no alarms and no surprises please..
-
Attackers Abuse Python, Cloudflare to Deliver AsyncRAT
Attackers Abuse Python, Cloudflare to Deliver AsyncRAT The phishing campaign shows how attackers continue to weaponize legitimate cloud services and open source tools to evade detection and gain trust. Elizabeth Montalbano, Contributing Writer Go to gbhackers.com
-
Hacker gets seven years for breaching Rotterdam and Antwerp ports
Hacker gets seven years for breaching Rotterdam and Antwerp ports The Amsterdam Court of Appeal sentenced a 44-year-old Dutch national to seven years in prison for multiple crimes, including computer hacking and attempted extortion. […] Bill Toulas Go to bleepingcomputer
-
Facebook login thieves now using browser-in-browser trick
Facebook login thieves now using browser-in-browser trick Hackers over the past six months have relied increasingly more on the browser-in-the-browser (BitB) method to trick users into providing Facebook account credentials. […] Bill Toulas Go to bleepingcomputer
-
CISA orders feds to patch Gogs RCE flaw exploited in zero-day attacks
CISA orders feds to patch Gogs RCE flaw exploited in zero-day attacks CISA has ordered government agencies to secure their systems against a high-severity Gogs vulnerability that was exploited in zero-day attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
‘Bad actor’ hijacks Apex Legends characters in live matches
‘Bad actor’ hijacks Apex Legends characters in live matches Apex Legends players over the weekend experienced disruptions during live matches as threat actors hijacked their characters, disconnected them, and changed their nicknames. […] Bill Toulas Go to bleepingcomputer
-
University of Hawaii Cancer Center hit by ransomware attack
University of Hawaii Cancer Center hit by ransomware attack University of Hawaii says a ransomware gang breached its Cancer Center in August 2025, stealing data of study participants, including documents from the 1990s containing Social Security numbers. […] Sergiu Gatlan Go to bleepingcomputer
-
New Angular Vulnerability Enables an Attacker to Execute Malicious Payload
New Angular Vulnerability Enables an Attacker to Execute Malicious Payload A critical Cross-Site Scripting (XSS) vulnerability has been discovered in Angular’s Template Compiler, affecting multiple versions of both @angular/compiler and @angular/core packages. Tracked as CVE-2026-22610, this vulnerability allows attackers to bypass Angular’s built-in security protections and execute arbitrary JavaScript code within victim browsers. The Vulnerability…
-
Hackers Leverage Browser-in-the-browser Tactic to Trick Facebook Users and Steal Logins
Hackers Leverage Browser-in-the-browser Tactic to Trick Facebook Users and Steal Logins Facebook users are increasingly becoming targets of a sophisticated phishing technique that bypasses conventional security measures. With over three billion active users on the platform, Facebook represents an attractive target for attackers seeking to compromise accounts and harvest personal credentials. The primary objective of…
-
100,000+ n8n Instances Exposed to Internet Vulnerable to RCE Attacks
100,000+ n8n Instances Exposed to Internet Vulnerable to RCE Attacks A critical vulnerability affecting the popular n8n workflow automation platform has put over 100,000 internet-exposed instances at severe risk. Security researchers from The Shadowserver Foundation discovered that 105,753 unique n8n instances are vulnerable to remote code execution (RCE) attacks through CVE-2026-21858. n8n is a workflow…
-
AsyncRAT Leveraging Cloudflare’s Free-Tier Services to Mask Malicious Activities and Detection
AsyncRAT Leveraging Cloudflare’s Free-Tier Services to Mask Malicious Activities and Detection A recent AsyncRAT campaign is using Cloudflare’s free tier services and TryCloudflare tunnels to hide remote access activity inside normal looking cloud traffic. In these attacks, threat actors send phishing emails that link to a Dropbox hosted ZIP archive named to look like an…
-
Multiple Hikvision Vulnerabilities Let Attackers Cause Device Malfunction Using Crafted Packets
Multiple Hikvision Vulnerabilities Let Attackers Cause Device Malfunction Using Crafted Packets Hikvision, a leading provider of surveillance and access control systems, faces serious security risks from two newly disclosed stack overflow vulnerabilities. These flaws, tracked as CVE-2025-66176 and CVE-2025-66177, allow attackers on the same local area network (LAN) to trigger device malfunctions by sending specially…
-
n8n Supply Chain Attack Abuses Community Nodes to Steal OAuth Tokens
n8n Supply Chain Attack Abuses Community Nodes to Steal OAuth Tokens Threat actors have been observed uploading a set of eight packages on the npm registry that masqueraded as integrations targeting the n8n workflow automation platform to steal developers’ OAuth credentials. One such package, named “n8n-nodes-hfgjf-irtuinvcm-lasdqewriit,” mimics a Google Ads integration, and prompts users to…
-
⚡ Weekly Recap: AI Automation Exploits, Telecom Espionage, Prompt Poaching & More
⚡ Weekly Recap: AI Automation Exploits, Telecom Espionage, Prompt Poaching & More This week made one thing clear: small oversights can spiral fast. Tools meant to save time and reduce friction turned into easy entry points once basic safeguards were ignored. Attackers didn’t need novel tricks. They used what was already exposed and moved in…
-
GoBruteforcer Botnet Targets Crypto Project Databases by Exploiting Weak Credentials
GoBruteforcer Botnet Targets Crypto Project Databases by Exploiting Weak Credentials A new wave of GoBruteforcer attacks has targeted databases of cryptocurrency and blockchain projects to co-opt them into a botnet that’s capable of brute-forcing user passwords for services such as FTP, MySQL, PostgreSQL, and phpMyAdmin on Linux servers. “The current wave of campaigns is driven…
-
Anthropic Launches Claude AI for Healthcare with Secure Health Record Access
Anthropic Launches Claude AI for Healthcare with Secure Health Record Access Anthropic has become the latest Artificial intelligence (AI) company to announce a new suite of features that allows users of its Claude platform to better understand their health information. Under an initiative called Claude for Healthcare, the company said U.S. subscribers of Claude Pro…
-
Researchers Uncover Service Providers Fueling Industrial-Scale Pig Butchering Fraud
Researchers Uncover Service Providers Fueling Industrial-Scale Pig Butchering Fraud Cybersecurity researchers have shed light on two service providers that supply online criminal networks with the necessary tools and infrastructure to fuel the pig butchering-as-a-service (PBaaS) economy. At least since 2016, Chinese-speaking criminal groups have erected industrial-scale scam centers across Southeast Asia, creating special economic zones…
-
Year in Review 2025: The major headlines and moments from Sophos this year
Year in Review 2025: The major headlines and moments from Sophos this year Go to sophos
-
Corrupting LLMs Through Weird Generalizations
Corrupting LLMs Through Weird Generalizations Fascinating research: Weird Generalization and Inductive Backdoors: New Ways to Corrupt LLMs. AbstractLLMs are useful because they generalize so well. But can you have too much of a good thing? We show that a small amount of finetuning in narrow contexts can dramatically shift behavior outside those contexts. In one…
-
ISC Stormcast For Tuesday, January 13th, 2026 https://isc.sans.edu/podcastdetail/9764, (Tue, Jan 13th)
ISC Stormcast For Tuesday, January 13th, 2026 https://isc.sans.edu/podcastdetail/9764, (Tue, Jan 13th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
BreachForums Breached, Exposing 324K Cybercriminals
BreachForums Breached, Exposing 324K Cybercriminals Massive data dump reveals real identities and details of administrators and members of the notorious hacker forum. Jai Vijayan, Contributing Writer Go to gbhackers.com
-
GoBruteforcer Botnet Targets 50K-plus Linux Servers
GoBruteforcer Botnet Targets 50K-plus Linux Servers Researchers detailed a souped-up version of the GoBruteforcer botnet that preys on servers with weak credentials and AI-generated configurations. Alexander Culafi Go to gbhackers.com
-
Navigating Privacy and Cybersecurity Laws in 2026 Will Prove Difficult
Navigating Privacy and Cybersecurity Laws in 2026 Will Prove Difficult No matter what new laws or regulations make the cut for 2026, it’s clear that compliance challenges will persist and federal legislation will be limited. Arielle Waldman Go to gbhackers.com
-
Hexnode Moves into Endpoint Security With Hexnode XDR
Hexnode Moves into Endpoint Security With Hexnode XDR Go to gbhackers.com
-
Two Separate Campaigns Target Exposed LLM Services
Two Separate Campaigns Target Exposed LLM Services A total of 91,403 sessions targeted public LLM endpoints to find leaks in organizations’ use of AI and map an expanding attack surface. Elizabeth Montalbano, Contributing Writer Go to gbhackers.com
-
Cybercriminal Crypto Transactions Surge to 2025 High
Cybercriminal Crypto Transactions Surge to 2025 High Illicit cryptocurrency transactions reached unprecedented levels in 2025 as nation-states weaponized digital assets to evade sanctions, transforming the cybercrime landscape into a geopolitical battleground… Go to gbhackers.com
-
Critical Apache Struts 2 Flaw Could Let Attackers Steal Sensitive Data
Critical Apache Struts 2 Flaw Could Let Attackers Steal Sensitive Data A newly disclosed vulnerability in Apache Struts 2’s XWork component could expose sensitive data and open the door to denial‑of‑service and server‑side request forgery… Go to gbhackers.com
-
ValleyRAT_S2: Stealth Intrusions Aimed at Financial Data Exfiltration
ValleyRAT_S2: Stealth Intrusions Aimed at Financial Data Exfiltration A sophisticated second-stage malware payload known as ValleyRAT_S2 has emerged as a critical threat to organizations across Chinese-speaking regions, including mainland China, Hong Kong,… Go to gbhackers.com
-
Critical React Router Flaws Could Let Attackers Access or Modify Server Files
Critical React Router Flaws Could Let Attackers Access or Modify Server Files A critical vulnerability has been discovered in React Router and Remix that could allow attackers to access or modify sensitive files on web servers. The flaw… Go to gbhackers.com
-
Fake Employee Performance Reports Deliver Guloader Malware
Fake Employee Performance Reports Deliver Guloader Malware Organizations are being warned about a new phishing campaign that weaponizes fake employee performance reports to deploy the Guloader malware and ultimately install Remcos… Go to gbhackers.com
-
Anthropic brings Claude to healthcare with HIPAA-ready Enterprise tools
Anthropic brings Claude to healthcare with HIPAA-ready Enterprise tools Anthropic is bringing Claude for healthcare, following a similar move by OpenAI for ChatGPT. […] Mayank Parmar Go to bleepingcomputer
-
Instagram denies breach amid claims of 17 million account data leak
Instagram denies breach amid claims of 17 million account data leak Instagram says it fixed a bug that allowed threat actors to mass-request password reset emails, amid claims that data from more than 17 million Instagram accounts was scraped and leaked online. […] Lawrence Abrams Go to bleepingcomputer
-
California bans data broker reselling health data of millions
California bans data broker reselling health data of millions The California Privacy Protection Agency (CalPrivacy) has taken action against the Datamasters marketing firm that sold the health and personal data of millions of users without being registered as a data broker. […] Bill Toulas Go to bleepingcomputer
-
ValleyRAT_S2 Attacking Organizations to Deploy Stealthy Malware and Extract Financial Details
ValleyRAT_S2 Attacking Organizations to Deploy Stealthy Malware and Extract Financial Details A new wave of attacks is using the ValleyRAT_S2 malware to quietly break into organizations, stay hidden for long periods, and steal sensitive financial information. ValleyRAT_S2 is the second-stage payload of the ValleyRAT family and is written in C++. Once inside a network, it…
-
Beware of Weaponized Employee Performance Reports that Deploys Guloader Malware
Beware of Weaponized Employee Performance Reports that Deploys Guloader Malware Cybersecurity threats continue to evolve with attackers using more creative social engineering techniques to target organizations. A recent threat has emerged involving the Guloader malware, which is being disguised as employee performance reports to trick users into downloading and executing malicious files. This sophisticated attack…
-
Critical InputPlumber Vulnerabilities Allows UI Input Injection and Denial-of-Service
Critical InputPlumber Vulnerabilities Allows UI Input Injection and Denial-of-Service Critical vulnerabilities in InputPlumber, a Linux input device utility used in SteamOS, could allow attackers to inject UI inputs and cause denial-of-service conditions on affected systems. The SUSE researchers tracked as CVE-2025-66005 and CVE-2025-14338, which affect InputPlumber versions before v0.69.0 and stem from inadequate D-Bus authorization mechanisms. InputPlumber combines…
-
Everest Hacking Group Allegedly Claims Breach of Nissan Motors
Everest Hacking Group Allegedly Claims Breach of Nissan Motors Everest hacking group has allegedly claimed a major breach of Nissan Motor Co., Ltd., raising fresh concerns about data security at large automotive manufacturers. According to early reports, the cybercrime group says it exfiltrated around 900 GB of sensitive data from the Japanese carmaker, a volume…
-
Critical Zlib Vulnerability Let Attackers Trigger Buffer Overflow by Invoking untgz
Critical Zlib Vulnerability Let Attackers Trigger Buffer Overflow by Invoking untgz A severe global buffer overflow vulnerability has been discovered in the zlib untgz utility version 1.3.1.2. Allowing attackers to corrupt memory and potentially execute malicious code through specially crafted command-line input. The security flaw resides in the TGZfname() function of the untgz utility, where…
-
ISC Stormcast For Monday, January 12th, 2026 https://isc.sans.edu/podcastdetail/9762, (Mon, Jan 12th)
ISC Stormcast For Monday, January 12th, 2026 https://isc.sans.edu/podcastdetail/9762, (Mon, Jan 12th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
YARA-X 1.11.0 Release: Hash Function Warnings, (Sun, Jan 11th)
YARA-X 1.11.0 Release: Hash Function Warnings, (Sun, Jan 11th) YARA-X’s 1.11.0 release brings a new feature: hash function warnings. When you write a YARA rule to match a cryptographic hash (either the full file content or a part of it), what’s actually going on are string comparisons: Function hash.sha256 returns a string (the hexadecimal SHA256…
-
Massive Instagram Data Breach Exposes Personal Details of 17.5 Million Users
Massive Instagram Data Breach Exposes Personal Details of 17.5 Million Users A staggering cybersecurity incident has come to light, with 17.5 million Instagram users’ personal information exposed in a data breach advertised on dark web… Go to gbhackers.com
-
Microsoft is retiring ‘Send to Kindle’ in Word
Microsoft is retiring ‘Send to Kindle’ in Word Microsoft is retiring a feature that allowed you to send your documents to Kindle straight from Microsoft Word. […] Mayank Parmar Go to bleepingcomputer
-
BreachForums hacking forum database leaked, exposing 324,000 accounts
BreachForums hacking forum database leaked, exposing 324,000 accounts The latest incarnation of the notorious BreachForums hacking forum has suffered a data breach, with its user database table leaked online. […] Lawrence Abrams Go to bleepingcomputer
-
Spain arrests 34 suspects linked to Black Axe cyber crime
Spain arrests 34 suspects linked to Black Axe cyber crime Authorities in Spain have arrested 34 individuals allegedly part of a criminal network involved in cyber fraud and believed to be connected to the Black Axe group responsible for illicit activities across Europe. […] Bill Toulas Go to bleepingcomputer
-
Ireland recalls almost 13,000 passports over missing ‘IRL’ code
Ireland recalls almost 13,000 passports over missing ‘IRL’ code Ireland’s Department of Foreign Affairs has recalled nearly 13,000 passports after a software update caused a printing defect. The printing error makes the documents non-compliant with international travel standards and potentially unreadable at automated border gates. […] Ax Sharma Go to bleepingcomputer
-
Leveraging OSINT Tools for Enhanced Cybersecurity Threat Intelligence
Leveraging OSINT Tools for Enhanced Cybersecurity Threat Intelligence Open Source Intelligence (OSINT) has become a cornerstone of cybersecurity threat intelligence. In today’s digital landscape, organizations face a constant barrage of cyber threats, ranging from data breaches and phishing attacks to sophisticated nation-state operations. To stay ahead of these threats, cybersecurity teams must leverage every available…
-
Data Breach at Texas Gas Station Operator Exposes Info of 377,000+ Customers
Data Breach at Texas Gas Station Operator Exposes Info of 377,000+ Customers A cybersecurity incident at Gulshan Management Services, Inc., a gas station operator based in Sugar Land, Texas, has compromised the personal information of over 377,000 customers. The breach, discovered on September 27, 2025, exposed sensitive data over 10 days from September 17 to…
-
MuddyWater Launches RustyWater RAT via Spear-Phishing Across Middle East Sectors
MuddyWater Launches RustyWater RAT via Spear-Phishing Across Middle East Sectors The Iranian threat actor known as MuddyWater has been attributed to a spear-phishing campaign targeting diplomatic, maritime, financial, and telecom entities in the Middle East with a Rust-based implant codenamed RustyWater. “The campaign uses icon spoofing and malicious Word documents to deliver Rust based implants…
-
Europol Arrests 34 Black Axe Members in Spain Over €5.9M Fraud and Organized Crime
Europol Arrests 34 Black Axe Members in Spain Over €5.9M Fraud and Organized Crime Europol on Friday announced the arrest of 34 individuals in Spain who are alleged to be part of an international criminal organization called Black Axe. As part of an operation conducted by the Spanish National Police, in coordination with the Bavarian…
-
Cybercriminals Exploit Maduro Arrest News to Spread Backdoor Malware
Cybercriminals Exploit Maduro Arrest News to Spread Backdoor Malware Cybercriminals are leveraging reports of Venezuelan President Nicolás Maduro’s arrest on January 3, 2025, to distribute backdoor malware through a sophisticated social engineering campaign…. Go to gbhackers.com
-
Microsoft Introduces Teams External Collaboration Administrator Role
Microsoft Introduces Teams External Collaboration Administrator Role Microsoft is expanding its administrative capabilities in Teams by introducing a new built-in role called Teams External Collaboration Administrator. This specialized RBAC role enables organizations to delegate external… Go to gbhackers.com
-
Fog Ransomware Targets U.S. Organizations via Compromised VPN Credentials
Fog Ransomware Targets U.S. Organizations via Compromised VPN Credentials Arctic Wolf Labs has uncovered a new ransomware variant dubbed “Fog” striking US organizations, primarily in education and recreation, through hijacked VPN access. First… Go to gbhackers.com
-
xRAT Malware Targets Windows Users via Fake Adult Game
xRAT Malware Targets Windows Users via Fake Adult Game AhnLab Security Intelligence Center (ASEC) has uncovered a dangerous distribution campaign targeting Windows users through Korean web hard services. Threat actors are leveraging xRAT… Go to gbhackers.com
-
OWASP CRS Vulnerability Enables Charset Validation Bypass
OWASP CRS Vulnerability Enables Charset Validation Bypass A newly disclosed vulnerability in the OWASP Core Rule Set (CRS) allows attackers to bypass charset validation in web application firewalls (WAFs), enabling dangerous payloads to reach… Go to gbhackers.com
-
Anthropic: Viral Claude “Banned and reported to authorities” message isn’t real
Anthropic: Viral Claude “Banned and reported to authorities” message isn’t real Anthropic has denied reports of banning legitimate accounts, after a viral post on X claimed the creator of Claude had banned a user. […] Mayank Parmar Go to bleepingcomputer
-
ChatGPT tests a new feature to find jobs, improve your resume, and more
ChatGPT tests a new feature to find jobs, improve your resume, and more OpenAI is testing “Jobs,” a new feature that could help you explore roles, improve your resume, and plan your career. This feature is being tested after ChatGPT gained support for the Health dashboard. […] Mayank Parmar Go to bleepingcomputer
-
Microsoft may soon allow IT admins to uninstall Copilot
Microsoft may soon allow IT admins to uninstall Copilot Microsoft is testing a new policy that allows IT administrators to uninstall the AI-powered Copilot digital assistant on managed devices. […] Sergiu Gatlan Go to bleepingcomputer
-
Hackers target misconfigured proxies to access paid LLM services
Hackers target misconfigured proxies to access paid LLM services Threat actors are systematically hunting for misconfigured proxy servers that could provide access to commercial large language model (LLM) services. […] Bill Toulas Go to bleepingcomputer
-
Illinois Department of Human Services data breach affects 700K people
Illinois Department of Human Services data breach affects 700K people The Illinois Department of Human Services (IDHS), one of Illinois’ largest state agencies, accidentally exposed the personal and health data of nearly 700,000 residents due to incorrect privacy settings. […] Sergiu Gatlan Go to bleepingcomputer
-
New MacSync Stealer Uses Signed macOS App to Evade Gatekeeper and Steal Data
New MacSync Stealer Uses Signed macOS App to Evade Gatekeeper and Steal Data Cybersecurity researchers have discovered a new variant of the MacSync malware targeting macOS users. Unlike previous versions that relied on complex ClickFix techniques, this iteration masquerades as a legitimately signed, notarised Apple application, thereby bypassing macOS Gatekeeper security and stealing sensitive data.…
-
Instagram Data Leak Exposes Sensitive Info of 17.5M Accounts
Instagram Data Leak Exposes Sensitive Info of 17.5M Accounts A significant security breach has compromised approximately 17.5 million Instagram user accounts, exposing sensitive personal information that is now circulating on the dark web. The incident reported earlier this week by cybersecurity firm Malwarebytes raised urgent concerns about user privacy and account security. What Data Was…
-
Europol‑Backed Operation Leads to 34 Arrests in Black Axe Crime Network Bust
Europol‑Backed Operation Leads to 34 Arrests in Black Axe Crime Network Bust The Spanish National Police, working alongside the Bavarian State Criminal Police Office and Europol, has conducted a major operation targeting the international Black Axe criminal organisation. The coordinated action resulted in 34 arrests and dealt a significant blow to the network’s operations across…
-
Phishing Campaign Uses Maduro Arrest Story to Deliver Backdoor Malware
Phishing Campaign Uses Maduro Arrest Story to Deliver Backdoor Malware Cybercriminals are leveraging the recent arrest of Venezuelan President Nicolás Maduro to distribute sophisticated backdoor malware. The threat actors exploited news surrounding Maduro’s arrest on January 3, 2025, demonstrating how geopolitical events continue to serve as effective lures for malicious campaigns. The attack likely begins…
-
BreachForums Hack: Hackers Expose All User Records from Popular Dark Web Forum
BreachForums Hack: Hackers Expose All User Records from Popular Dark Web Forum In a dramatic turn for the cybercrime underworld, a mysterious hacker known as “James” has leaked the complete user database of BreachForums, a notorious Dark Web forum serving as a hub for stolen data trading and hacking discussions. The breach, announced on January…
-
China-Linked Hackers Exploit VMware ESXi Zero-Days to Escape Virtual Machines
China-Linked Hackers Exploit VMware ESXi Zero-Days to Escape Virtual Machines Chinese-speaking threat actors are suspected to have leveraged a compromised SonicWall VPN appliance as an initial access vector to deploy a VMware ESXi exploit that may have been developed as far back as February 2024. Cybersecurity firm Huntress, which observed the activity in December 2025…
-
Russian APT28 Runs Credential-Stealing Campaign Targeting Energy and Policy Organizations
Russian APT28 Runs Credential-Stealing Campaign Targeting Energy and Policy Organizations Russian state-sponsored threat actors have been linked to a fresh set of credential harvesting attacks targeting individuals associated with a Turkish energy and nuclear research agency, as well as staff affiliated with a European think tank and organizations in North Macedonia and Uzbekistan. The activity…
-
Cybersecurity Predictions 2026: The Hype We Can Ignore (And the Risks We Can’t)
Cybersecurity Predictions 2026: The Hype We Can Ignore (And the Risks We Can’t) As organizations plan for 2026, cybersecurity predictions are everywhere. Yet many strategies are still shaped by headlines and speculation rather than evidence. The real challenge isn’t a lack of forecasts—it’s identifying which predictions reflect real, emerging risks and which can safely be…
-
Trend Micro Apex Central RCE Flaw Scores 9.8 CVSS in On-Prem Windows Versions
Trend Micro Apex Central RCE Flaw Scores 9.8 CVSS in On-Prem Windows Versions Trend Micro has released security updates to address multiple security vulnerabilities impacting on-premise versions of Apex Central for Windows, including a critical bug that could result in arbitrary code execution. The vulnerability, tracked as CVE-2025-69258, carries a CVSS score of 9.8 out…
-
CISA Retires 10 Emergency Cybersecurity Directives Issued Between 2019 and 2024
CISA Retires 10 Emergency Cybersecurity Directives Issued Between 2019 and 2024 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday said it’s retiring 10 emergency directives (Eds) that were issued between 2019 and 2024. The list of the directives now considered closed is as follows – ED 19-01: Mitigate DNS Infrastructure Tampering ED 20-02:…
-
Human-in-the-loop security will define 2026: Predictions from Sophos experts
Human-in-the-loop security will define 2026: Predictions from Sophos experts Go to sophos
-
Friday Squid Blogging: The Chinese Squid-Fishing Fleet off the Argentine Coast
Friday Squid Blogging: The Chinese Squid-Fishing Fleet off the Argentine Coast The latest article on this topic. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy. Bruce Schneier Go to bruce schneier
-
Palo Alto Crosswalk Signals Had Default Passwords
Palo Alto Crosswalk Signals Had Default Passwords Palo Alto’s crosswalk signals were hacked last year. Turns out the city never changed the default passwords. Bruce Schneier Go to bruce schneier
-
Malicious Process Environment Block Manipulation, (Fri, Jan 9th)
Malicious Process Environment Block Manipulation, (Fri, Jan 9th) Reverse engineers must have a good understanding of the environment where malware are executed (read: the operating system). In a previous diary, I talked about malicious code that could be executed when loading a DLL[1]. Today, I’ll show you how a malware can hide suspicious information related…
-
pcTattletale founder pleads guilty in rare stalkerware prosecution
pcTattletale founder pleads guilty in rare stalkerware prosecution The founder of a spyware company that encouraged customers to secretly monitor their romantic partners has pleaded guilty to federal charges – marking one of the few successful US prosecutions of a stalkerware operator. Read more in my article on the Hot for Security blog. Graham Cluley…
-
Deepfake Fraud Tools Are Lagging Behind Expectations
Deepfake Fraud Tools Are Lagging Behind Expectations Deepfakes are becoming more realistic and more popular. Luckily, defenders are still ahead in the arms race. Nate Nelson, Contributing Writer Go to gbhackers.com
-
Illicit Crypto Economy Surges as Nation-States Join in the Fray
Illicit Crypto Economy Surges as Nation-States Join in the Fray Cybercriminal cryptocurrency transactions totaled billions in 2025, with activity from sanctioned countries like Russia and Iran causing the largest jump. Robert Lemos, Contributing Writer Go to gbhackers.com
-
Notorious Russian APT Nabs Credentials From Global Targets
Notorious Russian APT Nabs Credentials From Global Targets “Fancy Bear” relies on basic techniques that are highly effective, often delivering greater ROI than more complex malware-heavy operations. Nate Nelson, Contributing Writer Go to gbhackers.com
-
CrowdSrike to Buy SGNL to Expand Identity Security Capabilities
CrowdSrike to Buy SGNL to Expand Identity Security Capabilities The CrowdStrike-SGNL deal underscores how identity security has become a critical component of enterprise cybersecurity as companies add cloud services and deploy AI-driven tools. Fahmida Y. Rashid Go to gbhackers.com
-
New OAuth Attack Lets Hackers Bypass Microsoft Entra Authentication and Steal Keys
New OAuth Attack Lets Hackers Bypass Microsoft Entra Authentication and Steal Keys In a year-end tradition that has become all too familiar for cybersecurity defenders, researchers have uncovered a novel attack vector targeting Microsoft Entra ID… Go to gbhackers.com
-
New DocuSign-Themed Phishing Scam Delivers Stealth Malware to Windows Devices
New DocuSign-Themed Phishing Scam Delivers Stealth Malware to Windows Devices New research has uncovered a sophisticated phishing campaign that abuses DocuSign’s brand to deliver Vidar malware and infect Windows systems. The operation uses a realistic phishing site, a fake… Go to gbhackers.com
-
Trump Signals Possible Cyber Involvement in Caracas Power Loss During Maduro Extraction
Trump Signals Possible Cyber Involvement in Caracas Power Loss During Maduro Extraction President Donald Trump has strongly hinted that the United States used offensive cyber capabilities to help plunge Caracas into darkness during the operation to capture Venezuelan… Go to gbhackers.com
-
Cisco ISE Vulnerability Enables Access to Sensitive Data
Cisco ISE Vulnerability Enables Access to Sensitive Data Cisco has disclosed a new XML External Entity (XXE) vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) that… Go to gbhackers.com
-
ChatGPT Health: A New Secure Space for Trusted Health and Medical Conversations
ChatGPT Health: A New Secure Space for Trusted Health and Medical Conversations ChatGPT Health is launching as a dedicated health-focused version of ChatGPT that combines personalized health data with stronger privacy and security controls to support not replace conversations with clinicians. The… Go to gbhackers.com
-
CISA retires 10 emergency cyber orders in rare bulk closure
CISA retires 10 emergency cyber orders in rare bulk closure The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has retired 10 Emergency Directives issued between 2019 and 2024, saying that the required actions have been completed or are now covered by Binding Operational Directive 22-01. […] Lawrence Abrams Go to bleepingcomputer
-
Gmail’s new AI Inbox uses Gemini, but Google says it won’t train AI on user emails
Gmail’s new AI Inbox uses Gemini, but Google says it won’t train AI on user emails Google says it’s rolling out a new feature called ‘AI Inbox,’ which summarizes all your emails, but the company promises it won’t train its models on your emails. […] Mayank Parmar Go to bleepingcomputer
-
New China-linked hackers breach telcos using edge device exploits
New China-linked hackers breach telcos using edge device exploits A sophisticated threat actor that uses Linux-based malware to target telecommunications providers has recently broadened its operations to include organizations in Southeastern Europe. […] Bill Toulas Go to bleepingcomputer
-
FBI warns about Kimsuky hackers using QR codes to phish U.S. orgs
FBI warns about Kimsuky hackers using QR codes to phish U.S. orgs The North Korean state-sponsored hacker group Kimsuki is using malicious QR codes in spearphishing campaigns that target U.S. organizations, the Federal Bureau of Investigation warns in a flash alert. […] Bill Toulas Go to bleepingcomputer
-
xAI teases major Grok upgrade, hints at Grok Code CLI
xAI teases major Grok upgrade, hints at Grok Code CLI Elon Musk-backed xAI has been missing in action for a while now, but today, Musk teased a major upgrade for Grok alongside new products. […] Mayank Parmar Go to bleepingcomputer
-
SmarterTools SmarterMail Vulnerability Enables Remote Code Execution Attack – PoC Released
SmarterTools SmarterMail Vulnerability Enables Remote Code Execution Attack – PoC Released A critical pre-authentication remote code execution vulnerability, identified as CVE-2025-52691, has been discovered in SmarterTools’ SmarterMail solution. The flaw received a maximum CVSS score of 10.0, indicating its severe nature and potential impact on affected systems. SmarterTools describes SmarterMail as “a secure, all-in-one business…
-
Hackers Actively Exploiting AI Deployments – 91,000+ Attack Sessions Observed
Hackers Actively Exploiting AI Deployments – 91,000+ Attack Sessions Observed Security researchers have identified over 91,000 attack sessions targeting AI infrastructure between October 2025 and January 2026, exposing systematic campaigns against large language model deployments. GreyNoise’s Ollama honeypot infrastructure captured 91,403 attack sessions during this period, revealing two distinct threat campaigns. The findings corroborate and…
-
New Ghost Tapped Attack Uses Your Android Device to Drain Your Bank Account
New Ghost Tapped Attack Uses Your Android Device to Drain Your Bank Account Chinese threat actors have developed a dangerous new way to steal money directly from bank accounts using specially crafted Android applications. Known as Ghost Tapped, these malicious apps exploit Near Field Communication (NFC) technology, the same wireless technology that powers contactless payments.…
-
Cisco Small Business Switches Face Global DNS Crash Outage
Cisco Small Business Switches Face Global DNS Crash Outage Network administrators worldwide reported widespread crashes in Cisco small business switches on January 8, 2026, triggered by fatal errors in the DNS client service. Devices entered reboot loops every few minutes, disrupting operations until DNS configurations were removed. The issue surfaced around 2 AM UTC, affecting…
-
What tools help reduce fraud or friendly fraud for online businesses?
What tools help reduce fraud or friendly fraud for online businesses? A customer buys. You ship. Everyone seems happy. Then, a few weeks later, you get a chargeback. Or you notice the same card being tried again and again in a few seconds, failing at first and then working. It can be a sign someone…
-
Credential stuffing: What it is and how to protect yourself
Credential stuffing: What it is and how to protect yourself Reusing passwords may feel like a harmless shortcut – until a single breach opens the door to multiple accounts Go to eset
-
FBI Warns North Korean Hackers Using Malicious QR Codes in Spear-Phishing
FBI Warns North Korean Hackers Using Malicious QR Codes in Spear-Phishing The U.S. Federal Bureau of Investigation (FBI) on Thursday released an advisory warning of North Korean state-sponsored threat actors leveraging malicious QR codes in spear-phishing campaigns targeting entities in the country. “As of 2025, Kimsuky actors have targeted think tanks, academic institutions, and both…
-
WhatsApp Worm Spreads Astaroth Banking Trojan Across Brazil via Contact Auto-Messaging
WhatsApp Worm Spreads Astaroth Banking Trojan Across Brazil via Contact Auto-Messaging Cybersecurity researchers have disclosed details of a new campaign that uses WhatsApp as a distribution vector for a Windows banking trojan called Astaroth in attacks targeting Brazil. The campaign has been codenamed Boto Cor-de-Rosa by Acronis Threat Research Unit. “The malware retrieves the victim’s…
-
China-Linked UAT-7290 Targets Telecoms with Linux Malware and ORB Nodes
China-Linked UAT-7290 Targets Telecoms with Linux Malware and ORB Nodes A China-nexus threat actor known as UAT-7290 has been attributed to espionage-focused intrusions against entities in South Asia and Southeastern Europe. The activity cluster, which has been active since at least 2022, primarily focuses on extensive technical reconnaissance of target organizations before initiating attacks, ultimately…
-
ThreatsDay Bulletin: RustFS Flaw, Iranian Ops, WebUI RCE, Cloud Leaks, and 12 More Stories
ThreatsDay Bulletin: RustFS Flaw, Iranian Ops, WebUI RCE, Cloud Leaks, and 12 More Stories The internet never stays quiet. Every week, new hacks, scams, and security problems show up somewhere. This week’s stories show how fast attackers change their tricks, how small mistakes turn into big risks, and how the same old tools keep finding…
-
The State of Trusted Open Source
The State of Trusted Open Source Chainguard, the trusted source for open source, has a unique view into how modern organizations actually consume open source software and where they run into risk and operational burdens. Across a growing customer base and an extensive catalog of over 1800 container image projects, 148,000 versions, 290,000 images, and…
-
5 ways your firewall can keep ransomware out and lock it down if it gets in
5 ways your firewall can keep ransomware out and lock it down if it gets in Go to sophos
-
AI & Humans: Making the Relationship Work
AI & Humans: Making the Relationship Work Leaders of many organizations are urging their teams to adopt agentic AI to improve efficiency, but are finding it hard to achieve any benefit. Managers attempting to add AI agents to existing human teams may find that bots fail to faithfully follow their instructions, return pointless or obvious…