no alarms and no surprises please..
-
Attackers Using DNS TXT Records in ClickFix Script to Execute Powershell Commands
Attackers Using DNS TXT Records in ClickFix Script to Execute Powershell Commands The cybersecurity landscape has darkened with the sophisticated evolution of the KongTuke campaign. Active since mid-2025, this threat actor group has continuously refined its techniques to bypass conventional enterprise security filters. Their primary weapon remains the “ClickFix” strategy, a social engineering vector that…
-
TR-26-0018 (Martcode Yazılım – Delta Kurs Otomasyonu Güvenlik Bildirimi)
TR-26-0018 (Martcode Yazılım – Delta Kurs Otomasyonu Güvenlik Bildirimi) Go to usom.gov
-
Protests Don’t Impede Iranian Spying on Expats, Syrians, Israelis
Protests Don’t Impede Iranian Spying on Expats, Syrians, Israelis Iranian threat actors have been stealing credentials from people of interest across the Middle East, using spear-phishing and social engineering. Nate Nelson, Contributing Writer Go to gbhackers.com
-
Critical n8n Flaw CVE-2026-25049 Enables System Command Execution via Malicious Workflows
Critical n8n Flaw CVE-2026-25049 Enables System Command Execution via Malicious Workflows A new, critical security vulnerability has been disclosed in the n8n workflow automation platform that, if successfully exploited, could result in the execution of arbitrary system commands. The flaw, tracked as CVE-2026-25049 (CVSS score: 9.4), is the result of inadequate sanitization that bypasses safeguards…
-
Malicious NGINX Configurations Enable Large-Scale Web Traffic Hijacking Campaign
Malicious NGINX Configurations Enable Large-Scale Web Traffic Hijacking Campaign Cybersecurity researchers have disclosed details of an active web traffic hijacking campaign that has targeted NGINX installations and management panels like Baota (BT) in an attempt to route it through the attacker’s infrastructure. Datadog Security Labs said it observed threat actors associated with the recent React2Shell…
-
Microsoft Develops Scanner to Detect Backdoors in Open-Weight Large Language Models
Microsoft Develops Scanner to Detect Backdoors in Open-Weight Large Language Models Microsoft on Wednesday said it built a lightweight scanner that it said can detect backdoors in open-weight large language models (LLMs) and improve the overall trust in artificial intelligence (AI) systems. The tech giant’s AI Security team said the scanner leverages three observable signals…
-
DEAD#VAX Malware Campaign Deploys AsyncRAT via IPFS-Hosted VHD Phishing Files
DEAD#VAX Malware Campaign Deploys AsyncRAT via IPFS-Hosted VHD Phishing Files Threat hunters have disclosed details of a new, stealthy malware campaign dubbed DEAD#VAX that employs a mix of “disciplined tradecraft and clever abuse of legitimate system features” to bypass traditional detection mechanisms and deploy a remote access trojan (RAT) known as AsyncRAT. “The attack leverages…
-
China-Linked Amaranth-Dragon Exploits WinRAR Flaw in Espionage Campaigns
China-Linked Amaranth-Dragon Exploits WinRAR Flaw in Espionage Campaigns Threat actors affiliated with China have been attributed to a fresh set of cyber espionage campaigns targeting government and law enforcement agencies across Southeast Asia throughout 2025. Check Point Research is tracking the previously undocumented activity cluster under the moniker Amaranth-Dragon, which it said shares links to…
-
Malicious use of virtual machine infrastructure
Malicious use of virtual machine infrastructure Go to sophos
-
US Declassifies Information on JUMPSEAT Spy Satellites
US Declassifies Information on JUMPSEAT Spy Satellites The US National Reconnaissance Office has declassified information about a fleet of spy satellites operating between 1971 and 2006. I’m actually impressed to see a declassification only two decades after decommission. Bruce Schneier Go to bruce schneier
-
ISC Stormcast For Thursday, February 5th, 2026 https://isc.sans.edu/podcastdetail/9796, (Thu, Feb 5th)
ISC Stormcast For Thursday, February 5th, 2026 https://isc.sans.edu/podcastdetail/9796, (Thu, Feb 5th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Malicious Script Delivering More Maliciousness, (Wed, Feb 4th)
Malicious Script Delivering More Maliciousness, (Wed, Feb 4th) Today, I received an interesting email with a malicious attachment. When I had a look at the automatic scan results, it seemed to be a malicious script to create a Chrome Injector to steal data. Because InfoStealers are very common these days, it looked “legit” but there…
-
Smashing Security podcast #453: The Epstein Files didn’t hide this hacker very well
Smashing Security podcast #453: The Epstein Files didn’t hide this hacker very well Supposedly redacted Jeffrey Epstein files can still reveal exactly who they’re talking about – especially when AI, LinkedIn, and a few biographical breadcrumbs do the heavy lifting. Sloppy redaction leads to explosive claims, and difficult reputational consequences for cybersecurity vendors, and we…
-
Weekly Update 489
Weekly Update 489 This week I’m in Hong Kong, and the day after recording, I gave the talk shown in the image above at INTERPOL’s Cybercrime Expert Group. I posted a little about this on Facebook and LinkedIn, but thought I’d expand on what really stuck with me after watching other speakers: the effort agencies…
-
Ransomware Gang Goes Full ‘Godfather’ With Cartel
Ransomware Gang Goes Full ‘Godfather’ With Cartel Since its launch in 2023, DragonForce has pushed a cartel model, emphasizing cooperation and coordination among ransomware gangs. Jai Vijayan, Contributing Writer Go to gbhackers.com
-
CISA Makes Unpublicized Ransomware Updates to KEV Catalog
CISA Makes Unpublicized Ransomware Updates to KEV Catalog A third of the “flipped” CVEs affected network edge devices, leading one researcher to conclude, “Ransomware operators are building playbooks around your perimeter.” Rob Wright Go to gbhackers.com
-
Attackers Use Windows Screensavers to Drop Malware, RMM Tools
Attackers Use Windows Screensavers to Drop Malware, RMM Tools By tapping the unusual .scr file type, attackers leverage “executables that don’t always receive executable-level controls,” one researcher noted. Alexander Culafi Go to gbhackers.com
-
Extra Extra! Announcing DR Global: Latin America
Extra Extra! Announcing DR Global: Latin America Dark Reading has something new hitting the newsstand: a content section purpose-built for Latin American readers, featuring news, analysis, features, and multimedia. Tara Seals Go to gbhackers.com
-
Big Breach or Nada de Nada? Mexican Gov’t Faces Leak Allegations
Big Breach or Nada de Nada? Mexican Gov’t Faces Leak Allegations A hacktivist group claims a 2.3-terabyte data breach exposes the information of 36 million Mexicans, but no sensitive accounts are at risk, says government. Robert Lemos, Contributing Writer Go to gbhackers.com
-
Google Looker Bugs Allow Cross-Tenant RCE, Data Exfil
Google Looker Bugs Allow Cross-Tenant RCE, Data Exfil Attackers could even have used one vulnerable Lookout user to gain access to other GCP tenants’ environments. Nate Nelson, Contributing Writer Go to gbhackers.com
-
Interlock Ransomware Exploits Zero-Day in Gaming Anti-Cheat Driver to Disable EDR, AV
Interlock Ransomware Exploits Zero-Day in Gaming Anti-Cheat Driver to Disable EDR, AV Interlock ransomware operators have been observed using a new process‑killing tool that abuses a zero‑day flaw in a gaming anti‑cheat kernel driver to try… Go to gbhackers.com
-
Supply Chain Attack Exploits Notepad++ Update Mechanism to Push Targeted Malware
Supply Chain Attack Exploits Notepad++ Update Mechanism to Push Targeted Malware Notepad++, a widely used text editor among developers, became the target of a sophisticated supply chain attack that compromised its update infrastructure for nearly… Go to gbhackers.com
-
CISA Warns of Exploited GitLab Community and Enterprise SSRF Vulnerability
CISA Warns of Exploited GitLab Community and Enterprise SSRF Vulnerability The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical server-side request forgery (SSRF) vulnerability affecting GitLab Community and Enterprise Editions to its… Go to gbhackers.com
-
Hackers Exfiltrate NTDS.dit File, Gain Full Control of Active Directory Environments
Hackers Exfiltrate NTDS.dit File, Gain Full Control of Active Directory Environments Active Directory serves as the central repository for an organization’s authentication infrastructure, making it a prime target for sophisticated threat actors. The NTDS.dit database,… Go to gbhackers.com
-
Threat Actors Conduct Widespread Scanning for Exposed Citrix NetScaler Login Pages
Threat Actors Conduct Widespread Scanning for Exposed Citrix NetScaler Login Pages A coordinated reconnaissance campaign targeting Citrix ADC (NetScaler) Gateway infrastructure worldwide. The operation used over 63,000 residential proxy IPs and AWS cloud infrastructure to… Go to gbhackers.com
-
Chrome Vulnerabilities Let Attackers Execute Arbitrary Code and Crash System
Chrome Vulnerabilities Let Attackers Execute Arbitrary Code and Crash System Google has released a critical security update for the Chrome Stable channel, addressing two high-severity vulnerabilities that expose users to potential arbitrary code execution (ACE) and denial-of-service (DoS) attacks. The update pushes the browser version to 144.0.7559.132/.133 for Windows and macOS, and 144.0.7559.132 for Linux.…
-
Hackers Exploiting React Server Components Vulnerability in the Wild to Deploy Malicious Payloads
Hackers Exploiting React Server Components Vulnerability in the Wild to Deploy Malicious Payloads Two months following the disclosure of CVE-2025-55182, exploitation activity targeting React Server Components has evolved from broad scanning into consolidated, high-volume attack campaigns. According to telemetry from GreyNoise collected between January 26 and February 2, 2026, threat actors are actively leveraging this…
-
GlassWorm Infiltrated VSX Extensions with More than 22,000 Downloads to Attack Developers
GlassWorm Infiltrated VSX Extensions with More than 22,000 Downloads to Attack Developers GlassWorm has emerged as a serious threat to developers using the Open VSX Registry, where popular VSX extensions were silently turned into delivery vehicles for malware. Threat actors compromised a trusted publisher account and pushed poisoned updates that looked like routine releases but…
-
Infostealer Campaigns Expand to macOS as Attackers Abuse Python and Trusted Platforms
Infostealer Campaigns Expand to macOS as Attackers Abuse Python and Trusted Platforms Infostealer campaigns that once focused mainly on Windows are now expanding aggressively to macOS, using Python and trusted platforms to reach new victims. Recent attacks show a clear shift: threat actors are abusing online ads, fake apps, and familiar tools to quietly steal…
-
Beware of Fake Dropbox Phishing Attack that Harvest Login Credentials
Beware of Fake Dropbox Phishing Attack that Harvest Login Credentials Cybercriminals are launching a dangerous phishing campaign that tricks users into giving away their login credentials by impersonating Dropbox. This attack uses a multi-stage approach to bypass email security checks and content scanners. The threat actors exploit trusted cloud platforms and harmless-looking PDF files to…
-
TR-26-0017 (Karel Elektronik – ViPort Güvenlik Bildirimi)
TR-26-0017 (Karel Elektronik – ViPort Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0016 (Emit Bilişim ve İletişim Teknolojileri – Verimlilik Yönetim Sistemi Güvenlik Bildirimi)
TR-26-0016 (Emit Bilişim ve İletişim Teknolojileri – Verimlilik Yönetim Sistemi Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0015 (Ofisimo Web Tabanlı Yazılım Teknolojileri – Dernek Web Paketi Flora v3.0 Güvenlik Bildirimi)
TR-26-0015 (Ofisimo Web Tabanlı Yazılım Teknolojileri – Dernek Web Paketi Flora v3.0 Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0014 (Ankara Hosting – Web Site Yazılımı Güvenlik Bildirimi)
TR-26-0014 (Ankara Hosting – Web Site Yazılımı Güvenlik Bildirimi) Go to usom.gov
-
TR-26-0013 (Seres Yazılım – syWEB Güvenlik Bildirimi)
TR-26-0013 (Seres Yazılım – syWEB Güvenlik Bildirimi) Go to usom.gov
-
Eclipse Foundation Mandates Pre-Publish Security Checks for Open VSX Extensions
Eclipse Foundation Mandates Pre-Publish Security Checks for Open VSX Extensions The Eclipse Foundation, which maintains the Open VSX Registry, has announced plans to enforce security checks before Microsoft Visual Studio Code (VS Code) extensions are published to the open-source repository to combat supply chain threats. The move marks a shift from a reactive to a…
-
CISA Adds Actively Exploited SolarWinds Web Help Desk RCE to KEV Catalog
CISA Adds Actively Exploited SolarWinds Web Help Desk RCE to KEV Catalog The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a critical security flaw impacting SolarWinds Web Help Desk (WHD) to its Known Exploited Vulnerabilities (KEV) catalog, flagging it as actively exploited in attacks. The vulnerability, tracked as CVE-2025-40551 (CVSS score: 9.8),…
-
Docker Fixes Critical Ask Gordon AI Flaw Allowing Code Execution via Image Metadata
Docker Fixes Critical Ask Gordon AI Flaw Allowing Code Execution via Image Metadata Cybersecurity researchers have disclosed details of a now-patched security flaw impacting Ask Gordon, an artificial intelligence (AI) assistant built into Docker Desktop and the Docker Command-Line Interface (CLI), that could be exploited to execute code and exfiltrate sensitive data. The critical vulnerability…
-
[Webinar] The Smarter SOC Blueprint: Learn What to Build, Buy, and Automate
[Webinar] The Smarter SOC Blueprint: Learn What to Build, Buy, and Automate Most security teams today are buried under tools. Too many dashboards. Too much noise. Not enough real progress. Every vendor promises “complete coverage” or “AI-powered automation,” but inside most SOCs, teams are still overwhelmed, stretched thin, and unsure which tools are truly pulling…
-
Hackers Exploit Metro4Shell RCE Flaw in React Native CLI npm Package
Hackers Exploit Metro4Shell RCE Flaw in React Native CLI npm Package Threat actors have been observed exploiting a critical security flaw impacting the Metro Development Server in the popular “@react-native-community/cli” npm package. Cybersecurity company VulnCheck said it first observed exploitation of CVE-2025-11953 (aka Metro4Shell) on December 21, 2025. With a CVSS score of 9.8, the…
-
Microsoft is Giving the FBI BitLocker Keys
Microsoft is Giving the FBI BitLocker Keys Microsoft gives the FBI the ability to decrypt BitLocker in response to court orders: about twenty times per year. It’s possible for users to store those keys on a device they own, but Microsoft also recommends BitLocker users store their keys on its servers for convenience. While that…
-
ISC Stormcast For Wednesday, February 4th, 2026 https://isc.sans.edu/podcastdetail/9794, (Wed, Feb 4th)
ISC Stormcast For Wednesday, February 4th, 2026 https://isc.sans.edu/podcastdetail/9794, (Wed, Feb 4th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Detecting and Monitoring OpenClaw (clawdbot, moltbot), (Tue, Feb 3rd)
Detecting and Monitoring OpenClaw (clawdbot, moltbot), (Tue, Feb 3rd) Last week, a new AI agent framework was introduced to automate “live”. It targets office work in particular, focusing on messaging and interacting with systems. The tool has gone viral not so much because of its features, which are similar to those of other agent frameworks,…
-
170: Phrack
170: Phrack Phrack is legendary. It is the oldest, and arguably the most prestigious, underground hacking magazine in the world. It started in 1985 and is still running today. In this episode we interview the Phrack staff to hear some stories about what it’s like running a hacker magazine for 40 years. phrack.org Sponsors Support…
-
Russian Hackers Weaponize Microsoft Office Bug in Just 3 Days
Russian Hackers Weaponize Microsoft Office Bug in Just 3 Days APT28’s attacks rely on specially crafted Microsoft Rich Text Format (RTF) documents to kick off a multistage infection chain to deliver malicious payloads. Jai Vijayan, Contributing Writer Go to gbhackers.com
-
GlassWorm Malware Returns to Shatter Developer Ecosystems
GlassWorm Malware Returns to Shatter Developer Ecosystems The self-replicating malware has poisoned a fresh set of Open VSX software components, leaving potential downstream victims with infostealer infections. Alexander Culafi Go to gbhackers.com
-
8-Minute Access: AI Accelerates Breach of AWS Environment
8-Minute Access: AI Accelerates Breach of AWS Environment The AI-assisted attack, which started with exposed credentials from public S3 buckets, rapidly achieved administrative privilges. Elizabeth Montalbano, Contributing Writer Go to gbhackers.com
-
Dark Patterns Undermine Security One Click at a Time
Dark Patterns Undermine Security One Click at a Time People trust organizations to do the right thing, but websites’ and apps’ dark patterns pose a hidden threat that can lead to inadequate security behaviors. Arielle Waldman Go to gbhackers.com
-
Chollima APT Hackers Weaponize LNK Files to Deploy Sophisticated Malware
Chollima APT Hackers Weaponize LNK Files to Deploy Sophisticated Malware In March 2025, the Ricochet Chollima APT group, widely recognized as APT37 and linked to North Korean state-sponsored operations, launched a targeted spear-phishing campaign… Go to gbhackers.com
-
Mozilla Introduces Global Kill Switch for Firefox AI Capabilities
Mozilla Introduces Global Kill Switch for Firefox AI Capabilities Mozilla has rolled out comprehensive AI controls in Firefox 148, launching February 24, 2026, allowing users to globally disable all generative AI features across… Go to gbhackers.com
-
GhostChat Malware Locks Victims’ Devices, Demands Passcodes for Restoration
GhostChat Malware Locks Victims’ Devices, Demands Passcodes for Restoration A new Android spyware campaign that uses romance scams and fake chat profiles to spy on users in Pakistan. The malicious app, named GhostChat… Go to gbhackers.com
-
Abuse of OpenClaw AI Capabilities Enables Stealthy Malware Campaigns
Abuse of OpenClaw AI Capabilities Enables Stealthy Malware Campaigns Hundreds of malicious skills are distributed through OpenClaw’s marketplace, transforming the popular AI agent ecosystem into a new supply chain attack vector. Threat actors… Go to gbhackers.com
-
Malicious Google Play App With 50K+ Downloads Spreads Anatsa Banking Trojan
Malicious Google Play App With 50K+ Downloads Spreads Anatsa Banking Trojan A malicious application on the Google Play Store masquerading as a legitimate document reader. The deceptive application, which has accumulated over 50,000 downloads, functions… Go to gbhackers.com
-
New GlassWorm attack targets macOS via compromised OpenVSX extensions
New GlassWorm attack targets macOS via compromised OpenVSX extensions A new GlassWorm malware attack through compromised OpenVSX extensions focuses on stealing passwords, crypto-wallet data, and developer credentials and configurations from macOS systems. […] Bill Toulas Go to bleepingcomputer
-
Russian hackers exploit recently patched Microsoft Office bug in attacks
Russian hackers exploit recently patched Microsoft Office bug in attacks Ukraine’s Computer Emergency Response Team (CERT) says that Russian hackers are exploiting CVE-2026-21509, a recently patched vulnerability in multiple versions of Microsoft Office. […] Bill Toulas Go to bleepingcomputer
-
Malicious MoltBot skills used to push password-stealing malware
Malicious MoltBot skills used to push password-stealing malware More than 230 malicious packages for the personal AI assistant OpenClaw (formerly known as Moltbot and ClawdBot) have been published in less than a week on the tool’s official registry and on GitHub. […] Bill Toulas Go to bleepingcomputer
-
Mozilla announces switch to disable all Firefox AI features
Mozilla announces switch to disable all Firefox AI features In response to user feedback on AI integration, Mozilla announced today that the next Firefox release will let users disable AI features entirely or manage them individually. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft: January update shutdown bug affects more Windows PCs
Microsoft: January update shutdown bug affects more Windows PCs Microsoft has confirmed that a known issue preventing some Windows 11 devices from shutting down also affects Windows 10 systems with Virtual Secure Mode (VSM) enabled. […] Sergiu Gatlan Go to bleepingcomputer
-
Malicious App on The Google Play with 50K+ Downloads Deploy Anatsa Banking Malware
Malicious App on The Google Play with 50K+ Downloads Deploy Anatsa Banking Malware A dangerous banking malware called Anatsa has been discovered spreading through the Google Play Store, reaching more than fifty thousand downloads before detection. The malicious application was cleverly hidden as a document reader, making it appear harmless to unsuspecting users searching for…
-
Hikvision Wireless Access Points Vulnerability Enables Malicious Command Execution
Hikvision Wireless Access Points Vulnerability Enables Malicious Command Execution A critical authenticated command execution vulnerability has been disclosed affecting multiple Hikvision Wireless Access Point (WAP) models. The flaw, tracked as CVE-2026-0709, stems from insufficient input validation in device firmware, potentially allowing attackers with valid credentials to execute arbitrary commands on affected systems. The vulnerability carries…
-
OpenClaw AI Agent Skills Abused by Threat Actors to Deliver Malware
OpenClaw AI Agent Skills Abused by Threat Actors to Deliver Malware Hundreds of malicious skills designed to deliver trojans, infostealers, and backdoors disguised as legitimate automation tools. VirusTotal has uncovered a significant malware distribution campaign targeting OpenClaw, a rapidly growing personal AI agent ecosystem. OpenClaw, previously known as Clawdbot and briefly as Moltbot, is a…
-
Notepad++ Hack Detailed Along With the IoCs and Custom Malware Used
Notepad++ Hack Detailed Along With the IoCs and Custom Malware Used A sophisticated espionage campaign attributed to the Chinese Advanced Persistent Threat (APT) group Lotus Blossom (also known as Billbug). The threat actors compromised the infrastructure hosting the popular text editor Notepad++ to deliver a custom, previously undocumented backdoor named “Chrysalis”. This campaign, discovered by…
-
DynoWiper Data-Wiping Malware Attacking Energy Companies to Destroy Data
DynoWiper Data-Wiping Malware Attacking Energy Companies to Destroy Data A dangerous new data-wiping malware known as DynoWiper has emerged, targeting energy companies in Poland with destructive attacks designed to permanently erase critical data. The malware surfaced in December 2025 when security researchers detected its deployment at a Polish energy firm. Unlike typical ransomware that encrypts…
-
A slippery slope: Beware of Winter Olympics scams and other cyberthreats
A slippery slope: Beware of Winter Olympics scams and other cyberthreats It’s snow joke – sporting events are a big draw for cybercriminals. Make sure you’re not on the losing side by following these best practices. Go to eset
-
TR-26-0011 (AKCE Yazılım – SKSPro Güvenlik Bildirimi)
TR-26-0011 (AKCE Yazılım – SKSPro Güvenlik Bildirimi) Go to usom.gov
-
Mozilla Adds One-Click Option to Disable Generative AI Features in Firefox
Mozilla Adds One-Click Option to Disable Generative AI Features in Firefox Mozilla on Monday announced a new controls section in its Firefox desktop browser settings that allows users to completely turn off generative artificial intelligence (GenAI) features. “It provides a single place to block current and future generative AI features in Firefox,” Ajit Varma, head…
-
Notepad++ Hosting Breach Attributed to China-Linked Lotus Blossom Hacking Group
Notepad++ Hosting Breach Attributed to China-Linked Lotus Blossom Hacking Group A China-linked threat actor known as Lotus Blossom has been attributed with medium confidence to the recently discovered compromise of the infrastructure hosting Notepad++. The attack enabled the state-sponsored hacking group to deliver a previously undocumented backdoor codenamed Chrysalis to users of the open-source editor,…
-
Researchers Find 341 Malicious ClawHub Skills Stealing Data from OpenClaw Users
Researchers Find 341 Malicious ClawHub Skills Stealing Data from OpenClaw Users A security audit of 2,857 skills on ClawHub has found 341 malicious skills across multiple campaigns, according to new findings from Koi Security, exposing users to new supply chain risks. ClawHub is a marketplace designed to make it easy for OpenClaw users to find…
-
OpenClaw Bug Enables One-Click Remote Code Execution via Malicious Link
OpenClaw Bug Enables One-Click Remote Code Execution via Malicious Link A high-severity security flaw has been disclosed in OpenClaw (formerly referred to as Clawdbot and Moltbot) that could allow remote code execution (RCE) through a crafted malicious link. The issue, which is tracked as CVE-2026-25253 (CVSS score: 8.8), has been addressed in version 2026.1.29 released…
-
Microsoft Begins NTLM Phase-Out With Three-Stage Plan to Move Windows to Kerberos
Microsoft Begins NTLM Phase-Out With Three-Stage Plan to Move Windows to Kerberos Microsoft has announced a three-phase approach to phase out New Technology LAN Manager (NTLM) as part of its efforts to shift Windows environments toward stronger, Kerberos-based options. The development comes more than two years after the tech giant revealed its plans to deprecate…
-
AI Coding Assistants Secretly Copying All Code to China
AI Coding Assistants Secretly Copying All Code to China There’s a new report about two AI coding assistants, used by 1.5 million developers, that are surreptitiously sending a copy of everything they ingest to China. Maybe avoid using them. Bruce Schneier Go to bruce schneier
-
ISC Stormcast For Tuesday, February 3rd, 2026 https://isc.sans.edu/podcastdetail/9792, (Tue, Feb 3rd)
ISC Stormcast For Tuesday, February 3rd, 2026 https://isc.sans.edu/podcastdetail/9792, (Tue, Feb 3rd) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Scanning for exposed Anthropic Models, (Mon, Feb 2nd)
Scanning for exposed Anthropic Models, (Mon, Feb 2nd) Yesterday, a single IP address (%%ip:204.76.203.210%%) scanned a number of our sensors for what looks like an anthropic API node. The IP address is known to be a Tor exit node. The requests are pretty simple: GET /anthropic/v1/models Host: 67.171.182.193:8000 X-Api-Key: password Anthropic-Version: 2023-06-01 It looks like…
-
Attackers Harvest Dropbox Logins Via Fake PDF Lures
Attackers Harvest Dropbox Logins Via Fake PDF Lures A malware-free phishing campaign targets corporate inboxes and asks employees to view “request orders,” ultimately leading to Dropbox credential theft. Alexander Culafi Go to gbhackers.com
-
County Pays $600K to Wrongfully Jailed Pen Testers
County Pays $600K to Wrongfully Jailed Pen Testers Iowa police arrested two penetration testers in 2019 for doing their jobs, highlighting the risk to security professionals in red teaming exercises. Nate Nelson, Contributing Writer Go to gbhackers.com
-
Chinese Hackers Hijack Notepad++ Updates for 6 Months
Chinese Hackers Hijack Notepad++ Updates for 6 Months State-sponsored threat actors compromised the popular code editor’s hosting provider to redirect targeted users to malicious downloads. Jai Vijayan, Contributing Writer Go to gbhackers.com
-
ShinyHunters Expands Scope of SaaS Extortion Attacks
ShinyHunters Expands Scope of SaaS Extortion Attacks Following its attacks on Salesforce instances last year, members of the cybercrime group have broadened their targeting and gotten more aggressive with extortion tactics. Elizabeth Montalbano, Contributing Writer Go to gbhackers.com
-
Hackers Target MongoDB Instances to Delete Databases and Plant Ransom Notes
Hackers Target MongoDB Instances to Delete Databases and Plant Ransom Notes A widespread ransomware campaign targeting misconfigured MongoDB databases continues to compromise thousands of servers worldwide, with attackers exploiting internet-exposed instances that lack basic authentication… Go to gbhackers.com
-
PeckBirdy Hackers Abuse LOLBins Across Environments to Deploy Advanced Malware
PeckBirdy Hackers Abuse LOLBins Across Environments to Deploy Advanced Malware A sophisticated JScript-based command-and-control framework, PeckBirdy, since 2023, exploiting living-off-the-land binaries (LOLBins) to deliver modular backdoors across diverse execution environments. The framework has been… Go to gbhackers.com
-
Notepad++ Users Targeted After State-Backed Attackers Hijack Update Servers
Notepad++ Users Targeted After State-Backed Attackers Hijack Update Servers Notepad++ fell victim to a sophisticated supply chain attack orchestrated by state-sponsored threat actors who compromised its update infrastructure over a six-month campaign. Security… Go to gbhackers.com
-
ShadowHS: New Stealthy Fileless Linux Malware Spreads Automatically
ShadowHS: New Stealthy Fileless Linux Malware Spreads Automatically A sophisticated fileless Linux malware framework, ShadowHS, that represents a significant evolution in post-exploitation tooling. Unlike traditional malware binaries, ShadowHS operates entirely in memory… Go to gbhackers.com
-
Windows 11 Introduces New Feature to Block Unauthorized Access to System Files
Windows 11 Introduces New Feature to Block Unauthorized Access to System Files Microsoft has released KB5074105, a critical preview update for Windows 11 versions 25H2 and 24H2 (OS Builds 26200.7705 and 26100.7705), introducing enhanced security mechanisms… Go to gbhackers.com
-
Exposed MongoDB instances still targeted in data extortion attacks
Exposed MongoDB instances still targeted in data extortion attacks A threat actor is targeting exposed MongoDB instances in automated data extortion attacks demanding low ransoms from owners to restore the data. […] Bill Toulas Go to bleepingcomputer
-
New Apple privacy feature limits location tracking on iPhones, iPads
New Apple privacy feature limits location tracking on iPhones, iPads Apple is introducing a new privacy feature that lets users limit the precision of location data shared with cellular networks on some iPhone and iPad models. […] Sergiu Gatlan Go to bleepingcomputer
-
Google Uncovered Significant Expansion in ShinyHunters Threat Activity with New Tactics
Google Uncovered Significant Expansion in ShinyHunters Threat Activity with New Tactics The ShinyHunters threat group has expanded its extortion operations with sophisticated attack methods targeting cloud-based systems across multiple organizations. These cybercriminals use voice phishing and fake credential harvesting websites to steal login information from employees. Once they gain access, they extract sensitive data from…
-
Windows 11 New Security Feature Denies Unauthorized Access to System Files
Windows 11 New Security Feature Denies Unauthorized Access to System Files Microsoft has introduced a significant security control in the latest Windows 11 preview update designed to restrict unauthorized interaction with critical system files. Released as part of the January 2026 non-security preview (KB5074105), this enhancement specifically targets the Storage settings menu, a sensitive area…
-
1-Click Clawdbot Vulnerability Enable Malicious Remote Code Execution Attacks
1-Click Clawdbot Vulnerability Enable Malicious Remote Code Execution Attacks A critical vulnerability in OpenClaw, the open-source AI personal assistant trusted by over 100,000 developers, has been discovered and weaponized into a devastating one-click remote code execution exploit. Security researchers at depthfirst General Security Intelligence uncovered a logic flaw that, when combined with other vulnerabilities, could…
-
State-Sponsored Actors Hijacked Notepad++ Update Servers to Redirect Users to Malicious Servers
State-Sponsored Actors Hijacked Notepad++ Update Servers to Redirect Users to Malicious Servers The developer of Notepad++ has confirmed that a targeted attack by a likely Chinese state-sponsored threat actor compromised the project’s former shared hosting infrastructure between June and December 2025. The breach allowed attackers to intercept and selectively redirect update traffic to malicious servers,…
-
Critical Johnson Controls Products Vulnerabilities Enables Remote SQL Injection Attacks
Critical Johnson Controls Products Vulnerabilities Enables Remote SQL Injection Attacks A critical advisory addressing a severe SQL injection vulnerability affecting multiple Johnson Controls industrial control system products. The vulnerability, tracked as CVE-2025-26385, carries a maximum CVSS v3 severity score of 10.0, indicating the highest level of risk to affected infrastructure. The flaw stems from improper…
-
eScan Antivirus Update Servers Compromised to Deliver Multi-Stage Malware
eScan Antivirus Update Servers Compromised to Deliver Multi-Stage Malware The update infrastructure for eScan antivirus, a security solution developed by Indian cybersecurity company MicroWorld Technologies, has been compromised by unknown attackers to deliver a persistent downloader to enterprise and consumer systems. “Malicious updates were distributed through eScan’s legitimate update infrastructure, resulting in the deployment of…
-
Open VSX Supply Chain Attack Used Compromised Dev Account to Spread GlassWorm
Open VSX Supply Chain Attack Used Compromised Dev Account to Spread GlassWorm Cybersecurity researchers have disclosed details of a supply chain attack targeting the Open VSX Registry in which unidentified threat actors compromised a legitimate developer’s resources to push malicious updates to downstream users. “On January 30, 2026, four established Open VSX extensions published by…
-
ISC Stormcast For Monday, February 2nd, 2026 https://isc.sans.edu/podcastdetail/9790, (Mon, Feb 2nd)
ISC Stormcast For Monday, February 2nd, 2026 https://isc.sans.edu/podcastdetail/9790, (Mon, Feb 2nd) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Top 10 Best DNS Filtering Solutions 2026
Top 10 Best DNS Filtering Solutions 2026 In 2026, the perimeter is gone. Your users are everywhere, and the “castle and moat” security model is obsolete. The most effective way to… Go to gbhackers.com
-
SCADA Flaw Enables DoS Condition, Impacting Availability of Affected Systems
SCADA Flaw Enables DoS Condition, Impacting Availability of Affected Systems A vulnerability affecting the Mitsubishi Electric Iconics Suite, a widely deployed supervisory control and data acquisition (SCADA) system used across industrial sectors, including automotive,… Go to gbhackers.com
-
Metasploit Update Introduces 7 Exploit Modules Affecting Popular Enterprise Platforms
Metasploit Update Introduces 7 Exploit Modules Affecting Popular Enterprise Platforms A significant Metasploit Framework update (version 6.4.111) featuring seven new exploit modules that target critical vulnerabilities across widely deployed enterprise systems. This release demonstrates… Go to gbhackers.com
-
OpenAI says you can trust ChatGPT answers, as it kicks off ads rollout preparation
OpenAI says you can trust ChatGPT answers, as it kicks off ads rollout preparation OpenAI previously confirmed that it’s testing ads in ChatGPT for free and $8 Go accounts, and now we’re seeing early signs of that rollout, at least on Android. […] Mayank Parmar Go to bleepingcomputer
-
OpenAI is retiring famous GPT-4o model, says GPT 5.2 is good enough
OpenAI is retiring famous GPT-4o model, says GPT 5.2 is good enough OpenAI has confirmed that it’s retiring ChatGPT’s most popular model called GPT-4o and several other models, including GPT-5 Instant, GPT-5 Thinking, GPT-4.1, GPT-4.1 mini, and o4-mini. […] Mayank Parmar Go to bleepingcomputer
-
U.S. convicts ex-Google engineer for sending AI tech data to China
U.S. convicts ex-Google engineer for sending AI tech data to China A U.S. federal jury has convicted Linwei Ding, a former software engineer at Google, for stealing AI supercomputer data from his employer and secretly sharing it with Chinese tech firms. […] Bill Toulas Go to bleepingcomputer
-
Cloud storage payment scam floods inboxes with fake renewals
Cloud storage payment scam floods inboxes with fake renewals Over the past few months, a large-scale cloud storage subscription scam campaign has been targeting users worldwide with repeated emails falsely warning recipients that their photos, files, and accounts are about to be blocked or deleted due to an alleged payment failure. […] Lawrence Abrams Go to…
-
Mandiant details how ShinyHunters abuse SSO to steal cloud data
Mandiant details how ShinyHunters abuse SSO to steal cloud data Mandiant says a wave of recent ShinyHunters SaaS data-theft attacks is being fueled by targeted voice phishing (vishing) attacks and company-branded phishing sites that steal single sign-on (SSO) credentials and multi-factor authentication (MFA) codes. […] Lawrence Abrams Go to bleepingcomputer