Tag: cyber-security-news
-
Chinese National Jailed to 46 Months for Laundering Millions of Dollars Stolen from American Investors
Chinese National Jailed to 46 Months for Laundering Millions of Dollars Stolen from American Investors A Chinese national named Jingliang Su has been sentenced to 46 months in prison for his involvement in a major cryptocurrency fraud scheme targeting American investors. On January 27, 2026, federal courts ordered Su to serve his sentence and pay…
-
Fake CAPTCHA Attack Leverages Microsoft Application Virtualization (App-V) to Deploy Malware
Fake CAPTCHA Attack Leverages Microsoft Application Virtualization (App-V) to Deploy Malware A newly discovered campaign demonstrates a sophisticated approach to delivering information-stealing malware through a combination of social engineering and legitimate Windows components. The attack begins with a deceptive CAPTCHA prompt that tricks users into executing commands manually through the Windows Run dialog, presenting the…
-
WhatsApp New Strict Account Settings Option to Protect Your Account from Hackers
WhatsApp New Strict Account Settings Option to Protect Your Account from Hackers WhatsApp has introduced Strict Account Settings, a lockdown-style security feature designed to protect users from highly sophisticated cyber-attacks. The new privacy feature is specifically tailored for individuals who may be targets of advanced threats, including journalists, activists, and public figures who face elevated…
-
HoneyMyte Hacker Group Updates CoolClient Malware to Deploy Browser Login Data Stealer
HoneyMyte Hacker Group Updates CoolClient Malware to Deploy Browser Login Data Stealer The HoneyMyte threat group, also known as Mustang Panda or Bronze President, continues to pose a significant risk to government organizations across Asia and Europe. Recent security research has revealed that this advanced hacker collective is actively upgrading its digital arsenal with enhanced…
-
Caminho Loader-as-a-Service Using Steganography to Conceal .NET Payloads within Image Files
Caminho Loader-as-a-Service Using Steganography to Conceal .NET Payloads within Image Files Caminho Loader is a new Loader-as-a-Service threat that blends steganography, fileless execution, and cloud abuse to quietly deliver malware across several regions. First seen in March 2025 and believed to originate from Brazil, this service hides .NET payloads inside harmless-looking image files hosted on…
-
Critical Vulnerability in Python PLY Library Enables Remote Code Execution – PoC Published
Critical Vulnerability in Python PLY Library Enables Remote Code Execution – PoC Published A critical vulnerability has been identified in the PyPI-distributed version of PLY (Python Lex-Yacc) 3.11, allowing arbitrary code execution through unsafe deserialization of untrusted pickle files. The vulnerability, assigned CVE-2025-56005, affects the undocumented picklefile parameter in the yacc() function, which remains absent from official documentation despite…
-
APT Hackers Attacking Indian Government Using GOGITTER Tool and GITSHELLPAD Malware
APT Hackers Attacking Indian Government Using GOGITTER Tool and GITSHELLPAD Malware Advanced persistent threat actors operating from Pakistan have launched coordinated attacks against Indian government organizations using newly discovered tools and malware designed to bypass security defenses. The campaign, identified as Gopher Strike, emerged in September 2025 and represents a significant escalation in targeted cyber…
-
Multiple Vulnerabilities in React Server Components Enable DoS Attacks
Multiple Vulnerabilities in React Server Components Enable DoS Attacks Multiple critical security vulnerabilities have recently been disclosed in React Server Components, enabling threat actors to launch Denial-of-Service (DoS) attacks against vulnerable servers. The flaws, tracked as CVE-2026-23864 with a CVSS score of 7.5, are due to incomplete patches from previous security fixes and require immediate…
-
China-Aligned APTs Use PeckBirdy C&C Framework in Multi-Vector Attacks, Exploiting Stolen Certificates
China-Aligned APTs Use PeckBirdy C&C Framework in Multi-Vector Attacks, Exploiting Stolen Certificates Since 2023, a dangerous malware framework called PeckBirdy has emerged as a primary weapon used by Chinese-aligned hacking groups. This JavaScript-based tool serves as a command-and-control platform designed to work across multiple system environments, giving attackers remarkable flexibility in how they deploy their…
-
Apache Hadoop Vulnerability Exposes Systems Potential Crashes or Data Corruption
Apache Hadoop Vulnerability Exposes Systems Potential Crashes or Data Corruption A moderate-severity vulnerability in the Hadoop Distributed File System (HDFS) native client could allow attackers to trigger system crashes or corrupt critical data through maliciously crafted URI inputs. The vulnerability, tracked as CVE-2025-27821, affects Apache Hadoop versions 3.2.0 through 3.4.1. Stems from an out-of-bounds write…
-
Microsoft Releases Out-of-Band Update KB5078127 to Fix Windows 11 File System and Outlook Freezes
Microsoft Releases Out-of-Band Update KB5078127 to Fix Windows 11 File System and Outlook Freezes An out-of-band (OOB) cumulative update, KB5078127, to address critical file system compatibility issues affecting Windows 11 users. The update resolves widespread problems introduced by the January 13, 2026, security update (KB5074109) that caused application freezes and cloud storage failures across multiple…
-
New Phishing Attack Leverages Vercel Hosting Platform to Deliver a Remote Access Tool
New Phishing Attack Leverages Vercel Hosting Platform to Deliver a Remote Access Tool A sophisticated phishing campaign active between November 2025 and January 2026 has been exploiting Vercel’s legitimate hosting platform to distribute remote access tools to unsuspecting victims. The attack chain combines social engineering with trusted domain exploitation, making it particularly effective at bypassing…
-
New Instagram Vulnerability Exposes Private Posts to Anyone
New Instagram Vulnerability Exposes Private Posts to Anyone A critical server-side vulnerability in Instagram’s infrastructure allowed unauthenticated attackers to access private photos and captions without a login or follower relationship, according to a disclosure released this week by security researcher Jatin Banga. The vulnerability, which was reportedly patched silently by Meta in October 2025, relied…
-
Sandworm APT Group Targeting Poland’s Power Grid with DynoWiper Malware
Sandworm APT Group Targeting Poland’s Power Grid with DynoWiper Malware Late December 2025 brought alarming news to Poland as its energy infrastructure became the target of what security experts describe as the country’s largest cyberattack in years. The Russian-aligned Sandworm group, known for orchestrating some of the most damaging attacks on critical infrastructure, emerged as…
-
Hackers Use ‘rn’ Typo Trick to Impersonate Microsoft and Marriott in New Phishing Attack
Hackers Use ‘rn’ Typo Trick to Impersonate Microsoft and Marriott in New Phishing Attack A sophisticated “homoglyph” phishing campaign targeting customers of Marriott International and Microsoft. Attackers are registering domains that replace the letter “m” with the combination “rn” (r + n), creating fake websites that look nearly identical to the real ones. This technique,…
-
CISA Warns of Critical VMware vCenter RCE Vulnerability Exploited in Attacks
CISA Warns of Critical VMware vCenter RCE Vulnerability Exploited in Attacks The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability affecting Broadcom’s VMware vCenter Server to its Known Exploited Vulnerabilities (KEV) catalog. This addition confirms that active exploitation of CVE-2024-37079 has been detected in the wild, posing a significant risk to enterprise…
-
Microsoft Teams to Share your Location With Your Employer Soon Based on Wi-Fi Network
Microsoft Teams to Share your Location With Your Employer Soon Based on Wi-Fi Network Microsoft is preparing to deploy a significant, potentially controversial update to Microsoft Teams that automatically detects and displays a user’s physical work location based on the Wi-Fi network they connect to. According to the latest update on the Microsoft 365 Roadmap…
-
Threat Actors Leverage SharePoint Services in Sophisticated AiTM Phishing Campaign
Threat Actors Leverage SharePoint Services in Sophisticated AiTM Phishing Campaign Microsoft Defender researchers have exposed a sophisticated adversary-in-the-middle (AiTM) phishing campaign targeting energy sector organizations through SharePoint file-sharing abuse. The multi-stage attack compromised multiple user accounts and evolved into widespread business email compromise (BEC) operations across several organisations. Initial Compromise Through Trusted Vendor The attack…
-
Microsoft Launches Open-Source WinApp CLI to Streamline Windows App Development
Microsoft Launches Open-Source WinApp CLI to Streamline Windows App Development Microsoft has unveiled the public preview of WinApp CLI (winapp), a new open-source command-line tool designed to simplify Windows app development for developers using diverse frameworks outside Visual Studio or MSBuild. Hosted on GitHub, the tool targets web devs with Electron, C++ experts on CMake,…
-
Microsoft Shares BitLocker Keys with FBI to Unlock Encrypted Laptops in Guam Fraud Investigation
Microsoft Shares BitLocker Keys with FBI to Unlock Encrypted Laptops in Guam Fraud Investigation Microsoft gave U.S. federal agents the digital keys needed to unlock three encrypted laptops linked to a massive COVID unemployment scam in Guam. This case shows how cloud-stored encryption keys can help law enforcement, but also raises big privacy worries for…
-
Hackers Exploiting telnetd Vulnerability for Root Access – Public PoC Released
Hackers Exploiting telnetd Vulnerability for Root Access – Public PoC Released Active exploitation of a critical authentication bypass vulnerability in the GNU InetUtils telnetd server (CVE-2026-24061) has been observed in the wild, allowing unauthenticated attackers to gain root access to Linux systems. The vulnerability, which affects GNU InetUtils versions 1.9.3 through 2.7, enables remote code…
-
20,000 WordPress Sites Affected by Backdoor Vulnerability Allowing Malicious Admin User Creation
20,000 WordPress Sites Affected by Backdoor Vulnerability Allowing Malicious Admin User Creation A critical backdoor vulnerability has been discovered in the LA-Studio Element Kit for Elementor, a popular WordPress plugin used by more than 20,000 active sites. This security flaw allows attackers to create administrator accounts without any authentication, putting thousands of websites at risk…
-
North Korean Hackers Adopted AI to Generate Malware Attacking Developers and Engineering Teams
North Korean Hackers Adopted AI to Generate Malware Attacking Developers and Engineering Teams North Korea–aligned hackers have launched a new campaign that turns artificial intelligence into a weapon against software teams. Using AI-written PowerShell code, the group known as KONNI is delivering a stealthy backdoor that blends real project content with malicious scripts. This operation…
-
Nike Allegedly Hacked by WorldLeaks Ransomware Group
Nike Allegedly Hacked by WorldLeaks Ransomware Group Athletic footwear and apparel manufacturer Nike has become the latest victim of WorldLeaks, a financially motivated ransomware group known for data extortion attacks. The group announced the breach on its darknet leak site on January 22, claiming responsibility for the incident and threatening to release stolen data on…
-
New Windows 11 KB5074109 Update Breaks Systems – Microsoft Asks Users to Remove Update
New Windows 11 KB5074109 Update Breaks Systems – Microsoft Asks Users to Remove Update Microsoft’s January 2026 Windows 11 security update KB5074109 has triggered multiple system stability issues, including lockups and black screens, prompting users to uninstall it. Reports highlight graphics regressions and app failures affecting both consumer and enterprise setups. KB5074109 targets Windows 11…
-
ZAP Releases OWASP PenTest Kit Browser Extension for Application Security Testing
ZAP Releases OWASP PenTest Kit Browser Extension for Application Security Testing The Zed Attack Proxy (ZAP) team has released the OWASP PTK add-on, version 0.2.0 alpha, integrating the OWASP Penetration Testing Kit (PTK) browser extension directly into ZAP-launched browsers. This streamlines application security testing by embedding DAST, IAST, SAST, SCA, and specialized tools like JWT…
-
New Osiris Ransomware Using Wide Range of Living off the Land and Dual-use Tools in Attacks
New Osiris Ransomware Using Wide Range of Living off the Land and Dual-use Tools in Attacks A newly discovered ransomware family called Osiris launched attacks against a major food service company in Southeast Asia during November 2025. Security researchers have identified this threat as a completely new malware variant with no connection to an older…
-
New ClearFake Campaign Leveraging Proxy Execution to Run PowerShell Commands via Trusted Window Feature
New ClearFake Campaign Leveraging Proxy Execution to Run PowerShell Commands via Trusted Window Feature ClearFake has entered a new and more dangerous phase, turning a familiar fake CAPTCHA scam into a highly evasive malware delivery chain. Across hundreds of hacked websites, visitors now see what looks like a routine verification challenge, but behind the scenes…
-
Cisco Unified Communications 0-day RCE Vulnerability Exploited in the Wild to Gain Root Access
Cisco Unified Communications 0-day RCE Vulnerability Exploited in the Wild to Gain Root Access Cisco has disclosed a critical zero-day remote code execution (RCE) vulnerability, CVE-2026-20045, actively exploited in the wild. Affecting key Unified Communications products, this flaw allows unauthenticated attackers to run arbitrary commands on the underlying OS, potentially gaining root access. The Cisco…
-
Fortinet SSO Vulnerability Actively Exploited to Hack Firewalls and Gain Admin Access
Fortinet SSO Vulnerability Actively Exploited to Hack Firewalls and Gain Admin Access A critical vulnerability in Fortinet’s Single Sign-On (SSO) feature for FortiGate firewalls, tracked as CVE-2025-59718, is under active exploitation. Attackers are leveraging it to create unauthorized local admin accounts, granting full administrative access to internet-exposed devices. Multiple users have reported identical attack patterns,…
-
Hackers Weaponized 2,500+ Security Tools to Terminate Endpoint Protection Before Deploying Ransomware
Hackers Weaponized 2,500+ Security Tools to Terminate Endpoint Protection Before Deploying Ransomware A large-scale campaign is turning a trusted Windows security driver into a weapon that shuts down protection tools before ransomware and remote access malware are dropped. The attacks abuse truesight.sys, a kernel driver from Adlice Software’s RogueKiller antivirus, and use more than 2,500 validly…
-
New AI Malware Era Begins as Advanced VoidLink Malware Emerges as the First Fully AI-Driven Threat Framework
New AI Malware Era Begins as Advanced VoidLink Malware Emerges as the First Fully AI-Driven Threat Framework The cybersecurity landscape has entered a dangerous new chapter with the discovery of VoidLink, the first documented advanced malware framework built almost entirely by artificial intelligence. Unlike earlier attempts where inexperienced hackers used AI to create basic malicious…
-
Google Chrome 144 Update Patches High-Severity V8 Vulnerability
Google Chrome 144 Update Patches High-Severity V8 Vulnerability A new Stable-channel release of Chrome version 144 addresses a high-severity vulnerability in the V8 JavaScript engine. The update, version 144.0.7559.96/.97 for Windows and Mac and 144.0.7559.96 for Linux, began rolling out on January 21, 2026, and will reach all users over the coming days and weeks.…
-
Critical GNU InetUtils Vulnerability Allows Unauthenticated Root Access Via “-f root”
Critical GNU InetUtils Vulnerability Allows Unauthenticated Root Access Via “-f root” A critical remote authentication bypass vulnerability has been disclosed in GNU InetUtils affecting the telnetd server component. The flaw, reported by a security researcher on January 19, 2026, allows unauthenticated attackers to gain root access by exploiting improper input sanitization in the telnetd authentication…
-
Attackers Leverages LinkedIn to Deliver Remote Access Trojan Targeting Corporate Environments
Attackers Leverages LinkedIn to Deliver Remote Access Trojan Targeting Corporate Environments A sophisticated phishing campaign is actively exploiting LinkedIn’s trusted social media platform to distribute a dangerous remote access trojan to corporate employees. Attackers are leveraging the professional credibility of LinkedIn to craft convincing messages that appear legitimate, making employees more likely to download and…
-
Critical Oracle WebLogic Server Proxy Vulnerability Lets Attackers Compromise the Server
Critical Oracle WebLogic Server Proxy Vulnerability Lets Attackers Compromise the Server Oracle has disclosed a severe security vulnerability affecting its Fusion Middleware suite, specifically targeting the Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in. Assigned CVE-2026-21962, this flaw carries the maximum severity rating and poses an immediate threat to enterprise environments that use…
-
Azure Private Endpoint Deployments Exposes Azure Resources to DoS Attack
Azure Private Endpoint Deployments Exposes Azure Resources to DoS Attack A critical architectural flaw in Microsoft Azure’s Private Endpoint implementation that enables denial-of-service (DoS) attacks against production Azure resources. The vulnerability affects over 5% of Azure storage accounts, exposing organizations to service disruptions across Key Vault, CosmosDB, Azure Container Registry, Function Apps, and OpenAI accounts.…
-
Attackers Abuse Discord to Deliver Clipboard Hijacker That Steals Wallet Addresses on Paste
Attackers Abuse Discord to Deliver Clipboard Hijacker That Steals Wallet Addresses on Paste A new clipboard hijacker is quietly draining cryptocurrency from gamers and streamers by abusing trust inside Discord communities. The campaign centers on a malicious Windows program shared as a supposed streaming or security tool. Once installed, it silently watches the user’s clipboard,…
-
Python-based Malware SolyxImmortal Leverages Discord to Silently Harvest Sensitive Data
Python-based Malware SolyxImmortal Leverages Discord to Silently Harvest Sensitive Data SolyxImmortal represents a notable advancement in information-stealing malware targeting Windows systems. This Python-based threat combines multiple data theft capabilities into a single, persistent implant designed for long-term surveillance rather than destructive activity. The malware operates silently in the background, collecting credentials, documents, keystrokes, and screenshots…
-
Critical AVEVA Software Vulnerabilities Enables Remote Code Execution Under System Privileges
Critical AVEVA Software Vulnerabilities Enables Remote Code Execution Under System Privileges Seven vulnerabilities were disclosed in Process Optimization (formerly ROMeo) 2024.1 and earlier on January 13, 2026, including a critical flaw enabling unauthenticated SYSTEM-level remote code execution. The most severe vulnerability enables unauthenticated attackers to achieve remote code execution under system privileges, posing an immediate…
-
WhisperPair Attack Allows Hijacking of Laptops, Earbuds Without User Consent – Millions Affected
WhisperPair Attack Allows Hijacking of Laptops, Earbuds Without User Consent – Millions Affected A critical vulnerability in Google’s Fast Pair protocol that allows attackers to hijack Bluetooth audio accessories and track users without their knowledge or consent. Security researchers from KU Leuven have uncovered a vulnerability, tracked as CVE-2025-36911 and dubbed WhisperPair, that affects hundreds…
-
Threat Actors Leverage Google Ads to Weaponize PDF Editor with TamperedChef
Threat Actors Leverage Google Ads to Weaponize PDF Editor with TamperedChef A malvertising campaign identified in September 2025 has brought a significant threat to Windows users worldwide. Attackers created fake PDF editing applications and promoted them through Google Ads to distribute a dangerous information-stealing malware called TamperedChef. The malware targets users searching for appliance manuals…
-
Windows SMB Client Vulnerability Enables Attacker to Own Active Directory
Windows SMB Client Vulnerability Enables Attacker to Own Active Directory A critical vulnerability in Windows SMB client authentication that enables attackers to compromise Active Directory environments through NTLM reflection exploitation. Classified as an improper access control vulnerability, this vulnerability allows authorized attackers to escalate privileges via carefully orchestrated authentication relay attacks over network connections. Seven…
-
CrashFix – Hackers Using Malicious Extensions to Display Fake Browser Warnings
CrashFix – Hackers Using Malicious Extensions to Display Fake Browser Warnings Cybersecurity researchers have discovered a sophisticated malware campaign using an unusual but effective tactic: deliberately crashing users’ browsers. The threat, named CrashFix, operates through a malicious Chrome extension disguised as the legitimate ad blocker NexShield. When users search for privacy tools online, malicious advertisements…
-
Redmi Buds Vulnerability Allow Attackers Access Call Data and Trigger Firmware Crashes
Redmi Buds Vulnerability Allow Attackers Access Call Data and Trigger Firmware Crashes Security researchers have uncovered significant vulnerabilities in the firmware of Xiaomi’s popular Redmi Buds series, specifically affecting models ranging from the Redmi Buds 3 Pro up to the latest Redmi Buds 6 Pro. The discovery highlights critical flaws in the Bluetooth implementation of…
-
17 New Malicious Chrome GhostPoster Extensions with 840,000+ Installs Steals User Data
17 New Malicious Chrome GhostPoster Extensions with 840,000+ Installs Steals User Data Cybercriminals have distributed 17 malicious browser extensions across Chrome, Firefox, and Edge platforms, collectively downloading over 840,000 times and compromising user security for years. The GhostPoster campaign, which emerged as early as 2020, used deceptive extension names like “Google Translate in Right Click,”…
-
New Kerberos Relay Attack Uses DNS CNAME to Bypass Mitigations – PoC Released
New Kerberos Relay Attack Uses DNS CNAME to Bypass Mitigations – PoC Released A critical flaw in Windows Kerberos authentication that significantly expands the attack surface for credential relay attacks in Active Directory environments. By abusing how Windows clients handle DNS CNAME responses during Kerberos service ticket requests, attackers can coerce systems into requesting tickets…
-
Mandiant Releases Rainbow Tables Enabling NTLMv1 Admin Password Hacking
Mandiant Releases Rainbow Tables Enabling NTLMv1 Admin Password Hacking Google-owned Mandiant has publicly released a comprehensive dataset of Net-NTLMv1 rainbow tables, marking a significant escalation in demonstrating the security risks of legacy authentication protocols. The release underscores an urgent message: organizations must immediately migrate away from Net-NTLMv1, a deprecated protocol that has been cryptographically broken…
-
Let’s Encrypt has made 6-day IP-based TLS certificates Generally Available
Let’s Encrypt has made 6-day IP-based TLS certificates Generally Available Let’s Encrypt, a key provider of free TLS certificates, has rolled out short-lived and IP address-based certificates for general use. These new options became available starting in early 2026, addressing long-standing issues in certificate security. Short-lived certificates last just 160 hours, about six and a…
-
Argus – Python-powered Toolkit for Information Gathering and Reconnaissance
Argus – Python-powered Toolkit for Information Gathering and Reconnaissance Argus is a comprehensive Python-based toolkit designed for reconnaissance tasks in cybersecurity. The developers recently released version 2.0, expanding it to include 135 modules. This tool consolidates network analysis, web app scanning, and threat intelligence into one interface. Users access modules through an interactive CLI that…
-
Google’s Vertex AI Vulnerability Enables Low-Privileged Users to Gain Service Agent Roles
Google’s Vertex AI Vulnerability Enables Low-Privileged Users to Gain Service Agent Roles Google’s Vertex AI contains default configurations that allow low-privileged users to escalate privileges by hijacking Service Agent roles. XM Cyber researchers identified two attack vectors in the Vertex AI Agent Engine and Ray on Vertex AI, which Google deemed “working as intended. Service…
-
Researchers Gain Access to StealC Malware Command-and-Control Systems
Researchers Gain Access to StealC Malware Command-and-Control Systems Security researchers successfully exploited vulnerabilities in the StealC malware infrastructure, gaining access to operator control panels and exposing a threat actor’s identity through their own stolen session cookies. The breach highlights critical security failures in criminal operations built around credential theft. XSS Vulnerability Exposes StealC Operators StealC,…
-
Windows 11 PCs Fail to Shut Down After January Security Update
Windows 11 PCs Fail to Shut Down After January Security Update Microsoft’s January 13, 2026, security update for Windows 11 has triggered a frustrating bug: affected PCs refuse to shut down or hibernate, instead restarting. The issue is caused by KB5073455, which targets OS Build 22621.6491 on Windows 11 version 23H2. It was first reported…
-
Cloudflare Acquired Open-source Web Framework Astro to Supercharge Development
Cloudflare Acquired Open-source Web Framework Astro to Supercharge Development Cloudflare has acquired the team behind Astro, the popular open-source web framework for building fast, content-driven sites. Announced on January 16, 2026, the deal brings The Astro Technology Company’s full-time employees under Cloudflare’s umbrella to accelerate Astro’s development. Cloudflare positions the move as a commitment to…
-
Cisco 0-Day RCE Secure Email Gateway Vulnerability Exploited in the Wild
Cisco 0-Day RCE Secure Email Gateway Vulnerability Exploited in the Wild Cisco has confirmed active exploitation of a critical zero-day remote code execution vulnerability in its Secure Email Gateway and Secure Email and Web Manager appliances. Tracked as CVE-2025-20393, the flaw allows unauthenticated attackers to execute arbitrary root-level commands via crafted HTTP requests to the…
-
Google Rolls Out Long-Awaited @gmail.com Email Change Feature for Users
Google Rolls Out Long-Awaited @gmail.com Email Change Feature for Users Google is gradually rolling out the ability to change the @gmail.com email address associated with a Google Account to a new @gmail.com address. This feature, previously unavailable, addresses a common pain point for users who regret their original username choice but didn’t want to abandon years…
-
Go 1.25.6 and 1.24.12 Patch Critical Vulnerabilities Lead to DoS and Memory Exhaustion Risks
Go 1.25.6 and 1.24.12 Patch Critical Vulnerabilities Lead to DoS and Memory Exhaustion Risks The Go programming language team has rolled out emergency point releases, Go 1.25.6 and 1.24.12, to address six high-impact security flaws. These updates fix denial-of-service (DoS) vectors, arbitrary code execution risks, and TLS mishandlings that could expose developers to remote attacks.…
-
New AWS Console Supply Chain Attack Lets Attackers Hijack AWS GitHub Repositories
New AWS Console Supply Chain Attack Lets Attackers Hijack AWS GitHub Repositories A critical misconfiguration in AWS CodeBuild enabled unauthenticated attackers to seize control of key AWS-owned GitHub repositories, including the widely used AWS JavaScript SDK powering the AWS Console itself. This supply chain vulnerability threatened platform-wide compromise, potentially injecting malicious code into applications and…
-
Hackers Abusing Legitimate Cloud and CDN Platforms to Host Phishing Kits
Hackers Abusing Legitimate Cloud and CDN Platforms to Host Phishing Kits Threat actors are increasingly using trusted cloud and content delivery network platforms to host phishing kits, creating major detection challenges for security teams. Unlike traditional phishing campaigns that rely on newly registered suspicious domains, these attacks use legitimate infrastructure from providers like Google, Microsoft…
-
Promptware Kill Chain – Five-Step Kill Chain Model for Analyzing Cyberthreats
Promptware Kill Chain – Five-Step Kill Chain Model for Analyzing Cyberthreats Large language models have become deeply integrated into everyday business operations, from customer service chatbots to autonomous agents managing calendars, executing code, and handling financial transactions. This rapid expansion has created a critical security blind spot. Researchers have identified that attacks targeting these systems…
-
Fortinet FortiSIEM Vulnerability CVE-2025-64155 Actively Exploited in Attacks
Fortinet FortiSIEM Vulnerability CVE-2025-64155 Actively Exploited in Attacks Fortinet FortiSIEM vulnerability CVE-2025-64155 is under active exploitation, as confirmed by Defused through their honeypot deployments. This critical OS command injection flaw enables unauthenticated remote code execution, posing severe risks to enterprise security monitoring systems. CVE-2025-64155 stems from improper neutralization of special elements in OS commands within…
-
Chinese Threat Actors Hosted 18,000 Active C2 Servers Across 48 Hosting Providers
Chinese Threat Actors Hosted 18,000 Active C2 Servers Across 48 Hosting Providers Threat actors linked to Chinese hosting infrastructure have established a massive network of over 18,000 active command-and-control servers across 48 different hosting providers in recent months. This widespread abuse highlights a serious issue in how malicious infrastructure can hide within trusted networks and…
-
Palo Alto Networks Firewall Vulnerability Allows Attacker to Trigger DoS Attacks
Palo Alto Networks Firewall Vulnerability Allows Attacker to Trigger DoS Attacks Palo Alto Networks has patched a critical denial-of-service vulnerability in its PAN-OS firewall software, tracked as CVE-2026-0227, which lets unauthenticated attackers disrupt GlobalProtect gateways and portals. The flaw carries a CVSS v4.0 base score of 7.7 (HIGH severity), stemming from improper checks for unusual conditions…
-
Microsoft SQL Server Vulnerability Allows Attackers to Elevate Privileges over a Network
Microsoft SQL Server Vulnerability Allows Attackers to Elevate Privileges over a Network Microsoft released security updates on January 13, 2026, addressing a critical elevation of privilege vulnerability in SQL Server that enables authorized attackers to bypass authentication controls and gain elevated system privileges remotely. Tracked as CVE-2026-20803, the vulnerability stems from missing authentication mechanisms for…
-
Stealthy CastleLoader Malware Attacking US Government Agencies and Critical Infrastructure
Stealthy CastleLoader Malware Attacking US Government Agencies and Critical Infrastructure A sophisticated malware loader known as CastleLoader has emerged as a critical threat to US government agencies and critical infrastructure organizations. First identified in early 2025, this stealthy malware has been used as the initial access point in coordinated attacks targeting multiple sectors including federal…
-
Researchers Breakdown DragonForce Ransomware Along with Decryptor for ESXi and Windows Systems
Researchers Breakdown DragonForce Ransomware Along with Decryptor for ESXi and Windows Systems DragonForce is the latest ransomware brand to move from noisy forum posts to full RaaS operations, targeting both Windows and VMware ESXi environments. First seen in December 2023 on BreachForums, the group advertises stolen data and uses a dark web blog to pressure…
-
New Magecart Attack Steals Customers Credit Cards from Website Checkout Pages
New Magecart Attack Steals Customers Credit Cards from Website Checkout Pages A sophisticated web-skimming campaign targeting online shoppers has emerged with renewed intensity in 2026, compromising e-commerce websites and extracting sensitive payment information during checkout processes. The attack, identified as part of the broader Magecart family of threats, represents an evolving challenge to online retail…
-
Top 12 Best Open Source Intelligence Tools (OSINT Tools) for Penetration Testing 2026
Top 12 Best Open Source Intelligence Tools (OSINT Tools) for Penetration Testing 2026 We all know very well that getting or gathering any information by using various tools becomes really easy. In this article, we have discussed various OSINT tools, as if we search over the internet, then there will be many different pages to…
-
Top 11 Best DNS Filtering Solutions – 2026
Top 11 Best DNS Filtering Solutions – 2026 Before diving into DNS filtering solutions, it’s essential to understand the concept of DNS filtering and its significance in cybersecurity. In today’s digital landscape, cybersecurity has become a critical priority as cyberattacks are increasingly prevalent worldwide. Organizations must protect not only their infrastructure but also their employees…
-
10 Most Dangerous Injection Attacks in 2026
10 Most Dangerous Injection Attacks in 2026 Since you are in the industry, especially in the network and admin team, you need to know a few vulnerabilities, such as injection attacks to stay alert from them. Each attack or vulnerability has a different method, most importantly injection-type attacks. To understand that and to take a…
-
5 Best Bug Bounty Platforms for White-Hat Hackers – 2026
5 Best Bug Bounty Platforms for White-Hat Hackers – 2026 Bug bounty platforms form a cornerstone of modern cybersecurity, empowering organizations to crowdsource vulnerability discovery from skilled external researchers. These programs reward private individuals for uncovering flaws in web apps, vulnerability management systems, and more through effective crowdsourced testing. White-hat hackers can flex their expertise…
-
New Angular Vulnerability Enables an Attacker to Execute Malicious Payload
New Angular Vulnerability Enables an Attacker to Execute Malicious Payload A critical Cross-Site Scripting (XSS) vulnerability has been discovered in Angular’s Template Compiler, affecting multiple versions of both @angular/compiler and @angular/core packages. Tracked as CVE-2026-22610, this vulnerability allows attackers to bypass Angular’s built-in security protections and execute arbitrary JavaScript code within victim browsers. The Vulnerability…
-
Hackers Leverage Browser-in-the-browser Tactic to Trick Facebook Users and Steal Logins
Hackers Leverage Browser-in-the-browser Tactic to Trick Facebook Users and Steal Logins Facebook users are increasingly becoming targets of a sophisticated phishing technique that bypasses conventional security measures. With over three billion active users on the platform, Facebook represents an attractive target for attackers seeking to compromise accounts and harvest personal credentials. The primary objective of…
-
100,000+ n8n Instances Exposed to Internet Vulnerable to RCE Attacks
100,000+ n8n Instances Exposed to Internet Vulnerable to RCE Attacks A critical vulnerability affecting the popular n8n workflow automation platform has put over 100,000 internet-exposed instances at severe risk. Security researchers from The Shadowserver Foundation discovered that 105,753 unique n8n instances are vulnerable to remote code execution (RCE) attacks through CVE-2026-21858. n8n is a workflow…
-
AsyncRAT Leveraging Cloudflare’s Free-Tier Services to Mask Malicious Activities and Detection
AsyncRAT Leveraging Cloudflare’s Free-Tier Services to Mask Malicious Activities and Detection A recent AsyncRAT campaign is using Cloudflare’s free tier services and TryCloudflare tunnels to hide remote access activity inside normal looking cloud traffic. In these attacks, threat actors send phishing emails that link to a Dropbox hosted ZIP archive named to look like an…
-
Multiple Hikvision Vulnerabilities Let Attackers Cause Device Malfunction Using Crafted Packets
Multiple Hikvision Vulnerabilities Let Attackers Cause Device Malfunction Using Crafted Packets Hikvision, a leading provider of surveillance and access control systems, faces serious security risks from two newly disclosed stack overflow vulnerabilities. These flaws, tracked as CVE-2025-66176 and CVE-2025-66177, allow attackers on the same local area network (LAN) to trigger device malfunctions by sending specially…
-
ValleyRAT_S2 Attacking Organizations to Deploy Stealthy Malware and Extract Financial Details
ValleyRAT_S2 Attacking Organizations to Deploy Stealthy Malware and Extract Financial Details A new wave of attacks is using the ValleyRAT_S2 malware to quietly break into organizations, stay hidden for long periods, and steal sensitive financial information. ValleyRAT_S2 is the second-stage payload of the ValleyRAT family and is written in C++. Once inside a network, it…
-
Beware of Weaponized Employee Performance Reports that Deploys Guloader Malware
Beware of Weaponized Employee Performance Reports that Deploys Guloader Malware Cybersecurity threats continue to evolve with attackers using more creative social engineering techniques to target organizations. A recent threat has emerged involving the Guloader malware, which is being disguised as employee performance reports to trick users into downloading and executing malicious files. This sophisticated attack…
-
Critical InputPlumber Vulnerabilities Allows UI Input Injection and Denial-of-Service
Critical InputPlumber Vulnerabilities Allows UI Input Injection and Denial-of-Service Critical vulnerabilities in InputPlumber, a Linux input device utility used in SteamOS, could allow attackers to inject UI inputs and cause denial-of-service conditions on affected systems. The SUSE researchers tracked as CVE-2025-66005 and CVE-2025-14338, which affect InputPlumber versions before v0.69.0 and stem from inadequate D-Bus authorization mechanisms. InputPlumber combines…
-
Everest Hacking Group Allegedly Claims Breach of Nissan Motors
Everest Hacking Group Allegedly Claims Breach of Nissan Motors Everest hacking group has allegedly claimed a major breach of Nissan Motor Co., Ltd., raising fresh concerns about data security at large automotive manufacturers. According to early reports, the cybercrime group says it exfiltrated around 900 GB of sensitive data from the Japanese carmaker, a volume…
-
Critical Zlib Vulnerability Let Attackers Trigger Buffer Overflow by Invoking untgz
Critical Zlib Vulnerability Let Attackers Trigger Buffer Overflow by Invoking untgz A severe global buffer overflow vulnerability has been discovered in the zlib untgz utility version 1.3.1.2. Allowing attackers to corrupt memory and potentially execute malicious code through specially crafted command-line input. The security flaw resides in the TGZfname() function of the untgz utility, where…
-
Leveraging OSINT Tools for Enhanced Cybersecurity Threat Intelligence
Leveraging OSINT Tools for Enhanced Cybersecurity Threat Intelligence Open Source Intelligence (OSINT) has become a cornerstone of cybersecurity threat intelligence. In today’s digital landscape, organizations face a constant barrage of cyber threats, ranging from data breaches and phishing attacks to sophisticated nation-state operations. To stay ahead of these threats, cybersecurity teams must leverage every available…
-
Data Breach at Texas Gas Station Operator Exposes Info of 377,000+ Customers
Data Breach at Texas Gas Station Operator Exposes Info of 377,000+ Customers A cybersecurity incident at Gulshan Management Services, Inc., a gas station operator based in Sugar Land, Texas, has compromised the personal information of over 377,000 customers. The breach, discovered on September 27, 2025, exposed sensitive data over 10 days from September 17 to…
-
New MacSync Stealer Uses Signed macOS App to Evade Gatekeeper and Steal Data
New MacSync Stealer Uses Signed macOS App to Evade Gatekeeper and Steal Data Cybersecurity researchers have discovered a new variant of the MacSync malware targeting macOS users. Unlike previous versions that relied on complex ClickFix techniques, this iteration masquerades as a legitimately signed, notarised Apple application, thereby bypassing macOS Gatekeeper security and stealing sensitive data.…
-
Instagram Data Leak Exposes Sensitive Info of 17.5M Accounts
Instagram Data Leak Exposes Sensitive Info of 17.5M Accounts A significant security breach has compromised approximately 17.5 million Instagram user accounts, exposing sensitive personal information that is now circulating on the dark web. The incident reported earlier this week by cybersecurity firm Malwarebytes raised urgent concerns about user privacy and account security. What Data Was…
-
Europol‑Backed Operation Leads to 34 Arrests in Black Axe Crime Network Bust
Europol‑Backed Operation Leads to 34 Arrests in Black Axe Crime Network Bust The Spanish National Police, working alongside the Bavarian State Criminal Police Office and Europol, has conducted a major operation targeting the international Black Axe criminal organisation. The coordinated action resulted in 34 arrests and dealt a significant blow to the network’s operations across…
-
Phishing Campaign Uses Maduro Arrest Story to Deliver Backdoor Malware
Phishing Campaign Uses Maduro Arrest Story to Deliver Backdoor Malware Cybercriminals are leveraging the recent arrest of Venezuelan President Nicolás Maduro to distribute sophisticated backdoor malware. The threat actors exploited news surrounding Maduro’s arrest on January 3, 2025, demonstrating how geopolitical events continue to serve as effective lures for malicious campaigns. The attack likely begins…
-
BreachForums Hack: Hackers Expose All User Records from Popular Dark Web Forum
BreachForums Hack: Hackers Expose All User Records from Popular Dark Web Forum In a dramatic turn for the cybercrime underworld, a mysterious hacker known as “James” has leaked the complete user database of BreachForums, a notorious Dark Web forum serving as a hub for stolen data trading and hacking discussions. The breach, announced on January…
-
SmarterTools SmarterMail Vulnerability Enables Remote Code Execution Attack – PoC Released
SmarterTools SmarterMail Vulnerability Enables Remote Code Execution Attack – PoC Released A critical pre-authentication remote code execution vulnerability, identified as CVE-2025-52691, has been discovered in SmarterTools’ SmarterMail solution. The flaw received a maximum CVSS score of 10.0, indicating its severe nature and potential impact on affected systems. SmarterTools describes SmarterMail as “a secure, all-in-one business…
-
Hackers Actively Exploiting AI Deployments – 91,000+ Attack Sessions Observed
Hackers Actively Exploiting AI Deployments – 91,000+ Attack Sessions Observed Security researchers have identified over 91,000 attack sessions targeting AI infrastructure between October 2025 and January 2026, exposing systematic campaigns against large language model deployments. GreyNoise’s Ollama honeypot infrastructure captured 91,403 attack sessions during this period, revealing two distinct threat campaigns. The findings corroborate and…
-
New Ghost Tapped Attack Uses Your Android Device to Drain Your Bank Account
New Ghost Tapped Attack Uses Your Android Device to Drain Your Bank Account Chinese threat actors have developed a dangerous new way to steal money directly from bank accounts using specially crafted Android applications. Known as Ghost Tapped, these malicious apps exploit Near Field Communication (NFC) technology, the same wireless technology that powers contactless payments.…
-
Cisco Small Business Switches Face Global DNS Crash Outage
Cisco Small Business Switches Face Global DNS Crash Outage Network administrators worldwide reported widespread crashes in Cisco small business switches on January 8, 2026, triggered by fatal errors in the DNS client service. Devices entered reboot loops every few minutes, disrupting operations until DNS configurations were removed. The issue surfaced around 2 AM UTC, affecting…
-
What tools help reduce fraud or friendly fraud for online businesses?
What tools help reduce fraud or friendly fraud for online businesses? A customer buys. You ship. Everyone seems happy. Then, a few weeks later, you get a chargeback. Or you notice the same card being tried again and again in a few seconds, failing at first and then working. It can be a sign someone…
-
GitLab Patches Multiple Vulnerabilities that Enables Arbitrary Code Execution
GitLab Patches Multiple Vulnerabilities that Enables Arbitrary Code Execution GitLab has released emergency security patches for multiple versions of its platform, addressing eight vulnerabilities that could enable arbitrary code execution and unauthorized access in self-managed installations. The updated versions 18.7.1, 18.6.3, and 18.5.5 were deployed to GitLab.com on January 7, 2026, with self-hosted customers strongly…
-
Linux Battery Utility Flaw Lets Hackers Bypass Authentication and Tamper System Settings
Linux Battery Utility Flaw Lets Hackers Bypass Authentication and Tamper System Settings A critical security vulnerability has been discovered in TLP, a widely used Linux laptop battery optimization utility, allowing local attackers to bypass authentication controls and manipulate system power settings without authorization. Security researchers from openSUSE identified a severe authentication bypass flaw in the…
-
China Hacked Email Systems Used by US Congressional Staff, New Report
China Hacked Email Systems Used by US Congressional Staff, New Report A sophisticated Chinese hacking group has breached email systems accessed by staffers on critical U.S. House committees, exposing sensitive communications amid escalating cyber tensions between Washington and Beijing. The Financial Times revealed on Wednesday that the intruders, tracked as Salt Typhoon, targeted aides supporting…
-
Top 50 Best Penetration Testing Companies in 2026
Top 50 Best Penetration Testing Companies in 2026 Penetration testing companies serve as vital cybersecurity allies, simulating real-world cyberattacks to expose vulnerabilities in systems, networks, and applications before malicious actors strike. Employing ethical hackers with advanced techniques, they rigorously assess defenses, pinpoint misconfigurations, and evaluate control effectiveness to ensure regulatory compliance and threat resilience. Their…
-
10 Best Web Scanners for Website Security In 2026
10 Best Web Scanners for Website Security In 2026 Securing websites demands top-tier web vulnerability scanners. These powerful tools pinpoint critical flaws like SQL injection, cross-site scripting (XSS), and command injection, keeping your site fortified against attacks. Elite scanners emulate attacker strategies, delivering concrete proof and precise fix instructions. They adeptly navigate contemporary web apps…
-
Crimson Collective Claims to have Disconnected Many Brightspeed Home Internet Users
Crimson Collective Claims to have Disconnected Many Brightspeed Home Internet Users Crimson Collective, an emerging extortion group, claims to have breached U.S. fiber broadband provider Brightspeed, stealing data on over 1 million residential customers and disconnecting many from home internet service. The group posted screenshots on Telegram detailing the alleged compromise and urging Brightspeed employees…
-
Top 10 Best Dynamic Malware Analysis Tools in 2026
Top 10 Best Dynamic Malware Analysis Tools in 2026 Dynamic malware analysis tools execute suspicious binaries in isolated sandboxes to capture runtime behaviors file modifications, network traffic, registry changes, and persistence mechanisms. This top 10 list details each tool’s features, strengths, and limitations to guide your selection. ANY.RUN’s Interactive Sandbox leads with real-time analysis mapped…