no alarms and no surprises please..

  • What to consider before asking an AI chatbot for health advice

    What to consider before asking an AI chatbot for health advice Using chatbots for medical advice could elicit hallucinations and even expose you to security and privacy risks. Here’s what’s at stake and how to stay safe. Go to eset

  • Nordic CISOs Handle Rising Cyber Threats Remarkably Well

    Nordic CISOs Handle Rising Cyber Threats Remarkably Well Artificial intelligence notwithstanding, the vast majority of CISOs in northern Europe say they’re facing no more serious cyberattacks than they did two years ago. Nate Nelson Go to gbhackers.com

  • Grandoreiro Malware and BTMOB RAT Campaigns Target Windows and Android Users

    Grandoreiro Malware and BTMOB RAT Campaigns Target Windows and Android Users Latin America and Europe become the target of two banking trojan campaigns that are designed to infect Windows and Android devices with Grandoreiro and BTMOB malware, respectively. That’s according to new findings from WatchGuard and ESET, which have observed the two malware families being…

  • Malicious npm Package Stole Files From Claude AI User Directory via GitHub

    Malicious npm Package Stole Files From Claude AI User Directory via GitHub Cybersecurity researchers have discovered a new malicious package on the npm registry that comes with information stealing capabilities. According to OX Security, the package, named “mouse5212-super-formatter,” is designed to upload files from “/mnt/user-data,” a dedicated directory used by Anthropic’s Claude artificial intelligence (AI)…

  • 5 Steps to Managing Shadow AI Tools Without Slowing Down Employees

    5 Steps to Managing Shadow AI Tools Without Slowing Down Employees When an employee installs an AI writing assistant, connects a coding copilot to their IDE, or starts summarizing meetings with a new browser tool, they are doing exactly what a productive employee should do: finding faster ways to work. Across most organizations today, employees…

  • GlassWorm Malware Takedown Disrupts Developer Supply Chain Attack Infrastructure

    GlassWorm Malware Takedown Disrupts Developer Supply Chain Attack Infrastructure CrowdStrike, in partnership with Google and the Shadowserver Foundation, has announced the simultaneous disruption of all command-and-control (C2) channels associated with GlassWorm, a persistent software chain campaign targeting software developers through malicious packages and extensions. “Since at least early 2025, GlassWorm operators have systematically targeted software…

  • 3 SOC Steps that Shut Down Incident Risks Early

    3 SOC Steps that Shut Down Incident Risks Early Most organizations still picture cyber defense as a fortress problem: build stronger walls, add more guards, buy another detection engine. But modern incidents rarely crash through the front gate. They drift in disguised as routine activity, hide inside legitimate processes, and quietly accumulate risk long before…

  • FBI’s 2025 Internet Crime Report

    FBI’s 2025 Internet Crime Report The 2025 Internet Crime Report was published a few weeks ago, but I only just saw it. Lots of interesting statistics. Press release. News articles. Bruce Schneier Go to bruce schneier

  • ISC Stormcast For Thursday, May 28th, 2026 https://isc.sans.edu/podcastdetail/9948, (Thu, May 28th)

    ISC Stormcast For Thursday, May 28th, 2026 https://isc.sans.edu/podcastdetail/9948, (Thu, May 28th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu

  • Reconstructing an Akira Ransomware Kill Chain from Perimeter and Endpoint Logs, (Wed, May 27th)

    Reconstructing an Akira Ransomware Kill Chain from Perimeter and Endpoint Logs, (Wed, May 27th) Most Akira write-ups focus on the ransom note or the encryption routine. By the time those show up the interesting forensic work is over. The questions that matter to defenders sit earlier. How did they get in. When did they get…

  • Smashing Security podcast #469: What your Oura ring won’t tell you

    Smashing Security podcast #469: What your Oura ring won’t tell you CISA, the US government agency whose entire job is keeping America’s critical infrastructure safe from hackers, has had a contractor publish dozens of plain-text credentials to a public GitHub profile. Meanwhile, your Oura ring is quietly transmitting some of its data unencrypted – and…

  • Ransomware Actors Show Up In Person to Steal Law Firm Data

    Ransomware Actors Show Up In Person to Steal Law Firm Data The FBI warned that the extortion gang Silent Ransom Group is targeting law firms and socially engineering its way into servers and databases. Alexander Culafi Go to gbhackers.com

  • Latin American Cybercriminals Hoover Up Government Data

    Latin American Cybercriminals Hoover Up Government Data A purported leak exposing 5.8 million records of Uruguayan citizens is the latest incident where cybercriminals targeted government agencies to monetize citizen data. Robert Lemos Go to gbhackers.com

  • Cybersecurity Evolution: How We Went From Perimeter Defense to AI-Native Security

    Cybersecurity Evolution: How We Went From Perimeter Defense to AI-Native Security The cybersecurity industry of 2006 barely resembled today’s billion-dollar behemoth. As part of Dark Reading’s 20th anniversary celebration, we trace the industry’s evolution through a technology lens. Fahmida Y. Rashid Go to gbhackers.com

  • Windows Kernel Vulnerability Lets Attackers Modify Kernel Memory Counters

    Windows Kernel Vulnerability Lets Attackers Modify Kernel Memory Counters A critical Windows kernel vulnerability, CVE-2026-40369, allows any unprivileged process, including a browser renderer sandbox, to increment arbitrary kernel memory and reliably escalate to… Delivered by PolitePaul service Go to gbhackers.com

  • GitHub Enterprise Server 3.20.3 Addresses Critical Security Flaws

    GitHub Enterprise Server 3.20.3 Addresses Critical Security Flaws GitHub has released Enterprise Server (GHES) version 3.20.3, addressing multiple critical and high-severity vulnerabilities that could allow attackers to access internal services, escalate privileges,… Delivered by PolitePaul service Go to gbhackers.com

  • New Zero-Click WhatsApp Account Takeover Attack Targets iOS 16 Users

    New Zero-Click WhatsApp Account Takeover Attack Targets iOS 16 Users A newly uncovered zero-click attack targets iPhone users running iOS 16, allowing threat actors to hijack WhatsApp accounts without any user interaction, visible prompts,… Delivered by PolitePaul service Go to gbhackers.com

  • Hackers Exploit Shared CDN Edge IPs to Evade Protective DNS Filtering

    Hackers Exploit Shared CDN Edge IPs to Evade Protective DNS Filtering Hackers are exploiting shared CDN edge infrastructure to bypass DNS-based security controls, according to new research from ADAMnetworks, which details a stealthy evasion technique… Delivered by PolitePaul service Go to gbhackers.com

  • Anthropic Launches Free Claude Code Terminal Plugin to Detect Security Vulnerabilities

    Anthropic Launches Free Claude Code Terminal Plugin to Detect Security Vulnerabilities Anthropic has launched a free Claude Code terminal plugin, “security-guidance,” that continuously reviews AI‑generated code in-session to detect and remediate security vulnerabilities before they… Delivered by PolitePaul service Go to gbhackers.com

  • Dutch police arrests suspect linked to Ajax football club hack

    Dutch police arrests suspect linked to Ajax football club hack The Dutch National Police arrested a 35-year-old man suspected of hacking the professional football club Ajax Amsterdam (AFC Ajax) earlier this year. […] Sergiu Gatlan Go to bleepingcomputer

  • Windows 11 KB5089573 update released with performance improvements

    Windows 11 KB5089573 update released with performance improvements Microsoft has released the KB5089573 preview cumulative update for Windows 11 versions 25H2 and 24H2, which comes with 30 changes, including performance and reliability improvements. […] Sergiu Gatlan Go to bleepingcomputer

  • KnowledgeDeliver flaw exploited as a zero-day to install web shells

    KnowledgeDeliver flaw exploited as a zero-day to install web shells Hackers exploited a critical zero-day vulnerability in a server running the KnowledgeDeliver learning management system (LMS) to deploy the Godzilla web shell. […] Ionut Ilascu Go to bleepingcomputer

  • Charter confirms data breach after ShinyHunters extortion threat

    Charter confirms data breach after ShinyHunters extortion threat U.S. telecommunications giant Charter Communications has confirmed it suffered a data breach after the ShinyHunters extortion group threatened to leak stolen data unless a ransom is paid. […] Lawrence Abrams Go to bleepingcomputer

  • How Varonis Atlas integrates Claude Compliance API for AI governance

    How Varonis Atlas integrates Claude Compliance API for AI governance AI governance requires visibility into how AI tools interact with enterprise data. Varonis explains how its Atlas platform uses Claude Compliance API data to help monitor usage, investigate risk, and support compliance. […] Sponsored by Varonis Go to bleepingcomputer

  • Apple’s New Anti-Snatching Feature Will Auto-Lock iPhones When Stolen From Your Hand

    Apple’s New Anti-Snatching Feature Will Auto-Lock iPhones When Stolen From Your Hand Apple is reportedly developing a new iPhone security feature designed to automatically lock the device the moment it detects a theft-in-progress, a significant upgrade to the company’s existing anti-theft protections that could close one of the most dangerous gaps in mobile security today.…

  • Developer-Targeting Glassworm Malware Abuses npm, PyPI, OpenVSX, and GitHub

    Developer-Targeting Glassworm Malware Abuses npm, PyPI, OpenVSX, and GitHub A dangerous malware campaign known as Glassworm has been spreading through the tools that software developers trust most every day. By abusing popular platforms like npm, PyPI, OpenVSX, and GitHub, the attackers have turned routine development workflows into entry points for data theft, credential harvesting, and…

  • Attackers Abuse Open RDP Ports to Gain Initial Access Into Business Networks

    Attackers Abuse Open RDP Ports to Gain Initial Access Into Business Networks There is a decades-old misconfiguration sitting quietly inside countless business networks, and attackers are still making full use of it. Remote Desktop Protocol, or RDP, allows users to connect to and control a computer remotely over a network. When its default port, 3389,…

  • New 0-Click WhatsApp Account Takeover Attack Targeting iOS 16 Users

    New 0-Click WhatsApp Account Takeover Attack Targeting iOS 16 Users A new 0-Click WhatsApp Account Takeover Attack Targeting iOS 16 Users is raising serious concerns after multiple iPhone users reported their accounts being hijacked without any interaction, warnings, or visible linked devices. According to a recent forensic investigation by the Italian security firm Forenser, attackers…

  • GitLab Suspends Windows Exploit Researcher Nightmare-Eclipse After GitHub Ban

    GitLab Suspends Windows Exploit Researcher Nightmare-Eclipse After GitHub Ban The anonymous researcher known as Nightmare-Eclipse has been blocked from two major code-hosting platforms in less than a week, as their disruptive public zero-day campaign against Microsoft draws serious real-world consequences. GitLab moved to suspend the account of security researcher Nightmare-Eclipse on May 26, 2026, just…

  • BTMOB: A stealthy RAT burrowing deep into Android devices

    BTMOB: A stealthy RAT burrowing deep into Android devices The malware pairs remote access capabilities with ready-made campaign tools, lowering the barrier for full device compromise Go to eset

  • MuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting 9 Countries

    MuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting 9 Countries The Iranian hacking group known as MuddyWater has been linked to a new campaign affecting at least nine organizations across nine countries on four continents in the first quarter of 2026. The activity targeted industrial and electronics manufacturing, education and public-sector bodies, financial services, and…

  • [THN Webinar] New AI DDoS Attacks Are Smarter. Learn How to Fight Back

    [THN Webinar] New AI DDoS Attacks Are Smarter. Learn How to Fight Back Every single day, hackers are finding new ways to crash websites and steal data. But right now, something has changed. Hackers are no longer working alone. They are now using powerful Artificial Intelligence (AI) tools to make their attacks faster, stronger, and…

  • Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions

    Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions Microsoft has rolled out updates to fix a remote code execution vulnerability impacting SharePoint that could be exploited by bad actors in attacks without requiring any specialized conditions to be met. The vulnerability, tracked as CVE-2026-45659, carries a CVSS score of 8.8. It has been assigned…

  • MFA Prompt Bombing: Why Your Second Factor Isn’t Saving You

    MFA Prompt Bombing: Why Your Second Factor Isn’t Saving You Multi-factor authentication (MFA) was supposed to close a critical gap in identity security. It meant that, even if an attacker possessed the account credentials, they couldn’t log in without the second factor. While that logic was sound, attackers have now figured out that they don’t…

  • CERT-In Recommends 12-Hour Patching for Internet-Facing Flaws Amid AI-Assisted Attacks

    CERT-In Recommends 12-Hour Patching for Internet-Facing Flaws Amid AI-Assisted Attacks The Indian Computer Emergency Response Team (CERT-In) has issued new guidelines requiring organizations to patch critical security vulnerabilities in internet-exposed systems within 12 hours of being flagged where “feasible” to safeguard against potential threats stemming from threat actors’ abuse of artificial intelligence (AI) tools and…

  • Identifying People Using Wi-Fi Routers

    Identifying People Using Wi-Fi Routers Not identifying people based on their use of Wi-Fi routers, but identifying people using Wi-Fi signals. This is accomplished through what is known as WiFi sensing, or the use of WiFi signals to infer information about a physical environment. When radio signals like WiFi travel through a space, they interact…

  • ISC Stormcast For Wednesday, May 27th, 2026 https://isc.sans.edu/podcastdetail/9946, (Wed, May 27th)

    ISC Stormcast For Wednesday, May 27th, 2026 https://isc.sans.edu/podcastdetail/9946, (Wed, May 27th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu

  • FBI warns of Kali365 phishing kit that breaks into Microsoft 365 accounts – no password required

    FBI warns of Kali365 phishing kit that breaks into Microsoft 365 accounts – no password required So, you’ve enabled multi-factor authentication. You’ve taught your staff never to type their passwords into dodgy-looking login pages. Surely your Microsoft 365 accounts are safe now? Well, think again. Read more in my article on the Hot for Security…

  • Feeding Frenzy: ‘Megalodon’ Malware Infects Thousands of GitHub Repos

    Feeding Frenzy: ‘Megalodon’ Malware Infects Thousands of GitHub Repos In just six hours, the campaign quietly pushed thousands of malicious commits to more than 5,500 GitHub repositories, stealing credentials, developer secrets, and more. Rob Wright Go to gbhackers.com

  • The Hackers Behind Shai-Hulud: Lucky or Skilled?

    The Hackers Behind Shai-Hulud: Lucky or Skilled? TeamPCP, the hackers behind the Shai-Hulud worm, has done significant damage to the open source ecosystem. But it’s not necessarily due to skill alone. Alexander Culafi Go to gbhackers.com

  • Remembering Tim Wilson, Whose Legacy Lives on at Dark Reading

    Remembering Tim Wilson, Whose Legacy Lives on at Dark Reading The co-founder and former editor-in-chief passed away five years ago in November. As Dark Reading enters is third decade, we pause to celebrate and honor Wilson’s instrumental role in building and elevating the media site. Kelly Jackson Higgins Go to gbhackers.com

  • China-Linked Hackers Hit SEA Edge Routers With Custom Linux Implant

    China-Linked Hackers Hit SEA Edge Routers With Custom Linux Implant China-linked hackers are conducting a stealthy infrastructure-centric espionage campaign across Southeast Asia by compromising Linux-based edge routers with a custom ELF implant and pairing… Delivered by PolitePaul service Go to gbhackers.com

  • Memcached SASL Flaw Exposes Usernames to Enumeration Attacks

    Memcached SASL Flaw Exposes Usernames to Enumeration Attacks A newly identified vulnerability in Memcached has raised concerns among security professionals after researchers confirmed a timing side-channel flaw that allows attackers to enumerate… Delivered by PolitePaul service Go to gbhackers.com

  • NightSpire Ransomware Abuses RDP for Stealthy Persistence

    NightSpire Ransomware Abuses RDP for Stealthy Persistence NightSpire has quickly emerged as a significant ransomware threat since its discovery in early 2025, combining classic double-extortion tactics with stealthy intrusion techniques. The… Delivered by PolitePaul service Go to gbhackers.com

  • Ghost CMS Vulnerability Exploited to Infect 700 Sites With ClickFix Malware

    Ghost CMS Vulnerability Exploited to Infect 700 Sites With ClickFix Malware Hackers are actively exploiting a critical SQL injection vulnerability in Ghost CMS (CVE-2026-26980) to compromise websites and distribute ClickFix malware through large-scale page-poisoning attacks…. Delivered by PolitePaul service Go to gbhackers.com

  • Apache CXF Flaw Exposes Systems to LDAP Injection Attacks

    Apache CXF Flaw Exposes Systems to LDAP Injection Attacks Apache CXF users are facing a significant security risk following the disclosure of a new vulnerability that exposes systems to LDAP injection attacks, potentially… Delivered by PolitePaul service Go to gbhackers.com

  • CISA orders feds to patch actively exploited Drupal vulnerability

    CISA orders feds to patch actively exploited Drupal vulnerability CISA has given U.S. government agencies until Wednesday evening to secure their servers against an SQL injection vulnerability in the Drupal content management system (CMS) that it flagged as actively exploited. […] Sergiu Gatlan Go to bleepingcomputer

  • Microsoft: Domain Controller lookup may fail on Windows Server 2016

    Microsoft: Domain Controller lookup may fail on Windows Server 2016 Microsoft has confirmed a new known issue affecting Windows Server 2016 systems that causes domain controller lookups to fail after installing the KB5087537 May 2026 security update. […] Sergiu Gatlan Go to bleepingcomputer

  • 7-Eleven data breach exposes personal information of 185,000 people

    7-Eleven data breach exposes personal information of 185,000 people The ShinyHunters extortion gang stole the personal information of over 183,000 people after hacking the systems of convenience store chain giant 7-Eleven in April, according to data breach notification service Have I Been Pwned. […] Sergiu Gatlan Go to bleepingcomputer

  • Anthropic’s restricted Claude Mythos model may be coming to Claude Code

    Anthropic’s restricted Claude Mythos model may be coming to Claude Code Anthropic appears to be preparing for the public rollout of the Mythos model, which was announced in April as a restricted model that poses major security risks to private and public software. […] Mayank Parmar Go to bleepingcomputer

  • FBI warns of Kali365 phishing service targeting Microsoft 365 accounts

    FBI warns of Kali365 phishing service targeting Microsoft 365 accounts The FBI is warning about the Kali365 phishing-as-a-service platform (PhaaS) that is used to hijack Microsoft 365 accounts by abusing OAuth device code authentication to steal session tokens and bypass multi-factor authentication (MFA). […] Lawrence Abrams Go to bleepingcomputer

  • Phishing Services Use RCS and iMessage to Bypass Traditional SMS Security Filters

    Phishing Services Use RCS and iMessage to Bypass Traditional SMS Security Filters A new wave of phishing operations is quietly changing the way cybercriminals steal financial data from everyday people. Rather than relying on traditional SMS messages that carriers can easily flag and block, threat actors are now using encrypted messaging channels like Rich Communication…

  • Payload Ransomware Uses ChaCha20 and Curve25519 ECDH to Encrypt Windows Files

    Payload Ransomware Uses ChaCha20 and Curve25519 ECDH to Encrypt Windows Files A dangerous new ransomware strain called Payload has been quietly building a global victim list since it first appeared in February 2026. The group launched its leak site with a high-profile target and has since expanded operations across Egypt, Mexico, Poland, and beyond. What…

  • PuTTY 0.84 Released With Fix for SSH KEX Crashes and Telnet Prompt Spoofing Flaw

    PuTTY 0.84 Released With Fix for SSH KEX Crashes and Telnet Prompt Spoofing Flaw PuTTY 0.84 has been released with fixes for multiple minor security flaws, including issues that could trigger SSH key exchange crashes and a Telnet prompt spoofing weakness. While these vulnerabilities are considered low severity, they highlight how even small flaws in…

  • New 7-Zip Vulnerabilities Let Attackers Execute Arbitrary Code and Compromise Systems

    New 7-Zip Vulnerabilities Let Attackers Execute Arbitrary Code and Compromise Systems A critical heap buffer overflow vulnerability has been disclosed in 7-Zip version 26.00, enabling attackers to achieve arbitrary code execution via a vtable hijack by exploiting a defect in the tool’s NTFS archive handler. Tracked as CVE-2026-48095 and assigned advisory GHSL-2026-140, the flaw resides…

  • Anthropic’s Restricted Claude Mythos Moves Toward Public Release via Claude Code and Security

    Anthropic’s Restricted Claude Mythos Moves Toward Public Release via Claude Code and Security Anthropic appears to be loosening its grip on Claude Mythos, the company’s most powerful and previously restricted AI model, with new signals pointing to a commercially versioned release under the name Mythos 1 (claude-mythos-1-preview), integrated directly into Claude Code and a revamped…

  • KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt Strike

    KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt Strike A now-patched high-severity security flaw affecting Digital Knowledge KnowledgeDeliver, a Learning Management System (LMS) popular in Japan, was exploited as a zero-day to deliver the Godzilla web shell and ultimately facilitate the deployment of Cobalt Strike Beacon. The vulnerability, tracked as CVE-2026-5426 (CVSS score: 7.5),…

  • ⚡ Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaos

    ⚡ Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaos Monday recap. Same mess, new week. A sketchy dev tool got people pwned, old bugs came back from the dead, and security products somehow needed protecting from themselves. A bunch of companies spent the week checking old boxes and forgotten servers they…

  • Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks

    Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks Threat actors are exploiting a recently disclosed critical security flaw in Ghost CMS to inject malicious JavaScript code with an aim to fuel ClickFix attacks. According to QiAnXin XLab, the activity involves the exploitation of CVE-2026-26980 (CVSS score: 9.4), an SQL injection vulnerability in…

  • The Alert Firehose Finally Meets Its Match

    The Alert Firehose Finally Meets Its Match Ask a cybersecurity pro about Network Detection and Response (NDR) and you might still hear “Noisy,” “Too much data.” But ask the teams running NDR that includes agentic AI capabilities and you’ll hear they’re actually using it to catch threats earlier, triage faster, and chase fewer false positives.…

  • Lazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto Firms

    Lazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto Firms Cybersecurity researchers have shed light on a cross-platform malware called RemotePE that has been put to use by the North Korea-linked Lazarus Group in attacks targeting financial and cryptocurrency organizations. RemotePE, per NCC Group subsidiary Fox-IT, is part of a multi-stage attack chain that involves…

  • ISC Stormcast For Tuesday, May 26th, 2026 https://isc.sans.edu/podcastdetail/9944, (Tue, May 26th)

    ISC Stormcast For Tuesday, May 26th, 2026 https://isc.sans.edu/podcastdetail/9944, (Tue, May 26th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu

  • Possible ACR Stealer From Page Impersonating Claude, (Tue, May 26th)

    Possible ACR Stealer From Page Impersonating Claude, (Tue, May 26th) Introduction In recent weeks, I’ve searched for pages impersonating Claude that distribute malware. In recent weeks, I’ve reliably found these sites through malicious ads in Google searches that lead to these pages, often concealed in URLs for sites.google[.]com, such as this example from 2026-05-11. These…

  • Microsoft Access VBA, (Mon, May 25th)

    Microsoft Access VBA, (Mon, May 25th) Microsoft Access files (Microsoft Office’s Database) can contain VBA code. But they are not ole or OOXML files. You can’t analyze them with oledump.py: Neither do they contain an embedded OLE file: Microsoft does not publish official documentation for the Microsoft Access file format, like it does for CFB…

  • TeamPCP Supply Chain Campaign: Activity Through 2026-05-24, (Mon, May 25th)

    TeamPCP Supply Chain Campaign: Activity Through 2026-05-24, (Mon, May 25th) TeamPCP now operates across three package ecosystems in parallel, it reached GitHub’s own internal codebase, it trojanized an officially Microsoft-published Python SDK, and it appears to have open-sourced its own framework on GitHub. Bottom line up front Three escalations stacked inside a single week. First,…

  • TeamPCP Supply Chain Campaign: Activity Through 2026-05-24, (Mon, May 25th)

    TeamPCP Supply Chain Campaign: Activity Through 2026-05-24, (Mon, May 25th) TeamPCP now operates across three package ecosystems in parallel, it reached GitHub’s own internal codebase, it trojanized an officially Microsoft-published Python SDK, and it appears to have open-sourced its own framework on GitHub. Bottom line up front Three escalations stacked inside a single week. First,…

  • Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks

    Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks Authorities in the Netherlands have arrested the co-owners of two related Internet hosting companies for operating IT infrastructure used by Russia to carry out cyberattacks, influence operations and disinformation campaigns inside the European Union. The two men were the focus of a 2025 KrebsOnSecurity story about…

  • Welcoming the Bhutanese Government to Have I Been Pwned

    Welcoming the Bhutanese Government to Have I Been Pwned Today, we welcome the 45th government onboarded to Have I Been Pwned’s free gov service: Bhutan. The Bhutan Computer Incident Response Team, BtCIRT, now has access to monitor Bhutanese government domains against the data in HIBP. As Bhutan’s national CIRT, BtCIRT is responsible for consuming threat…

  • WhatsApp Chat Histories Exposed in Unencrypted Storage on macOS and iOS

    WhatsApp Chat Histories Exposed in Unencrypted Storage on macOS and iOS Security researchers have raised concerns over how WhatsApp stores user chat data on macOS and iOS, revealing that message databases may be stored in… Delivered by PolitePaul service Go to gbhackers.com

  • Telegram Channels Fuel Sale of Verified Bank Mule Accounts

    Telegram Channels Fuel Sale of Verified Bank Mule Accounts Cybercriminal groups are increasingly using Telegram channels and encrypted platforms to sell verified bank and fintech mule accounts, signaling a major shift in how… Delivered by PolitePaul service Go to gbhackers.com

  • Italian Authorities Dismantle CINEMAGOAL App Enabling Unauthorised Access to Streaming Platforms

    Italian Authorities Dismantle CINEMAGOAL App Enabling Unauthorised Access to Streaming Platforms Italian law enforcement agencies have dismantled a sophisticated piracy operation centered around the CINEMAGOAL application, which enabled unauthorized access to premium streaming platforms including… Delivered by PolitePaul service Go to gbhackers.com

  • Hackers Actively Scan SonicWall Firewall Interfaces as 597,000 Sessions Observed

    Hackers Actively Scan SonicWall Firewall Interfaces as 597,000 Sessions Observed A sharp surge in internet scanning activity targeting SonicWall firewall management interfaces has raised concerns among cybersecurity researchers, with GreyNoise reporting nearly 597,000 sessions… Delivered by PolitePaul service Go to gbhackers.com

  • CISA Warns Drupal Core SQL Injection Vulnerability Is Being Exploited in Attacks

    CISA Warns Drupal Core SQL Injection Vulnerability Is Being Exploited in Attacks The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning regarding a critical SQL injection vulnerability in Drupal Core, tracked as CVE-2026-9082,… Delivered by PolitePaul service Go to gbhackers.com

  • Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign

    Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign A large-scale campaign is exploiting a critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS to inject malicious JavaScript code that triggers ClickFix attack flows. […] Bill Toulas Go to bleepingcomputer

  • MiniUpdate RAT Uses Azure-Hosted C2 Domains for Targeted Espionage Campaigns

    MiniUpdate RAT Uses Azure-Hosted C2 Domains for Targeted Espionage Campaigns A new wave of targeted espionage attacks has put technology professionals across the United States, Israel, and the United Arab Emirates on high alert. The threat comes from an Iran-linked hacking group deploying two families of remote access trojans through cleverly disguised recruitment lures and…

  • WhatsApp Chat Histories Stored Unencrypted on macOS and iOS

    WhatsApp Chat Histories Stored Unencrypted on macOS and iOS Security researchers have revealed that WhatsApp chat histories may be stored unencrypted on both macOS and iOS devices, raising fresh concerns about local data protection and cross-application access within the Apple ecosystem. The issue, highlighted by iOS security researchers at Mysk, centers on how WhatsApp stores…

  • Authorities Seized 800 Servers of Hosting Company Used to Launch Cyberattacks

    Authorities Seized 800 Servers of Hosting Company Used to Launch Cyberattacks Dutch authorities have seized more than 800 servers and arrested two individuals as part of a major investigation into a hosting infrastructure allegedly used to support cyberattacks, disinformation campaigns, and sanctions evasion linked to Russia. The Fiscal Information and Investigation Service (FIOD) confirmed that…

  • CISA Warns of Drupal Core SQL Injection Vulnerability Exploited in Attacks

    CISA Warns of Drupal Core SQL Injection Vulnerability Exploited in Attacks CISA has issued an urgent alert regarding a critical SQL injection vulnerability in Drupal Core, tracked as CVE-2026-9082, which is now being actively exploited in real-world attacks. The flaw, classified under CWE-89, affects Drupal’s database abstraction API and could allow attackers to execute malicious…

  • GitHub Adds Staged Publishing to npm to Block Automated Supply Chain Attacks

    GitHub Adds Staged Publishing to npm to Block Automated Supply Chain Attacks GitHub has introduced a major security upgrade to the npm ecosystem with the general availability of staged publishing and new install-time controls, aimed at reducing automated supply chain attacks targeting open-source packages. The newly released staged publishing feature changes how npm packages are…

  • TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO

    TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO A new coordinated cross-ecosystem software supply chain attack campaign has targeted npm, PyPI, and Crates.io to distribute credential-stealing malware. The campaign, codenamed TrapDoor, spans more than 34 malicious packages across over 384 versions. The earliest activity was recorded on May 22, 2026, at…

  • Wireshark 4.6.6 Released, (Sun, May 24th)

    Wireshark 4.6.6 Released, (Sun, May 24th) Wireshark release 4.6.6 fixes 1 vulnerability and 11 bugs. For WIndows, Npcap is updated to version 1.88.   Didier Stevens Senior handler blog.DidierStevens.com (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu

  • Weekly Update 505

    Weekly Update 505 Well, that didn’t last long! Recording this on Saturday morning my time, I observed ShinyHunters having gone quiet since the massive haul that would have been the Instructure ransom. It was two weeks almost to the hour since I’d first heard rumour of payment being made, and I posited that groups like…

  • Laravel Lang packages hijacked to deploy credential-stealing malware

    Laravel Lang packages hijacked to deploy credential-stealing malware A supply chain attack targeting the Laravel Lang localization packages has exposed developers to a sophisticated credential-stealing malware campaign after attackers abused GitHub version tags to distribute malicious code through Composer packages. […] Lawrence Abrams Go to bleepingcomputer

  • Italy disrupts CINEMAGOAL piracy app that stole streaming auth codes

    Italy disrupts CINEMAGOAL piracy app that stole streaming auth codes Italian authorities have dismantled a piracy ecosystem centered around the CINEMAGOAL app that provided access to various streaming platforms, including Netflix, Disney+, and Spotify. […] Bill Toulas Go to bleepingcomputer

  • PyrsistenceSniper – Tool that Detects 117 Persistence Malware Techniques on Windows, Linux, and macOS

    PyrsistenceSniper – Tool that Detects 117 Persistence Malware Techniques on Windows, Linux, and macOS PyrsistenceSniper is an advanced tool for detecting offline persistence, enabling cybersecurity analysts to identify 117 separate persistence mechanisms across Windows, Linux, and macOS platforms. Originally inspired by Autoruns and PersistenceSniper, this Python-based solution developed by Hexastrike enables rapid triage of forensic…

  • Nginx-poolslip Vulnerability Enables DoS and Code Execution Attacks — Patch Now!

    Nginx-poolslip Vulnerability Enables DoS and Code Execution Attacks — Patch Now! A newly disclosed flaw in one of the world’s most widely deployed web servers is forcing administrators into another emergency patch cycle. Tracked as CVE-2026-9256 and publicly nicknamed nginx-poolslip, the vulnerability affects both NGINX Plus and NGINX Open Source, and can be triggered by…

  • Hackers Exploit F5 BIG-IP Appliance to Gain SSH Access and Pivot Into Enterprise Linux Networks

    Hackers Exploit F5 BIG-IP Appliance to Gain SSH Access and Pivot Into Enterprise Linux Networks A multi-stage intrusion attack where a threat actor exploited an internet-facing F5 BIG-IP edge appliance as the entry point for a widespread, identity-focused attack that ultimately accessed Active Directory. According to Microsoft’s Defender Security Research, the attack reflects a growing…

  • npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks

    npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks GitHub has rolled out new controls for npm to improve the security of the software supply chain, giving maintainers the ability to explicitly approve a release prior to the packages becoming publicly available for installation. Called staged publishing, the feature is now generally…

  • Packagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux Malware

    Packagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux Malware A new “coordinated” supply chain attack campaign has impacted eight packages on Packagist including malicious code designed to run a Linux binary retrieved from a GitHub Releases URL. “Although the affected packages were all Composer packages, the malicious code was not added to composer.json,”…

  • Claude Mythos AI Finds 10,000 High-Severity Flaws in Widely Used Software

    Claude Mythos AI Finds 10,000 High-Severity Flaws in Widely Used Software Anthropic on Friday disclosed that Project Glasswing has helped uncover more than 10,000 high- or critical-severity vulnerabilities across some of the most “systemically” important software across the world since the cybersecurity initiative went live last month. Project Glasswing is a defensive effort launched by…

  • Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential Stealer

    Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential Stealer Cybersecurity researchers have flagged a fresh software supply chain attack campaign that has targeted multiple PHP packages belonging to Laravel-Lang to deliver a comprehensive credential-stealing framework. The affected packages include – laravel-lang/lang laravel-lang/http-statuses laravel-lang/attributes laravel-lang/actions “The timing and pattern of the newly published tags Go to…

  • LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root

    LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root A maximum-severity security vulnerability impacting LiteSpeed User-End cPanel Plugin has come under active exploitation in the wild. The flaw, tracked as CVE-2026-48172 (CVSS score: 10.0), relates to an instance of incorrect privilege assignment that an attacker could abuse to run arbitrary scripts with elevated permissions.…

  • An Example of Stack String in High Level Language, (Sat, May 23rd)

    An Example of Stack String in High Level Language, (Sat, May 23rd) This week, I’m attending the SEC670[1] training (“Red Teaming Tools – Developing Windows Implants, Shellcode, Command and Control”). From my point of view, this training fits perfectly with FOR610 or FOR710 (malware analysis) because it addresses malware from the opposite: Instead of performing…

  • Hackers Exploit F5 BIG-IP to Gain SSH Access and Pivot Into Linux Networks

    Hackers Exploit F5 BIG-IP to Gain SSH Access and Pivot Into Linux Networks Threat actors are actively exploiting end-of-life F5 BIG-IP appliances to gain unauthorized SSH access into enterprise networks, using the compromised devices as launchpads for… Delivered by PolitePaul service Go to gbhackers.com

  • LiteSpeed cPanel Plugin 0-Day Exploited for Server Root Access

    LiteSpeed cPanel Plugin 0-Day Exploited for Server Root Access A critical zero-day privilege escalation vulnerability in the LiteSpeed User-End cPanel plugin is being actively exploited in the wild, enabling any authenticated cPanel user… Delivered by PolitePaul service Go to gbhackers.com

  • Ubiquiti Patches Critical UniFi OS Privilege Escalation Flaws

    Ubiquiti Patches Critical UniFi OS Privilege Escalation Flaws Ubiquiti has released urgent security patches for five critical and high-severity vulnerabilities across its UniFi OS platform, addressing flaws that could allow remote attackers… Delivered by PolitePaul service Go to gbhackers.com

  • Hackers Use SEO Poisoning to Fake Gemini CLI, Claude Installers

    Hackers Use SEO Poisoning to Fake Gemini CLI, Claude Installers Financially motivated threat actors are running an active campaign that impersonates Google’s Gemini CLI and Anthropic’s Claude Code, using SEO poisoning to deliver a… Delivered by PolitePaul service Go to gbhackers.com

  • Hackers Compromise Laravel-Lang Packages via 700 GitHub Repos

    Hackers Compromise Laravel-Lang Packages via 700 GitHub Repos A sophisticated and active supply chain attack has struck the Laravel-Lang open-source organization, compromising over 700 historical package versions across four widely used PHP… Delivered by PolitePaul service Go to gbhackers.com

  • Netherlands seizes 800 servers of hosting firm enabling cyberattacks

    Netherlands seizes 800 servers of hosting firm enabling cyberattacks Financial crime investigators in the Netherlands (FIOD) arrested two men and seized 800 servers linked to a web hosting company that enabled cyberattacks, interference operations, and disinformation campaigns. […] Bill Toulas Go to bleepingcomputer

  • Former US execs plead guilty to aiding tech support scammers

    Former US execs plead guilty to aiding tech support scammers Two former executives of a call-tracking and analytics company pleaded guilty to concealing a years-long tech support fraud scheme that victimized individuals worldwide. […] Sergiu Gatlan Go to bleepingcomputer