Day Vulnerability Exploited in the Wild to Escalate Privileges Microsoft has patched CVE-2026-21533, a zero-day elevation of privilege vulnerability in Windows Remote Desktop Services (RDS) that attackers are exploiting in the wild to gain SYSTEM-level access. The flaw stems from improper privilege management and was addressed in the February 2026 Patch…
-
Taxing times: Top IRS scams to look out for in 2026
Taxing times: Top IRS scams to look out for in 2026 It’s time to file your tax return. And cybercriminals are lurking to make an already stressful period even more edgy. Go to eset
-
TR-26-0055 (Saastech Temizlik Yolda İnternet Hizmetleri – TemizlikYolda Güvenlik Bildirimi)
TR-26-0055 (Saastech Temizlik Yolda İnternet Hizmetleri – TemizlikYolda Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0054 (Microsoft Azure Güvenlik Bildirimi)
TR-26-0054 (Microsoft Azure Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0053 (WordPress Eklenti Güvenlik Bildirimi)
TR-26-0053 (WordPress Eklenti Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0052 (Ergosis Güvenlik Sistemleri – ZEUS PDKS Güvenlik Bildirimi)
TR-26-0052 (Ergosis Güvenlik Sistemleri – ZEUS PDKS Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0051 (Dinibh Puzzle Yazılım Çözümleri – Dinibh Devriye Takip Sistemi Güvenlik Bildirimi)
TR-26-0051 (Dinibh Puzzle Yazılım Çözümleri – Dinibh Devriye Takip Sistemi Güvenlik Bildirimi) Go to usom.gov
-
DPRK Operatives Impersonate Professionals on LinkedIn to Infiltrate Companies
DPRK Operatives Impersonate Professionals on LinkedIn to Infiltrate Companies The information technology (IT) workers associated with the Democratic People’s Republic of Korea (DPRK) are now applying to remote positions using real LinkedIn accounts of individuals they’re impersonating, marking a new escalation of the fraudulent scheme. “These profiles often have verified workplace emails and identity badges,…
-
Reynolds Ransomware Embeds BYOVD Driver to Disable EDR Security Tools
Reynolds Ransomware Embeds BYOVD Driver to Disable EDR Security Tools Cybersecurity researchers have disclosed details of an emergent ransomware family dubbed Reynolds that comes embedded with a built-in bring your own vulnerable driver (BYOVD) component for defense evasion purposes within the ransomware payload itself. BYOVD refers to an adversarial technique that abuses legitimate but flawed…
-
From Ransomware to Residency: Inside the Rise of the Digital Parasite
From Ransomware to Residency: Inside the Rise of the Digital Parasite Are ransomware and encryption still the defining signals of modern cyberattacks, or has the industry been too fixated on noise while missing a more dangerous shift happening quietly all around them? According to Picus Labs’ new Red Report 2026, which analyzed over 1.1 million…
-
From Security Operations to Security Leadership: Sophos CISO Advantage
From Security Operations to Security Leadership: Sophos CISO Advantage Go to sophos
-
Asia Fumbles With Throttling Back Telnet Traffic in Region
Asia Fumbles With Throttling Back Telnet Traffic in Region Only Taiwan made the top 10 list of governments, effectively blocking the threat-ridden protocol, but overall the region lagged in curbing Telnet traffic. Robert Lemos, Contributing Writer Go to gbhackers.com
-
AI-Generated Text and the Detection Arms Race
AI-Generated Text and the Detection Arms Race In 2023, the science fiction literary magazine Clarkesworld stopped accepting new submissions because so many were generated by artificial intelligence. Near as the editors could tell, many submitters pasted the magazine’s detailed story guidelines into an AI and sent in the results. And they weren’t alone. Other fiction…
-
ISC Stormcast For Wednesday, February 11th, 2026 https://isc.sans.edu/podcastdetail/9804, (Wed, Feb 11th)
ISC Stormcast For Wednesday, February 11th, 2026 https://isc.sans.edu/podcastdetail/9804, (Wed, Feb 11th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Microsoft Patch Tuesday – February 2026, (Tue, Feb 10th)
Microsoft Patch Tuesday – February 2026, (Tue, Feb 10th) Today’s patch Tuesday addresses 59 different vulnerabilities (plus two Chromium vulnerabilities affecting Microsoft Edge). While this is a lower-than-normal number, this includes six vulnerabilities that are already exploited. Three vulnerabilities have already been exploited and made public. In addition, five critical vulnerabilities are included in this…
-
Patch Tuesday, February 2026 Edition
Patch Tuesday, February 2026 Edition Microsoft today released updates to fix more than 50 security holes in its Windows operating systems and other software, including patches for a whopping six “zero-day” vulnerabilities that attackers are already exploiting in the wild. Zero-day #1 this month is CVE-2026-21510, a security feature bypass vulnerability in Windows Shell wherein…
-
SolarWinds WHD Attacks Highlight Risks of Exposed Apps
SolarWinds WHD Attacks Highlight Risks of Exposed Apps Organizations that have exposed their instances of Web Help Desk to the public Internet have inadvertently made them prime targets for attackers. Rob Wright Go to gbhackers.com
-
In Bypassing MFA, ZeroDayRAT Is ‘Textbook Stalkerware’
In Bypassing MFA, ZeroDayRAT Is ‘Textbook Stalkerware’ With access to SIM, location data, and a preview of recent SMSes, attackers have everything they need for account takeover or targeted social engineering. Alexander Culafi Go to gbhackers.com
-
Microsoft Patches 6 Actively Exploited Zero-Days
Microsoft Patches 6 Actively Exploited Zero-Days Three of those zero-days are security feature bypass flaws, which give attackers a way to slip past built-in protections in multiple Microsoft products. Jai Vijayan, Contributing Writer Go to gbhackers.com
-
OT Attacks Get Scary With ‘Living-off-the-Plant’ Techniques
OT Attacks Get Scary With ‘Living-off-the-Plant’ Techniques Ironically, security by obscurity has helped prevent dangerous OT attacks in recent years. It won’t be that way forever. Nate Nelson, Contributing Writer Go to gbhackers.com
-
TransUnion’s Real Networks Deal Focuses on Robocall Blocking
TransUnion’s Real Networks Deal Focuses on Robocall Blocking The acquisition allows the credit reporting agency to add SMS spam and scam prevention to its robocall blocking capabilities. Jeffrey Schwartz Go to gbhackers.com
-
Windows Error Reporting Flaw Allows Attackers to Elevate Privileges
Windows Error Reporting Flaw Allows Attackers to Elevate Privileges A newly documented Windows vulnerability, CVE-2026-20817, impacts the Windows Error Reporting Service (WER) and enables local privilege escalation. The issue matters because WER runs… Go to gbhackers.com
-
Attackers Weaponize Windows Shortcut Files to Deploy Global Group Ransomware
Attackers Weaponize Windows Shortcut Files to Deploy Global Group Ransomware A high-volume phishing campaign leveraging the Phorpiex botnet has been distributing GLOBAL GROUP ransomware through weaponized Windows shortcut files. The attack begins with an… Go to gbhackers.com
-
Axios Vulnerability Allows Attackers to Trigger DoS and Crash Node.js Servers
Axios Vulnerability Allows Attackers to Trigger DoS and Crash Node.js Servers A serious security flaw has been discovered in Axios, one of the most popular HTTP client libraries for Node.js, allowing attackers to crash servers… Go to gbhackers.com
-
Fancy Bear Exploits Microsoft Zero-Day to Deploy Backdoors and Email Stealers
Fancy Bear Exploits Microsoft Zero-Day to Deploy Backdoors and Email Stealers Fancy Bear has launched a sophisticated campaign exploiting a critical zero-day vulnerability in Microsoft RTF files to target users across Central and Eastern Europe…. Go to gbhackers.com
-
15,200 OpenClaw Control Panels Exposed Online with Full System Access
15,200 OpenClaw Control Panels Exposed Online with Full System Access A critical security oversight has left thousands of AI agents wide open to the public internet. 15,200 instances of the OpenClaw AI framework (formerly… Go to gbhackers.com
-
Fugitive behind $73M ‘pig butchering’ scheme gets 20 years in prison
Fugitive behind $73M ‘pig butchering’ scheme gets 20 years in prison A dual Chinese and St. Kitts and Nevis national was sentenced to 20 years in prison in absentia for his role in an international cryptocurrency investment scheme (also known as pig butchering or romance baiting) that defrauded victims of more than $73 million. […]…
-
Chinese cyberspies breach Singapore’s four largest telcos
Chinese cyberspies breach Singapore’s four largest telcos The Chinese threat actor tracked as UNC3886 breached Singapore’s four largest telecommunication service providers, Singtel, StarHub, M1, and Simba, at least once last year. […] Bill Toulas Go to bleepingcomputer
-
Hackers exploit SolarWinds WHD flaws to deploy DFIR tool in attacks
Hackers exploit SolarWinds WHD flaws to deploy DFIR tool in attacks Hackers are now exploiting SolarWinds Web Help Desk (WHD) vulnerabilities to gain code execution rights on exposed systems and deploy legitimate tools, including the Velociraptor forensics tools, for persistence and remote control. […] Bill Toulas Go to bleepingcomputer
-
Hackers breach SmarterTools network using flaw in its own software
Hackers breach SmarterTools network using flaw in its own software SmarterTools confirmed last week that the Warlock ransomware gang breached its network after compromising an email system, but did not impact business applications or account data. […] Bill Toulas Go to bleepingcomputer
-
Password guessing without AI: How attackers build targeted wordlists
Password guessing without AI: How attackers build targeted wordlists Attackers don’t need AI to crack passwords, they build targeted wordlists from an organization’s own public language. This article explains how tools like CeWL turn websites into high-success password guesses and why complexity rules alone fall short. […] Sponsored by Specops Software Go to bleepingcomputer
-
AI Chat App Exposes 300 Million Messages from 25 Million Users
AI Chat App Exposes 300 Million Messages from 25 Million Users The popular mobile application “Chat & Ask AI” has inadvertently exposed hundreds of millions of private user conversations. The app, which boasts over 50 million users across the Google Play and Apple App stores, failed to secure its backend database, allowing unauthorized access to…
-
Bloody Wolf Hackers Attacking Organizations to Deploy NetSupport RAT and Gain Remote Access
Bloody Wolf Hackers Attacking Organizations to Deploy NetSupport RAT and Gain Remote Access Stan Ghouls, a cybercriminal group also known as Bloody Wolf, has launched a sophisticated wave of targeted attacks against organizations across Russia and Uzbekistan. Active since at least 2023, the group focuses heavily on the manufacturing, finance, and IT sectors. While they…
-
Augustus – Open-source LLM Vulnerability Scanner With 210+ Attacks Across 28 LLM Providers
Augustus – Open-source LLM Vulnerability Scanner With 210+ Attacks Across 28 LLM Providers Augustus is a new open-source vulnerability scanner designed to secure Large Language Models (LLMs) against an evolving landscape of adversarial threats. Built by Praetorian, Augustus aims to bridge the gap between academic research tools and production-grade security testing, offering a single-binary solution…
-
Chinese Hackers Attacking Singapore’s Telecommunications Sector to Compromise Edge Devices
Chinese Hackers Attacking Singapore’s Telecommunications Sector to Compromise Edge Devices Singapore’s telecommunications sector has recently been the target of a highly sophisticated cyber espionage campaign orchestrated by the Advanced Persistent Threat (APT) group known as UNC3886. The details of this extensive intrusion were formally disclosed following Operation CYBER GUARDIAN, a major multi-agency response led by…
-
15,200 OpenClaw Control Panels with Full System Access Exposed to the Internet
15,200 OpenClaw Control Panels with Full System Access Exposed to the Internet A critical security failure in the rapidly adopting “agentic AI” ecosystem has left tens of thousands of personal and corporate AI assistants fully exposed to the public internet. New research released today by the SecurityScorecard STRIKE Threat Intelligence Team reveals that 15,200 instances…
-
TR-26-0047 (Centreon Infra Monitoring Güvenlik Bildirimi)
TR-26-0047 (Centreon Infra Monitoring Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0046 (Sony BRAVIA Digital Signage Güvenlik Bildirimi)
TR-26-0046 (Sony BRAVIA Digital Signage Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0045 (Veeam Backup & Replication Güvenlik Bildirimi)
TR-26-0045 (Veeam Backup & Replication Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0044 (Zohocorp ManageEngine Güvenlik Bildirimi)
TR-26-0044 (Zohocorp ManageEngine Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0043 (IBM Güvenlik Bildirimi)
TR-26-0043 (IBM Güvenlik Bildirimi) Go to usom.gov
-
Fortinet Patches Critical SQLi Flaw Enabling Unauthenticated Code Execution
Fortinet Patches Critical SQLi Flaw Enabling Unauthenticated Code Execution Fortinet has released security updates to address a critical flaw impacting FortiClientEMS that could lead to the execution of arbitrary code on susceptible systems. The vulnerability, tracked as CVE-2026-21643, has a CVSS rating of 9.1 out of a maximum of 10.0. “An improper neutralization of special…
-
China-Linked UNC3886 Targets Singapore Telecom Sector in Cyber Espionage Campaign
China-Linked UNC3886 Targets Singapore Telecom Sector in Cyber Espionage Campaign The Cyber Security Agency (CSA) of Singapore on Monday revealed that the China-nexus cyber espionage group known as UNC3886 targeted its telecommunications sector. “UNC3886 had launched a deliberate, targeted, and well-planned campaign against Singapore’s telecommunications sector,” CSA said. “All four of Singapore’s major telecommunications operators…
-
SolarWinds Web Help Desk Exploited for RCE in Multi-Stage Attacks on Exposed Servers
SolarWinds Web Help Desk Exploited for RCE in Multi-Stage Attacks on Exposed Servers Microsoft has revealed that it observed a multi‑stage intrusion that involved the threat actors exploiting internet‑exposed SolarWinds Web Help Desk (WHD) instances to obtain initial access and move laterally across the organization’s network to other high-value assets. That said, the Microsoft Defender…
-
⚡ Weekly Recap: AI Skill Malware, 31Tbps DDoS, Notepad++ Hack, LLM Backdoors and More
⚡ Weekly Recap: AI Skill Malware, 31Tbps DDoS, Notepad++ Hack, LLM Backdoors and More Cyber threats are no longer coming from just malware or exploits. They’re showing up inside the tools, platforms, and ecosystems organizations use every day. As companies connect AI, cloud apps, developer tools, and communication systems, attackers are following those same paths.…
-
How Top CISOs Solve Burnout and Speed up MTTR without Extra Hiring
How Top CISOs Solve Burnout and Speed up MTTR without Extra Hiring Why do SOC teams keep burning out and missing SLAs even after spending big on security tools? Routine triage piles up, senior specialists get dragged into basic validation, and MTTR climbs, while stealthy threats still find room to slip through. Top CISOs have…
-
LLMs are Getting a Lot Better and Faster at Finding and Exploiting Zero-Days
LLMs are Getting a Lot Better and Faster at Finding and Exploiting Zero-Days This is amazing: Opus 4.6 is notably better at finding high-severity vulnerabilities than previous models and a sign of how quickly things are moving. Security teams have been automating vulnerability discovery for years, investing heavily in fuzzing infrastructure and custom harnesses to…
-
ISC Stormcast For Tuesday, February 10th, 2026 https://isc.sans.edu/podcastdetail/9802, (Tue, Feb 10th)
ISC Stormcast For Tuesday, February 10th, 2026 https://isc.sans.edu/podcastdetail/9802, (Tue, Feb 10th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
ISC Stormcast For Monday, February 9th, 2026 https://isc.sans.edu/podcastdetail/9800, (Mon, Feb 9th)
ISC Stormcast For Monday, February 9th, 2026 https://isc.sans.edu/podcastdetail/9800, (Mon, Feb 9th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Quick Howto: Extract URLs from RTF files, (Mon, Feb 9th)
Quick Howto: Extract URLs from RTF files, (Mon, Feb 9th) Malicious RTF (Rich Text Format) documents are back in the news with the exploitation of CVE-2026-21509 by APT28. The malicious RTF documents BULLETEN_H.doc and Consultation_Topics_Ukraine(Final).doc mentioned in the news are RTF files (despite their .doc extension, a common trick used by threat actors). Here is a quick…
-
YARA-X 1.13.0 Release, (Mon, Feb 9th)
YARA-X 1.13.0 Release, (Mon, Feb 9th) YARA-X’s 1.13.0 release brings 4 improvements and 4 bugfixes. Didier Stevens Senior handler blog.DidierStevens.com (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu