Tag: cyber-security-news

  • CISA Warns of Google Chromium 0-Day Vulnerability Actively Exploited in Attacks

    CISA Warns of Google Chromium 0-Day Vulnerability Actively Exploited in Attacks An urgent warning regarding a newly discovered zero-day vulnerability in Google Chromium, which is reportedly under active exploitation in the wild. The vulnerability, tracked as CVE-2026-2441, affects Chromium’s CSS (Cascading Style Sheets) engine and can enable remote attackers to execute arbitrary code on a victim’s…

  • Microsoft VS Code Extension with 11M Downloads Expose Developers to One-Click XSS Attacks

    Microsoft VS Code Extension with 11M Downloads Expose Developers to One-Click XSS Attacks A critical vulnerability discovered in Microsoft’s popular Visual Studio Code (VS Code) Live Preview extension, downloaded over 11 million times, exposes developers to one-click cross-site scripting (XSS) and local file exfiltration attacks. The flaw, now patched, was discovered by researchers Nir Zadok and Moshe Siman Tov Bustan from OX Security. The issue…

  • Notepad++ v8.9.2 Released with “Double-Lock” Update Mechanism Following Recent Hack

    Notepad++ v8.9.2 Released with “Double-Lock” Update Mechanism Following Recent Hack The widely used open-source text and code editor has released version v8.9.2, introducing a major security enhancement known as the “Double-Lock” update mechanism. This update addresses vulnerabilities that were exploited in a recent state-sponsored attack targeting the application’s update infrastructure. Last month, Notepad++’s official site confirmed that attackers…

  • New ‘Foxveil’ Malware Loader Leverages Cloudflare, Netlify, and Discord to Evade Detection

    New ‘Foxveil’ Malware Loader Leverages Cloudflare, Netlify, and Discord to Evade Detection A new malware loader called “Foxveil” has been discovered actively targeting systems through legitimate cloud platforms, raising concerns about how threat actors are weaponizing trusted services to bypass security measures. The malware has been operational since August 2025 and has since evolved significantly.…

  • Critical Windows Admin Center Vulnerability Allows Privilege Escalation

    Critical Windows Admin Center Vulnerability Allows Privilege Escalation A critical security update addressing a high‑severity elevation of privilege vulnerability in Windows Admin Center (WAC), identified as CVE‑2026‑26119. The flaw, rated CVSS 8.8 (Critical), stems from improper authentication (CWE‑287) that could allow an authorized attacker to gain elevated network privileges. According to Microsoft, this vulnerability affects Windows Admin Center version 2.6.4, and…

  • Apache NiFi Vulnerability Enables Authorization Bypass

    Apache NiFi Vulnerability Enables Authorization Bypass A newly disclosed high-severity vulnerability in Apache NiFi exposes systems to an authorization bypass that could allow lower-privileged users to modify restricted components. Tracked as CVE-2026-25903, the flaw impacts Apache NiFi versions 1.1.0 through 2.7.2 and has been fixed in version 2.8.0. According to the Apache NiFi security advisory, the issue arises from missing…

  • Malicious Chrome Extension Steals Facebook Business Manage 2FA Codes and Analytics Data

    Malicious Chrome Extension Steals Facebook Business Manage 2FA Codes and Analytics Data A malicious Chrome extension that claims to help Meta Business users quietly steals Facebook Business Manager 2FA codes and analytics data, putting high‑value ad accounts at risk of takeover. The extension, “CL Suite by @CLMasters” (ID: jkphinfhmfkckkcnifhjiplhfoiefffl), is still available in the Chrome Web…

  • Langchain Community SSRF Bypass Vulnerability Enables Access to Internal Services

    Langchain Community SSRF Bypass Vulnerability Enables Access to Internal Services A Server‑Side Request Forgery (SSRF) vulnerability has been identified in the langchain/community package, affecting versions up to 1.1.13. The flaw, tracked as CVE‑2026‑26019, has a moderate severity rating, with a CVSS 3.1 score, due on its potential to expose sensitive cloud metadata and internal infrastructure. The vulnerability originates from the RecursiveUrlLoader class, which…

  • 25 Vulnerabilities in Cloud Password Managers Allow Unauthorized Access and Modifications

    25 Vulnerabilities in Cloud Password Managers Allow Unauthorized Access and Modifications Researchers from ETH Zurich have uncovered 25 serious vulnerabilities in three leading cloud-based password managers: Bitwarden, LastPass, and Dashlane. These flaws enable a malicious server to bypass zero-knowledge encryption claims, allowing unauthorized access, modification, and recovery of users’ stored passwords and vault data. Bitwarden,…

  • Noodlophile Malware Creators Evolve Tactics with Fake Job Postings and Phishing Lures

    Noodlophile Malware Creators Evolve Tactics with Fake Job Postings and Phishing Lures The Noodlophile information stealer, originally uncovered in May 2025, has significantly evolved its attack strategies to bypass security measures. Initially, this malware hid behind deceptive advertisements for fake AI video generation platforms on social media, tricking users into downloading malicious ZIP files. These…

  • Critical BeyondTrust Vulnerability Exploited in the Wild to Gain Full Domain Control

    Critical BeyondTrust Vulnerability Exploited in the Wild to Gain Full Domain Control A critical vulnerability tracked as CVE-2026-1731 is being actively exploited in the wild, enabling attackers to gain full domain control over affected systems. Threat actors are leveraging this flaw to execute operating system commands remotely without authentication. The flaw, discovered in self-hosted BeyondTrust deployments, allows unauthenticated…

  • Chrome 0-Day Vulnerability Actively Exploited by Attackers in the Wild

    Chrome 0-Day Vulnerability Actively Exploited by Attackers in the Wild Google has urgently patched a high-severity zero-day vulnerability in Chrome, confirming active exploitation in the wild. Tracked as CVE-2026-2441, the flaw is a use-after-free bug in the browser’s CSS handling, reported by independent researcher Shaheen Fazim just five days ago on February 11, 2026. The…

  • Windows 11 KB5077181 Security Update Causing Some Devices to Restart in an Infinite Loop

    Windows 11 KB5077181 Security Update Causing Some Devices to Restart in an Infinite Loop Microsoft’s February 10, 2026, security update KB5077181 for Windows 11 versions 24H2 (build 26200.7840) and 25H2 (build 26100.7840) has triggered widespread reports of critical boot failures just days after deployment. Users describe devices entering infinite restart loops, often exceeding 15 cycles,…

  • PentestAgent – AI Penetration Testing Tool With Prebuilt Attack Playbooks and HexStrike Integration

    PentestAgent – AI Penetration Testing Tool With Prebuilt Attack Playbooks and HexStrike Integration PentestAgent, an open-source AI agent framework from developer Masic (GH05TCREW), has introduced enhanced capabilities, including prebuilt attack playbooks and seamless HexStrike integration. Released on GitHub by a researcher with the alias GH05TCREW, this tool leverages large language models (LLMs) like Claude Sonnet…

  • New Clickfix Exploit Tricks Users into Changing DNS Settings for Malware Installation

    New Clickfix Exploit Tricks Users into Changing DNS Settings for Malware Installation A new evolution in the ClickFix social engineering campaign, which now employs a custom DNS hijacking technique to deliver malware. This attack method tricks users into executing malicious commands that utilize DNS lookups to fetch the next stage of the infection, allowing attackers…

  • Threat Actors Exploit Claude Artifacts and Google Ads to Target macOS Users

    Threat Actors Exploit Claude Artifacts and Google Ads to Target macOS Users A sophisticated malware campaign targeting macOS users through Google-sponsored search results and legitimate platforms, including Anthropic’s Claude AI and Medium. The campaign has already reached over 15,000 potential victims through two distinct attack variants that exploit users’ trust in established online services. 15,000…

  • Threat Actor Allegedly Selling Critical Severity OpenSea 0-day Exploit Chain on Hacking Forums

    Threat Actor Allegedly Selling Critical Severity OpenSea 0-day Exploit Chain on Hacking Forums A threat actor is reportedly selling a purported critical severity zero-day exploit chain targeting OpenSea for $100,000 USD in Bitcoin or Monero. The listing claims the vulnerability remains unpatched and undisclosed, raising alarms in the NFT community. The exploit allegedly targets flaws…

  • CISA Warns of Microsoft Configuration Manager SQL Injection Vulnerability Exploited in Attacks

    CISA Warns of Microsoft Configuration Manager SQL Injection Vulnerability Exploited in Attacks CISA has issued an urgent alert about a critical SQL injection vulnerability in Microsoft Configuration Manager (SCCM). Tracked as CVE-2024-43468, this flaw lets unauthenticated attackers run malicious commands on servers and databases. Added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on February 12,…

  • Malicious Chrome AI Extensions Attacking 260,000 Users via Injected IFrames

    Malicious Chrome AI Extensions Attacking 260,000 Users via Injected IFrames A coordinated campaign is using malicious Chrome extensions that impersonate popular AI tools like ChatGPT, Claude, Gemini, and Grok. These fake “AI assistants” spy on users through injected, remote-controlled iframes, turning helpful browser add-ons into surveillance tools. More than 260,000 users have installed these extensions.…

  • Chrome Extensions Infected 500K Users to Hijack VKontakte Accounts

    Chrome Extensions Infected 500K Users to Hijack VKontakte Accounts Over half a million VKontakte users have fallen victim to a sophisticated malware campaign that silently hijacks accounts through seemingly harmless Chrome extensions. The malicious extensions, disguised as VK customization tools, automatically subscribe users to attacker-controlled groups, reset account settings every 30 days, and manipulate security…

  • New ClickFix Attack Wave Targeting Windows Systems to Deploy StealC Stealer

    New ClickFix Attack Wave Targeting Windows Systems to Deploy StealC Stealer A sophisticated social engineering campaign is targeting Windows users through fake CAPTCHA verification pages to deliver the StealC information stealer malware. The attack begins when victims visit compromised websites that display fraudulent Cloudflare security checks, tricking them into executing malicious PowerShell commands. The compromised…

  • Critical Vulnerability in Next-Mdx-Remote Allows Arbitrary Code Execution in React Server-Side Rendering

    Critical Vulnerability in Next-Mdx-Remote Allows Arbitrary Code Execution in React Server-Side Rendering Security advisory HCSEC-2026-01 revealed a critical vulnerability in the next-mdx-remote library that allows attackers to execute arbitrary code on servers rendering untrusted MDX content. Tracked as CVE-2026-0969, the issue affects versions 4.3.0 through 5.0.0 and is fixed in 6.0.0. Next-mdx-remote is a popular…

  • Over 1,800 Windows Servers Compromised by BADIIS Malware in Large-Scale SEO Poisoning Campaign

    Over 1,800 Windows Servers Compromised by BADIIS Malware in Large-Scale SEO Poisoning Campaign A sophisticated cyber campaign has compromised over 1,800 Windows servers globally, using a potent malware strain known as BADIIS. This operation targets Internet Information Services (IIS) environments, transforming legitimate infrastructure into a massive network for SEO poisoning. By hijacking these servers, threat…

  • CISA Warns of Notepad++ Code Execution Vulnerability Exploited in Attacks

    CISA Warns of Notepad++ Code Execution Vulnerability Exploited in Attacks CISA has added CVE-2025-15556 to its Known Exploited Vulnerabilities (KEV) catalog, highlighting active exploitation of a critical code execution flaw in Notepad++, a widely used open-source text editor popular among developers and IT professionals. Added on February 12, 2026, with a federal civilian executive branch…

  • Odido Telecom Suffers Cyberattack – 6.2 Million Customer Accounts Affected

    Odido Telecom Suffers Cyberattack – 6.2 Million Customer Accounts Affected Odido Telecom, a leading Dutch telecommunications provider, confirmed on February 12, 2026, that hackers accessed personal data from 6.2 million customer accounts in a major cyberattack. The breach, detected over the February 7-8 weekend, has raised alarms about phishing risks despite no disruption to services.…

  • 287 Chrome Extensions Exfiltrate Browsing History From 37.4 Million Users

    287 Chrome Extensions Exfiltrate Browsing History From 37.4 Million Users A massive data exfiltration operation involving 287 Chrome extensions that secretly steal browsing history from approximately 37.4 million users worldwide. According to research with alias qcontinuum1, the discovery represents roughly one percent of the global Chrome user base, highlighting a significant privacy breach affecting millions of…

  • Fake CAPTCHA Attacks Emerge as Key Entry Point for LummaStealer Malware Campaigns

    Fake CAPTCHA Attacks Emerge as Key Entry Point for LummaStealer Malware Campaigns LummaStealer, a notorious information-stealing malware, has made a significant comeback following a major law enforcement disruption in 2025. This resurgence is characterized by a shift in distribution tactics, moving away from traditional exploit kits towards aggressive social engineering campaigns. Cybercriminals are now leveraging…

  • Microsoft Outlook Add-in Stolen 4,000 Microsoft account Credentials and Credit Card Numbers

    Microsoft Outlook Add-in Stolen 4,000 Microsoft account Credentials and Credit Card Numbers Security researchers have identified the first documented instance of a malicious Microsoft Outlook add-in being used against users in real-world scenarios. A compromised meeting scheduler named AgreeTo was used to steal over 4,000 Microsoft account credentials, credit card numbers, and answers to banking security questions.…

  • Promptware – Hackers Can Use Google Calendar Invites to Stream Victims’ Cameras via Zoom

    Promptware – Hackers Can Use Google Calendar Invites to Stream Victims’ Cameras via Zoom A new and dangerous class of cyberattack called “Promptware” has been discovered, capable of turning your personal AI assistant into a sleeper agent that spies on you. Security researchers from Ben-Gurion University, Tel Aviv University, and Harvard have demonstrated a terrifying…

  • $44 Evilmouse Autonomously Executes Commands and Compromises Systems Once Connected

    $44 Evilmouse Autonomously Executes Commands and Compromises Systems Once Connected A $44 hardware implant disguised as an ordinary computer mouse. This device acts as a covert keystroke injector, akin to the Hak5 Rubber Ducky, but leverages the innocuous form factor of a mouse to bypass basic user awareness training. Plug it in, and it autonomously…

  • Palo Alto Networks Firewall Vulnerability Allows an Attacker to Force Firewalls into a Reboot Loop

    Palo Alto Networks Firewall Vulnerability Allows an Attacker to Force Firewalls into a Reboot Loop A critical denial-of-service (DoS) flaw in Palo Alto Networks’ PAN-OS software could let unauthenticated attackers crash firewalls into endless reboot cycles, potentially crippling enterprise networks. Dubbed CVE-2026-0229, the vulnerability lurks in the Advanced DNS Security (ADNS) feature. An attacker sends…

  • Socelars Malware Attacking Windows Systems to Steal Sensitive Business Data

    Socelars Malware Attacking Windows Systems to Steal Sensitive Business Data A dangerous information-stealing malware called Socelars is actively targeting Windows systems to collect sensitive authentication data, with particular focus on Facebook Ads Manager accounts and session cookies. Unlike traditional malware that causes immediate system damage, Socelars operates silently in the background, turning infected machines into…

  • Windows Shell Security Feature 0-Day Vulnerability Let Attackers Bypass Authentication

    Windows Shell Security Feature 0-Day Vulnerability Let Attackers Bypass Authentication Microsoft released Microsoft Patch Tuesday updates to address a critical zero-day vulnerability in Windows Shell that is currently being actively exploited in the wild. Tracked as CVE-2026-21510, this security flaw allows remote attackers to bypass essential protection mechanisms, putting millions of Windows users at risk. The…

  • GitLab Patches Multiple Vulnerabilities That Enables DoS and Cross-site Scripting Attacks

    GitLab Patches Multiple Vulnerabilities That Enables DoS and Cross-site Scripting Attacks A critical security update has been released for both the Community Edition (CE) and Enterprise Edition (EE) to address multiple high-severity vulnerabilities. The patches, available in versions 18.8.4, 18.7.4, and 18.6.6, fix flaws that could allow attackers to crash servers, steal data, or hijack…

  • Windows Notepad Vulnerability Allows Attackers to Execute Malicious Code Remotely

    Windows Notepad Vulnerability Allows Attackers to Execute Malicious Code Remotely Microsoft has patched a critical remote code execution (RCE) flaw in the Windows Notepad app, tracked as CVE-2026-20841, which could let attackers run malicious code on victims’ machines. Disclosed on February 10, 2026, Microsoft Patch Tuesday updates, the vulnerability stems from improper neutralization of special…

  • Windows Remote Desktop Services 0-Day Vulnerability Exploited in the Wild to Escalate Privileges

    Windows Remote Desktop Services 0-Day Vulnerability Exploited in the Wild to Escalate Privileges Microsoft has patched CVE-2026-21533, a zero-day elevation of privilege vulnerability in Windows Remote Desktop Services (RDS) that attackers are exploiting in the wild to gain SYSTEM-level access. The flaw stems from improper privilege management and was addressed in the February 2026 Patch…

  • AI Chat App Exposes 300 Million Messages from 25 Million Users

    AI Chat App Exposes 300 Million Messages from 25 Million Users The popular mobile application “Chat & Ask AI” has inadvertently exposed hundreds of millions of private user conversations. The app, which boasts over 50 million users across the Google Play and Apple App stores, failed to secure its backend database, allowing unauthorized access to…

  • Bloody Wolf Hackers Attacking Organizations to Deploy NetSupport RAT and Gain Remote Access

    Bloody Wolf Hackers Attacking Organizations to Deploy NetSupport RAT and Gain Remote Access Stan Ghouls, a cybercriminal group also known as Bloody Wolf, has launched a sophisticated wave of targeted attacks against organizations across Russia and Uzbekistan. Active since at least 2023, the group focuses heavily on the manufacturing, finance, and IT sectors. While they…

  • Augustus – Open-source LLM Vulnerability Scanner With 210+ Attacks Across 28 LLM Providers

    Augustus – Open-source LLM Vulnerability Scanner With 210+ Attacks Across 28 LLM Providers Augustus is a new open-source vulnerability scanner designed to secure Large Language Models (LLMs) against an evolving landscape of adversarial threats. Built by Praetorian, Augustus aims to bridge the gap between academic research tools and production-grade security testing, offering a single-binary solution…

  • Chinese Hackers Attacking Singapore’s Telecommunications Sector to Compromise Edge Devices

    Chinese Hackers Attacking Singapore’s Telecommunications Sector to Compromise Edge Devices Singapore’s telecommunications sector has recently been the target of a highly sophisticated cyber espionage campaign orchestrated by the Advanced Persistent Threat (APT) group known as UNC3886. The details of this extensive intrusion were formally disclosed following Operation CYBER GUARDIAN, a major multi-agency response led by…

  • 15,200 OpenClaw Control Panels with Full System Access Exposed to the Internet

    15,200 OpenClaw Control Panels with Full System Access Exposed to the Internet A critical security failure in the rapidly adopting “agentic AI” ecosystem has left tens of thousands of personal and corporate AI assistants fully exposed to the public internet. New research released today by the SecurityScorecard STRIKE Threat Intelligence Team reveals that 15,200 instances…

  • Vortex Werewolf Attacking Organizations to Gain Tor-Enabled Remote Access Over the RDP, SMB, SFTP, and SSH Protocols

    Vortex Werewolf Attacking Organizations to Gain Tor-Enabled Remote Access Over the RDP, SMB, SFTP, and SSH Protocols A new cyber espionage cluster has recently emerged, focusing its aggressive targeting on Russian government and defense organizations. Active since at least December 2025, the group, designated as Vortex Werewolf, employs a combination of social engineering and legitimate…

  • New RecoverIt Tool Exploits Windows Service Failure Recovery Functions to Execute Payload

    New RecoverIt Tool Exploits Windows Service Failure Recovery Functions to Execute Payload A new open-source offensive security tool named “RecoverIt” has been released, offering Red Teamers and penetration testers a novel method for establishing persistence and executing lateral movement on compromised Windows systems. The tool, developed by security researcher TwoSevenOneT, weaponizes the built-in failure recovery…

  • Critical FortiClientEMS Vulnerability Let Attackers Execute Malicious Code Remotely

    Critical FortiClientEMS Vulnerability Let Attackers Execute Malicious Code Remotely Fortinet has issued a critical security advisory warning administrators to immediately patch instances of FortiClientEMS, its central management solution for endpoint protection. The vulnerability, tracked as CVE-2026-21643, carries a CVSSv3 score of 9.1 and could allow unauthenticated, remote attackers to execute arbitrary code or unauthorized commands…

  • New Telegram Phishing Attack Abuses Authentication Workflows to Obtain Full Authorized User Sessions

    New Telegram Phishing Attack Abuses Authentication Workflows to Obtain Full Authorized User Sessions A sophisticated Telegram phishing campaign has re-emerged, marking a significant evolution in how threat actors compromise user accounts. Unlike traditional credential harvesting, this operation does not rely on cloning login pages to steal passwords but instead manipulates the platform’s legitimate authentication infrastructure.…

  • Ransomware Detection With Windows Minifilter by Intercepting File Filter and Change Events

    Ransomware Detection With Windows Minifilter by Intercepting File Filter and Change Events Ransomware continues to be the most financially damaging type of cyberattack affecting organizations around the world. One of the most effective tools for monitoring in Windows is the minifilter driver. By sitting directly in the file system I/O pipeline, a minifilter can observe,…

  • LocalGPT – A Secure Local Device Focused AI Assistant Built in Rust

    LocalGPT – A Secure Local Device Focused AI Assistant Built in Rust In an era where AI assistants like ChatGPT and Claude dominate cloud infrastructures, exposing user data to remote breaches, a new Rust-based tool called LocalGPT promises a fortress-like alternative. Developed as a single ~27MB binary, LocalGPT runs entirely on local devices, keeping sensitive…

  • Microsoft Data Center Power Outage Disrupts Windows 11 Updates and Store Functionality

    Microsoft Data Center Power Outage Disrupts Windows 11 Updates and Store Functionality Microsoft has confirmed that a significant power outage at one of its West US data centers triggered widespread service disruptions yesterday, leaving thousands of Windows 11 users unable to access the Microsoft Store or complete Windows Updates. The incident, which began early Saturday…

  • BridgePay Payment Gateway Hit by Ransomware, Causing Nationwide Outages

    BridgePay Payment Gateway Hit by Ransomware, Causing Nationwide Outages BridgePay Network Solutions, a major U.S. payment gateway provider, confirmed a ransomware attack caused a widespread outage, disrupting card processing for merchants nationwide. The outage began early on February 6, 2026, around 3:29 a.m. EST with degraded performance in systems like the Gateway.Itstgate.com virtual terminal, reporting,…

  • Hackers Linked to State Actors Target Signal Messages of Military Officials and Journalists

    Hackers Linked to State Actors Target Signal Messages of Military Officials and Journalists Germany’s top security agencies issued an urgent warning yesterday regarding a sophisticated cyber espionage campaign targeting high-ranking officials and journalists across Europe. The Federal Office for the Protection of the Constitution (BfV) and the Federal Office for Information Security (BSI) revealed that…

  • OpenClaw v2026.2.6 Released With Support for Opus 4.6, GPT-5.3-Codex and Safety Scanner

    OpenClaw v2026.2.6 Released With Support for Opus 4.6, GPT-5.3-Codex and Safety Scanner OpenClaw v2026.2.6 enhances security in response to increasing concerns about malicious skills within its ecosystem. This release includes a code safety scanner and model support, and addresses recent vulnerabilities highlighted by researchers. It is an open-source framework for local AI agents that manage…

  • nmapUnleashed Makes Nmap Scanning More Comfortable and Effective

    nmapUnleashed Makes Nmap Scanning More Comfortable and Effective nmapUnleashed emerges as a powerful CLI wrapper enhancing Nmap’s capabilities for penetration testers and network auditors. Released in late January 2026 by developer Sharkeonix, this open-source tool streamlines complex scans while retaining full Nmap compatibility. nmapUnleashed, or “nu,” wraps Nmap to add multithreading, allowing up to customizable…

  • Cybercriminals Use Malicious Cybersquatting Attacks to Distribute Malware and Hijack Data

    Cybercriminals Use Malicious Cybersquatting Attacks to Distribute Malware and Hijack Data Digital squatting has evolved from a simple trademark nuisance into a dangerous cybersecurity threat. In 2025, the World Intellectual Property Organization (WIPO) handled a record-breaking 6,200 domain disputes. This represents a 68% increase since 2020. Security experts warn that criminal networks are now using…

  • Claude Opus 4.6 Released with Improved Cybersecurity, Validating 500+ high-severity Vulnerabilities

    Claude Opus 4.6 Released with Improved Cybersecurity, Validating 500+ high-severity Vulnerabilities Anthropic’s latest AI model autonomously identifies critical flaws in decades-old codebases, raising the stakes for both defenders and attackers Anthropic released Claude Opus 4.6 on February 5, 2026, with dramatically enhanced cybersecurity capabilities that have already identified more than 500 previously unknown high-severity vulnerabilities…

  • Transparent Tribe Hacker Group Attacking India’s Startup Ecosystem

    Transparent Tribe Hacker Group Attacking India’s Startup Ecosystem The threat landscape for India’s technology sector has taken an unexpected turn. A Pakistan-based hacking group called Transparent Tribe has shifted its focus from traditional government targets to the country’s vibrant startup ecosystem, particularly companies working in cybersecurity and intelligence domains. The group, also tracked as APT36,…

  • Bulletproof Hosting Providers Leverage Legitimate ISPsystem to Supply Servers for Cybercriminals

    Bulletproof Hosting Providers Leverage Legitimate ISPsystem to Supply Servers for Cybercriminals In the constantly shifting landscape of online threats, cybercriminals have found a new way to strengthen their attacks by hiding behind legitimate technology. Late in 2025, a series of ransomware incidents revealed that attackers were using virtual machines provisioned through ISPsystem, a popular platform…

  • Dutch Authorities Seized Servers of Windscribe VPN Provider

    Dutch Authorities Seized Servers of Windscribe VPN Provider Dutch authorities seized a Windscribe VPN server located in the Netherlands as part of an undisclosed investigation. The Canadian provider quickly highlighted how its privacy-focused design thwarted any data recovery efforts. Windscribe disclosed the incident via social media, sharing an image of an empty server rack slot…

  • Hackers Leveraging Windows Screensaver to Deploy RMM Tools and Gain Remote Access to Systems

    Hackers Leveraging Windows Screensaver to Deploy RMM Tools and Gain Remote Access to Systems Cybersecurity threats are constantly evolving, and a recent campaign highlights a deceptive new tactic where attackers leverage Windows screensaver (.scr) files to compromise systems. This method allows threat actors to deploy legitimate Remote Monitoring and Management (RMM) tools, granting them persistent…

  • New Epstein Tool Searches LinkedIn Connections Against 3.5 Million Pages Epstein Files

    New Epstein Tool Searches LinkedIn Connections Against 3.5 Million Pages Epstein Files A new open-source Python tool named EpsteIn enables users to check if their LinkedIn connections appear in over 3.5 million pages of Jeffrey Epstein court documents recently released by the U.S. Department of Justice. Developed by Christopher Finke, it runs locally to prioritize…

  • Spam Campaign Distributes Fake PDFs, Installing Remote Monitoring Tools for Persistent Access

    Spam Campaign Distributes Fake PDFs, Installing Remote Monitoring Tools for Persistent Access Security teams have discovered an active spam campaign that uses fake PDF documents to trick users into installing remote monitoring and management (RMM) software. The campaign targets organizations by sending emails containing PDF attachments that appear to be invoices, receipts, or important documents.…

  • F5 Patches Critical Vulnerabilities in BIG-IP, NGINX, and Related Products

    F5 Patches Critical Vulnerabilities in BIG-IP, NGINX, and Related Products F5 released its February 2026 Quarterly Security Notification on February 4, announcing several medium and low-severity CVEs, plus a security exposure affecting BIG-IP, NGINX, and container services. These issues primarily stem from denial-of-service (DoS) risks and configuration weaknesses, potentially disrupting high-traffic environments like web application…

  • APT28 Hackers Exploiting Microsoft Office Vulnerability to Compromise Government Agencies

    APT28 Hackers Exploiting Microsoft Office Vulnerability to Compromise Government Agencies Russian state-sponsored actors known as APT28 have initiated a sophisticated cyber espionage campaign targeting high-value government and military entities across Europe. The primary targets include maritime and transport organizations in nations such as Poland, Ukraine, and Turkey. The attackers are actively exploiting a critical vulnerability…

  • New DesckVB RAT with Multi-stage Infection Chain and Plugin-Based Architecture

    New DesckVB RAT with Multi-stage Infection Chain and Plugin-Based Architecture A sophisticated new threat has surfaced in the wild, identified as the DesckVB RAT version 2.9. This modular Remote Access Trojan, built on the .NET framework, has been observed in active malware campaigns throughout early 2026. Unlike simple backdoors, this threat demonstrates a high level…

  • Threat Actors Hacking NGINX Servers to Redirect Web Traffic to Malicious Servers

    Threat Actors Hacking NGINX Servers to Redirect Web Traffic to Malicious Servers A sophisticated campaign in which threat actors are stealthily compromising NGINX servers to redirect web traffic to malicious destinations. The attackers, previously linked to “React2Shell” exploits, are now targeting NGINX configurations, specifically those using the Baota (BT) management panel, widely used in Asia.…

  • New 3 Step Malvertising Chain Abusing Facebook Paid Ads to Push Tech Support Scam Kit

    New 3 Step Malvertising Chain Abusing Facebook Paid Ads to Push Tech Support Scam Kit A sophisticated new cyber threat has emerged within the digital advertising ecosystem, specifically targeting users through the vast reach of Facebook’s paid advertising platform. Malicious actors are increasingly weaponizing social media ads to bypass traditional security filters and deliver harmful…

  • Attackers Using DNS TXT Records in ClickFix Script to Execute Powershell Commands

    Attackers Using DNS TXT Records in ClickFix Script to Execute Powershell Commands The cybersecurity landscape has darkened with the sophisticated evolution of the KongTuke campaign. Active since mid-2025, this threat actor group has continuously refined its techniques to bypass conventional enterprise security filters. Their primary weapon remains the “ClickFix” strategy, a social engineering vector that…

  • Chrome Vulnerabilities Let Attackers Execute Arbitrary Code and Crash System

    Chrome Vulnerabilities Let Attackers Execute Arbitrary Code and Crash System Google has released a critical security update for the Chrome Stable channel, addressing two high-severity vulnerabilities that expose users to potential arbitrary code execution (ACE) and denial-of-service (DoS) attacks. The update pushes the browser version to 144.0.7559.132/.133 for Windows and macOS, and 144.0.7559.132 for Linux.…

  • Hackers Exploiting React Server Components Vulnerability in the Wild to Deploy Malicious Payloads

    Hackers Exploiting React Server Components Vulnerability in the Wild to Deploy Malicious Payloads Two months following the disclosure of CVE-2025-55182, exploitation activity targeting React Server Components has evolved from broad scanning into consolidated, high-volume attack campaigns. According to telemetry from GreyNoise collected between January 26 and February 2, 2026, threat actors are actively leveraging this…

  • GlassWorm Infiltrated VSX Extensions with More than 22,000 Downloads to Attack Developers

    GlassWorm Infiltrated VSX Extensions with More than 22,000 Downloads to Attack Developers GlassWorm has emerged as a serious threat to developers using the Open VSX Registry, where popular VSX extensions were silently turned into delivery vehicles for malware. Threat actors compromised a trusted publisher account and pushed poisoned updates that looked like routine releases but…

  • Infostealer Campaigns Expand to macOS as Attackers Abuse Python and Trusted Platforms

    Infostealer Campaigns Expand to macOS as Attackers Abuse Python and Trusted Platforms Infostealer campaigns that once focused mainly on Windows are now expanding aggressively to macOS, using Python and trusted platforms to reach new victims. Recent attacks show a clear shift: threat actors are abusing online ads, fake apps, and familiar tools to quietly steal…

  • Beware of Fake Dropbox Phishing Attack that Harvest Login Credentials

    Beware of Fake Dropbox Phishing Attack that Harvest Login Credentials Cybercriminals are launching a dangerous phishing campaign that tricks users into giving away their login credentials by impersonating Dropbox. This attack uses a multi-stage approach to bypass email security checks and content scanners. The threat actors exploit trusted cloud platforms and harmless-looking PDF files to…

  • Malicious App on The Google Play with 50K+ Downloads Deploy Anatsa Banking Malware

    Malicious App on The Google Play with 50K+ Downloads Deploy Anatsa Banking Malware A dangerous banking malware called Anatsa has been discovered spreading through the Google Play Store, reaching more than fifty thousand downloads before detection. The malicious application was cleverly hidden as a document reader, making it appear harmless to unsuspecting users searching for…

  • Hikvision Wireless Access Points Vulnerability Enables Malicious Command Execution

    Hikvision Wireless Access Points Vulnerability Enables Malicious Command Execution A critical authenticated command execution vulnerability has been disclosed affecting multiple Hikvision Wireless Access Point (WAP) models. The flaw, tracked as CVE-2026-0709, stems from insufficient input validation in device firmware, potentially allowing attackers with valid credentials to execute arbitrary commands on affected systems. The vulnerability carries…

  • OpenClaw AI Agent Skills Abused by Threat Actors to Deliver Malware

    OpenClaw AI Agent Skills Abused by Threat Actors to Deliver Malware Hundreds of malicious skills designed to deliver trojans, infostealers, and backdoors disguised as legitimate automation tools. VirusTotal has uncovered a significant malware distribution campaign targeting OpenClaw, a rapidly growing personal AI agent ecosystem. OpenClaw, previously known as Clawdbot and briefly as Moltbot, is a…

  • Notepad++ Hack Detailed Along With the IoCs and Custom Malware Used

    Notepad++ Hack Detailed Along With the IoCs and Custom Malware Used A sophisticated espionage campaign attributed to the Chinese Advanced Persistent Threat (APT) group Lotus Blossom (also known as Billbug). The threat actors compromised the infrastructure hosting the popular text editor Notepad++ to deliver a custom, previously undocumented backdoor named “Chrysalis”. This campaign, discovered by…

  • DynoWiper Data-Wiping Malware Attacking Energy Companies to Destroy Data

    DynoWiper Data-Wiping Malware Attacking Energy Companies to Destroy Data A dangerous new data-wiping malware known as DynoWiper has emerged, targeting energy companies in Poland with destructive attacks designed to permanently erase critical data. The malware surfaced in December 2025 when security researchers detected its deployment at a Polish energy firm. Unlike typical ransomware that encrypts…

  • Google Uncovered Significant Expansion in ShinyHunters Threat Activity with New Tactics

    Google Uncovered Significant Expansion in ShinyHunters Threat Activity with New Tactics The ShinyHunters threat group has expanded its extortion operations with sophisticated attack methods targeting cloud-based systems across multiple organizations. These cybercriminals use voice phishing and fake credential harvesting websites to steal login information from employees. Once they gain access, they extract sensitive data from…

  • Windows 11 New Security Feature Denies Unauthorized Access to System Files

    Windows 11 New Security Feature Denies Unauthorized Access to System Files Microsoft has introduced a significant security control in the latest Windows 11 preview update designed to restrict unauthorized interaction with critical system files. Released as part of the January 2026 non-security preview (KB5074105), this enhancement specifically targets the Storage settings menu, a sensitive area…

  • 1-Click Clawdbot Vulnerability Enable Malicious Remote Code Execution Attacks

    1-Click Clawdbot Vulnerability Enable Malicious Remote Code Execution Attacks A critical vulnerability in OpenClaw, the open-source AI personal assistant trusted by over 100,000 developers, has been discovered and weaponized into a devastating one-click remote code execution exploit. Security researchers at depthfirst General Security Intelligence uncovered a logic flaw that, when combined with other vulnerabilities, could…

  • State-Sponsored Actors Hijacked Notepad++ Update Servers to Redirect Users to Malicious Servers

    State-Sponsored Actors Hijacked Notepad++ Update Servers to Redirect Users to Malicious Servers The developer of Notepad++ has confirmed that a targeted attack by a likely Chinese state-sponsored threat actor compromised the project’s former shared hosting infrastructure between June and December 2025. The breach allowed attackers to intercept and selectively redirect update traffic to malicious servers,…

  • Critical Johnson Controls Products Vulnerabilities Enables Remote SQL Injection Attacks

    Critical Johnson Controls Products Vulnerabilities Enables Remote SQL Injection Attacks A critical advisory addressing a severe SQL injection vulnerability affecting multiple Johnson Controls industrial control system products. The vulnerability, tracked as CVE-2025-26385, carries a maximum CVSS v3 severity score of 10.0, indicating the highest level of risk to affected infrastructure. The flaw stems from improper…

  • Moltbook AI Vulnerability Exposes Email Addresses, Login Tokens, and API Keys

    Moltbook AI Vulnerability Exposes Email Addresses, Login Tokens, and API Keys A critical vulnerability in Moltbook, the nascent AI agent social network launched late January 2026 by Octane AI’s Matt Schlicht, exposes email addresses, login tokens, and API keys for its registered entities amid hype over 1.5 million “users.” Researchers revealed an exposed database misconfiguration…

  • Essential E-Signature Solutions for Cybersecurity in 2026

    Essential E-Signature Solutions for Cybersecurity in 2026 E-signatures are now part of your security posture. In 2026, most organizations sign contracts, approvals, onboarding packets, and financial documents electronically. That increases exposure to account takeover, identity theft, document tampering, and audit gaps especially when teams rely on weak methods like a pasted signature image or email-only…

  • AutoPentestX – Automated Penetration Testing Toolkit Designed for Linux systems

    AutoPentestX – Automated Penetration Testing Toolkit Designed for Linux systems AutoPentestX, an open-source automated penetration testing toolkit for Linux systems, enables comprehensive security assessments from a single command. Developed by Gowtham Darkseid and released in November 2025, it generates professional PDF reports while emphasizing safe, non-destructive testing. AutoPentestX targets Kali Linux, Ubuntu, and Debian-based distributions,…

  • SCADA Vulnerability Triggers DoS, Potentially Disrupting Industrial Operations

    SCADA Vulnerability Triggers DoS, Potentially Disrupting Industrial Operations A medium-severity vulnerability in the Iconics Suite SCADA system that could allow attackers to trigger denial-of-service conditions on critical industrial control systems. The flaw, tracked as CVE-2025-0921, affects supervisory control and data acquisition infrastructure widely deployed across automotive, energy, and manufacturing sectors. Vulnerability Overview CVE-2025-0921 stems from…

  • Metasploit Releases 7 New Exploit Modules covering FreePBX, Cacti and SmarterMail

    Metasploit Releases 7 New Exploit Modules covering FreePBX, Cacti and SmarterMail The latest update to the Metasploit Framework this week provides a significant enhancement for penetration testers and red teamers, introducing seven new exploit modules targeting commonly used enterprise software. The highlight of this release is a sophisticated trio of modules directed at FreePBX, alongside…

  • UAT-8099 Targets Vulnerable IIS Servers Using Web Shells, PowerShell, and Region-Customized BadIIS

    UAT-8099 Targets Vulnerable IIS Servers Using Web Shells, PowerShell, and Region-Customized BadIIS A new wave of targeted attacks has emerged against Internet Information Services (IIS) servers across Asia, with threat actors deploying sophisticated malware designed to compromise vulnerable systems. The campaign, active from late 2025 through early 2026, focuses primarily on victims in Thailand and…

  • 175,000 Exposed Ollama Hosts Enable Code Execution and External System Access

    175,000 Exposed Ollama Hosts Enable Code Execution and External System Access A significant security discovery reveals that approximately 175,000 Ollama servers remain publicly accessible across the internet, creating a serious risk for widespread code execution and unauthorized access to external systems. Ollama, an open-source framework designed to run artificial intelligence models locally, has become unexpectedly…

  • TAMECAT PowerShell-Based Backdoor Exfiltrates Login Credentials from Microsoft Edge and Chrome

    TAMECAT PowerShell-Based Backdoor Exfiltrates Login Credentials from Microsoft Edge and Chrome A sophisticated PowerShell-based malware named TAMECAT has emerged as a critical threat to enterprise security, targeting login credentials stored in Microsoft Edge and Chrome browsers. This malware operates as part of espionage campaigns conducted by APT42, an Iranian state-sponsored cyber-espionage group that has been…

  • Critical Ivanti Endpoint Manager 0-day RCE Vulnerabilities Actively Exploited in Attacks

    Critical Ivanti Endpoint Manager 0-day RCE Vulnerabilities Actively Exploited in Attacks Two critical code-injection vulnerabilities have been disclosed in the Endpoint Manager Mobile (EPMM) platform, which are currently being actively exploited in real-world attacks. The security flaws, tracked as CVE-2026-1281 and CVE-2026-1340, allow unauthenticated attackers to execute arbitrary code remotely on vulnerable systems. The vulnerabilities…

  • Education-Themed Malicious Domains Linked to Bulletproof Hosting Infrastructure Exposed

    Education-Themed Malicious Domains Linked to Bulletproof Hosting Infrastructure Exposed Security researchers have uncovered a sophisticated traffic distribution network leveraging deceptive education-themed domains to deliver malware and phishing attacks. The operation, tracked under infrastructure indicators pointing to TOXICSNAKE, uses legitimate-looking university and educational institution branding to deceive users into visiting malicious websites. This tactic exploits the…

  • Microsoft Teams New Feature to Flag Suspicious One-to-One Calls

    Microsoft Teams New Feature to Flag Suspicious One-to-One Calls A new security feature is being added to Teams to help organizations detect and stop voice-based scams and phishing attacks. The new “Report a Call” button will allow users to flag suspicious one-to-one calls directly from their Teams call history. As use of Microsoft Teams calling…

  • Hackers Weaponized Open VSX Extension with Sophisticated Malware After Reaching 5060+ Downloads

    Hackers Weaponized Open VSX Extension with Sophisticated Malware After Reaching 5060+ Downloads A dangerous malware campaign has infiltrated the Open VSX extension marketplace, compromising over 5,000 developer workstations through a fake Angular Language Service extension. The malicious package disguised itself as legitimate development tooling, bundling authentic Angular and TypeScript components alongside encrypted malware code that…

  • 3,280,081 Fortinet Devices Online With Exposed Web Properties Under Risk

    3,280,081 Fortinet Devices Online With Exposed Web Properties Under Risk Over 3,280,081 Fortinet Devices Were exposed, with web properties running vulnerable Fortinet devices affected by CVE-2026-24858, a severe authentication-bypass flaw actively exploited in the wild. The vulnerability, rated 9.4 on the CVSS scale, affects multiple Fortinet product lines, including FortiOS, FortiManager, FortiAnalyzer, FortiProxy, and FortiWeb. Critical…

  • eScan Antivirus Update Server Hacked to Push Malicious Update packages

    eScan Antivirus Update Server Hacked to Push Malicious Update packages A critical supply chain compromise affecting MicroWorld Technologies’ eScan antivirus product, wherein threat actors successfully hijacked the vendor’s legitimate update infrastructure to distribute malware. Discovered on January 20, 2026, by Morphisec, the attack utilized a trojanized update package to deploy multi-stage malware across enterprise and…

  • Microsoft Exchange Online to Deprecate SMTP AUTH Basic Authentication for Tenants

    Microsoft Exchange Online to Deprecate SMTP AUTH Basic Authentication for Tenants Microsoft is preparing a major security shift for cloud email customers as Exchange Online moves toward deprecating SMTP AUTH Basic Authentication for all tenants. The change targets one of the oldest and weakest ways to sign in to email systems, where usernames and passwords…

  • Critical Solarwinds Web Vulnerability Allows Remote Code Execution and Security Bypass

    Critical Solarwinds Web Vulnerability Allows Remote Code Execution and Security Bypass Multiple critical vulnerabilities in SolarWinds Web Help Desk (WHD), culminating in unauthenticated remote code execution (RCE) via Java deserialization in CVE-2025-40551, were uncovered by Horizon3.ai researchers. These flaws chain static credentials, security bypasses, and deserialization weaknesses, affecting versions prior to 2026.1. SolarWinds WHD, an…

  • Attackers Targeting Canadian Citizens by Exploiting Their Reliance on Digital Services

    Attackers Targeting Canadian Citizens by Exploiting Their Reliance on Digital Services Attackers are increasingly targeting Canadian citizens by abusing their heavy dependence on online government and commercial services. From paying traffic fines and renewing licenses to tracking parcels and booking flights, people now expect these tasks to be quick and digital. Threat actors are taking…

  • Swarmer Tool Evading EDR With a Stealthy Modification on Windows Registry for Persistence

    Swarmer Tool Evading EDR With a Stealthy Modification on Windows Registry for Persistence Praetorian Inc. has publicly released Swarmer, a tool enabling low-privilege attackers to achieve stealthy Windows registry persistence by sidestepping Endpoint Detection and Response (EDR) monitoring. Deployed operationally since February 2025, Swarmer exploits mandatory user profiles and the obscure Offline Registry API to…

  • WhatsApp Denies Lawsuit Claim and Confirms Messages are Device-encrypted and Private

    WhatsApp Denies Lawsuit Claim and Confirms Messages are Device-encrypted and Private WhatsApp has strongly denied a new class-action lawsuit accusing Meta of secretly accessing users’ end-to-end encrypted messages, labeling the claims as false and baseless. The messaging giant reiterated that messages remain private through device-based encryption via the open-source Signal protocol. A class-action complaint filed…