Xuts Labs

Intel

Curated cyber intelligence with direct source paths when the local feed carries only an excerpt.

Ask EXO
criticalvulnerabilitysource excerpt

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the privileges of the Java process. Tracked as CVE-2026-16723, the vulnerability carries an Alibaba-assigned CVSS score of 9.0.

vulnerabilitycve
The Hacker News / 2026-07-25T12:52:43+00:00Read Intel
lowadvisorysource excerpt

CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking

For years, phishing campaigns targeting financial institutions followed the same playbook. Victims were tricked into entering usernames and passwords, attackers collected the credentials, and accounts were compromised later when an opportunity arose. That model is changing. Recent investigations into insurance-focused phishing operations reveal a more immediate approach.

tradecraftemail
The Hacker News / 2026-07-25T10:14:21+00:00Read Intel
highransomwaresource excerpt

DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts

The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to build payloads, oversee earnings, and manage various aspects related to victims. Swiss cybersecurity company PRODAFT is tracking the centrally administered RaaS operation under the name Funky Mantis.

ransomware
The Hacker News / 2026-07-25T09:53:41+00:00Read Intel
mediumvulnerabilitysource excerpt

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

Security researcher Yuhang Wu at depthfirst has published a working proof-of-concept (PoC) exploit that executes commands as git on an unpatched self-managed GitLab 18.11.3 server. An ordinary authenticated user triggers it by committing two crafted Jupyter notebooks and requesting their diff.

vulnerabilityexploitation
The Hacker News / 2026-07-25T08:34:15+00:00Read Intel
lowmalwaresource excerpt

BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing platforms in social engineering campaigns designed to deliver malware.

malwaretradecraftemail
The Hacker News / 2026-07-24T15:12:35+00:00Read Intel
lowadvisorysource excerpt

Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine. They codenamed the flaw Certighost. Because Domain Controller accounts carry directory replication rights, the resulting Kerberos credential can retrieve the krbtgt secret through DCSync.

exploitationwindows
The Hacker News / 2026-07-24T14:15:21+00:00Read Intel
lowadvisorysource excerpt

Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack

Slopsquatting, phantom squatting, and HalluSquatting all exploit the same late-binding attack pattern, where AI coding agents trust hallucinated package, repo, or domain names. ActiveState explains how pre-fetch verification and governed dependency management can help stop these attacks before malicious code enters the pipeline.

exploitation
BleepingComputer / 2026-07-24T14:01:11+00:00Read Intel
criticalvulnerabilitysource excerpt

ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link

Cybersecurity researchers have disclosed a critical vulnerability in OpenAI's ChatGPT Workspace Agents that could have allowed a single phishing link to stealthily build, authorize, and deploy an autonomous artificial intelligence (AI) agent inside a victim's organization. The vulnerability has been codenamed AgentForger by Zenity Labs.

vulnerabilitytradecraftemail
The Hacker News / 2026-07-24T11:53:55+00:00Read Intel
criticalvulnerabilitysource excerpt

Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers

A crafted SVG submitted to Bing's image search ran commands as NT AUTHORITY\SYSTEM on Microsoft's production image-processing workers, and as root on the Linux machines in the same fleet. XBOW's testing got the same result on workers across different hosts and network ranges, so the problem sat in Bing's image tier, not on one bad machine.

vulnerabilitycvelinux
The Hacker News / 2026-07-24T11:45:17+00:00Read Intel
lowadvisorysource excerpt

Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do

AI agent security is moving through a familiar maturity curve: adoption, then visibility, and finally, control. But what we've collectively discovered is that enforcing least privilege for AI agents is harder than we ever imagined. This is why there are so many approaches, from prompt filtering to identity-layer access controls.

identity
The Hacker News / 2026-07-24T11:30:00+00:00Read Intel
highadvisorysource excerpt

NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats

Eight security flaws in NodeBB went public on Wednesday, along with the code to exploit them. Aikido Security rates all eight as high severity and says its AI pentest agents found them in a six-hour review of the forum software's source code. Every version before 4.14.0 is affected. NodeBB has fixed them all, and administrators should be on 4.14.2. The simplest one takes a settings change.

exploitation
The Hacker News / 2026-07-24T07:41:06+00:00Read Intel
mediumvulnerabilitysource excerpt

Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say

Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0. All four chains require RESTORE. The Streams chains also need EVAL and XGROUP; the 8.8.0 chain needs EVAL and the bundled RedisBloom module. Redis says the underlying memory flaws may lead to remote code execution.

vulnerabilityexploitation
The Hacker News / 2026-07-24T06:58:27+00:00Read Intel
lowmalwaresource excerpt

New Dolphin X malware uses AI to rank high-value targets

A new Dolphin X remote access trojan claims to use an AI-powered profiling feature to score and rank infected users, helping cybercriminals identify which victims should be targeted first.

malware
BleepingComputer / 2026-07-23T21:20:34+00:00Read Intel
lowvulnerabilitysource excerpt

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra's webmail client. The payload goes after the last 90 days of email, the organization's entire email directory, the password saved in the browser and the codes kept for two-factor recovery. Opening the message was enough to start it.

vulnerabilityemail
The Hacker News / 2026-07-23T18:36:08+00:00Read Intel
criticalvulnerabilitysource excerpt

Don’t swing at everything

Thorsten explores Q2 2026 stats, the artificial buffer zone of 2026, and why smart, prioritized patching is more critical than ever.

vulnerability
Cisco Talos / 2026-07-23T18:00:46+00:00Read Intel
lowvulnerabilitysource excerpt

Russian hackers exploit Zimbra zero-click flaw for email theft

CISA is warning that the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is targeting organizations using Zimbra Collaboration email servers by combining phishing attacks with the exploitation of a now-patched Zimbra vulnerability.

aptvulnerabilityexploitationtradecraftemail
BleepingComputer / 2026-07-23T16:49:27+00:00Read Intel
lowtradecraftsource excerpt

Hackers abuse Notepad++ plugins to stealthily install malware

Ukraine's CERT has uncovered attacks distributing an archive containing the legitimate Notepad++ application and a malicious utility called LunchPoke disguised as a plugin to establish persistence.

malwaretradecraft
BleepingComputer / 2026-07-23T16:32:35+00:00Read Intel
lowotsource excerpt

ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories

Most of this week's trouble came dressed as something useful. A package stole data. A fake extension opened remote access. A safety app became spyware. An image gave hidden orders to an AI agent. Other threats hid in open systems, weak code, and normal network traffic. The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out.

ot
The Hacker News / 2026-07-23T15:02:07+00:00Read Intel
lowaptsource excerpt

Email threat landscape: Q2 2026 trends and insights

In the second quarter of 2026, the continuing effects of Microsoft’s disruption of the Tycoon2FA phishing platform contributed to sustained declines in several major phishing techniques, while threat actors expanded into Teams-based social engineering and employed increasingly automated and multi-stage attack chains.

aptmalwaretradecraftwindowsemail
Microsoft Security Blog / 2026-07-23T15:00:00+00:00Read Intel
lowvulnerabilitysource excerpt

Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files

Cybersecurity researchers have uncovered a sandbox escape vulnerability in Anthropic's Claude Cowork that makes it possible to break out of the confines of a Linux virtual machine (VM) within which the agent runs to read or write files anywhere on the Mac.

vulnerabilitylinux
The Hacker News / 2026-07-23T13:27:59+00:00Read Intel
highransomwaresource excerpt

Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge

The Chaos ransomware group ran its command-and-control through the victim's own browser. Cisco Talos on Thursday detailed msaRAT, the Rust implant behind it, found on a compromised Windows machine ahead of the encryptor. The implant never opens an outbound connection of its own. Its process talks to 127.0.0.1 and nothing else.

ransomwarewindows
The Hacker News / 2026-07-23T13:11:09+00:00Read Intel
lowadvisorysource excerpt

China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks

An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Latin America with a previously undocumented Windows loader called TriBack Loader.

malwarewindowscloud
The Hacker News / 2026-07-23T12:20:23+00:00Read Intel
lowadvisorysource excerpt

How Synthetic Identity Fraud is Coming for Machine Identities

Most people understand identity theft as an attacker stealing a real person's sensitive information and impersonating them. Synthetic identity fraud is much harder to catch. Instead of stealing a real identity, the attacker manufactures a new one, frankensteining together several real data points with fabricated ones to create a person who doesn't exist.

identity
The Hacker News / 2026-07-23T11:45:00+00:00Read Intel
highransomwaresource excerpt

Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel

The Chaos ransomware group uses new malware "msaRAT" that hijacks browsers. The malware doesn't communicate directly with C2 but connects through the browser. It enables arbitrary command execution while hiding the attacker's IP from victims via WebRTC over TURN.

ransomwaremalwarenetwork
Cisco Talos / 2026-07-23T10:00:38+00:00Read Intel
mediumvulnerabilitysource excerpt

Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs

RefluXFS, a Linux kernel flaw disclosed on July 22 and tracked as CVE-2026-64600, lets an unprivileged local user overwrite root-owned files on an XFS filesystem and gain persistent root access. Qualys said default installations of Red Hat Enterprise Linux and its derivatives, Fedora Server, and Amazon Linux can meet the conditions for exploitation.

vulnerabilitycvelinux
The Hacker News / 2026-07-23T08:04:35+00:00Read Intel
mediumvulnerabilitysource excerpt

Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs

Cybersecurity researchers have disclosed details of a new local privilege escalation (LPE) vulnerability in snap-confine that an unprivileged user can trigger to obtain root access and gain complete control of a target environment. The high-severity flaw, tracked as CVE-2026-8933 (CVSS score: 7.8), impacts default installations of Ubuntu Desktop 24.04, 25.10, and 26.04.

vulnerabilitycvelinux
The Hacker News / 2026-07-22T18:07:16+00:00Read Intel
criticalransomwaresource excerpt

Real world incident response: Microsoft and AXA XL strengthen cyber resilience

Our collaboration with AXA XL brings Microsoft Incident Response services directly to cyber insurance policyholders, helping organizations coordinate technical, business, and insurance decisions. The post Real world incident response: Microsoft and AXA XL strengthen cyber resilience appeared first on Microsoft Security Blog .

ransomwaretradecraftwindows
Microsoft Security Blog / 2026-07-22T16:00:00+00:00Read Intel
mediumvulnerabilitysource excerpt

Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data

Cybersecurity researchers have disclosed details of a now-patched vulnerability chain in the Adobe Acrobat Chrome extension that has over 314 million users, which, if exploited, could facilitate a silent hijack of a user's WhatsApp data. The shortcoming has been codenamed HermeticReader by Guardio Labs.

vulnerabilitycve
The Hacker News / 2026-07-22T15:01:21+00:00Read Intel
mediumvulnerabilitysource excerpt

Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication

A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck. The vulnerability in question is CVE-2026-29059 (CVSS score: 7.5), a case of unauthenticated path traversal impacting Windmill's "get_log_file" endpoint ("/api/w/{workspace}/jobs_u/get_log_file/{filename}").

vulnerabilitycveexploitation
The Hacker News / 2026-07-22T12:36:36+00:00Read Intel
lowadvisorysource excerpt

The Fastest Path to AI Adoption Runs Through Security

Security leaders who build fast, visible paths to AI adoption are becoming the most valued partners in their organizations. AI governance done right gives security teams the visibility they need, employees the tools they want, and CISOs the strategic influence they have earned.

The Hacker News / 2026-07-22T11:58:00+00:00Read Intel
lowmalwaresource excerpt

Why Modern SOCs Need Multi-Layered Detections

The cycle is over. For years, cybersecurity followed a familiar pattern: defenses improved, attackers adapted, and the back-and-forth continued. Today, AI-equipped attackers are simply outpacing defenses. Most intrusions now bypass endpoint and malware-based detection entirely.

malwaredetection
The Hacker News / 2026-07-22T11:25:35+00:00Read Intel
lowmalwaresource excerpt

Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library

Cybersecurity researchers have discovered a NuGet typosquat that's unlike the typical information-stealing malware distributed via package registries: usual info-stealers: it's designed to rig live game results on Digitain. The package, named "Newtonsoftt.Json.Net," masquerades as the Newtonsoft.Json library and is a trojanized fork.

malware
The Hacker News / 2026-07-22T06:00:06+00:00Read Intel
lowadvisorysource excerpt

AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code

Hidden text on a web page was enough to make Kiro, AWS's agentic coding IDE, rewrite its own configuration file and run an attacker's code on a developer's machine, with no approval step able to stop it. Intezer, in research with Kodem Security, found that a request as ordinary as asking Kiro to summarize a page could end in remote code execution.

cloud
The Hacker News / 2026-07-21T16:06:12+00:00Read Intel
criticalvulnerabilitysource excerpt

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC

A third SharePoint Server flaw patched by Microsoft as part of its Patch Tuesday update for July 2026 has come under active exploitation, per watchTowr. The vulnerability in question is CVE-2026-50522 (CVSS score: 9.8), a critical deserialization of untrusted data in Microsoft Office SharePoint that could allow an unauthorized attacker to execute code over a network.

vulnerabilitycveexploitation
The Hacker News / 2026-07-21T14:57:51+00:00Read Intel
criticalvulnerabilitysource excerpt

Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities

Zimbra has rolled out fixes to address multiple critical security issues, including a command injection flaw in the Simple Network Management Protocol (SNMP) monitoring component. As many as nine security vulnerabilities have been patched in Zimbra 10.1.20. Topping the list is a command injection vulnerability in the SNMP monitoring component when SNMP notifications are enabled.

vulnerability
The Hacker News / 2026-07-21T13:18:31+00:00Read Intel
lowadvisorysource excerpt

N-day is Becoming N-Hour. Patching Faster Won't Save You.

Every patch is a confession. The moment a vendor ships a security fix, the diff between the old code and the new code tells anyone watching exactly what was broken and where. Turn that diff back into a working exploit, and you can hit every system that hasn't updated yet.

exploitation
The Hacker News / 2026-07-21T11:42:23+00:00Read Intel
criticalvulnerabilitysource excerpt

WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites. The two security flaws, tracked as CVE-2026-63030 and CVE-2026-60137, have been codenamed wp2shell.

vulnerabilitycveexploitation
The Hacker News / 2026-07-21T08:59:30+00:00Read Intel
criticalransomwaresource excerpt

New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack

Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator it first documented earlier this month. The same operator has now been spotted deploying ENCFORGE, a new compiled Go ransomware designed to encrypt model weights, vector indexes, training datasets, and other AI infrastructure files across the host filesystem.

ransomwarevulnerability
The Hacker News / 2026-07-21T07:34:32+00:00Read Intel
criticalvulnerabilitysource excerpt

Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution

Threat actors are now exploiting a recently disclosed critical security flaw impacting ServiceNow AI Platform, according to Defused Cyber. In a post shared on X, the threat intelligence firm said it's observing in-the-wild exploitation of CVE-2026-6875 (CVSS score: 9.5), a sandbox escape vulnerability that could allow an unauthenticated user to run arbitrary code.

vulnerabilitycve
The Hacker News / 2026-07-21T06:29:26+00:00Read Intel
mediumvulnerabilitysource excerpt

'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover

Barely three days after disclosure, attackers are widely chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of the largest attack surfaces on the Internet.

vulnerabilitycveexploitation
Dark Reading / 2026-07-20T21:38:18+00:00Read Intel
mediumvulnerability

WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)

Last week, Searchlight Cyber released details about a vulnerability they are calling "wp2shell". The vulnerability was initially announced without a CVE number. But now has been assigned CVE-2026-63030. Many WordPress plugin vulnerabilities are never assigned CVE numbers. But wp2shell is different.

vulnerabilitycve
SANS ISC / 2026-07-20T18:41:24+00:00Read Intel
lowadvisorysource excerpt

Attackers Combo Up Evasion Tactics for BEC Phishing

"The TFF Trap" uses fileless techniques and loaders with low detection rates to deploy various RATs and stealers, including Agent Tesla, Remcos, XWorm, and Best Private Logger.

tradecraftdetectionemail
Dark Reading / 2026-07-20T18:30:22+00:00Read Intel
lowmalwaresource excerpt

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers to deliver a malware family known as SmartLoader as part of an ongoing campaign codenamed FakeGit.

malware
The Hacker News / 2026-07-20T18:23:03+00:00Read Intel
lowmalwaresource excerpt

Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign

A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against Windows users in Mexico, delivering an infostealer through a fake government ID-lookup site over WebDAV.

malwaretradecraftwindowsemail
The Hacker News / 2026-07-20T17:29:50+00:00Read Intel
highvulnerabilitysource excerpt

⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More

A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools. The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery. Some bugs were new. Others were already being used before defenders had time to patch.

malwarevulnerability
The Hacker News / 2026-07-20T13:32:26+00:00Read Intel
mediumvulnerabilitysource excerpt

New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction

Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how the archiver processes XZ chunked data, and Trend Micro's Zero Day Initiative (ZDI) detailed it on July 15. A fix shipped on June 25 in 7-Zip 26.02.

vulnerabilitycve
The Hacker News / 2026-07-20T09:10:56+00:00Read Intel
mediumvulnerabilitysource excerpt

Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy

A technical analysis of three chained zero-day vulnerabilities in Siemens ROX II OT switches that allow privilege escalation and persistent root access. The post Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy appeared first on Unit 42 .

vulnerabilityot
Unit 42 / 2026-07-17T10:00:24+00:00Read Intel
lowaptsource excerpt

ACR Stealer: Two observed intrusion chains amid increased threat activity

From late April 2026 to mid-June 2026, Microsoft Defender Experts observed increased ACR Stealer activity across customer environments. These campaigns are successfully using ClickFix lures to steal browser credentials, authentication tokens, and sensitive documents from enterprise environments.

aptmalwaretradecraftdetectionwindowscloud
Microsoft Security Blog / 2026-07-16T23:12:02+00:00Read Intel
criticalvulnerabilitysource excerpt

Begun, the Patch Wars have

Long foretold, the Great Patching has begun and it’s a doozy. Buckle in as Joe takes you through the story.

vulnerability
Cisco Talos / 2026-07-16T18:00:50+00:00Read Intel
criticaladvisorysource excerpt

Least privilege for AI agents: Identity, access, and tool binding

As AI agents become more autonomous, strong identity, access, and auditing controls are critical to keeping them secure. The post Least privilege for AI agents: Identity, access, and tool binding appeared first on Microsoft Security Blog .

vulnerabilitydetectionidentityemail
Microsoft Security Blog / 2026-07-16T16:00:00+00:00Read Intel
hightradecraftsource excerpt

Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery

Threat actors compromised AsyncAPI packages and weaponized trusted CI/CD workflows to distribute malware through npm. This analysis breaks down the attack chain, payload delivery, and recommended defenses. The post Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery appeared first on Microsoft Security Blog .

malwareexploitationtradecraftwindowscloudidentity
Microsoft Security Blog / 2026-07-16T01:36:21+00:00Read Intel
highransomwaresource excerpt

Identity Attacks Overtake Exploits as Top Ransomware Cause

Email attacks overtook exploits as the top ransomware root cause last year. Multifactor authentication (MFA) was deployed in 97% of credential-based attacks but failed to prevent compromise.

ransomwareidentityemail
Dark Reading / 2026-07-15T20:16:13+00:00Read Intel
lowadvisorysource excerpt

Turning threat intelligence into decisive action with Defender Experts

Security teams have never had more visibility, yet rarely have they felt more uncertain. Signal pours in from endpoints, identities, cloud workloads, and a sprawling mix of third-party tools. The post Turning threat intelligence into decisive action with Defender Experts appeared first on Microsoft Security Blog .

windowscloudidentity
Microsoft Security Blog / 2026-07-15T16:00:35+00:00Read Intel
lowtradecraftsource excerpt

OkoBot: new sophisticated malware framework targets cryptocurrency users

Kaspersky GReAT experts dissect the new OkoBot campaign targeting cryptocurrency users. This complex framework employs TookPS, exfiltrates seed phrases, monitors Chromium-based browsers, and installs various malware strains, including the Rilide stealer.

malwaretradecraftwindows
Securelist / 2026-07-15T10:00:26+00:00Read Intel
lowaptsource excerpt

The serpent’s tongue: Luring the Python out of its den

This blog examines the full lifecycle of a Python package, from hosting on repositories such as PyPI or custom web servers, through source and wheel distribution formats, to the final installation into virtual or system-wide Python environments.

aptmalwaretradecraft
Cisco Talos / 2026-07-14T10:00:06+00:00Read Intel
lowaptsource excerpt

Defending SaaS-based applications against ShinyHunters OAuth abuse

Microsoft Threat Intelligence identified threat actor activity with overlapping tradecraft commonly associated with ShinyHunters, including voice phishing (vishing), supply-chain compromise, and misconfigured guest access targeting SaaS-based applications. The post Defending SaaS-based applications against ShinyHunters OAuth abuse appeared first on Microsoft Security Blog .

aptmalwarevulnerabilitytradecraftdetectionwindows
Microsoft Security Blog / 2026-07-13T22:02:41+00:00Read Intel
hightradecraftsource excerpt

Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID

Microsoft Entra ID makes passkeys the default sign-in experience and introduces a new model for SMS and voice authentication. Read about how to prepare. The post Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID appeared first on Microsoft Security Blog .

vulnerabilitytradecraftidentityemail
Microsoft Security Blog / 2026-07-13T17:00:00+00:00Read Intel
lowadvisorysource excerpt

Turning the Tables on Email Scammers With 'ScamBuster'

An open source, AI-driven system adopts victim personas to engage with phishing attackers, allowing organizations and law enforcement to gather relevant data on cybercriminal operations.

tradecraftemail
Dark Reading / 2026-07-13T13:00:00+00:00Read Intel
highransomwaresource excerpt

No Manners Here: The Ruthless Rise of The Gentlemen Ransomware

Unit 42 explores The Gentlemen ransomware operations, revealing the affiliate model driving its rapid growth. Learn more here. The post No Manners Here: The Ruthless Rise of The Gentlemen Ransomware appeared first on Unit 42 .

ransomware
Unit 42 / 2026-07-10T22:00:39+00:00Read Intel
lowadvisorysource excerpt

Securing our future: July 2026 progress report on Microsoft’s Secure Future Initiative

Microsoft’s latest Secure Future Initiative report outlines progress on secure foundations, AI-powered defense, and future-ready cybersecurity. The post Securing our future: July 2026 progress report on Microsoft’s Secure Future Initiative appeared first on Microsoft Security Blog .

exploitationtradecraftcloudidentityemail
Microsoft Security Blog / 2026-07-10T16:00:00+00:00Read Intel
mediumvulnerabilitysource excerpt

WolfSSL, GeoVision, VTK vulnerabilities

Cisco Talos’ Vulnerability Discovery & Research team recently disclosed three vulnerabilities in WolfSSF, fourteen in GeoVision, and one vulnerability in VTK-DICOM.

vulnerabilitycvedetection
Cisco Talos / 2026-07-09T18:52:29+00:00Read Intel
lowadvisorysource excerpt

Winning 54% of the time

With Wimbledon's help, Hazel argues against the popular myth that "Attackers only need to be right once, but defenders need to be right 100% of the time."

Cisco Talos / 2026-07-09T18:00:06+00:00Read Intel
lowadvisorysource excerpt

Catan and Mouse

What do board games and cybersecurity have in common? Pattern recognition. Strategy. Adaptation. In this week’s Threat Source Bill explores why curiosity may be a defender’s most valuable skill.

windowsidentity
Cisco Talos / 2026-07-02T18:00:34+00:00Read Intel
lowtradecraftsource excerpt

ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365

Talos has identified "ARToken," a phishing-as-a-service platform that targets Microsoft 365. The ARToken panel exposes 80+ API endpoints for device code phishing, Primary Refresh Token persistence, email access, BEC operations, and SharePoint exfiltration.

tradecraftidentityemail
Cisco Talos / 2026-07-01T10:00:38+00:00Read Intel
highvulnerabilitysource excerpt

New DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned Packets

DirtyClone is a new Linux kernel privilege escalation in the DirtyFrag family. JFrog Security Research published a working exploit walkthrough for the flaw on June 25, the first public demonstration for this variant. Tracked as CVE-2026-43503 (CVSS 8.8), it lets a local user corrupt file-backed memory through a cloned network packet and gain root.

vulnerabilitycveexploitationlinux
The Hacker News / 2026-06-26T11:51:35+00:00Read Intel
lowaptsource excerpt

Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks

The Russian state-sponsored threat actor known as Turla has been attributed to a previously undocumented .NET backdoor called STOCKSTAY that has been deployed against government and military organizations in Ukraine, and entities that have an interest in Italian foreign policy.

aptmalwarewindows
The Hacker News / 2026-06-26T07:15:46+00:00Read Intel
criticalmalwaresource excerpt

CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure

Government entities and critical infrastructure were targeted for espionage in SE Asia by attackers using a hybrid toolkit, including custom TinyRCT backdoor. The post CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure appeared first on Unit 42 .

malware
Unit 42 / 2026-06-25T22:00:52+00:00Read Intel
lowadvisorysource excerpt

Order-tracking app Shop abused to push callback phishing attacks

Threat actors are increasingly abusing Shop, the order-tracking app from Shopify, by adding fake purchase receipts in users' order histories to trick them into providing sensitive data or installing remote access software.

tradecraftemail
BleepingComputer / 2026-06-25T19:45:48+00:00Read Intel
lowtradecraftsource excerpt

Beyond IOCs: AI-enabled threat intelligence

In this week’s newsletter, Martin considers how AI will help threat intelligence by creating an easily queryable data source of intelligence reports.

malwaretradecraftwindows
Cisco Talos / 2026-06-25T18:00:26+00:00Read Intel
criticalvulnerabilitysource excerpt

Microsoft a Leader in The Forrester Wave™ for Endpoint Management Platforms

Microsoft named a Leader in the Forrester Wave™: Endpoint Management Platforms, Q2 2026, with the highest scores in the current offering and strategy categories. The post Microsoft a Leader in The Forrester Wave™ for Endpoint Management Platforms appeared first on Microsoft Security Blog .

vulnerabilitywindowscloudidentity
Microsoft Security Blog / 2026-06-25T16:00:00+00:00Read Intel
lowadvisorysource excerpt

The Four Elevations of Effective Fraud Prevention

Fraudsters don't attack just one transaction. They target accounts, platforms, and entire ecosystems. IPQS explains the four elevations of fraud prevention and why broader visibility improves fraud detection.

detection
BleepingComputer / 2026-06-25T14:01:11+00:00Read Intel
lowadvisorysource excerpt

Webinar: Why account takeovers remain one of the hardest threats to stop

Account takeover attacks continue to challenge security teams because attackers often operate through legitimate accounts and trusted services. This webinar explores how behavioral AI can help organizations identify compromised accounts faster and automate response workflows.

BleepingComputer / 2026-06-25T12:12:20+00:00Read Intel
lowtradecraftsource excerpt

Introduction to COM usage by Windows threats

Component Object Model (COM) is a fundamental Windows technology used by legitimate applications for object activation, inter-process communication, automation and language-independent component reuse. Those same qualities make it useful to threat actors.

malwaretradecraftwindows
Cisco Talos / 2026-06-25T10:00:26+00:00Read Intel
lowmalwaresource excerpt

New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis

A previously undocumented Rust-based macOS implant and information stealer has been found to embed a prompt injection payload designed to trick a malware analyst's artificial intelligence (AI) tools and trick it into aborting or refusing an analysis of the artifact. The malware has been codenamed Gaslight owing to this deceptive behavior.

malware
The Hacker News / 2026-06-25T09:23:03+00:00Read Intel
criticaladvisorysource excerpt

CNAPP evolution: How Microsoft aligns with leading cloud risk management platforms

Learn how CNAPP platforms are helping organizations prioritize exploitable risks, reduce exposure, and operationalize security across the application lifecycle. The post CNAPP evolution: How Microsoft aligns with leading cloud risk management platforms appeared first on Microsoft Security Blog .

exploitationwindowscloudidentity
Microsoft Security Blog / 2026-06-24T18:00:00+00:00Read Intel
criticalvulnerabilitysource excerpt

CISA Warns Critical Lantronix EDS5000 Flaw Is Being Actively Exploited

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation of a critical security flaw impacting Lantronix EDS5000 Series devices, urging Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by June 26, 2026.

vulnerabilitycve
The Hacker News / 2026-06-24T17:19:18+00:00Read Intel
lowadvisorysource excerpt

Securing the service desk: Why social engineering attacks keep succeeding

Service desks have become a favored target for attackers seeking password resets, MFA changes, and access to corporate accounts. Specops Software breaks down how service desk social engineering attacks work and how organizations can defend against them.

identity
BleepingComputer / 2026-06-24T14:02:12+00:00Read Intel
highransomwaresource excerpt

StealC and Amadey: Breaking down infostealers and the cybercrime services that deliver them

On June 24, 2026, Microsoft’s Digital Crimes Unit (DCU) facilitated the takedown, suspension, and blocking of domains that formed the backbone of the StealC and Amadey infrastructure. This blog is a technical breakdown of StealC and Amadey. The post StealC and Amadey: Breaking down infostealers and the cybercrime services that deliver them appeared first on Microsoft Security Blog .

ransomwaremalwarewindowsidentitynetworkemail
Microsoft Security Blog / 2026-06-24T12:30:00+00:00Read Intel
lowmalware

Linux Process Name Masquerading, (Wed, Jun 24th)

In a previous diary, I talked about stack strings&&#x23&#x3b;x26&#x3b;&#x23&#x3b;x5b&#x3b;1&&#x23&#x3b;x26&#x3b;&#x23&#x3b;x5d&#x3b; with a practical example of them.

malwaretradecraftlinux
SANS ISC / 2026-06-24T06:29:03+00:00Read Intel
lowadvisorysource excerpt

Webinar: Why email security teams are drowning in alerts

Phishing, BEC, and account takeover attacks continue to overwhelm security teams with alerts and investigations. This webinar explores how behavioral AI can help automate detection and response workflows, reducing alert fatigue and improving operational efficiency.

tradecraftdetectionemail
BleepingComputer / 2026-06-23T12:12:20+00:00Read Intel
lowadvisorysource excerpt

JaredFromSubway MEV bot hacked in $15 million crypto theft

The JaredFromSubway Ethereum MEV (Maximal Extractable Value) bot suffered a $15 million loss after an attacker manipulated the opportunity-detection logic by creating fake cryptocurrency trading opportunities.

detection
BleepingComputer / 2026-06-22T21:52:18+00:00Read Intel
lowadvisorysource excerpt

FFmpeg fixes PixelSmash flaw in widely used video decoder

A newly disclosed FFmpeg flaw dubbed 'PixelSmash' could be exploited for remote code execution on Jellyfin servers under certain conditions, and can also trigger a denial-of-service condition in applications like Kodi, Emby, Nextcloud, PhotoPrism, and OBS Studio.

BleepingComputer / 2026-06-22T21:05:01+00:00Read Intel
lowadvisorysource excerpt

Guarding AI memory

What happens when threat actors target what AI remembers? Microsoft breaks down the risks and the defenses. The post Guarding AI memory appeared first on Microsoft Security Blog .

Microsoft Security Blog / 2026-06-22T19:07:28+00:00Read Intel
lowvulnerabilitysource excerpt

Microsoft fixes AutoGen Studio flaw that enabled code execution

A vulnerability chain dubbed AutoJack in Microsoft's AutoGen Studio interface for prototyping AI agents could let attackers manipulate an agent into executing arbitrary commands on its host system simply by visiting a malicious webpage.

vulnerability
BleepingComputer / 2026-06-22T17:28:57+00:00Read Intel
lowadvisorysource excerpt

Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants

Cybersecurity researchers have disclosed details of four vulnerabilities in Dify, an open-source agentic workflow platform with more than 146,000 GitHub stars, that could allow attackers to stealthily read artificial intelligence (AI) conversions from other customers' applications without requiring authentication. The vulnerabilities have been collectively codenamed DifyTap by Zafran Security.

The Hacker News / 2026-06-22T16:13:28+00:00Read Intel
criticalransomwaresource excerpt

One intrusion, two cyberattackers: Uncovering parallel threat activity

Ransomware case reveals two parallel threat actors, blending tactics and evasion—showing why isolated signals can often miss modern, overlapping cyberattacks. The post One intrusion, two cyberattackers: Uncovering parallel threat activity appeared first on Microsoft Security Blog .

ransomwareaptvulnerabilitytradecraftdetection
Microsoft Security Blog / 2026-06-22T16:00:00+00:00Read Intel
lowaptsource excerpt

New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer

Cybersecurity researchers have disclosed details of a new campaign that delivers CastleStealer by means of a previously unreported malware loader dubbed OXLOADER. According to Elastic Security Labs, the campaign leverages malicious Google Ads as a starting point to distribute the malware.

aptmalware
The Hacker News / 2026-06-22T13:20:12+00:00Read Intel
lowadvisorysource excerpt

Stop Your Legacy Infrastructure from Hijacking Your AI Agents

Earlier this month, I spoke at the Gartner Security & Risk Management Summit about a blind spot most security programs are still not accounting for - how attackers are circumventing AI security programs by using legacy infrastructure to hijack AI agents. AI adoption is moving faster than security programs can account for.

The Hacker News / 2026-06-22T11:58:00+00:00Read Intel
lowmalwaresource excerpt

AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network

A new malware family is turning forgotten home routers into a distributed reconnaissance and proxy network, not the DDoS botnet these devices usually end up in. QiAnXin's XLab calls it AryStinger and counts at least 4,300 infected routers, a total it says is still rising. The distinction matters. AryStinger exists for the stage of an attack that comes before the break-in.

malware
The Hacker News / 2026-06-22T06:57:44+00:00Read Intel
lowadvisorysource excerpt

Threat Brief: Mitigating Large-Scale Credential Attacks

We provide guidance for preparing for and mitigating large-scale credential attacks, focusing on recent campaigns targeting security vendors' devices. The post Threat Brief: Mitigating Large-Scale Credential Attacks appeared first on Unit 42 .

Unit 42 / 2026-06-20T02:05:33+00:00Read Intel
lowadvisorysource excerpt

Klue OAuth breach victim list grows as Icarus hackers claim attack

Market intelligence platform Klue has publicly confirmed a recent security incident that allowed threat actors to steal OAuth tokens used to connect to customers' Salesforce environments, as the new "Icarus" extortion group publicly claims the attack.

BleepingComputer / 2026-06-19T22:31:04+00:00Read Intel
lowadvisorysource excerpt

Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chain

Security researchers at Paradigm Shift have published a working exploit, dubbed usbliter8, that achieves arbitrary code execution inside the SecureROM of Apple's A12 and A13 chips. That code is burned into the silicon at manufacture. No software update can reach it. Affected devices will carry this flaw for as long as they stay in use. This is not a remote attack.

exploitation
The Hacker News / 2026-06-19T18:37:41+00:00Read Intel
highransomwaresource excerpt

The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes

The Gentlemen ransomware-as-a-service (RaaS) operation is actively developing and maintaining a suite of endpoint detection and response (EDR) killers that it hands out to affiliates for impairing system defenses before deploying the encryptor. This mature portfolio of EDR-terminating tools is centered around a framework that's known as GentleKiller.

ransomwaredetection
The Hacker News / 2026-06-19T18:33:07+00:00Read Intel
lowadvisorysource excerpt

AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution

Microsoft researchers have detailed an exploit chain, named AutoJack, that turns an AI browsing agent into a delivery vehicle for remote code execution. Steer the agent to load an attacker's web page, and that page's JavaScript can reach a privileged local service on the same machine and spawn a process on the host.

exploitation
The Hacker News / 2026-06-19T15:30:47+00:00Read Intel
lowadvisorysource excerpt

Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites

Dutch law enforcement authorities, along with counterparts from Canada , Germany, and the U.S., have disrupted malicious infrastructure associated with SocGholish and cleaned up nearly 15,000 infected WordPress websites. "With these actions we deprive cybercriminals of access to infected computer systems," Maikel Rollman of the Netherlands National High Tech Crime Unit said.

The Hacker News / 2026-06-19T15:07:54+00:00Read Intel
lowadvisorysource excerpt

Webinar: How attackers bypass MFA and how defenders can respond

Modern phishing attacks, including Device Code phishing, can undermine MFA protections and grant attackers access to corporate accounts without stealing passwords. This webinar explores how behavioral AI can help security teams detect compromised accounts faster and automate response workflows.

tradecraftidentityemail
BleepingComputer / 2026-06-19T12:12:20+00:00Read Intel
lowadvisorysource excerpt

Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data

Salesforce has revealed that it disabled the Klue Battlecards app integration within its platform in response to a security incident impacting the competitive intelligence company on June 11, 2026. To that end, organizations will be unable to connect to Salesforce via the app until further notice, the American cloud-based software company noted in an alert published this week.

cloud
The Hacker News / 2026-06-19T09:03:57+00:00Read Intel
highvulnerabilitysource excerpt

Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone

Apple has updated its Beats Studio Buds wireless earbuds to patch a high-severity vulnerability that could be exploited by nearby hackers to eavesdrop on users. The vulnerability, tracked as CVE-2025-20701 (CVSS score: 8.8), refers to a case of incorrect authorization impacting the Airoha Bluetooth audio SDK that makes it possible to pair a Bluetooth audio device without user consent.

vulnerabilitycve
The Hacker News / 2026-06-19T06:36:09+00:00Read Intel
mediumvulnerabilitysource excerpt

AutoJack: How a single page can RCE the host running your AI agent

AutoJack is a novel exploit chain showing how a single malicious webpage can turn an AI browsing agent into a remote code execution vector on the host machine. By abusing trust in localhost, missing authentication, and unsafe parameter handling, attackers can trigger arbitrary process execution through AutoGen Studio’s MCP WebSocket.

vulnerabilityexploitationtradecraftwindows
Microsoft Security Blog / 2026-06-19T00:17:54+00:00Read Intel
lowadvisorysource excerpt

Close Encounters of the Human Kind

In the latest Threat Source, Hazel channels her inner Spielberg to explore why humans are delightfully irrational, reminding us that while security best practices are simple in theory, they’re a lot harder to pull off when you’re busy dealing with real life.

identity
Cisco Talos / 2026-06-18T18:00:24+00:00Read Intel
lowmalwaresource excerpt

ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More Stories

The internet did not break this week. It got used exactly as designed, which is worse. Searches were siphoned through shady browser add-ons. AI chat links turned into malware delivery paths. macOS attacks ran in memory and left almost nothing behind. Cloud agents looked like helpers until attackers treated them like open shells.

malwaretradecraftcloudemail
The Hacker News / 2026-06-18T15:27:54+00:00Read Intel
lowmalwaresource excerpt

Microsoft Details Windows Clipper Malware Campaign Using USB LNK Worm and Tor-Based C2

Microsoft has disclosed details of a Windows-based cryptocurrency clipper campaign that has targeted users since February 2026. "The clipper in this campaign relies on Windows Script Host and ActiveX-driven logic to launch a bundled Tor proxy and poll a hidden-service C2 [command-and-control] server," the Microsoft Defender Security Research Team said in an analysis published Tuesday.

malwarewindows
The Hacker News / 2026-06-18T14:30:42+00:00Read Intel
highransomwaresource excerpt

DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic

Threat actors associated with the DragonForce ransomware have been observed using a custom Go-based remote access trojan (RAT) called Backdoor.Turn to conceal command-and-control (C2) traffic inside Microsoft Teams relay infrastructure. According to findings from Broadcom-owned Symantec and Carbon Black, the backdoor was deployed against a major U.S. services firm.

ransomwaremalware
The Hacker News / 2026-06-18T13:30:07+00:00Read Intel
criticaladvisorysource excerpt

F5 issues out-of-band patches for critical NGINX vulnerabilities

Cybersecurity company F5 has released out-of-band security updates to address multiple NGINX web server vulnerabilities, including two critical-severity flaws that could allow attackers to execute code on vulnerable systems.

BleepingComputer / 2026-06-18T11:33:00+00:00Read Intel
highdetectionsource excerpt

From package to postinstall payload: Inside the Mastra npm supply chain compromise by Sapphire Sleet

A poisoned npm package infected 140+ projects with a hidden payload. This report highlights how to detect, hunt, and defend against supply chain attacks using Microsoft Defender and actionable threat intelligence. The post From package to postinstall payload: Inside the Mastra npm supply chain compromise by Sapphire Sleet appeared first on Microsoft Security Blog .

exploitationtradecraftdetectionwindows
Microsoft Security Blog / 2026-06-18T03:43:04+00:00Read Intel
mediumtradecraftsource excerpt

Crypto Clipper uses Tor and worm-like propagation for persistence and control

Microsoft Threat Intelligence analyzed a cryptocurrency clipper campaign that combines clipboard theft, wallet replacement, Tor-based communications, and worm-like propagation. Beyond stealing cryptocurrency transactions, the malware establishes persistent access and enables follow-on activity through a lightweight backdoor capability.

malwaretradecraftwindows
Microsoft Security Blog / 2026-06-17T23:11:43+00:00Read Intel
lowvulnerabilitysource excerpt

Beyond the benchmark: Advancing security at AI speed

Read how Microsoft Security has advanced its agentic vulnerability detection system, codename MDASH, integrating into real-world workflows across Windows, Azure, and identity systems. The post Beyond the benchmark: Advancing security at AI speed appeared first on Microsoft Security Blog .

vulnerabilitydetectionwindowscloudidentity
Microsoft Security Blog / 2026-06-17T19:30:00+00:00Read Intel
highransomwaresource excerpt

​​Forrester names Microsoft a Leader in the 2026 Extended Detection and Response Platforms Wave™ report

Microsoft has been named a Leader in The Forrester Wave™: Extended Detection and Response Platforms, Q2 2026. The post ​​Forrester names Microsoft a Leader in the 2026 Extended Detection and Response Platforms Wave™ report appeared first on Microsoft Security Blog .

ransomwaredetectionwindowscloudidentityemail
Microsoft Security Blog / 2026-06-17T18:30:00+00:00Read Intel
highvulnerabilitysource excerpt

Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development

Microsoft has formally disclosed that it's working to release a patch to address a Defender zero-day codenamed RoguePlanet. The vulnerability has now been assigned the CVE identifier CVE-2026-50656 (CVSS score: 7.8), with the tech giant describing it as a privilege escalation flaw.

malwarevulnerabilitycvewindows
The Hacker News / 2026-06-17T17:36:28+00:00Read Intel
criticaladvisorysource excerpt

AI is accelerating cyberattacks—here’s how to stay ahead

See how Microsoft unifies identity and security signals to help teams prevent, detect, and respond to AI-accelerated attacks faster. The post AI is accelerating cyberattacks—here’s how to stay ahead appeared first on Microsoft Security Blog .

detectionwindowsidentity
Microsoft Security Blog / 2026-06-17T17:00:00+00:00Read Intel
lowadvisorysource excerpt

Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline

A French-speaking attacker broke into a small French automotive business, planted a keylogger, and stole banking and email credentials. Ordinary stuff, until one move near the end. Before his command-and-control server went dark, he installed OpenSSH and Tailscale on a victim's machine, building a way back in that did not run through the C2 at all.

email
The Hacker News / 2026-06-17T16:00:56+00:00Read Intel
lowadvisorysource excerpt

Why Account Takeovers Are Rising and How to Stop Them

Account takeovers are rising as attackers bypass traditional defenses through phishing, session hijacking, and MFA fatigue. Specops Software explores how device trust and continuous verification help reduce account takeover risk.

tradecraftidentityemail
BleepingComputer / 2026-06-17T14:00:10+00:00Read Intel
lowvulnerabilitysource excerpt

The Top 10 Attack Surface Exposures in 2026

Breaches don't always start with a zero-day. An exposed admin panel can get brute-forced, or credentials reused from a previous attack. But when a vulnerability does drop — like MongoBleed earlier this year, which let attackers pull credentials and session tokens from server memory without authentication — anything internet-facing is immediately at risk.

vulnerabilityexploitation
The Hacker News / 2026-06-17T10:30:00+00:00Read Intel
lowadvisorysource excerpt

144 Mastra npm Packages Compromised via Hijacked Contributor Account

As many as 144 npm packages associated with the Mastra namespace ("@mastra/*"), a popular open-source JavaScript and TypeScript framework for building artificial intelligence (AI) applications, have been compromised as part of a software supply chain attack codenamed easy-day-js, per findings from JFrog, SafeDep, Socket, and StepSecurity.

The Hacker News / 2026-06-17T07:38:24+00:00Read Intel
criticalvulnerabilitysource excerpt

CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting Widget Factory Joomla Content Editor (JCE) to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

vulnerabilitycve
The Hacker News / 2026-06-17T05:50:46+00:00Read Intel
lowadvisorysource excerpt

Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads via Bucket Squatting

A flaw in the Google Cloud Vertex AI SDK for Python let an attacker with no access to a victim's project hijack the victim's machine learning model upload and run code inside Google's serving infrastructure. Palo Alto Networks Unit 42, which found and reported the bug through Google's bug bounty program, calls the technique "Pickle in the Middle" and said it saw no exploitation in the wild.

tradecraftcloud
The Hacker News / 2026-06-16T19:05:41+00:00Read Intel
lowmalwaresource excerpt

ClickFix Campaigns Expand Malware Delivery With New Loaders and Fake Update Lures

Cybersecurity researchers have flagged multiple ClickFix campaigns that deliver three malware loaders called BabaDeda Loader, Lorem Ipsum Loader, and Potemkin, per independent reports from Morphisec, BlueVoyant, and Huntress, respectively. Attacks involving BabaDeda Loader, observed in April 2026, have targeted education and financial organizations.

malware
The Hacker News / 2026-06-16T17:41:28+00:00Read Intel
lowmalwaresource excerpt

GhostTree Attack Abused Recursive Windows Junctions to Hide Malware

GhostTree uses recursive NTFS junctions to generate vast numbers of valid Windows file paths. Varonis explains how the technique could cause Microsoft Defender folder scans to never complete, leaving malware undetected.

malwaretradecraftwindows
BleepingComputer / 2026-06-16T14:17:27+00:00Read Intel
criticalvulnerabilitysource excerpt

CISA warns of another cPanel plugin flaw exploited in attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given U.S. government agencies three days to secure their servers against an actively exploited vulnerability (CVE-2026-54420) in the LiteSpeed cPanel user-end plugin.

vulnerabilitycve
BleepingComputer / 2026-06-16T10:47:59+00:00Read Intel
mediumvulnerabilitysource excerpt

Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week

Bad actors are exploiting multiple security vulnerabilities in Fortinet FortiSandbox, according to threat intelligence firm Defused Cyber. In a post shared on X, the company said it has observed exploitation of CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089 over the past 24 hours.

vulnerabilitycveexploitation
The Hacker News / 2026-06-16T10:30:41+00:00Read Intel
lowaptsource excerpt

Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware

The North Korean state-sponsored hacking group known as ScarCruft (aka APT37) has been observed using spear-phishing messages impersonating Microsoft Account security notifications to deliver malware called NarwhalRAT. "The attack email contained a message impersonating an MS account security alert," the Genians Security Center (GSC) said.

aptmalwaretradecraftemail
The Hacker News / 2026-06-16T08:14:55+00:00Read Intel
mediumvulnerabilitysource excerpt

CISA Flags LiteSpeed cPanel Plugin Flaw Exploited for Root Privilege Escalation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a security flaw impacting LiteSpeed cPanel Plugin to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by June 18, 2026.

vulnerabilitycve
The Hacker News / 2026-06-16T05:41:52+00:00Read Intel
lowadvisorysource excerpt

Inside the Modern SOC: The 72-Minute Race

Attackers can move from access to exfiltration in 72 minutes. Learn how modern SOC teams close the speed gap with Unit 42's AI-driven automation, threat hunting, MDR and Managed XSIAM. The post Inside the Modern SOC: The 72-Minute Race appeared first on Unit 42 .

Unit 42 / 2026-06-15T23:00:19+00:00Read Intel
lowvulnerabilitysource excerpt

LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers

A default low-privilege account on a LiteLLM proxy can climb to full admin and run code on the server by chaining three vulnerabilities, researchers at Obsidian Security disclosed LiteLLM is a widely deployed open-source AI gateway that brokers calls to more than 100 model providers behind one OpenAI-compatible interface.

vulnerabilitynetwork
The Hacker News / 2026-06-15T16:39:01+00:00Read Intel
lowadvisorysource excerpt

Cyberattack on Russian tech firm Astral disrupts business, government services for week

According to customer complaints, the disruption affected a range of services used by businesses, leading to interruptions in cash register operations, difficulties selling certain regulated goods, loss of access to customer portals and corporate email and problems with electronic human resources document management systems and authentication using digital certificates.

email
The Record / 2026-06-15T15:07:00+00:00Read Intel
lowadvisorysource excerpt

⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and More

Stuff broke again. Not in a movie way. An old tool was left exposed. An abandoned package was abused. A deprecated feature was still running in prod. This week is the same lesson in a new form: phishing kits are easier to rent, AI names are useful bait, old login paths still fail, and forgotten software keeps becoming someone else's entry point.

tradecraftnetworkemail
The Hacker News / 2026-06-15T13:49:29+00:00Read Intel
criticalvulnerabilitysource excerpt

New attack turned Microsoft 365 Copilot into 1-click data theft tool

A critical vulnerability chain dubbed SearchLeak in Microsoft 365 Copilot Enterprise could allow attackers to steal sensitive data from a target's mailbox, OneDrive, or SharePoint account through a specially crafted URL.

vulnerability
BleepingComputer / 2026-06-15T13:00:00+00:00Read Intel
lowadvisorysource excerpt

Webinar: How behavioral AI stops phishing and account takeovers

Modern phishing, BEC, and account takeover attacks increasingly bypass traditional email defenses and create operational strain for security teams. This webinar explores how behavioral AI can help automate detection, investigation, and remediation to reduce alert fatigue and accelerate response times.

tradecraftdetectionemail
BleepingComputer / 2026-06-15T12:12:20+00:00Read Intel
lowadvisorysource excerpt

Popular WordPress Plugin Scripts Tampered to Plant Hidden Backdoors on Sites

An attacker tampered with trusted JavaScript files used by WordPress sites running PushEngage, OptinMonster, and TrustPulse, turning those files into a way to break into the sites. When a site administrator was logged in as the file loaded, the code created an admin account under the attacker's control and installed a hidden plugin that opened a way back in.

The Hacker News / 2026-06-15T09:59:38+00:00Read Intel
lowadvisorysource excerpt

Ex-school district employee jailed for hacks on former employer

A former IT employee at an Iowa school district was sentenced to 21 months in prison after conducting a prolonged cyberattack against the former employer that disrupted classroom operations, deleted accounts, and caused tens of thousands of dollars in damages.

BleepingComputer / 2026-06-13T20:53:13+00:00Read Intel
criticalvulnerabilitysource excerpt

Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication

Splunk has released security updates to address a critical security flaw in Splunk Enterprise that could be exploited to conduct unauthenticated file operations and even remote code execution. The vulnerability, tracked as CVE-2026-20253, is rated 9.8 on the CVSS scoring system.

vulnerabilitycve
The Hacker News / 2026-06-13T13:23:03+00:00Read Intel
lowmalwaresource excerpt

Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit

Attackers took over more than 400 packages in the Arch User Repository (AUR) this week and rewrote their build scripts to install a credential stealer on any machine that built them. The malware is a Rust binary built to harvest developer secrets. When it lands with root, it can also load an eBPF rootkit to hide itself.

malwarelinux
The Hacker News / 2026-06-12T19:33:25+00:00Read Intel
lowmalwaresource excerpt

400+ Arch Linux AUR Packages Hijacked to Install Rust Credential Stealer

Attackers took over more than 400 packages in the Arch User Repository (AUR) this week and rewrote their build scripts to install a credential stealer on any machine that built them. The malware is a Rust binary built to harvest developer secrets. When it lands with root, it can also load an eBPF rootkit to hide itself.

malwarelinux
The Hacker News / 2026-06-12T19:24:50+00:00Read Intel
lowadvisorysource excerpt

Agentjacking Attack Tricks AI Coding Agents Into Running Malicious Code

Cybersecurity researchers have described what they say is a new class of attack that can trick artificial intelligence (AI) coding agents into running arbitrary code on developer machines. Called Agentjacking by Tenet Security, the attack can be triggered by means of a fake error report crafted using Sentry, an open-source error-tracking and performance-monitoring platform.

The Hacker News / 2026-06-12T12:04:33+00:00Read Intel
lowadvisorysource excerpt

Rethinking MDR as Attackers and Defenders Embrace AI

For most of the past decade, managed detection and response was the answer to a real problem. Security teams couldn't staff around the clock, couldn't hire enough analysts, and needed someone else to handle the alert queue. MDR stepped in. It worked well enough. Until now. The threat landscape has changed faster than the MDR model can adapt.

detection
The Hacker News / 2026-06-12T11:00:00+00:00Read Intel
criticalvulnerabilitysource excerpt

LangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code Execution

Cybersecurity researchers have disclosed details of three now-patched security flaws impacting LangGraph, including a critical vulnerability chain that could result in remote code execution. LangGraph is an open-source framework created by LangChain to build complex, stateful, and multi-agent artificial intelligence (AI) agentic applications.

vulnerability
The Hacker News / 2026-06-12T09:50:36+00:00Read Intel
highadvisorysource excerpt

CISA orders feds to patch actively exploited Ivanti flaw by Sunday

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered government agencies to patch an actively exploited Ivanti Sentry flaw within three days, as mandated by the newly issued Binding Operational Directive (BOD) 26-04.

BleepingComputer / 2026-06-12T08:26:55+00:00Read Intel
highransomwaresource excerpt

Europol Disrupts AudiA6 Crypto Laundering Service Used by Ransomware Gangs

Authorities in Europe have disrupted AudiA6, a cryptocurrency laundering service used by ransomware gangs and cybercriminal networks. Europol, in a statement issued Thursday, said the dismantling of AudiA6 cut off a "key financial pipeline used to wash hundreds of millions in illicit profits."

ransomware
The Hacker News / 2026-06-12T06:38:41+00:00Read Intel
highvulnerabilitysource excerpt

ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities

The ShinyHunters extortion crew exploited an unpatched flaw in Oracle PeopleSoft to break into enterprise systems, steal data, and demand payment to keep it private. The campaign hit universities hardest. Google's Mandiant attributes it to the group it tracks as UNC6240, and dates the activity between May 27 and June 9.

vulnerabilitycve
The Hacker News / 2026-06-11T20:29:23+00:00Read Intel
criticalvulnerabilitysource excerpt

Oracle mitigates PeopleSoft zero-day exploited in data theft attacks

Oracle is warning about a critical PeopleSoft Suite zero-day vulnerability tracked as CVE-2026-35273 that allows unauthenticated remote code execution, with the flaw actively exploited in ShinyHunter data theft attacks.

vulnerabilitycve
BleepingComputer / 2026-06-11T19:39:53+00:00Read Intel
lowvulnerabilitysource excerpt

A tale of two eras

In this week’s newsletter, Amy reminisces on the tech toys of their childhood, inspired by a hilarious lesson about why your digital privacy shouldn't be left on an open channel.

vulnerability
Cisco Talos / 2026-06-11T18:00:49+00:00Read Intel
lowadvisorysource excerpt

New Attacks Trick OpenClaw AI Agent Into Running Code and Leaking Secrets

Two security teams have shown, in separate research published this week, that OpenClaw, the popular self-hosted AI agent, can be driven to run attacker-controlled code or hand over sensitive data through ordinary-looking inputs. Imperva buried instructions inside shared contacts, vCards, and location pins that the agent executed without the victim ever seeing them.

The Hacker News / 2026-06-11T17:46:32+00:00Read Intel
lowadvisorysource excerpt

New GreatXML Exploit Bypasses Windows BitLocker via Recovery Partition XML Files

Security researcher Chaotic Eclipse (aka Nightmare-Eclipse and MSNightmare) has released a new Windows BitLocker bypass dubbed GreatXML, a day after they published an exploit for Microsoft Defender. "This was an accidental discovery, it took a total of 4 hours to find this," the researcher said in a post on Blogger.

exploitationwindows
The Hacker News / 2026-06-11T17:43:52+00:00Read Intel
highransomwaresource excerpt

The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm

A new analysis of The Gentlemen operation has revealed that the financially motivated threat group initially operated as an affiliate responsible for conducting double extortion attacks, while leveraging resources from various ransomware-as-a-service (RaaS) schemes like LockBit (aka Tenacious Mantis), Qilin (aka Pestilent Mantis), and Medusa (aka Venomous Mantis).

ransomware
The Hacker News / 2026-06-11T16:50:47+00:00Read Intel
lowadvisorysource excerpt

Cyber Force not included in Senate defense policy roadmap

An amendment by Sen. Kirsten Gillibrand (D-NY) to the chamber’s fiscal 2027 national defense authorization bill that would have created the digital-focused service was defeated 14-13 when the Senate Armed Services Committee took up the nearly $1.2 trillion legislation behind closed doors this week.

The Record / 2026-06-11T16:47:00+00:00Read Intel
criticalaptsource excerpt

ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit

Introduction Mandiant and Google Threat Intelligence Group (GTIG) have identified an active compromise and extortion campaign attributed to UNC6240 (ShinyHunters) targeting Oracle PeopleSoft application infrastructure.

aptvulnerabilitycveexploitationtradecraftcloud
Mandiant / 2026-06-11T14:00:00+00:00Read Intel
lowmalwaresource excerpt

ThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Action Patch + 28 New Stories

It's been one of those weeks. You expect the usual noise: recycled malware, sloppy attacks, another easy target getting hit. Instead, there's a supply chain attack kit in a public repo, a $5,000-a-month RAT that clones browsers, and research showing AI agents can be tricked into leaking real credentials. The bigger problem is how polished this all looks now. Mule networks run like SaaS.

malware
The Hacker News / 2026-06-11T13:20:41+00:00Read Intel
lowadvisorysource excerpt

Coupang hit with record $409 million data breach fine in Korea

​​The Personal Information Protection Commission (PIPC), South Korea's data protection regulator, has fined e-commerce giant Coupang a record 624.6 billion won (roughly $409 million) following a massive data breach affecting more than 37 million

BleepingComputer / 2026-06-11T12:52:41+00:00Read Intel
lowvulnerabilitysource excerpt

AI Broke Vulnerability Management. That's Why CISOs Are Moving Budget to BAS.

For thirty years, vulnerability management ran on a buffer: the months between when a vulnerability was found and when someone could figure out how to weaponize it. The solution was straightforward enough; triage by severity, schedule the fix, validate, and move on. The buffer was what made that work. Today, that buffer is gone. AI didn't make your team slower.

vulnerability
The Hacker News / 2026-06-11T11:30:00+00:00Read Intel
lowadvisorysource excerpt

Trust No Skill: Integrity Verification for AI Agent Supply Chains

Protect enterprise AI agents from supply chain risks by auditing third-party skills for hidden vulnerabilities and multi-stage attack chains. The post Trust No Skill: Integrity Verification for AI Agent Supply Chains appeared first on Unit 42 .

Unit 42 / 2026-06-11T10:00:24+00:00Read Intel
lowadvisorysource excerpt

GitHub to Disable npm Install Scripts by Default to Stop Supply Chain Attacks

GitHub has announced what it said are "breaking changes" coming to npm version 12, one of which turns off install scripts by default to combat software supply chain threats. The changes aim to combat attack techniques that abuse the "npm install" command to trigger the execution of malicious code using npm lifecycle hooks.

The Hacker News / 2026-06-11T06:23:03+00:00Read Intel
lowadvisorysource excerpt

Turn specs into evals for any agent with ASSERT

Adaptive Spec-driven Scoring for Evaluation and Regression Testing (ASSERT) is an open-source framework for converting natural language behavior requirements into executable evaluations of AI models and agents. The post Turn specs into evals for any agent with ASSERT appeared first on Microsoft Security Blog .

Microsoft Security Blog / 2026-06-10T16:00:00+00:00Read Intel
lowadvisorysource excerpt

Cyberattack shuts down major Australian sugar mills, disrupting harvest

Australia's second-largest sugar producer said on Wednesday that it was responding to a cybersecurity incident affecting parts of its operations and had engaged cybersecurity experts and local authorities to investigate the attack and restore its systems safely.

The Record / 2026-06-10T15:18:00+00:00Read Intel
criticalvulnerabilitysource excerpt

Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities

Fortinet, Ivanti, and SAP have released security updates to address multiple critical security vulnerabilities that could result in arbitrary code execution and information disclosure. The security flaw patched by Fortinet relates to a command injection vulnerability in FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS WEB UI. It's tracked as CVE-2026-25089 (CVSS score: 9.1).

vulnerabilitycvecloud
The Hacker News / 2026-06-10T15:10:59+00:00Read Intel
mediumvulnerabilitysource excerpt

Langflow Vulnerability CVE-2026-5027 Exploited for Unauthenticated RCE

A high-severity security flaw in Langflow, an open-source low-code platform to build artificial intelligence (AI) applications, has come under active exploitation in the wild, according to findings from VulnCheck. The vulnerability in question is CVE-2026-5027 (CVSS score: 8.8), a case of path traversal that could allow an attacker to write files to arbitrary locations.

vulnerabilitycve
The Hacker News / 2026-06-10T15:00:59+00:00Read Intel
lowadvisorysource excerpt

The 5 Best Practices for Secure Identity Verification

Attackers are increasingly bypassing weak authentication through phishing, MFA fatigue, and service desk social engineering. Specops Software breaks down five best practices for stronger identity verification and access security.

tradecraftidentityemail
BleepingComputer / 2026-06-10T14:05:15+00:00Read Intel
highvulnerabilitysource excerpt

Microsoft patches Exchange Server zero-day exploited in attacks

Microsoft has patched an actively exploited Exchange Server vulnerability that allows threat actors to execute arbitrary JavaScript code in cross-site scripting (XSS) attacks targeting Outlook Web Access users.

vulnerability
BleepingComputer / 2026-06-10T13:44:19+00:00Read Intel
lowvulnerabilitysource excerpt

Microsoft patches YellowKey, GreenPlasma, MiniPlasma zero-days

On Tuesday, Microsoft patched two zero-day vulnerabilities that let attackers gain SYSTEM privileges on fully patched Windows systems, and a third one that grants access to BitLocker-protected drives.

vulnerabilitywindows
BleepingComputer / 2026-06-10T09:57:33+00:00Read Intel
lowadvisorysource excerpt

ServiceNow Flaw Exploited to Gain Unauthorized Access to Customer Instances

ServiceNow has warned about a security incident in which unknown threat actors exploited a flaw to obtain deeper unauthorized access to susceptible instances. "On June 5, 2026, ServiceNow applied a security update to hosted customer instances," the company revealed in an advisory that requires customer access.

The Hacker News / 2026-06-10T07:02:08+00:00Read Intel
lowvulnerabilitysource excerpt

Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows

The anonymous security researcher going by the name Chaotic Eclipse (aka Nightmare-Eclipse) has released a proof-of-concept (PoC) exploit for yet another Microsoft Defender zero-day named RoguePlanet. "The exploit is a race condition, so it's a hit or miss," the researcher, who published the exploit under a new GitHub account, "MSNightmare" said.

vulnerabilityexploitationwindows
The Hacker News / 2026-06-10T05:22:01+00:00Read Intel
mediumvulnerabilitysource excerpt

Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS

Cybersecurity researchers have flagged half a dozen vulnerabilities in protobuf.js, a JavaScript and TypeScript implementation of Protocol Buffers (Protobuf), that, if successfully exploited, could result in remote code execution (RCE) and denial-of-service (DoS) attacks.

vulnerability
The Hacker News / 2026-06-10T05:08:35+00:00Read Intel
lowvulnerabilitysource excerpt

Blame AI: Patch Tuesday Hits Record 206 CVEs

Voluminous patch updates could soon be the norm, as artificial intelligence accelerates the speed and scale of vulnerability discovery.

vulnerability
Dark Reading / 2026-06-09T21:42:57+00:00Read Intel
lowadvisorysource excerpt

Reconstructing AI activity in investigations

Learn how to investigate AI activity in Microsoft 365 Copilot and Azure AI services using a structured, telemetry-driven approach. This playbook helps security teams reconstruct events, assess data exposure, and detect potential threats faster. The post Reconstructing AI activity in investigations appeared first on Microsoft Security Blog .

detectionwindowscloudidentity
Microsoft Security Blog / 2026-06-09T17:35:06+00:00Read Intel
criticalvulnerabilitysource excerpt

Veeam Backup & Replication RCE Flaw Lets Domain Users Run Remote Code

Veeam has released security patches to address a critical flaw in its Backup & Replication software that could result in remote code execution. Tracked as CVE-2026-44963, the vulnerability carries a CVSS score of 9.4 out of a maximum of 10.0. "A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user," Veeam said in a Tuesday advisory.

vulnerabilitycve
The Hacker News / 2026-06-09T16:39:47+00:00Read Intel
lowmalwaresource excerpt

Microsoft Restores Some GitHub Repos, Keeps Others Offline as Miasma Probe Continues

Microsoft on Monday confirmed that it temporarily removed some GitHub repositories in response to a recent security incident that led to 73 of its open-source projects being compromised to inject an information stealer into the code. "Our priority is to protect customers and the broader ecosystem," a Microsoft spokesperson told The Hacker News via email.

malwareemail
The Hacker News / 2026-06-09T16:34:52+00:00Read Intel
lowvulnerabilitysource excerpt

XBOW tests Anthropic's Mythos Preview for offensive security

Anthropic's Mythos Preview was highly effective at finding vulnerability candidates, especially when analyzing source code. XBOW explores how the model performed across exploit discovery, reverse engineering, and live-site validation.

vulnerabilityexploitation
BleepingComputer / 2026-06-09T16:16:38+00:00Read Intel
mediumvulnerabilitysource excerpt

WinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in Ukraine

Two Russia-aligned cyber attack campaigns have continued to exploit a security flaw in WinRAR to target Ukrainian organisations, almost a year after patches for the vulnerability were released. The activity has been attributed by Trend Micro to Earth Dahu (aka Gamaredon) and SHADOW-EARTH-066 (aka UAC-0226).

vulnerabilitycveexploitation
The Hacker News / 2026-06-09T12:26:10+00:00Read Intel
lowadvisorysource excerpt

Researchers Build Self-Replicating AI Worm That Operates Entirely on Local, Open-Weight Models

University of Toronto researchers have built and tested a proof-of-concept AI-driven computer worm that uses a locally hosted open-weight large language model to reason its way through a network, generate tailored attack strategies for each target it encounters, and replicate itself, all without human intervention and without touching a commercial AI service.

The Hacker News / 2026-06-09T11:59:03+00:00Read Intel
highvulnerabilitysource excerpt

Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild - Patch Now

Google has released security updates to address 74 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-11645 (CVSS score: 8.8), has been described as an out-of-bounds memory access in V8, Chrome's JavaScript and WebAssembly engine.

vulnerabilitycve
The Hacker News / 2026-06-09T11:58:49+00:00Read Intel
lowadvisorysource excerpt

New FROST Attack Lets Websites Track What Sites and Apps You Open via SSD Timing

A malicious website can work out which sites you visit and which apps you open, using nothing but JavaScript and the timing of your SSD. The attack, called FROST, needs no native code, no extension, and no permission prompt. You open the page, leave the tab sitting there, and it watches the drive for contention in the background.

The Hacker News / 2026-06-09T09:50:41+00:00Read Intel
lowmalwaresource excerpt

Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer

The Miasma supply chain campaign has sparked a fresh attack wave called Hades, this time involving 37 malicious wheel artifacts across 19 packages in the Python Package Index (PyPI) registry, as the Mini Shai-Hulud-style attacks continue to be refined and splintered to target specific ecosystems.

malware
The Hacker News / 2026-06-09T09:13:32+00:00Read Intel
lowadvisorysource excerpt

When “Hi, This Is IT” Comes Through Microsoft Teams

Attackers are increasingly targeting collaboration platforms like Microsoft Teams. Learn the risks and key steps to strengthen your organization's security. The post When “Hi, This Is IT” Comes Through Microsoft Teams appeared first on Unit 42 .

tradecraftemail
Unit 42 / 2026-06-08T23:00:45+00:00Read Intel
criticalransomwaresource excerpt

Check Point VPN Flaw Exploited Since Early May

A newly discovered, critical zero-day vulnerability is under attack; a Qilin ransomware affiliate has been blamed for at least one incident.

ransomwarevulnerabilitynetwork
Dark Reading / 2026-06-08T20:28:35+00:00Read Intel
mediumvulnerabilitysource excerpt

One-Character Linux Kernel Flaw Enables Local Root Access, Exploits Now Public

Security researchers have published a detailed, working exploit for a Linux kernel use-after-free that lets an unprivileged local user escalate to root and break out of a container. The flaw, CVE-2026-23111, sits in the kernel's nf_tables packet-filtering code and was patched upstream on February 5, 2026.

vulnerabilitycveexploitationlinuxcloud
The Hacker News / 2026-06-08T20:17:39+00:00Read Intel
lowadvisorysource excerpt

Meta Blocks NSO Group's New WhatsApp Phishing Attack, Files Contempt Order

Meta on Monday said it detected and blocked spear-phishing attempts linked to Israeli spyware vendor NSO Group. In addition, the tech giant said it's filing a federal court contempt order against the company for violating a permanent injunction that barred it from targeting WhatsApp and its users.

tradecraftemail
The Hacker News / 2026-06-08T17:08:44+00:00Read Intel
lowaptsource excerpt

AI brands as bait: How threat actors are using the AI hype in social engineering

As threat actors operationalize AI to accelerate attacks, they are also leveraging the wider global interest around AI itself as a social engineering lure. The post AI brands as bait: How threat actors are using the AI hype in social engineering appeared first on Microsoft Security Blog .

aptmalwaretradecraftdetectionwindowsidentity
Microsoft Security Blog / 2026-06-08T16:00:00+00:00Read Intel
lowvulnerabilitysource excerpt

⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and More

Monday again. The weekend was meant to be quiet. It wasn't. Last week had poisoned packages, a broken AI helper, and a worm tearing through repos. The ugly part: basic tricks still worked. A chatbot got fooled. A bot token got leaked inside the malware. The same old mistakes showed up again.

malwarevulnerability
The Hacker News / 2026-06-08T13:18:57+00:00Read Intel
criticalransomwaresource excerpt

Check Point links VPN zero-day attacks to Qilin ransomware gang

Israeli cybersecurity company Check Point has released security updates to patch a critical flaw affecting Remote Access VPN and Mobile Access deployments, which was exploited in zero-day attacks.

ransomwarevulnerabilitynetwork
BleepingComputer / 2026-06-08T13:05:16+00:00Read Intel
lowmalwaresource excerpt

AI Phishing Is Crushing SOCs with Alert Volume: How to Reduce Tier 1 Overload

Phishing has always been a numbers game. AI has turned it into a volume machine. Attackers can now create convincing emails, fake login pages, and tailored lures in minutes. Every polished message adds another case for Tier 1 to review, another link to inspect, and another alert that cannot be dismissed at a glance.

malwaretradecraftemail
The Hacker News / 2026-06-08T13:00:00+00:00Read Intel
mediumvulnerabilitysource excerpt

The Hardest Fork

Mythos is real. I know a big chunk of the industry thinks it's a marketing stunt, and I get why. I get it. But I've seen the findings, and they're bad. These aren't "whoops, this line right here is wrong, and that's RCE." They're novel combinations of a few dozen issues out of thousands of things every SAST scanner already finds, chained together into something much worse.

vulnerability
The Hacker News / 2026-06-08T11:53:00+00:00Read Intel
mediumadvisorysource excerpt

Silent Ransom Group targets law firms with fake IT support calls

The Silent Ransom Group extortion gang is actively targeting U.S. law firms and professional services organizations in social engineering attacks that often lead to data theft within hours of initial contact, according to a new report by cybersecurity firm Mandiant.

BleepingComputer / 2026-06-07T14:09:19+00:00Read Intel
lowadvisorysource excerpt

New ChatGPT Lockdown Mode Limits Tools That Could Enable Data Exfiltration

OpenAI has begun rolling out a new Lockdown Mode to ChatGPT for eligible personal accounts to reduce the risk of data exfiltration arising from prompt injection attacks. The feature is primarily designed for people and organizations that handle sensitive data and require stricter protection guarantees.

The Hacker News / 2026-06-06T13:36:57+00:00Read Intel
criticalvulnerabilitysource excerpt

CISA Adds Actively Exploited SolarWinds Serv-U DoS Flaw to KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity security flaw impacting SolarWinds Serv-U multi-protocol file server software to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

vulnerabilitycve
The Hacker News / 2026-06-06T08:14:31+00:00Read Intel
lowadvisorysource excerpt

AI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 Bugs

Two things landed within days of each other this week. A security startup reported 21 previously unknown vulnerabilities in FFmpeg, the media library inside almost everything that touches video, all of them found by an autonomous AI agent. The same week, Google shipped Chrome 149 with patches for 429 security bugs, the most ever in a single release. Only the FFmpeg bugs were found by AI.

The Hacker News / 2026-06-06T07:28:30+00:00Read Intel
lowadvisorysource excerpt

Miasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain Attack

Microsoft's GitHub repositories have become the latest to fall victim to the ongoing Miasma self-replicating supply chain attack campaign. The incident impacted 73 Microsoft repositories across four of its GitHub organizations, including Azure, Azure-Samples, Microsoft, and MicrosoftDocs, per OpenSourceMalware. The development has GitHub to disable access to those repositories.

cloud
The Hacker News / 2026-06-06T06:58:04+00:00Read Intel
lowmalwaresource excerpt

IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks

Multiple software supply chain attacks have hit the npm ecosystem, with threat actors using both malicious and poisoned versions of over 50 legitimate packages to distribute a Rust-based information stealer and a self-spreading worm, respectively.

malware
The Hacker News / 2026-06-05T18:05:30+00:00Read Intel
lowmalwaresource excerpt

Securing CI/CD in an agentic world: Claude Code Github action case

Microsoft Threat Intelligence identified a prompt injection pathway in Claude Code GitHub Action that allowed access to workflow secrets under specific conditions. This research examines the attack chain, responsible disclosure process, Anthropic's mitigation, and guidance for securing AI-powered CI/CD workflows.

malware
Microsoft Security Blog / 2026-06-05T16:46:47+00:00Read Intel
criticaladvisorysource excerpt

Over 900 US gas station tank gauge systems exposed to attacks

Over 900 automatic tank gauge (ATG) systems across the United States, used to monitor fuel and chemical storage tanks across various critical infrastructure sectors, have been found exposed online and are vulnerable to ongoing attacks.

BleepingComputer / 2026-06-05T14:50:15+00:00Read Intel
mediumvulnerabilitysource excerpt

Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257

We include indicators of activity and mitigations for PAN-OS vulnerability CVE-2026-0257. The post Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257 appeared first on Unit 42 .

vulnerabilitycve
Unit 42 / 2026-06-05T14:05:42+00:00Read Intel
lowadvisorysource excerpt

What 2026 DBIR Confirms: Attacks Are Living in the Browser

Phishing, shadow AI, malicious extensions, and credential theft increasingly happen inside the browser. Keep Aware explains what the 2026 Verizon DBIR reveals about browser-layer security gaps and modern attacks.

tradecraftemail
BleepingComputer / 2026-06-05T14:00:10+00:00Read Intel
highadvisorysource excerpt

Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms

Written by: Chad Reams, Tufail Ahmed, Keith Knapp, Ashley Frazer, Tyler McLellan Introduction From January through May 2026, Mandiant identified a financially motivated data theft extortion campaign executed by the threat cluster UNC3753 (also tracked as "Luna Moth," “Chatty Spider,” and "Silent Ransom Group") targeting dozens of organizations across professional, legal, and financial services in the United States.

tradecraftcloudemail
Mandiant / 2026-06-05T14:00:00+00:00Read Intel
criticalvulnerabilitysource excerpt

Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites

Threat actors are actively exploiting a critical security flaw in Everest Forms Pro, a WordPress plugin with about 4,000 active installations, to execute arbitrary code, leading to a complete site compromise. The vulnerability in question is CVE-2026-3300 (CVSS score: 9.8), a remote code execution bug impacting all versions of the plugin up to, and including, 1.9.12.

vulnerabilitycveexploitation
The Hacker News / 2026-06-05T08:38:59+00:00Read Intel
lowmalwaresource excerpt

FIFA World Cup 2026 Scams Are Already Live: Fake Sites, Banking Malware, and Stolen Logins

Security researchers and the FBI are warning that a wave of FIFA-themed fraud is already hitting World Cup 2026 fans, days before the June 11 kickoff. Recent reports describe thousands of lookalike FIFA domains, banking malware hidden inside pirate streaming apps, and at least one operation that copies FIFA's login page well enough to take over real accounts. It is an obvious target.

malware
The Hacker News / 2026-06-05T07:01:41+00:00Read Intel
criticalvulnerabilitysource excerpt

Cisco warns of unpatched SD-WAN zero-day exploited in attacks

On Thursday, Cisco warned of a high-severity, unpatched zero-day in the Cisco Catalyst SD-WAN Manager (tracked as CVE-2026-20245) actively exploited in attacks enabling root privilege escalation.

vulnerabilitycve
BleepingComputer / 2026-06-05T06:24:20+00:00Read Intel
lowadvisorysource excerpt

Trump considers Palantir exec to lead CISA

Shyam Sankar, the chief technology officer at Palantir Technologies, has emerged as a lead contender for the long vacant Cybersecurity and Infrastructure Security Agency (CISA) director role, according to the sources, who requested anonymity to discuss the administration’s search.

The Record / 2026-06-04T20:40:00+00:00Read Intel
mediumvulnerabilitysource excerpt

Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public

Cisco has patched a bug in Unified Communications Manager that lets an unauthenticated attacker on the network write files to the box and, from there, climb to root. It is tracked as CVE-2026-20230, and proof-of-concept exploit code is already public. Cisco's PSIRT says it has not seen the flaw used in attacks yet. The PoC shortens that runway. The flaw is a server-side request forgery.

vulnerabilitycveexploitation
The Hacker News / 2026-06-04T16:55:51+00:00Read Intel
lowadvisorysource excerpt

Claude Code GitHub Action Flaw Let One Malicious Issue Hijack Repositories

A security researcher found a flaw in Anthropic's Claude Code GitHub Action that let an attacker take over vulnerable public repositories running it, with nothing more than a single opened GitHub issue. Because Anthropic's own action repo used the same workflow, a working attack could have pushed malicious code into the action itself and onto the projects downstream that pull it.

The Hacker News / 2026-06-04T15:15:26+00:00Read Intel
lowadvisorysource excerpt

Winning the cyber marathon with Tony Giandomenico

Tony Giandomenico, Senior Director of Product Management, joins Amy to discuss the Talos Threat Hunting launch what he's excited about for the future of cybersecurity, and, of course, his Ironman triathlons.

detection
Cisco Talos / 2026-06-04T12:05:31+00:00Read Intel
lowmalwaresource excerpt

FlutterShell Backdoor Spreads to macOS via Malicious Google and YouTube Ads

Cybersecurity researchers have shed light on a macOS malvertising campaign codenamed Operation FlutterBridge that spreads a new backdoor called FlutterShell. According to Palo Alto Networks Unit 42, the campaign is said to be the next stage of a previously reported activity cluster dubbed JSCoreRunner (aka FileRipple) in late August 2025.

malware
The Hacker News / 2026-06-04T11:19:53+00:00Read Intel
lowadvisorysource excerpt

Hackers Spied on a Stock Exchange Executive's Outlook Mailbox for Five Months

Unknown attackers spent at least five months inside the Outlook mailbox of a senior executive at a major global stock exchange, copying the inbox out in small, repeated batches and routing it through Dropbox and OneDrive so the traffic blended into normal cloud activity. Symantec and Carbon Black's Threat Hunter Team reported the campaign this week.

cloud
The Hacker News / 2026-06-04T09:33:57+00:00Read Intel
criticalvulnerabilitysource excerpt

CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical flaw impacting Mirasvit Cache Warmer, a popular Magento full-page cache extension, to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild.

vulnerabilitycve
The Hacker News / 2026-06-04T07:19:33+00:00Read Intel
criticaladvisorysource excerpt

CISA warns of cyberattacks targeting fuel tank monitoring systems

CISA, the FBI, the NSA, the Department of Energy, and other US government partners are warning that hackers are targeting internet-exposed automatic tank gauge (ATG) systems used to monitor fuel and liquid storage tanks across various critical infrastructure sectors.

BleepingComputer / 2026-06-03T20:21:56+00:00Read Intel
lowadvisorysource excerpt

Microsoft Fixes One-Click GitHub Dev Attack That Let Attackers Steal OAuth Tokens

Cybersecurity researchers have disclosed a one-click attack via Microsoft Visual Studio Code (VS Code) that makes it possible to steal a user's GitHub token. "Just by clicking a link, it's possible for an attacker to steal a GitHub token that can read and write to your repos, including private ones," security researcher Ammar Askar said.

The Hacker News / 2026-06-03T17:58:00+00:00Read Intel
criticaladvisorysource excerpt

What 345 Days of Untested Exposure Looks Like at a Bank

A two-week penetration test can leave roughly 345 days of real-world exposure unvalidated. Sprocket Security explores why continuous testing is becoming critical as attack surfaces constantly change.

BleepingComputer / 2026-06-03T14:02:12+00:00Read Intel
mediumvulnerabilitysource excerpt

Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479)

Redis has patched a use-after-free in its blocking-client code that lets an authenticated user run arbitrary OS commands on the machine hosting the database. The flaw was found by an autonomous AI tool built to hunt bugs in large codebases. Tracked as CVE-2026-23479, the flaw was introduced in Redis 7.2.0 and remained in every stable branch until the May 5 fixes, unnoticed for over two years.

vulnerabilitycve
The Hacker News / 2026-06-03T13:47:09+00:00Read Intel
lowvulnerabilitysource excerpt

Beyond the Zero-Day: See Your Network Like an Attacker | Webinar with HD Moore

Assume the breach. Zero-days keep shipping, AI is writing exploits faster than anyone patches, and "patch everything in time" stopped working years ago. Stop betting the org on winning that race. You don't control which bug lands. You control what it can reach once it does. That is a question about the shape of your network, and most teams have the shape wrong.

vulnerability
The Hacker News / 2026-06-03T11:28:59+00:00Read Intel
mediumvulnerabilitysource excerpt

Unpatched Windows Search URI Vulnerability Lets Attackers Steal NTLMv2 Hashes

Cybersecurity researchers have disclosed details of an unpatched issue that could be exploited to disclose a user's NTLMv2 hash to the attacker. Like in the case of CVE-2026-33829, which impacted the Windows Snipping Tool's ms-screensketch: URI handler, the newly flagged issue resides in the search: URI handler, per Huntress.

vulnerabilitycvewindowsemail
The Hacker News / 2026-06-03T10:18:52+00:00Read Intel
lowtradecraftsource excerpt

Argamal: Malware hidden in hentai games

Kaspersky researchers analyze new Argamal RAT distributed via infected hentai games and allowing the attacker to control the target machine.

malwaretradecraftwindows
Securelist / 2026-06-03T09:00:22+00:00Read Intel
lowvulnerabilitysource excerpt

VS Code zero-day lets hackers steal GitHub tokens in one click

A security researcher has released exploit code for a Visual Studio Code (VS Code) zero-day vulnerability that allows attackers to steal GitHub authentication tokens by tricking users into clicking a link.

vulnerabilityexploitation
BleepingComputer / 2026-06-03T06:50:30+00:00Read Intel
lowmalwaresource excerpt

Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content

Cybersecurity researchers have flagged a new campaign targeting Minecraft players via YouTube to spread malware capable of gaining control of victims' systems. The Minecraft-focused malware-as-a-service (MaaS) campaign has been codenamed Weedhack by McAfee Labs, stating the activity has been active since January 2026 and impersonates Minecraft clients and mods to infect users.

malware
The Hacker News / 2026-06-03T06:16:54+00:00Read Intel
lowtradecraft

Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign

A large-scale npm supply chain attack compromised over 90 versions of @redhat-cloud-services packages, silently infecting CI/CD environments and developer systems. The malicious code steals credentials from GitHub, cloud platforms, and local machines, then spreads like a worm by republishing trusted packages. Discover how the attack works, what data is at risk, and the steps you can take to protect your organization.

malwaretradecraftwindowslinuxcloud
Microsoft Security Blog / 2026-06-03T04:45:06+00:00Read Intel
criticalvulnerabilitysource excerpt

Google June 2026 Android Update Patches 124 Flaws, One Actively Exploited

Google on Monday released patches for 124 security vulnerabilities impacting its Android operating system for the month of June 2026, including one high-severity flaw in the Framework component that has come under active exploitation. Tracked as CVE-2025-48595 (CVSS score: 8.4), the security flaw has been described as a case of privilege escalation without requiring any user interaction.

vulnerabilitycve
The Hacker News / 2026-06-02T18:46:00+00:00Read Intel
mediumvulnerabilitysource excerpt

Oracle WebLogic CVE-2024-21182 Added to KEV Catalog After Active Exploitation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. The vulnerability, CVE-2024-21182 (CVSS score: 7.5), allows an unauthenticated attacker with network access to take control of susceptible servers.

vulnerabilitycve
The Hacker News / 2026-06-02T18:14:42+00:00Read Intel
criticaladvisorysource excerpt

Why the browser is now the front line for AI security

AI-powered attacks and shadow AI adoption are creating new security risks inside the browser. Push Security explains why browser visibility is becoming critical for both threat detection and AI governance.

detection
BleepingComputer / 2026-06-02T14:30:40+00:00Read Intel
highvulnerabilitysource excerpt

AI-Driven Exploitation is Destroying Vulnerability Management. Here’s How to Handle It.

AI-driven exploitation timelines are rapidly shrinking, and they are not going to stop shrinking. Vulnerabilities are being discovered, reproduced, and weaponized faster than ever in the history of enterprise security. As a result, the window between a vulnerability being disclosed and indiscriminate exploitation observed across the internet is now measured in hours, not days.

vulnerabilityexploitation
The Hacker News / 2026-06-02T11:58:00+00:00Read Intel
lowadvisorysource excerpt

How Leading Organizations Are Turning EDR Into Operational Resilience

Most organizations now recognize that endpoint protection alone is no longer sufficient. That's why adoption of endpoint detection and response (EDR) has accelerated rapidly in recent years. Organizations understand that modern attacks move faster, evade traditional prevention controls, and require continuous visibility into suspicious activity across the environment.

detection
The Hacker News / 2026-06-02T10:30:00+00:00Read Intel
lowmalwaresource excerpt

Red Hat npm packages compromised to steal developer credentials

More than 30 npm packages under Red Hat's '@redhat-cloud-services' namespace were compromised in a supply-chain attack that distributed a new variant of the Shai-Hulud credential-stealing malware, dubbed "Miasma."

malwarelinuxcloud
BleepingComputer / 2026-06-01T21:38:29+00:00Read Intel
lowvulnerabilitysource excerpt

Microsoft's Zero-Day Legal Threats Spark Backlash

After a disgruntled security researcher published several zero-day exploits in recent weeks, Microsoft seemingly indicated criminal charges were in order.

vulnerability
Dark Reading / 2026-06-01T18:52:26+00:00Read Intel
lowvulnerabilitysource excerpt

Race Against Time: Why Faster Vulnerability Alerts Matter

Attackers are exploiting vulnerabilities faster than many organizations can identify and patch them. SecAlerts explains why faster vulnerability alerts can help reduce exposure and improve response times.

vulnerability
BleepingComputer / 2026-06-01T14:00:10+00:00Read Intel
lowadvisorysource excerpt

⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More

Monday hit like a cron job with anger issues. A busted auth path here, a repo-side faceplant there, some "patched-ish" thing already getting chewed on in the wild, and then the usual bonus round: poisoned dev tools, sketchy forum chatter, phishing kits pretending to be productivity, and AI lowering the bar for people who already thought 'curl | sh' had a personality.

exploitationtradecraftlinuxemail
The Hacker News / 2026-06-01T13:59:54+00:00Read Intel
criticalvulnerabilitysource excerpt

Critical Windows Netlogon RCE flaw now exploited in attacks

The Centre for Cybersecurity Belgium (CCB), the country's national authority for cybersecurity, warned on Friday that threat actors are now exploiting a recently patched critical Windows Netlogon vulnerability in attacks.

vulnerabilitywindows
BleepingComputer / 2026-06-01T12:30:27+00:00Read Intel
lowadvisorysource excerpt

China-Aligned Groups Ramp Up Attacks: Dragon Weave Hits Czech Republic & Taiwan

A new cyber espionage campaign codenamed Operation Dragon Weave has been observed targeting officials and citizens in the Czech Republic and Taiwan to deliver an AdaptixC2 agent. According to Seqrite Labs, targets of the campaign include government, research, academic, technology, and financial services sectors.

tradecraftemail
The Hacker News / 2026-06-01T11:54:24+00:00Read Intel
lowadvisorysource excerpt

OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack

Cybersecurity researchers have disclosed details of a new malicious supply chain campaign that's targeting developers using OpenAI Codex through a legitimate-looking remote web UI. The tool, named codexui-android, is advertised on GitHub and npm as a remote web UI for OpenAI Codex, attracting over 29,000 weekly downloads. The package is still available for download from the repository.

The Hacker News / 2026-06-01T09:31:15+00:00Read Intel
criticaladvisorysource excerpt

Critical WP Maps Pro Flaw Actively Exploited to Create Admin Accounts

Threat actors are attempting to actively exploit a critical security flaw impacting WP Maps Pro, a WordPress plugin that has had over 15,000 sales on the Envato Market, to create malicious administrator accounts on susceptible sites. WP Maps Pro allows site owners to embed customizable Google Maps and OpenStreetMap with markers, listings, and advanced location features on WordPress sites.

exploitation
The Hacker News / 2026-06-01T08:45:29+00:00Read Intel
lowadvisorysource excerpt

Dutch Authorities Dismantle Botnet Linked to 17 Million Infected Devices

Dutch authorities have announced the takedown of a botnet that enslaved millions of infected devices, including computers, tablets, smartphones, and IoT devices, to carry out malicious attacks. The bot network, per the Dutch Politie and the National Cyber Security Center (NCSC), consisted of at least 17 million infected devices.

The Hacker News / 2026-05-31T12:22:12+00:00Read Intel
mediumvulnerabilitysource excerpt

New CIFSwitch Linux flaw gives root on multiple distributions

A newly discovered local privilege escalation vulnerability dubbed 'CIFSwitch' in the Linux kernel could allow attackers to forge CIFS authentication key descriptions, abuse the kernel's key request mechanism, and gain root privileges.

vulnerabilitylinux
BleepingComputer / 2026-05-30T14:16:08+00:00Read Intel
mediumvulnerabilitysource excerpt

PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation

Palo Alto Networks has warned that a recently disclosed medium-severity security flaw impacting PAN-OS and Prisma Access has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-0257 (CVSS score: 7.8), refers to a case of authentication bypass that could be exploited by bad actors to set up VPN connections.

vulnerabilitycvenetwork
The Hacker News / 2026-05-30T06:41:26+00:00Read Intel
lowaptsource excerpt

Malicious npm packages abuse dependency confusion to profile developer environments

A dependency confusion campaign leveraged 33 malicious npm packages to collect reconnaissance data from developer and build environments. This report details the attack chain, observed tradecraft, and detection opportunities to help organizations identify and disrupt related activity.

apttradecraftdetectionwindowslinux
Microsoft Security Blog / 2026-05-30T00:06:20+00:00Read Intel
lowvulnerabilitysource excerpt

ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface

Cybersecurity researchers have disclosed details of a vulnerability in OpenAI ChatGPT that leverages the artificial intelligence (AI) assistant's implicit trust in Markdown links and images to trigger prompt injections and open the door to phishing attacks. The technique has been codenamed ChatGPhish by Permiso Security.

vulnerabilitytradecraftemail
The Hacker News / 2026-05-29T18:07:12+00:00Read Intel
lowaptsource excerpt

Typosquatted npm packages used to steal cloud and CI/CD secrets

The Mini Shai-Hulud campaign used malicious npm packages to target cloud and CI/CD credentials across developer environments. This report details the attack chain, detection opportunities, and mitigation guidance to help organizations identify and disrupt related activity. The post Typosquatted npm packages used to steal cloud and CI/CD secrets appeared first on Microsoft Security Blog .

aptmalwaretradecraftdetectionwindowscloud
Microsoft Security Blog / 2026-05-29T03:04:52+00:00Read Intel
lowvulnerabilitysource excerpt

Less panic patching, more precision

In this newsletter, Thor breaks down why you should stop relying solely on CVSS and start using EPSS and GCVE to focus your patching efforts on the threats that actually matter.

vulnerabilityexploitation
Cisco Talos / 2026-05-28T18:00:27+00:00Read Intel
mediumvulnerabilitysource excerpt

Hackers exploit FortiClient EMS flaw to push infostealer malware

Hackers are exploiting an authentication bypass vulnerability (CVE-2026-35616) in FortiClient Enterprise Management Server (EMS) to deliver an undocumented credential stealer called EKZ.

malwarevulnerabilitycveexploitation
BleepingComputer / 2026-05-28T17:25:43+00:00Read Intel
criticalvulnerabilitysource excerpt

Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code

A critical security vulnerability has been disclosed in Gogs, a popular open-source self-hosted Git service, that allows an authenticated user to execute arbitrary code under certain conditions. The security flaw, per Rapid7, is rated 9.4 on the CVSS scoring system. It does not have a CVE identifier.

vulnerability
The Hacker News / 2026-05-28T17:24:44+00:00Read Intel
criticalmalwaresource excerpt

Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer

Threat actors are continuing to exploit a critical, now-patched security flaw impacting FortiClient Endpoint Management Server (EMS) deployments to deliver credential-stealing malware. "The campaign abused trusted endpoint management infrastructure to deliver malware across managed endpoints," Arctic Wolf said.

malwareexploitation
The Hacker News / 2026-05-28T15:26:04+00:00Read Intel
highransomwaresource excerpt

The Gentlemen ransomware: Dissecting a self-propagating Go encryptor

Microsoft Threat Intelligence presents a comprehensive analysis of The Gentlemen, a Go-based ransomware deployed by affiliates of Storm-2697 that combines per-file ephemeral key encryption with an aggressive self-propagation module to deploy itself across an entire network using series of simultaneous lateral movement techniques per target.

ransomwareapttradecraftwindows
Microsoft Security Blog / 2026-05-28T15:00:00+00:00Read Intel
criticalransomwaresource excerpt

2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface

The 2026 World Cup presents major cyber risks from ransomware groups, state-aligned actors, and other groups targeting critical infrastructure. Learn more here. The post 2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface appeared first on Unit 42 .

ransomware
Unit 42 / 2026-05-28T10:00:53+00:00Read Intel
lowmalwaresource excerpt

GPU mining malware spreads via SEO poisoning, AI chatbots

Threat actors are targeting systems with high-performance computers in an ongoing cryptojacking campaign spread through a coordinated SEO poisoning operation that also manipulated AI chatbot recommendations.

malware
BleepingComputer / 2026-05-27T21:31:25+00:00Read Intel
highransomware

Reconstructing an Akira Ransomware Kill Chain from Perimeter and Endpoint Logs, (Wed, May 27th)

Most Akira write-ups focus on the ransom note or the encryption routine. By the time those show up the interesting forensic work is over. The questions that matter to defenders sit earlier. How did they get in. When did they get domain admin. What did they touch before the binary fired. Those answers live in the days before impact. They sit in two log sources that almost never get joined.

ransomwarewindowsnetwork
SANS ISC / 2026-05-27T21:14:03+00:00Read Intel
lowmalwaresource excerpt

Grandoreiro Malware and BTMOB RAT Campaigns Target Windows and Android Users

Latin America and Europe become the target of two banking trojan campaigns that are designed to infect Windows and Android devices with Grandoreiro and BTMOB malware, respectively. That's according to new findings from WatchGuard and ESET, which have observed the two malware families being used to single out companies in Spain, Portugal, and Mexico, as well as mobile users in Brazil.

malwarewindows
The Hacker News / 2026-05-27T16:10:21+00:00Read Intel
lowadvisorysource excerpt

Dutch police arrest man over cyber breach at Ajax football club

The suspect was detained in the central Dutch town of Buren, where law enforcement officers also searched his home and seized multiple digital storage devices, according to a statement released Tuesday by the Dutch National Police.

The Record / 2026-05-27T13:28:00+00:00Read Intel
lowmalwaresource excerpt

GlassWorm Malware Takedown Disrupts Developer Supply Chain Attack Infrastructure

CrowdStrike, in partnership with Google and the Shadowserver Foundation, has announced the simultaneous disruption of all command-and-control (C2) channels associated with GlassWorm, a persistent software chain campaign targeting software developers through malicious packages and extensions.

malware
The Hacker News / 2026-05-27T11:48:37+00:00Read Intel
mediumvulnerabilitysource excerpt

Gitea Vulnerability Exposes Private Container Images without Authentication

Cybersecurity researchers have disclosed a security flaw in Gitea, an open-source, self-hosted platform for version control, that allows unauthenticated remote attackers to pull private container images from Gitea deployments without requiring an account, password, or other credentials.

vulnerabilitycvecloud
The Hacker News / 2026-05-27T10:06:32+00:00Read Intel
criticalvulnerabilitysource excerpt

CISA gives feds 4 days to patch actively exploited cPanel plugin flaw

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given U.S. federal agencies four days to secure their servers against a critical vulnerability in the LiteSpeed cPanel user-end plugin, which is actively being exploited in attacks.

vulnerability
BleepingComputer / 2026-05-27T10:06:17+00:00Read Intel
criticalransomwaresource excerpt

From poisoned search results to GPU mining: A cryptojacking campaign abusing ScreenConnect and Microsoft .NET utilities

Microsoft exposes a cryptojacking campaign using SEO poisoning and ScreenConnect to target high-performance PCs, with malicious sites also surfaced through AI chatbots. The post From poisoned search results to GPU mining: A cryptojacking campaign abusing ScreenConnect and Microsoft .NET utilities appeared first on Microsoft Security Blog .

ransomwareapttradecraftwindowscloud
Microsoft Security Blog / 2026-05-26T21:35:34+00:00Read Intel
lowadvisorysource excerpt

New AI DDoS Attacks Are Smarter. Learn How to Fight Back in This Webinar

Every single day, hackers are finding new ways to crash websites and steal data. But right now, something has changed. Hackers are no longer working alone. They are now using powerful Artificial Intelligence (AI) tools to make their attacks faster, stronger, and much harder to stop.

The Hacker News / 2026-05-26T11:58:00+00:00Read Intel
mediumvulnerabilitysource excerpt

Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions

Microsoft has rolled out updates to fix a remote code execution vulnerability impacting SharePoint that could be exploited by bad actors in attacks without requiring any specialized conditions to be met. The vulnerability, tracked as CVE-2026-45659, carries a CVSS score of 8.8. It has been assigned an important severity.

vulnerabilitycve
The Hacker News / 2026-05-26T11:49:53+00:00Read Intel
criticaladvisorysource excerpt

MFA Prompt Bombing: Why Your Second Factor Isn't Saving You

Multi-factor authentication (MFA) was supposed to close a critical gap in identity security. It meant that, even if an attacker possessed the account credentials, they couldn't log in without the second factor. While that logic was sound, attackers have now figured out that they don't need to steal the second factor: they just need the user to hand it over.

identity
The Hacker News / 2026-05-26T10:30:00+00:00Read Intel
criticalvulnerabilitysource excerpt

CERT-In Mandates 12-Hour Patching for Internet-Facing Flaws Amid AI-Assisted Attacks

The Indian Computer Emergency Response Team (CERT-In) has issued new guidelines requiring organizations to patch critical security vulnerabilities in internet-exposed systems within 12 hours of being flagged where "feasible" to safeguard against potential threats stemming from threat actors' abuse of artificial intelligence (AI) tools and large language models (LLMs) to automate

vulnerability
The Hacker News / 2026-05-26T09:13:02+00:00Read Intel
highvulnerabilitysource excerpt

CISA orders feds to patch actively exploited Drupal vulnerability

CISA has given U.S. government agencies until Wednesday evening to secure their servers against an SQL injection vulnerability in the Drupal content management system (CMS) that it flagged as actively exploited.

vulnerability
BleepingComputer / 2026-05-26T08:46:45+00:00Read Intel
mediumvulnerabilitysource excerpt

KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt Strike

A now-patched high-severity security flaw affecting Digital Knowledge KnowledgeDeliver, a Learning Management System (LMS) popular in Japan, was exploited as a zero-day to deliver the Godzilla web shell and ultimately facilitate the deployment of Cobalt Strike Beacon.

vulnerabilitycve
The Hacker News / 2026-05-26T05:19:38+00:00Read Intel
criticalaptsource excerpt

Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability

Written by: Takahiro Sugiyama, Peter Revelant, Mathew Potaczek Introduction In late 2025, Mandiant responded to a security incident involving a compromised web server running KnowledgeDeliver . KnowledgeDeliver is a Learning Management System (LMS) developed by Digital Knowledge commonly used in Japan. Mandiant identified a critical vulnerability that allowed unauthenticated Remote Code Execution (RCE).

aptvulnerabilitycvetradecraftcloud
Mandiant / 2026-05-25T14:00:00+00:00Read Intel
lowmalwaresource excerpt

Lazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto Firms

Cybersecurity researchers have shed light on a cross-platform malware called RemotePE that has been put to use by the North Korea-linked Lazarus Group in attacks targeting financial and cryptocurrency organizations. RemotePE, per NCC Group subsidiary Fox-IT, is part of a multi-stage attack chain that involves two loaders tracked as DPAPILoader and RemotePELoader.

malware
The Hacker News / 2026-05-25T09:32:54+00:00Read Intel
lowmalwaresource excerpt

Laravel Lang packages hijacked to deploy credential-stealing malware

A supply chain attack targeting the Laravel Lang localization packages has exposed developers to a sophisticated credential-stealing malware campaign after attackers abused GitHub version tags to distribute malicious code through Composer packages.

malware
BleepingComputer / 2026-05-23T20:48:23+00:00Read Intel
lowmalwaresource excerpt

Packagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux Malware

A new "coordinated" supply chain attack campaign has impacted eight packages on Packagist including malicious code designed to run a Linux binary retrieved from a GitHub Releases URL. "Although the affected packages were all Composer packages, the malicious code was not added to composer.json," Socket said.

malwarelinux
The Hacker News / 2026-05-23T16:07:51+00:00Read Intel
mediumvulnerabilitysource excerpt

LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root

A maximum-severity security vulnerability impacting LiteSpeed User-End cPanel Plugin has come under active exploitation in the wild. The flaw, tracked as CVE-2026-48172 (CVSS score: 10.0), relates to an instance of incorrect privilege assignment that an attacker could abuse to run arbitrary scripts with elevated permissions.

vulnerabilitycve
The Hacker News / 2026-05-23T07:35:13+00:00Read Intel
criticalvulnerabilitysource excerpt

Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a recently patched critical security flaw impacting Drupal Core to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerability in question is CVE-2026-9082 (CVSS score: 6.5), an SQL injection vulnerability affecting all supported versions of Drupal Core.

vulnerabilitycve
The Hacker News / 2026-05-23T07:23:48+00:00Read Intel
criticalransomwaresource excerpt

First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups

Authorities in Europe and North America have announced the dismantling of a criminal virtual private network (VPN) service used by criminal actors to obscure the origins of ransomware attacks, data theft, scanning, and denial-of-service attacks.

ransomwarenetwork
The Hacker News / 2026-05-22T17:35:02+00:00Read Intel
lowadvisorysource excerpt

Microsoft recognized as a Leader in The Forrester Wave™ for Workforce Identity Security Platforms

Microsoft has been recognized as a Leader in The Forrester Wave™: Workforce Identity Security Platforms, Q2 2026, receiving the highest scores in both the current offering and strategy categories. The post Microsoft recognized as a Leader in The Forrester Wave™ for Workforce Identity Security Platforms appeared first on Microsoft Security Blog .

exploitationtradecraftdetectionidentityemail
Microsoft Security Blog / 2026-05-22T17:00:00+00:00Read Intel
criticalaptsource excerpt

From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5 and Confluence

A multi-stage attack on Linux devices began with an exposed F5 BIG-IP edge appliance and pivoted to an internal Confluence server for credential theft and identity compromise. Learn how the threat actor attempted Kerberos relay and lateral movement, and how Microsoft Defender detected, blocked, and unraveled the attack.

apttradecraftdetectionwindowslinuxcloud
Microsoft Security Blog / 2026-05-22T16:53:39+00:00Read Intel
criticaladvisorysource excerpt

Microsoft Security success stories: How St. Luke’s and ManpowerGroup are securing AI foundations

How Frontier firms secure AI at scale: read how Microsoft customers embed governance, identity, and cloud security to make protection an enabler of AI growth. The post Microsoft Security success stories: How St. Luke’s and ManpowerGroup are securing AI foundations appeared first on Microsoft Security Blog .

windowscloudidentityemail
Microsoft Security Blog / 2026-05-22T16:00:00+00:00Read Intel
lowvulnerabilitysource excerpt

Making Vulnerable Drivers Exploitable Without Hardware - The BYOVD Perspective

1 Introduction This article provides a technical analysis of how many Windows kernel mode drivers can be interacted with from user mode without the hardware they were developed for. This work was motivated by driver-oriented vulnerability research and the need to evaluate the exploitability of individual findings, which frequently affect code whose reachability is hardware-gated.

vulnerabilitywindows
The Hacker News / 2026-05-22T11:38:12+00:00Read Intel
lowadvisorysource excerpt

Kimwolf DDoS Botnet Operator Arrested in Canada Over DDoS-for-Hire Attacks

The U.S. Department of Justice (DoJ) on Thursday announced the arrest of a Canadian man in connection with allegedly operating a distributed denial-of-service (DDoS) botnet known as Kimwolf. In tandem, Jacob Butler (aka Dort), 23, Ottawa, Canada, has been charged with offenses related to the development and operation of the botnet. Kimwolf is assessed to be a variant of AISURU.

The Hacker News / 2026-05-22T08:50:18+00:00Read Intel
mediumvulnerabilitysource excerpt

Cisco Patches CVSS 10.0 Secure Workload REST API Flaw Enabling Data Access

Cisco has rolled out updates for a maximum-severity security flaw impacting Secure Workload that could allow an unauthenticated, remote attacker to access sensitive data. Tracked as CVE-2026-20223 (CVSS score: 10.0), the vulnerability arises from insufficient validation and authentication when accessing REST API endpoints.

vulnerabilitycveexploitation
The Hacker News / 2026-05-22T05:36:18+00:00Read Intel
lowadvisorysource excerpt

The art of being ungovernable

In this edition of the Threat Source newsletter, William explores the value of being "ungovernable" in a professional setting, sharing how challenging the status quo and seeking out the smartest people in the room can lead to a more fulfilling and successful career.

Cisco Talos / 2026-05-21T18:00:14+00:00Read Intel
lowadvisorysource excerpt

What’s new in Microsoft Security: May 2026

Microsoft Security’s latest updates extend visibility, control, and protection across expanding ecosystems as organizations accelerate AI adoption. The post What’s new in Microsoft Security: May 2026 appeared first on Microsoft Security Blog .

cloud
Microsoft Security Blog / 2026-05-21T16:00:00+00:00Read Intel
lowadvisory

Selective HTTP Proxying in Linux, (Thu, May 21st)

Recently, Rob wrote about a tool, Proxifier, that can intercept requests from specific processes. Proxifier is available for Windows, macOS, and Android. But I have not seen a generic Linux option yet. The advantage of a tool like Proxifier is the ability to target specific software.

windowslinux
SANS ISC / 2026-05-21T13:34:09+00:00Read Intel
lowadvisorysource excerpt

ThreatsDay Bulletin: Linux Rootkits, Router 0-Day, AI Intrusions, Scam Kits and 25 New Stories

This week starts small. A token leaks. A bad package slips in. A login trick works. An old tool shows up again. At first, it feels like the usual mess. Then you see the pattern: attackers are not always breaking in. They are using the parts we already trust. That is what makes it worrying. The danger is in normal things now - updates, apps, cloud buttons, support chats, trusted accounts.

linuxcloudnetwork
The Hacker News / 2026-05-21T11:52:14+00:00Read Intel
criticalvulnerabilitysource excerpt

Microsoft Warns of Two Actively Exploited Defender Vulnerabilities

Microsoft has disclosed that a privilege escalation and a denial-of-service flaw in Defender has come under active exploitation in the wild. The former, tracked as CVE-2026-41091, is rated 7.8 on the CVSS scoring system. Successful exploitation of the flaw could allow an attacker to gain SYSTEM privileges.

vulnerabilitycvewindows
The Hacker News / 2026-05-21T10:55:57+00:00Read Intel
lowadvisorysource excerpt

When Identity is the Attack Path

Consider a cached access key on a single Windows machine. It got there the way most cached credentials do - a user logged in, and the key stored itself automatically. Standard AWS behavior. No one misconfigured anything or violated a policy.

windowscloudidentity
The Hacker News / 2026-05-21T10:30:00+00:00Read Intel
criticalvulnerabilitysource excerpt

Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites to RCE Attacks

Drupal has released security updates for a "highly critical" security vulnerability in Drupal Core that could be exploited by attackers to achieve remote code execution, privilege escalation, or information disclosure. The vulnerability, now tracked as CVE-2026-9082, carries a CVSS score of 6.5 out of 10.0, per CVE.org.

vulnerabilitycve
The Hacker News / 2026-05-21T03:44:11+00:00Read Intel
lowadvisorysource excerpt

Xi and Putin pledge closer cooperation on AI, cyberspace and satellite systems

In a lengthy joint statement, Moscow and Beijing pledged closer cooperation on satellite internet technologies and joint work on software development and open-source initiatives — part of a broader effort to reduce reliance on Western technology and build a more independent technological ecosystem capable of competing with countries both states consider

The Record / 2026-05-20T23:00:00+00:00Read Intel
criticalaptsource excerpt

Mini Shai Hulud: Compromised @antv npm packages enable CI/CD credential theft

Compromised @antv npm packages deploy the Mini Shai-Hulud payload to steal CI/CD secrets from Linux-based automation environments. The malware executes during npm install and targets credentials across GitHub, AWS, Kubernetes, Vault, npm, and 1Password platforms. The post Mini Shai Hulud: Compromised @antv npm packages enable CI/CD credential theft appeared first on Microsoft Security Blog .

aptmalwarevulnerabilitylinuxcloud
Microsoft Security Blog / 2026-05-20T17:48:44+00:00Read Intel
lowadvisorysource excerpt

Securing the gaming culture of cultures

Read about the unique challenges and rewards of securing gaming platforms and how to better protect gaming communities. The post Securing the gaming culture of cultures appeared first on Microsoft Security Blog .

cloudidentity
Microsoft Security Blog / 2026-05-20T16:00:00+00:00Read Intel
lowadvisorysource excerpt

Introducing RAMPART and Clarity: Open source tools to bring safety into Agent development workflow

The AI systems shipping inside enterprises today are fundamentally different from the ones we were building even two years ago, because they have moved well past answering questions and into accessing your email, retrieving records from your CRM, writing and executing code, and taking actions on your behalf across dozens of connected systems.

email
Microsoft Security Blog / 2026-05-20T15:00:00+00:00Read Intel
highransomwaresource excerpt

Microsoft Takes Down Malware-Signing Service Behind Ransomware Attacks

Microsoft on Tuesday said it disrupted a malware-signing-as-a-service (MSaaS) operation that weaponized the company's Artifact Signing system to deliver malicious code and conduct ransomware and other attacks, compromising thousands of machines and networks across the world.

ransomwareaptmalwareexploitation
The Hacker News / 2026-05-20T14:36:44+00:00Read Intel
mediumvulnerabilitysource excerpt

Exploit released for new PinTheft Arch Linux root escalation flaw

PinTheft, a recently patched Linux privilege escalation vulnerability, now has a publicly available proof-of-concept (PoC) exploit that allows local attackers to gain root privileges on Arch Linux systems.

vulnerabilityexploitationlinux
BleepingComputer / 2026-05-20T10:52:31+00:00Read Intel
lowadvisorysource excerpt

Typosquatting Is No Longer a User Problem. It's a Supply Chain Problem

AI-generated lookalike domains are now embedded inside the third-party scripts running on your web properties. Here's why your current stack can't see them, and what detection actually requires. Download the CISO Expert Guide to Typosquatting in the AI Era → TL;DR Typosquatting is no longer a user problem. Attackers now embed lookalike domains inside legitimate third-party scripts.

detection
The Hacker News / 2026-05-20T10:30:00+00:00Read Intel
lowmalwaresource excerpt

Tracking TamperedChef Clusters via Certificate and Code Reuse

Unit 42 analyzes TamperedChef malware clusters that use trojanized productivity apps and malvertising to deliver stealthy payloads to targets. The post Tracking TamperedChef Clusters via Certificate and Code Reuse appeared first on Unit 42 .

malware
Unit 42 / 2026-05-20T10:00:46+00:00Read Intel
mediumvulnerabilitysource excerpt

Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit

Microsoft on Tuesday released a mitigation for a BitLocker bypass vulnerability named YellowKey following its public disclosure last week. The zero-day flaw, now tracked as CVE-2026-45585, carries a CVSS score of 6.8. It has been described as a BitLocker security feature bypass.

vulnerabilitycveexploitationwindows
The Hacker News / 2026-05-20T08:28:26+00:00Read Intel
lowadvisorysource excerpt

Grafana GitHub Breach Exposes Source Code via TanStack npm Attack

Grafana Labs, on May 19, 2026, said an investigation into its recent breach found no evidence of customer production systems or operations being compromised. It said the scope of the incident is limited to the Grafana Labs GitHub environment, which includes public and private source code along with internal GitHub repositories.

The Hacker News / 2026-05-20T05:12:06+00:00Read Intel
lowadvisorysource excerpt

What Will Make AI BOMs Real?

A brief overview of the forces at play that will get more organizations on board with creating and consuming AI bill of materials (BOM).

Dark Reading / 2026-05-19T22:17:55+00:00Read Intel
highvulnerabilitysource excerpt

TP-Link, Photoshop, OpenVPN, Norton VPN vulnerabilities

Cisco Talos’ Vulnerability Discovery & Research team recently disclosed eight vulnerabilities in TP-Link, and one each in Adobe Photoshop, OpenVPN, and Gen Digital's Norton VPN.

vulnerabilitycvedetectionnetwork
Cisco Talos / 2026-05-19T15:39:37+00:00Read Intel
highransomwaresource excerpt

Exposing Fox Tempest: A malware-signing service operation

Fox Tempest is a financially motivated threat actor operating a malware‑signing‑as‑a‑service (MSaaS) used by other cybercriminals, including Vanilla Tempest and Storm groups, to more effectively distribute malicious code, including ransomware. The post Exposing Fox Tempest: A malware-signing service operation appeared first on Microsoft Security Blog .

ransomwareaptmalwarewindowscloudnetwork
Microsoft Security Blog / 2026-05-19T15:07:01+00:00Read Intel
lowadvisorysource excerpt

Looking Back, Looking Forward: Digesting a Dynamic Bouillabaisse of Cyber Evolution

Dark Reading editors reflect on two decades of dramatic change — from perimeter defense to assume-breach strategies — and warn that while AI, cloud, and COVID-19 have transformed the threat landscape, organizations are still failing at fundamental security hygiene that could stop sophisticated attacks in their tracks.

cloud
Dark Reading / 2026-05-19T13:28:43+00:00Read Intel
lowadvisorysource excerpt

Drupal to Release Urgent Core Security Updates on May 20, Sites Told to Prepare

Drupal has issued an alert stating that it intends to release a "core security release" for all supported branches on May 20, 2026, from 5-9 p.m. UTC. "The Drupal Security Team urges you to reserve time for core updates at that time because exploits might be developed within hours or days," the maintainers of the PHP-based content management system (CMS) said.

The Hacker News / 2026-05-19T10:44:45+00:00Read Intel
criticalvulnerabilitysource excerpt

SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access

Critical security vulnerabilities have been disclosed in SEPPMail Secure E-Mail Gateway, an enterprise-grade email security solution, that could be exploited to achieve remote code execution and enable an attacker to read arbitrary mails from the virtual appliance.

vulnerabilitynetworkemail
The Hacker News / 2026-05-19T09:23:15+00:00Read Intel
mediumaptsource excerpt

How Storm-2949 turned a compromised identity into a cloud-wide breach

Storm-2949 turned stolen credentials into a cloud-wide breach, moving from identity compromise to large-scale data theft without using malware. This incident shows how threat actors can exploit trusted systems to operate undetected. The post How Storm-2949 turned a compromised identity into a cloud-wide breach appeared first on Microsoft Security Blog .

aptmalwareexploitationtradecraftwindowscloud
Microsoft Security Blog / 2026-05-18T22:42:50+00:00Read Intel
highransomwaresource excerpt

How to better protect your growing business in an AI-powered world

See how built-in security helps keep your growing business running, protect customer trust, and support growth. The post How to better protect your growing business in an AI-powered world appeared first on Microsoft Security Blog .

ransomwaremalwaretradecraftcloudemail
Microsoft Security Blog / 2026-05-18T16:00:00+00:00Read Intel
lowmalwaresource excerpt

⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More

Monday opens with a trust problem. A mail server flaw is under active use. A network control system was targeted. Trusted packages were poisoned. A fake model page pushed a stealer. Then came the familiar ransom claim: the data was returned and deleted. The pattern is clear. One weak dependency can leak keys. One leaked key can open cloud access.

malwareexploitationcloud
The Hacker News / 2026-05-18T13:50:17+00:00Read Intel
lowadvisorysource excerpt

How to Reduce Phishing Exposure Before It Turns into Business Disruption

What happens when a phishing email looks clean enough to pass through security, but dangerous enough to expose the business after one click? That is the gap many SOCs still struggle with: the attacks that leave teams unsure what was exposed, who else was targeted, and how far the risk has spread. Early phishing detection closes that gap.

tradecraftdetectionemail
The Hacker News / 2026-05-18T13:00:00+00:00Read Intel
lowadvisorysource excerpt

The Boring Stuff is Dangerous Now

AI agents capable of discovering and exploiting obscure vulnerabilities are emerging alongside developers producing vast amounts of potentially flawed AI-generated code, forcing defenders to adapt accordingly.

Dark Reading / 2026-05-18T13:00:00+00:00Read Intel
highransomwaresource excerpt

IT threat evolution in Q1 2026. Mobile statistics

This report contains mobile threat statistics for Q1 2026, along with noteworthy discoveries and quarterly trends: new versions of SparkCat and Triada.

ransomwaremalware
Securelist / 2026-05-18T12:00:30+00:00Read Intel
criticalransomwaresource excerpt

IT threat evolution in Q1 2026. Non-mobile statistics

The report presents key trends and statistics on malware that targeted personal computers running Windows and macOS, as well as Internet of Things (IoT) devices, during Q1 2026.

ransomwareaptmalwarevulnerabilitycvedetection
Securelist / 2026-05-18T12:00:22+00:00Read Intel
lowadvisorysource excerpt

Developer Workstations Are Now Part of the Software Supply Chain

Supply chain attackers are not only trying to slip malicious code into trusted software. They are trying to steal the access that makes trusted software possible. Recently, three separate campaigns hit npm, PyPI, and Docker Hub in a 48-hour window, and all three targeted secrets from developer environments and CI/CD pipelines, including API keys, cloud credentials, SSH keys, and tokens.

cloud
The Hacker News / 2026-05-18T11:23:41+00:00Read Intel
criticalvulnerabilitysource excerpt

Ivanti, Fortinet, SAP, VMware, n8n Patch RCE, SQL Injection, Privilege Escalation Flaws

Ivanti, Fortinet, n8n, SAP, and VMware have released security fixes for various vulnerabilities that could be exploited by bad actors to bypass authentication and execute arbitrary code. Topping the list is a critical flaw impacting Ivanti Xtraction (CVE-2026-8043, CVSS score: 9.6) that could be exploited to achieve information disclosure or client-side attacks.

vulnerabilitycve
The Hacker News / 2026-05-18T10:54:05+00:00Read Intel
mediumvulnerabilitysource excerpt

MiniPlasma Windows 0-Day Enables SYSTEM Privilege Escalation on Fully Patched Systems

Chaotic Eclipse, the security researcher behind the recently disclosed Windows flaws, YellowKey and GreenPlasma, has released a proof-of-concept (PoC) for a Windows privilege escalation zero-day flaw that grants attackers SYSTEM privileges on fully patched Windows systems.

vulnerabilityexploitationwindowscloud
The Hacker News / 2026-05-18T08:57:34+00:00Read Intel
lowmalwaresource excerpt

Pre-Stuxnet Fast16 Malware Tampered with Nuclear Weapons Simulations

A new analysis of the Lua-based fast16 malware has confirmed that it was a cyber sabotage tool designed to tamper with nuclear weapons testing simulations. According to Broadcom-owned Symantec and Carbon Black teams, the pre-Stuxnet tool was engineered to corrupt uranium-compression simulations that are central to nuclear weapon design.

malware
The Hacker News / 2026-05-18T06:46:37+00:00Read Intel
mediumvulnerabilitysource excerpt

NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE

A newly disclosed security flaw impacting NGINX Plus and NGINX Open has come under active exploitation in the wild, days after its public disclosure, according to VulnCheck. The vulnerability, tracked as CVE-2026-42945 (CVSS score: 9.2), is a heap buffer overflow in ngx_http_rewrite_module affecting NGINX versions 0.6.27 through 1.30.0.

vulnerabilitycve
The Hacker News / 2026-05-17T11:57:53+00:00Read Intel
criticalvulnerabilitysource excerpt

Microsoft rejects critical Azure vulnerability report, no CVE issued

A security researcher claims Microsoft quietly fixed an Azure Backup for AKS vulnerability after rejecting his report, and without issuing a CVE. Microsoft disputes the claim, telling BleepingComputer the behavior was expected and that "no product changes were made," despite the researcher documenting a silent fix.

vulnerabilitycloud
BleepingComputer / 2026-05-16T20:55:44+00:00Read Intel
criticalvulnerabilitysource excerpt

Funnel Builder Flaw Under Active Exploitation Enables WooCommerce Checkout Skimming

A critical security vulnerability impacting the Funnel Builder plugin for WordPress has come under active exploitation in the wild to inject malicious JavaScript code into WooCommerce checkout pages with the goal of stealing payment data. Details of the activity were published by Sansec this week. The vulnerability currently does not have an official CVE identifier.

vulnerability
The Hacker News / 2026-05-16T15:20:48+00:00Read Intel
lowvulnerabilitysource excerpt

Microsoft Exchange, Windows 11 hacked on second day of Pwn2Own

​During the second day of Pwn2Own Berlin 2026, competitors collected $385,750 in cash awards after exploiting 15 unique zero-day vulnerabilities in multiple products, including Windows 11, Microsoft Exchange, and Red Hat Enterprise Linux for Workstations.

vulnerabilitywindowslinux
BleepingComputer / 2026-05-15T17:47:25+00:00Read Intel
criticalaptsource excerpt

Welcome to BlackFile: Inside a Vishing Extortion Operation

Written by: Austin Larsen, Tyler McLellan, Genevieve Stark, Dan Ebreo Introduction Google Threat Intelligence Group (GTIG) has continued to track an expansive extortion campaign by UNC6671, a threat actor operating under the "BlackFile" brand, that targets organizations via sophisticated voice phishing (vishing) and single sign-on (SSO) compromise.

aptvulnerabilitytradecraftwindowscloudidentity
Mandiant / 2026-05-15T14:00:00+00:00Read Intel
mediumtradecraftsource excerpt

Four OpenClaw Flaws Enable Data Theft, Privilege Escalation, and Persistence

Cybersecurity researchers have disclosed a set of four security flaws in OpenClaw that could be chained to achieve data theft, privilege escalation, and persistence. The vulnerabilities, collectively dubbed Claw Chain by Cyera, can permit an attacker to establish a foothold, expose sensitive data, and plant backdoors.

vulnerabilitytradecraft
The Hacker News / 2026-05-15T13:35:04+00:00Read Intel
lowmalwaresource excerpt

What 45 Days of Watching Your Own Tools Will Tell You About Your Real Attack Surface

In Your Biggest Security Risk Isn't Malware — It's What You Already Trust, we made a simple argument: the most dangerous activity inside most organizations no longer looks like an attack. It looks like administration. PowerShell, WMIC, netsh, Certutil, MSBuild — the same trusted utilities your IT team uses every day are also the preferred toolkit of modern threat actors.

malwarewindows
The Hacker News / 2026-05-15T11:00:00+00:00Read Intel
lowvulnerabilitysource excerpt

Microsoft warns of Exchange zero-day flaw exploited in attacks

On Thursday, Microsoft shared mitigations for a high-severity Exchange Server vulnerability exploited in attacks that allow threat actors to execute arbitrary code via cross-site scripting (XSS) while targeting Outlook on the web users.

vulnerability
BleepingComputer / 2026-05-15T09:40:42+00:00Read Intel
mediumvulnerabilitysource excerpt

On-Prem Microsoft Exchange Server CVE-2026-42897 Exploited via Crafted Email

Microsoft has disclosed a new security vulnerability impacting on-premise versions of Exchange Server that it said has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-42897 (CVSS score: 8.1), has been described as a spoofing bug stemming from a cross-site scripting flaw. An anonymous researcher has been credited with discovering and reporting the issue.

vulnerabilitycveemail
The Hacker News / 2026-05-15T06:19:04+00:00Read Intel
criticalvulnerabilitysource excerpt

CISA Adds Cisco SD-WAN CVE-2026-20182 to KEV After Admin Access Exploits

The U.S.Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly disclosed vulnerability impacting Cisco Catalyst SD-WAN Controller to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to remediate the issue by May 17, 2026. The vulnerability is a critical authentication bypass tracked as CVE-2026-20182.

vulnerabilitycve
The Hacker News / 2026-05-15T05:28:03+00:00Read Intel
lowadvisorysource excerpt

Congress Puts Heat on Instructure After Canvas Outage

The House Committee on Homeland Security sent a letter about the Canvas cyberattack, the same day that the edtech company said it reached an "agreement" with the ShinyHunters cybercriminals.

Dark Reading / 2026-05-14T20:19:20+00:00Read Intel
criticalvulnerabilitysource excerpt

Cisco warns of new critical SD-WAN flaw exploited in zero-day attacks

Cisco is warning that a critical Catalyst SD-WAN Controller authentication bypass flaw, tracked as CVE-2026-20182, was actively exploited in zero-day attacks that allowed attackers to gain administrative privileges on compromised devices.

vulnerabilitycve
BleepingComputer / 2026-05-14T20:09:56+00:00Read Intel
lowadvisorysource excerpt

OpenAI confirms security breach in TanStack supply chain attack

OpenAI says two employees' devices were breached in the recent TanStack supply chain attack that impacted hundreds of npm and PyPI packages, causing the company to rotate code-signing certificates for its applications as a precaution.

BleepingComputer / 2026-05-14T19:07:24+00:00Read Intel
highransomwaresource excerpt

The time of much patching is coming

In this week’s newsletter, Martin reflects on what the next iteration of AI tools means for vulnerability discovery and our ability to manage large-scale patch releases.

ransomwareaptvulnerability
Cisco Talos / 2026-05-14T18:00:24+00:00Read Intel
mediumvulnerabilitysource excerpt

ThreatsDay Bulletin: PAN-OS RCE, Mythos cURL Bug, AI Tokenizer Attacks, and 10+ Stories

Everything is still on fire. This week feels dumb in the worst way — bad links, weak checks, fake help desks, shady forum posts, and people turning supply chain attacks into some cursed little game for clout and cash. Half of it feels new. Half of it feels like crap we should have fixed years ago.

vulnerability
The Hacker News / 2026-05-14T16:07:46+00:00Read Intel
highaptsource excerpt

Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities

Cisco Talos is tracking the active exploitation of CVE-2026-20182, an authentication bypass vulnerability in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage.

aptvulnerabilitycvedetection
Cisco Talos / 2026-05-14T16:02:36+00:00Read Intel
lowadvisorysource excerpt

Defense in depth for autonomous AI agents

As AI agents gain autonomy, defense in depth must evolve, with application-layer design, identity, and human oversight at the center. The post Defense in depth for autonomous AI agents appeared first on Microsoft Security Blog .

identity
Microsoft Security Blog / 2026-05-14T16:00:00+00:00Read Intel
mediumvulnerabilitysource excerpt

18-year-old NGINX vulnerability allows DoS, potential RCE

An 18-year-old flaw in the NGINX open-source web server, discovered using an autonomous scanning system, can be exploited for denial of service and, under certain conditions, remote code execution.

vulnerability
BleepingComputer / 2026-05-14T15:43:41+00:00Read Intel
lowaptsource excerpt

Kazuar: Anatomy of a nation-state botnet

Kazuar, a sophisticated malware family attributed to the Russian state actor Secret Blizzard, has been under constant development for years and continues to evolve in support of espionage-focused operations. Over time, Kazuar has expanded from a relatively traditional backdoor into a highly modular peer-to-peer (P2P) botnet ecosystem designed to enable persistent, covert access to target environments.

aptmalwaredetectionwindows
Microsoft Security Blog / 2026-05-14T15:00:00+00:00Read Intel
criticalvulnerabilitysource excerpt

When configuration becomes a vulnerability: Exploitable misconfigurations in AI apps

Exposed UIs, weak authentication, and risky defaults could turn cloud-native AI apps on Kubernetes into potential targets by threat actors. Learn how exploitable misconfigurations lead to RCE and data leaks. The post When configuration becomes a vulnerability: Exploitable misconfigurations in AI apps appeared first on Microsoft Security Blog .

vulnerabilitywindowscloud
Microsoft Security Blog / 2026-05-14T14:20:55+00:00Read Intel
lowadvisorysource excerpt

Ghostwriter Targets Ukrainian Government With Geofenced PDF Phishing, Cobalt Strike

The Belarus-aligned threat group known as Ghostwriter has been attributed to a fresh set of attacks targeting governmental organizations in Ukraine. Active since at least 2016, Ghostwriter has been linked to both cyber espionage and influence operations targeting neighboring countries, particularly Ukraine.

tradecraftemail
The Hacker News / 2026-05-14T14:00:37+00:00Read Intel
highransomwaresource excerpt

Foxconn Attack Highlights Manufacturing's Cyber Crisis

A Nitrogen ransomware attack on Foxconn's North American facilities is one of 600 hits on manufacturers this year, as gangs increasingly target the sector for its low tolerance for downtime.

ransomware
Dark Reading / 2026-05-14T12:00:00+00:00Read Intel
criticaladvisorysource excerpt

How AI Hallucinations Are Creating Real Security Risks

AI hallucinations are introducing serious security risks into critical infrastructure decision-making by exploiting human trust through highly confident yet incorrect outputs. When an AI model lacks certainty, it doesn’t have a mechanism to recognize that. Instead, it generates the most probable response based on patterns in its training data, even if that response is inaccurate.

The Hacker News / 2026-05-14T11:30:00+00:00Read Intel
mediumadvisorysource excerpt

Windows Zero-Days Expose BitLocker Bypasses And CTFMON Privilege Escalation

An anonymous cybersecurity researcher who disclosed three Microsoft Defender vulnerabilities has returned with two more zero-days involving a BitLocker bypass and a privilege escalation impacting Windows Collaborative Translation Framework (CTFMON).

vulnerabilitywindows
The Hacker News / 2026-05-14T09:25:50+00:00Read Intel
mediumvulnerabilitysource excerpt

New Fragnesia Linux flaw lets attackers gain root privileges

Linux distros are rolling out patches for a new high-severity kernel privilege escalation vulnerability (known as Fragnasia and tracked as CVE-2026-46300) that allows attackers to run malicious code as root.

vulnerabilitycvelinux
BleepingComputer / 2026-05-14T07:34:19+00:00Read Intel
mediumvulnerabilitysource excerpt

New Fragnesia Linux Kernel LPE Grants Root Access via Page Cache Corruption

Details have emerged about a new variant of the recent Dirty Frag Linux local privilege escalation (LPE) vulnerability that allows local attackers to gain root access, making it the third such bug to be identified in the kernel within a span of two weeks.

vulnerabilitycvelinux
The Hacker News / 2026-05-14T07:06:15+00:00Read Intel
criticalvulnerabilitysource excerpt

New critical Exim mailer flaw allows remote code execution

A critical vulnerability affecting certain configurations of the Exim open-source mail transfer agent could be exploited by an unauthenticated remote attacker to execute arbitrary code.

vulnerability
BleepingComputer / 2026-05-13T20:23:50+00:00Read Intel
lowadvisorysource excerpt

Webinar tomorrow: Why security alone won't stop modern attacks

Tomorrow's webinar examines why prevention alone is no longer enough against modern cyberattacks. The session explores how organizations combine security, backups, and recovery planning to improve cyber resilience after attacks.

BleepingComputer / 2026-05-13T15:45:56+00:00Read Intel
lowvulnerabilitysource excerpt

Microsoft's MDASH AI System Finds 16 Windows Flaws Fixed in Patch Tuesday

Microsoft has unveiled a new multi-model artificial intelligence (AI)-driven system called MDASH to facilitate vulnerability discovery and remediation at scale, adding that it's being tested by some customers as part of a limited private preview.

vulnerabilitywindows
The Hacker News / 2026-05-13T13:46:02+00:00Read Intel
lowadvisorysource excerpt

[Webinar] How Modern Attack Paths Cross Code, Pipelines, and Cloud

TL;DR: Stop chasing thousands of "toast" alerts. Join experts from Wiz to learn how hackers connect tiny flaws to build a "Lethal Chain" to your data—and how to break it. Register for the Strategic Briefing Here. Most security tools work like a smoke alarm that goes off every time you burn a piece of toast. You get so many alerts that you eventually start to ignore them. The real danger?

cloud
The Hacker News / 2026-05-13T11:52:43+00:00Read Intel
lowadvisorysource excerpt

Most Remediation Programs Never Confirm the Fix Actually Worked

Security teams have never had better visibility into their environments and never been worse at confirming what they fix stays fixed. Mandiant's M-Trends 2026 report puts the mean time to exploit at an estimated negative seven days. The Verizon 2025 DBIR puts median time to remediate edge device vulnerabilities at 32 days.

exploitation
The Hacker News / 2026-05-13T11:30:00+00:00Read Intel
criticalvulnerabilitysource excerpt

Microsoft Patches 138 Vulnerabilities, Including DNS and Netlogon RCE Flaws

Microsoft on Tuesday released patches for 138 security vulnerabilities spanning its product portfolio, although none of them have been listed as publicly known or under active attack. Of the 138 flaws, 30 are rated Critical, 104 are rated Important, three are rated Moderate, and one is rated Low in severity.

vulnerability
The Hacker News / 2026-05-13T10:36:10+00:00Read Intel
criticalvulnerabilitysource excerpt

Breaking things to keep them safe with Philippe Laulheret

Philippe shares his unique journey from French engineering school to the front lines of cybersecurity, explaining how his lifelong love for solving puzzles helps him uncover critical security flaws before they can be exploited.

vulnerabilityexploitationdetection
Cisco Talos / 2026-05-13T10:00:54+00:00Read Intel
lowmalwaresource excerpt

GemStuffer Abuses 150+ RubyGems to Exfiltrate Scraped U.K. Council Portal Data

Cybersecurity researchers are calling attention to a new campaign dubbed GemStuffer that has targeted the RubyGems repository with more than 150 gems that use the registry as a data exfiltration channel rather than for malware distribution. "The packages do not appear designed for mass developer compromise," Socket said.

malware
The Hacker News / 2026-05-13T08:08:54+00:00Read Intel
lowadvisorysource excerpt

Android Adds Intrusion Logging for Sophisticated Spyware Forensics

Google on Tuesday unveiled a new opt-in Android feature called Intrusion Logging for storing forensic logs to better analyze sophisticated spyware attacks. Intrusion Logging, available as part of Advanced Protection Mode, enables "persistent and privacy-preserving forensics logging to allow for investigation of devices in the event of a suspected compromise," the company said.

The Hacker News / 2026-05-13T06:55:42+00:00Read Intel
lowadvisorysource excerpt

US govt seeks Instructure testimony on massive Canvas cyberattack

The U.S. House Committee on Homeland Security is calling on Instructure executives to testify about two cyberattacks by the ShinyHunters extortion group that targeted the company's Canvas platform, allowing threat actors to steal student data and disrupt schools during final exams.

BleepingComputer / 2026-05-12T23:09:55+00:00Read Intel
lowadvisorysource excerpt

Accelerating detection engineering using AI-assisted synthetic attack logs generation

What if you could generate realistic attack telemetry on demand? Explore research methods that translate attacker behaviors (TTPs) into synthetic logs that can trigger detections at scale and without sensitive data. The post Accelerating detection engineering using AI-assisted synthetic attack logs generation appeared first on Microsoft Security Blog .

detectionwindowscloud
Microsoft Security Blog / 2026-05-12T22:53:09+00:00Read Intel
criticalvulnerabilitysource excerpt

Defense at AI speed: Microsoft’s new multi-model agentic security system finds 16 new vulnerabilities

Today Microsoft is announcing a major step forward in AI-powered cyber defense: a new multi-model agentic scanning harness (codenamed MDASH). The post Defense at AI speed: Microsoft’s new multi-model agentic security system finds 16 new vulnerabilities appeared first on Microsoft Security Blog .

vulnerabilitycvewindows
Microsoft Security Blog / 2026-05-12T22:00:00+00:00Read Intel
criticalvulnerabilitysource excerpt

Defense at AI speed: Microsoft’s new multi-model agentic security system tops leading industry benchmark

Today Microsoft is announcing a major step forward in AI-powered cyber defense: a new multi-model agentic scanning harness (codenamed MDASH). The post Defense at AI speed: Microsoft’s new multi-model agentic security system tops leading industry benchmark appeared first on Microsoft Security Blog .

vulnerabilitycvewindows
Microsoft Security Blog / 2026-05-12T22:00:00+00:00Read Intel
lowadvisorysource excerpt

Foxconn confirms cyberattack impacting North American factories

A spokesperson for the company confirmed the incident but declined to provide specifics on how many factories in North America were impacted. Foxconn has factories in Wisconsin, Ohio, Texas, Virginia, Indiana and several across Mexico.

The Record / 2026-05-12T19:57:00+00:00Read Intel
mediumvulnerabilitysource excerpt

New Exim BDAT Vulnerability Exposes GnuTLS Builds to Potential Code Execution

Exim has released security updates to address a severe security issue affecting certain configurations that could enable memory corruption and potential code execution. Exim is an open-source Mail Transfer Agent (MTA) designed for Unix-like systems to receive, route, and deliver email.

vulnerabilitycveemail
The Hacker News / 2026-05-12T16:44:00+00:00Read Intel
lowmalwaresource excerpt

Defending consumer web properties against modern DDoS attacks

Read how to protect consumer websites and defend against modern DDoS attacks with layered security, resilient architecture, and graceful service degradation. The post Defending consumer web properties against modern DDoS attacks appeared first on Microsoft Security Blog .

malwareotcloudidentity
Microsoft Security Blog / 2026-05-12T16:00:00+00:00Read Intel
lowaptsource excerpt

Undermining the trust boundary: Investigating a stealthy intrusion through third-party compromise

Microsoft Incident Response investigated an attack operated through legitimate and trusted administrative mechanisms to blend seamlessly into routine operations and remain undetected demonstrating that intrusions have increasingly avoided using noisy exploits, obvious malware, or custom tooling, instead leveraging systems that organizations already trust within their environments.

aptmalwarevulnerabilitydetectionwindowsidentity
Microsoft Security Blog / 2026-05-12T15:00:00+00:00Read Intel
lowadvisorysource excerpt

RubyGems Suspends New Signups After Hundreds of Malicious Packages Are Uploaded

RubyGems, the standard package manager for the Ruby programming language, has temporarily paused account sign ups following what has been described as a "major malicious attack." "We're dealing with a major malicious attack on Ruby Gems right now," Maciej Mensfeld, senior product manager for software supply chain security at Mend.io, said in a post on X. "Signups are paused for the time being.

The Hacker News / 2026-05-12T14:47:00+00:00Read Intel
criticaladvisorysource excerpt

SAP fixes critical vulnerabilities in Commerce Cloud and S/4HANA

SAP has released the May 2026 security updates addressing 15 vulnerabilities across multiple products, including two critical flaws in the Commerce Cloud enterprise-grade e-commerce platform and the S/4HANA ERP suite.

cloud
BleepingComputer / 2026-05-12T11:04:55+00:00Read Intel
highransomwaresource excerpt

State-sponsored actors, better known as the friends you don’t want

Responding to a state-sponsored threat is nothing like responding to ransomware, and the differences can make or break the outcome. Learn why your IR plan might need revisiting, and the factors you should consider.

ransomwareaptmalwaredetectionotcloud
Cisco Talos / 2026-05-12T10:00:54+00:00Read Intel
highransomwaresource excerpt

State of ransomware in 2026

Kaspersky researchers are sharing insights into the main ransomware trends for 2026: EDR killers on the rise, switching from data encryption to data leaks, and more.

ransomwaretradecraft
Securelist / 2026-05-12T07:00:04+00:00Read Intel
lowadvisorysource excerpt

New GhostLock tool abuses Windows API to block file access

A security researcher has released a proof-of-concept tool named GhostLock that demonstrates how a legitimate Windows file API can be abused in attacks to block access to files stored locally or on SMB network shares.

windows
BleepingComputer / 2026-05-11T22:02:00+00:00Read Intel
lowadvisorysource excerpt

Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools

Unit 42 analyzes AD CS exploitation through template misconfigurations and shadow credential misuse while offering behavioral detection for defenders. The post Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools appeared first on Unit 42 .

detection
Unit 42 / 2026-05-11T22:00:43+00:00Read Intel
lowadvisorysource excerpt

TeamPCP Compromises Checkmarx Jenkins AST Plugin Weeks After KICS Supply Chain Attack

Checkmarx has confirmed that a modified version of the Jenkins AST plugin was published to the Jenkins Marketplace. "If you are using Checkmarx Jenkins AST plugin, you need to ensure that you are using the version 2.0.13-829.vc72453fa_1c16 that was published on December 17, 2025 or previously," the cybersecurity company said in a statement over the weekend.

The Hacker News / 2026-05-11T18:30:00+00:00Read Intel
lowaptsource excerpt

Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation

Google on Monday disclosed that it identified an unknown threat actor using a zero-day exploit that it said was likely developed with an artificial intelligence (AI) system, marking the first time the technology has been put to use in the wild in a malicious context for vulnerability discovery and exploit generation.

aptvulnerabilityexploitation
The Hacker News / 2026-05-11T15:45:00+00:00Read Intel
lowadvisory

Why we use CAPTCHAs, (Mon, May 11th)

A few months ago, I implemented Cloudflare&&#x23&#x3b;x26&#x3b;&#x23&#x3b;39&#x3b;s Turnstile CAPTCHA on some pages. The reason for implementing these CAPTCHAs is obvious: Bots make up a large percentage of traffic and affect site performance.

SANS ISC / 2026-05-11T14:20:16+00:00Read Intel
lowaptsource excerpt

GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access

Executive Summary Since our February 2026 report on AI-related threat activity, Google Threat Intelligence Group (GTIG) has continued to track a maturing transition from nascent AI-enabled operations to the industrial-scale application of generative models within adversarial workflows.

aptmalwarevulnerabilityexploitationotcloud
Mandiant / 2026-05-11T14:00:00+00:00Read Intel
lowadvisorysource excerpt

Your Purple Team Isn't Purple — It's Just Red and Blue in the Same Room

Defending a network at 2 am looks a lot like this: an analyst copy-pasting a hash from a PDF into a SIEM query. A red team script is being rewritten by hand so the blue team can use it. A patch waiting on a change-approval window that's longer than the exploitation window itself. Nobody in that chain is incompetent. Every human is doing their job correctly.

The Hacker News / 2026-05-11T11:30:00+00:00Read Intel
lowmalwaresource excerpt

TrickMo Android banker adopts TON blockchain for covert comms

A new variant of the TrickMo Android banking malware, delivered in campaigns targeting users across Europe, introduces new commands and uses The Open Network (TON) for stealthy command-and-control communications.

malware
BleepingComputer / 2026-05-11T09:03:02+00:00Read Intel
lowmalwaresource excerpt

Hackers abuse Google ads, Claude.ai chats to push Mac malware

Attackers are abusing Google Ads and legitimate Claude.ai shared chats in an active malvertising campaign. Users searching for "Claude mac download" may come across sponsored search results that list claude.ai as the target website, but lead to instructions that install malware on their Mac.

malware
BleepingComputer / 2026-05-10T17:52:15+00:00Read Intel
criticalvulnerabilitysource excerpt

Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak

Cybersecurity researchers have disclosed a critical security vulnerability in Ollama that, if successfully exploited, could allow a remote, unauthenticated attacker to leak its entire process memory. The out-of-bounds read flaw, which likely impacts over 300,000 servers globally, is tracked as CVE-2026-7482 (CVSS score: 9.1). It has been codenamed Bleeding Llama by Cyera.

vulnerabilitycve
The Hacker News / 2026-05-10T12:41:00+00:00Read Intel
mediumvulnerabilitysource excerpt

Active attack: Dirty Frag Linux vulnerability expands post-compromise risk

Dirty Frag is a newly disclosed Linux local privilege escalation vulnerability affecting kernel networking and memory-fragment handling components including esp4, esp6, and rxrpc. The vulnerability enables reliable escalation from an unprivileged user to root and may be leveraged after initial compromise through SSH access, web shells, containers, or low-privileged accounts.

vulnerabilitycveexploitationdetectionwindowslinux
Microsoft Security Blog / 2026-05-08T17:12:46+00:00Read Intel
lowaptsource excerpt

New Linux PamDOORa Backdoor Uses PAM Modules to Steal SSH Credentials

Cybersecurity researchers have disclosed details of a new Linux backdoor named PamDOORa that's being advertised on the Rehub Russian cybercrime forum for $1,600 by a threat actor called "darkworm." The backdoor is designed as a Pluggable Authentication Module (PAM)-based post-exploitation toolkit that enables persistent SSH access by means of a magic password and specific TCP port combination.

aptmalwarelinux
The Hacker News / 2026-05-08T08:41:00+00:00Read Intel
highvulnerabilitysource excerpt

CVE-2025-68670: discovering an RCE vulnerability in xrdp

During a security assessment of Kaspersky USB Redirector, we discovered CVE-2025-68670: a pre-auth RCE in the xrdp server component. Project maintainers promptly patched the vulnerability.

vulnerabilitycvelinux
Securelist / 2026-05-08T08:00:54+00:00Read Intel
mediumvulnerability

Another Universal Linux Local Privilege Escalation (LPE) Vulnerability: Dirty Frag, (Fri, May 8th)

Less than two weeks after the public disclosure of the Copy Fail vulnerability (CVE-2026-31431), another local privilege escalation (LPE) vulnerability in the Linux kernel has been revealed. Referred to as "Dirty Frag," this vulnerability was discovered and reported by Hyunwoo Kim (@v4bel) [1]. In this diary, I will provide a brief background on Dirty Frag, and discuss its relationship to Copy Fail.

vulnerabilitycvelinux
SANS ISC / 2026-05-08T07:50:01+00:00Read Intel
mediumvulnerabilitysource excerpt

Linux Kernel Dirty Frag LPE Exploit Enables Root Access Across Major Distributions

Details have emerged about a new, unpatched local privilege escalation (LPE) vulnerability impacting the Linux kernel. Dubbed Dirty Frag, it has been described as a successor to Copy Fail (CVE-2026-31431, CVSS score: 7.8), a recently disclosed LPE flaw impacting the Linux kernel that has since come under active exploitation in the wild.

vulnerabilitycveexploitationlinux
The Hacker News / 2026-05-08T05:12:00+00:00Read Intel
highransomwaresource excerpt

Iranian government hackers using Chaos ransomware as cover, researchers say

Incident responders from cybersecurity firm Rapid7 published a report about a recent intrusion that initially appeared to be a Chaos ransomware attack but was later discovered to be an attack attributed to MuddyWater, an Iranian APT group tied to the country’s Ministry of Intelligence and Security (MOIS).

ransomware
The Record / 2026-05-07T21:30:00+00:00Read Intel
mediumvulnerabilitysource excerpt

When prompts become shells: RCE vulnerabilities in AI agent frameworks

New research exposes how prompt injection in AI agent frameworks can lead to remote code execution. Learn how these vulnerabilities work, what’s impacted, and how to secure your agents. The post When prompts become shells: RCE vulnerabilities in AI agent frameworks appeared first on Microsoft Security Blog .

vulnerabilitycveexploitation
Microsoft Security Blog / 2026-05-07T20:22:39+00:00Read Intel
lowadvisorysource excerpt

Unplug your way to better code

Cybersecurity concepts — logs, packets, DNS exfiltration, and more — are usually intangible, and its practitioners are prone to mental fatigue, Amy takes a second to yell at you to go touch grass.

Cisco Talos / 2026-05-07T18:00:40+00:00Read Intel
mediumvulnerabilitysource excerpt

Ivanti EPMM CVE-2026-6973 RCE Under Active Exploitation Grants Admin-Level Access

Ivanti is warning that a new security flaw impacting Endpoint Manager Mobile (EPMM) has been explored in limited attacks in the wild. The high-severity vulnerability, CVE-2026-6973 (CVSS score: 7.2), is a case of improper input validation affecting EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1.

vulnerabilitycve
The Hacker News / 2026-05-07T17:55:00+00:00Read Intel
lowmalwaresource excerpt

World Passkey Day: Advancing passwordless authentication

This World Passkey Day, read how Microsoft is advancing passkey adoption to replace passwords, cut phishing risk, and deliver simpler, more secure sign-ins. The post World Passkey Day: Advancing passwordless authentication appeared first on Microsoft Security Blog .

malwaretradecraftwindowsidentityemail
Microsoft Security Blog / 2026-05-07T16:00:00+00:00Read Intel
lowotsource excerpt

ThreatsDay Bulletin: Edge Plaintext Passwords, ICS 0-Days, Patch-or-Die Alerts and 25+ New Stories

Bad week. Turns out the easiest way to get hacked in 2026 is still the same old garbage: shady packages, fake apps, forgotten DNS junk, scam ads, and stolen logins getting dumped into Discord channels like it’s normal. Some of these attack chains don’t even feel sophisticated anymore. More like some tired guy with a Telegram account and too much free time.

ot
The Hacker News / 2026-05-07T11:33:00+00:00Read Intel
criticalaptsource excerpt

Exploits and vulnerabilities in Q1 2026

This report provides statistical data on published vulnerabilities and exploits we researched during Q1 2026. It also includes summary data on the use of C2 frameworks in APT attacks.

aptvulnerabilitycveexploitationwindowslinux
Securelist / 2026-05-07T10:00:43+00:00Read Intel
lowadvisorysource excerpt

Instructure Breach Exposes Schools' Vendor Dependence

ShinyHunters' attack on Instructure, which owns the widely used Canvas learning management system (LMS), carries big questions about the trust educational institutions put into their vendors.

Dark Reading / 2026-05-06T21:02:57+00:00Read Intel
criticaladvisorysource excerpt

​​Microsoft named an overall leader in KuppingerCole Analyst’s 2026 Emerging AI Security Operations Center (SOC) report ​​

Microsoft is excited to be named an Overall Leader, and the Market Leader in the Kuppinger Cole Analyst’s 2026 Emerging AI Security Operations Center (SOC) report, as we see automation and AI as core components of the future of cybersecurity. The post ​​Microsoft named an overall leader in KuppingerCole Analyst’s 2026 Emerging AI Security Operations Center (SOC) report ​​ appeared first on Microsoft Security Blog .

tradecraftdetectionemail
Microsoft Security Blog / 2026-05-06T16:00:00+00:00Read Intel
lowmalwaresource excerpt

ClickFix campaign uses fake macOS utilities lures to deliver infostealers

Threat actors are targeting macOS users with fake utility fixes that trick them into running malicious Terminal commands. This campaign evades traditional defenses by stealing credentials, wallets, and sensitive data. The post ClickFix campaign uses fake macOS utilities lures to deliver infostealers appeared first on Microsoft Security Blog .

malwaredetection
Microsoft Security Blog / 2026-05-06T15:20:32+00:00Read Intel
highransomwaresource excerpt

Why ransomware attacks succeed even when backups exist

Backups don't fail because they're missing, they fail because attackers destroy them first. Acronis explains how ransomware targets backup systems before encryption, leaving no path to recovery.

ransomware
BleepingComputer / 2026-05-06T14:04:14+00:00Read Intel
lowmalwaresource excerpt

OceanLotus suspected of using PyPI to deliver ZiChatBot malware

Kaspersky researchers uncovered malicious wheel packages in PyPI that targeted both Windows and Linux and contained a dropper delivering malware dubbed ZiChatBot. We attribute this activity to OceanLotus APT.

malwarewindowslinuxemail
Securelist / 2026-05-06T13:00:34+00:00Read Intel
highransomwaresource excerpt

MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware Attack

The Iranian state-sponsored hacking group known as MuddyWater (aka Mango Sandstorm, Seedworm, and Static Kitten) has been attributed to a ransomware attack in what has been described as a "false flag" operation. The attack, observed by Rapid7 in early 2026, has been found to leverage social engineering techniques via Microsoft Teams to initiate the infection sequence.

ransomwareapt
The Hacker News / 2026-05-06T13:00:00+00:00Read Intel
criticaldetectionsource excerpt

Insights into the clustering and reuse of phone numbers in scam emails

Talos has recently started to collect and gather intelligence around phone numbers within emails as an additional indicator of compromise (IOC). In this blog, we discuss new insights into in-the-wild phone number reuse in scam emails.

exploitationdetectionemail
Cisco Talos / 2026-05-06T10:00:12+00:00Read Intel
lowadvisorysource excerpt

Websites with an undefined trust level: avoiding the trap

We explain what suspicious websites are and how to distinguish a safe site from a fraudulent one. A new category in Kaspersky solutions: we're sharing global statistics on untrusted site detection.

tradecraftdetectionemail
Securelist / 2026-05-06T09:30:46+00:00Read Intel
lowadvisorysource excerpt

Google's Android Apps Get Public Verification to Stop Supply Chain Attacks

Google has announced expanded Binary Transparency for Android as a way to safeguard the ecosystem from supply chain attacks. "This new public ledger ensures the Google apps on your device are exactly what we intended to build and distribute," Google's product and security teams said.

The Hacker News / 2026-05-06T09:13:00+00:00Read Intel
criticalvulnerabilitysource excerpt

Palo Alto PAN-OS Flaw Under Active Exploitation Enables Remote Code Execution

Palo Alto Networks has released an advisory warning that a critical buffer overflow vulnerability in its PAN-OS software has been exploited in the wild. The vulnerability, tracked as CVE-2026-0300, has been described as a case of unauthenticated remote code execution.

vulnerabilitycve
The Hacker News / 2026-05-06T06:14:00+00:00Read Intel
criticalvulnerabilitysource excerpt

Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years

Copy Fail (CVE-2026-31431) is a critical Linux kernel LPE that allows stealthy root access. This flaw impacts millions of systems. Read our analysis. The post Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years appeared first on Unit 42 .

vulnerabilitycvelinux
Unit 42 / 2026-05-05T23:00:33+00:00Read Intel
criticalvulnerabilitysource excerpt

Critical Apache HTTP/2 Flaw (CVE-2026-23918) Enables DoS and Potential RCE

The Apache Software Foundation (ASF) has released security updates to address several security vulnerabilities in the HTTP Server, including a severe vulnerability that could potentially lead to remote code execution (RCE). The vulnerability, tracked as CVE-2026-23918 (CVSS score: 8.8), has been described as a case of "double free and possible RCE" in the HTTP/2 protocol handling.

vulnerabilitycve
The Hacker News / 2026-05-05T16:19:00+00:00Read Intel
criticaladvisorysource excerpt

The EOL Blind Spot in Your CVE Feed: What SCA Tools Don't Check.

Critical vulnerabilities can exist in open source software your scanners don't check. HeroDevs reveals how EOL software creates blind spots in CVE feeds and SCA tools, and how you can receive a free end-of-life scan for your projects.

BleepingComputer / 2026-05-05T14:00:10+00:00Read Intel
criticaladvisorysource excerpt

The EOL Blind Spot in Your CVE Feed: What SCA Tools Miss

Critical vulnerabilities can exist in open source software your scanners don't check. HeroDevs reveals how EOL software creates blind spots in CVE feeds and SCA tools, and how you can receive a free end-of-life scan for your projects.

BleepingComputer / 2026-05-05T14:00:10+00:00Read Intel
lowadvisorysource excerpt

The Back Door Attackers Know About — and Most Security Teams Still Haven’t Closed

Every AI tool, workflow automation, and productivity app your employees connected to Google or Microsoft this year left something behind: a persistent OAuth token with no expiration date, no automatic cleanup, and in most organizations, no one watching it. Your perimeter controls don't see it. Your MFA doesn't stop it. And when an attacker gets hold of one, they don't need a password.

identity
The Hacker News / 2026-05-05T11:58:00+00:00Read Intel
criticalvulnerabilitysource excerpt

MetInfo CMS CVE-2026-29014 Exploited for Remote Code Execution Attacks

Threat actors are actively exploiting a critical security flaw impacting an open-source content management system (CMS) known as MetInfo, according to new findings from VulnCheck. The vulnerability in question is CVE-2026-29014 (CVSS score: 9.8), a code injection flaw that could result in arbitrary code execution.

vulnerabilitycve
The Hacker News / 2026-05-05T11:56:00+00:00Read Intel
lowvulnerabilitysource excerpt

Google now offers up to $1.5 million for some Android exploits

Google overhauls its Android and Chrome vulnerability rewards programs, offering bounties of up to $1.5 million for the most difficult exploits while scaling back payouts for flaws that artificial intelligence (AI) has made easier to find.

vulnerability
BleepingComputer / 2026-05-05T11:24:48+00:00Read Intel
lowadvisorysource excerpt

We Scanned 1 Million Exposed AI Services. Here's How Bad the Security Actually Is

While the software industry has made genuine strides over the past few decades to deliver products securely, the furious pace of AI adoption is putting that progress at risk. Businesses are moving fast to self-host LLM infrastructure, drawn by the promise of AI as a force multiplier and the pressure to deliver more value faster. But speed is coming at the expense of security.

The Hacker News / 2026-05-05T10:30:00+00:00Read Intel
lowmalwaresource excerpt

UAT-8302 and its box full of malware

Cisco Talos is disclosing UAT-8302, a sophisticated, China-nexus advanced persistent threat (APT) group targeting government entities in South America since at least late 2024 and government agencies in southeastern Europe in 2025.

malware
Cisco Talos / 2026-05-05T10:00:30+00:00Read Intel
criticalvulnerabilitysource excerpt

Weaver E-cology RCE Flaw CVE-2026-22679 Actively Exploited via Debug API

A critical security vulnerability in Weaver (Fanwei) E-cology, an enterprise office automation (OA) and collaboration platform, has come under active exploitation in the wild. The vulnerability (CVE-2026-22679, CVSS score: 9.8) relates to a case of unauthenticated remote code execution affecting Weaver E-cology 10.0 versions prior to 20260312.

vulnerabilitycve
The Hacker News / 2026-05-05T07:37:00+00:00Read Intel
lowadvisorysource excerpt

RMM Tools Fuel Stealthy Phishing Campaign

Attackers are abusing two remote monitoring and management (RMM) tools to evade detection in a campaign that has impacted over 80 organizations so far.

tradecraftdetectionemail
Dark Reading / 2026-05-04T20:56:34+00:00Read Intel
highvulnerabilitysource excerpt

⚡ Weekly Recap: AI-Powered Phishing, Android Spying Tool, Linux Exploit, GitHub RCE & More

This week, the shadows moved faster than the patches. While most teams were still triaging last month’s alerts, attackers had already turned control panels into kill switches, kernels into open doors, and open-source pipelines into silent delivery systems. The game has shifted from breach to occupation.

vulnerabilityexploitationtradecraftlinuxemail
The Hacker News / 2026-05-04T14:23:00+00:00Read Intel
lowadvisorysource excerpt

2026: The Year of AI-Assisted Attacks

On December 4, 2025, a 17-year-old was arrested in Osaka under Japan’s Unauthorized Access Prohibition Act. The young man had run malicious code to extract the personal data of over 7 million users of Kaikatsu Club, Japan's largest internet cafe chain. When asked, the young man shared his motivation for the hack: he wanted to buy Pokémon cards. In a sense, this is a fairly conventional story.

The Hacker News / 2026-05-04T11:58:00+00:00Read Intel
lowmalwaresource excerpt

Silver Fox Deploys ABCDoor Malware via Tax-Themed Phishing in India and Russia

The China-based cybercrime group known as Silver Fox has been linked to a new campaign targeting organizations in Russia and India with a new malware called ABCDoor. The activity involved using phishing emails that mimic correspondence from the Income Tax Department of India in December 2025, followed by a similar campaign aimed at Russian entities.

malwaretradecraftemail
The Hacker News / 2026-05-04T11:57:00+00:00Read Intel
lowmalwaresource excerpt

Silver Fox Springs Tax-Themed Attacks on Orgs in India, Russia

More than 1,600 socially engineered messages from the China-backed advanced persistent threat (APT) group target various sectors to deliver the previously undocumented ABCDoor backdoor, ValleyRAT, and other malware.

malware
Dark Reading / 2026-05-04T11:35:44+00:00Read Intel
lowvulnerabilitysource excerpt

CISA says ‘Copy Fail’ flaw now exploited to root Linux systems

CISA has warned that threat actors have started exploiting the "Copy Fail" Linux security vulnerability in the wild, one day after Theori researchers disclosed it and shared a proof-of-concept (PoC) exploit.

vulnerabilityexploitationlinux
BleepingComputer / 2026-05-04T11:28:15+00:00Read Intel
criticalaptsource excerpt

Critical cPanel Vulnerability Weaponized to Target Government and MSP Networks

A previously unknown threat actor has been observed targeting government and military entities in Southeast Asia, alongside a smaller cluster of managed service providers (MSPs) and hosting providers in the Philippines, Laos, Canada, South Africa, and the U.S., by exploiting the recently disclosed vulnerability in cPanel.

aptvulnerabilityexploitation
The Hacker News / 2026-05-04T09:27:00+00:00Read Intel
criticalvulnerabilitysource excerpt

CISA Adds Actively Exploited Linux Root Access Bug CVE-2026-31431 to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a recently disclosed security flaw impacting various Linux distributions to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild.

vulnerabilitycvelinux
The Hacker News / 2026-05-03T06:26:00+00:00Read Intel
lowadvisorysource excerpt

Trellix Confirms Source Code Breach With Unauthorized Repository Access

Cybersecurity company Trellix has announced that it suffered a breach that enabled unauthorized access to a "portion" of its source code. It said it "recently identified" the compromise of its source code repository and that it began working with "leading forensic experts" to resolve the matter immediately. It also said it has notified law enforcement of the matter.

The Hacker News / 2026-05-02T06:41:00+00:00Read Intel
highaptsource excerpt

CVE-2026-31431: Copy Fail vulnerability enables Linux root privilege escalation across cloud environments

A high-severity Linux vulnerability, “Copy Fail” (CVE-2026-31431), enables root privilege escalation across cloud environments and Kubernetes workloads. With a working exploit already in the wild, organizations should act quickly to detect, mitigate, and reduce risk.

aptvulnerabilitycveexploitationtradecraftdetection
Microsoft Security Blog / 2026-05-02T03:06:08+00:00Read Intel
lowadvisorysource excerpt

Essential Data Sources for Detection Beyond the Endpoint

Unit 42 highlights the need for a comprehensive security strategy that spans every IT zone. Explore the full details here. The post Essential Data Sources for Detection Beyond the Endpoint appeared first on Unit 42 .

detection
Unit 42 / 2026-05-01T23:00:13+00:00Read Intel
lowadvisorysource excerpt

15-year-old detained over French govt agency data breach

French authorities have detained a 15-year-old suspected of selling data stolen in a cyberattack on France Titres (ANTS), the country's agency for issuing and managing administrative documents.

BleepingComputer / 2026-05-01T17:52:06+00:00Read Intel
lowadvisorysource excerpt

Microsoft Agent 365, now generally available, expands capabilities and integrations

​Today we’re announcing the general availability of Agent 365, plus previews of new capabilities to discover and manage shadow AI agents, including local agents like OpenClaw and Claude Code. The post Microsoft Agent 365, now generally available, expands capabilities and integrations appeared first on Microsoft Security Blog .

windowscloud
Microsoft Security Blog / 2026-05-01T15:00:00+00:00Read Intel
highransomwaresource excerpt

Two Cybersecurity Professionals Get 4-Year Sentences in BlackCat Ransomware Attacks

The U.S. Department of Justice (DoJ) on Thursday announced the sentencing of two cybersecurity professionals to four years each in prison for their role in facilitating BlackCat ransomware attacks in 2023. Ryan Goldberg, 40, of Georgia, and Kevin Martin, 36, of Texas, were accused of deploying the ransomware against multiple victims located throughout the U.S. between April and December 2023.

ransomware
The Hacker News / 2026-05-01T09:56:00+00:00Read Intel
lowtradecraftsource excerpt

Poisoned Ruby Gems and Go Modules Exploit CI Pipelines for Credential Theft

A new software supply chain attack campaign has been observed using sleeper packages as a conduit to subsequently push malicious payloads that enabled credential theft, GitHub Actions tampering, and SSH persistence. The activity has been attributed to the GitHub account "BufferZoneCorp," which has published a set of repositories that are associated with malicious Ruby gems and Go modules.

exploitationtradecraft
The Hacker News / 2026-05-01T09:43:00+00:00Read Intel
lowadvisorysource excerpt

That AI Extension Helping You Write Emails? It’s Reading Them First

Unit 42 uncovers high-risk AI browser extensions. Disguised as productivity tools, they steal data, intercept prompts, and exfiltrate passwords. Protect your browser. The post That AI Extension Helping You Write Emails? It’s Reading Them First appeared first on Unit 42 .

Unit 42 / 2026-04-30T22:00:57+00:00Read Intel
lowadvisorysource excerpt

Great responsibility, without great power

In this week’s newsletter, Hazel uses International Superhero Day as a springboard to explore why empathy — rather than just technical prowess — is the most essential, underrated superpower for navigating the human side of cybersecurity.

Cisco Talos / 2026-04-30T18:00:07+00:00Read Intel
lowadvisorysource excerpt

FBI links cybercriminals to sharp surge in cargo theft attacks

The U.S. Federal Bureau of Investigation (FBI) warned the transportation and logistics industry of a sharp rise in cyber-enabled cargo theft, with estimated losses in the United States and Canada reaching nearly $725 million in 2025.

BleepingComputer / 2026-04-30T16:32:18+00:00Read Intel
lowadvisorysource excerpt

PyTorch Lightning Compromised in PyPI Supply Chain Attack to Steal Credentials

In yet another software supply chain attack, threat actors have managed to compromise the popular Python package Lightning to push two malicious versions to conduct credential theft. According to Aikido Security, Socket, and StepSecurity, the two malicious versions are versions 2.6.2 and 2.6.3, both of which were published on April 30, 2026.

The Hacker News / 2026-04-30T16:31:00+00:00Read Intel
lowadvisorysource excerpt

What’s new, updated, or recently released in Microsoft Security

Stay ahead of emerging threats with Microsoft’s newest security innovations and updates, delivered through the In the Loop series. The post What’s new, updated, or recently released in Microsoft Security appeared first on Microsoft Security Blog .

windowscloudnetwork
Microsoft Security Blog / 2026-04-30T16:00:00+00:00Read Intel
lowaptsource excerpt

Email threat landscape: Q1 2026 trends and insights

In early 2026, email threats increased with a rise in credential phishing, QR code phishing, and CAPTCHA-gated campaigns, highlighted by Microsoft’s disruption of the Tycoon2FA phishing platform which led to a 15% volume decrease and shifts in threat actor tactics. The post Email threat landscape: Q1 2026 trends and insights appeared first on Microsoft Security Blog .

apttradecraftwindowsemail
Microsoft Security Blog / 2026-04-30T15:00:00+00:00Read Intel
mediumvulnerabilitysource excerpt

New Linux ‘Copy Fail’ flaw gives hackers root on major distros

An exploit has been published for a local privilege escalation vulnerability dubbed "Copy Fail" that impacts Linux kernels released since 2017, allowing an unprivileged local attacker to gain root permissions.

vulnerabilityexploitationlinux
BleepingComputer / 2026-04-30T13:54:47+00:00Read Intel
mediumvulnerabilitysource excerpt

New Linux 'Copy Fail' Vulnerability Enables Root Access on Major Distributions

Cybersecurity researchers have disclosed details of a Linux local privilege escalation (LPE) flaw that could allow an unprivileged local user to obtain root. The high-severity vulnerability tracked as CVE-2026-31431 (CVSS score: 7.8) has been codenamed Copy Fail by Xint.io and Theori.

vulnerabilitycvelinux
The Hacker News / 2026-04-30T09:24:00+00:00Read Intel
mediumvulnerabilitysource excerpt

Google Fixes CVSS 10 Gemini CLI CI RCE and Cursor Flaws Enable Code Execution

Google has addressed a maximum severity security flaw in Gemini CLI -- the "@google/gemini-cli" npm package and the "google-github-actions/run-gemini-cli" GitHub Actions workflow -- that could have allowed attackers to execute arbitrary commands on host systems.

vulnerability
The Hacker News / 2026-04-30T07:07:00+00:00Read Intel
lowadvisorysource excerpt

8 best practices for CISOs conducting risk reviews

Embracing strong proactive security is something we can all do to mitigate our increased exposure to security threats. The post 8 best practices for CISOs conducting risk reviews appeared first on Microsoft Security Blog .

Microsoft Security Blog / 2026-04-29T16:00:00+00:00Read Intel
criticalvulnerabilitysource excerpt

cPanel, WHM emergency update fixes critical auth bypass bug

A critical vulnerability affecting all but the latest versions of cPanel and the WebHost Manager (WHM) dashboard could be exploited to obtain access to the control panel without authentication.

vulnerability
BleepingComputer / 2026-04-29T15:51:44+00:00Read Intel
lowmalwaresource excerpt

New Wave of DPRK Attacks Uses AI-Inserted npm Malware, Fake Firms, and RATs

Cybersecurity researchers have discovered malicious code in an npm package after a malicious package as a dependency to the project by Anthropic's Claude Opus large language model (LLM). The package in question is "@validate-sdk/v2," which is listed on npm as a utility software development kit (SDK) for hashing, validation, encoding/decoding, and secure random generation.

malware
The Hacker News / 2026-04-29T14:43:00+00:00Read Intel
lowadvisorysource excerpt

Learning from the Vercel breach: Shadow AI & OAuth sprawl

A single third-party OAuth integration can become a direct path into your environment. Push explains how the Vercel breach shows a compromised OAuth app can lead to widespread impact across downstream customers.

BleepingComputer / 2026-04-29T13:05:14+00:00Read Intel
lowadvisorysource excerpt

Webinar: How to Automate Exposure Validation to Match the Speed of AI Attacks

In February 2026, researchers uncovered a shift that completely changed the game: threat actors are now using custom AI setups to automate attacks directly into the kill chain. We aren't just talking about AI writing better phishing emails anymore. We’re talking about autonomous agents mapping Active Directory and seizing Domain Admin credentials in minutes. The problem?

tradecraftwindowsemail
The Hacker News / 2026-04-29T12:02:00+00:00Read Intel
criticalaptsource excerpt

AI-powered honeypots: Turning the tables on malicious AI agents

Just as AI brings time-saving advantages to our lives, it brings similar advantages to threat actors. We can take the advantage back. This blog shows how generative AI can be used to rapidly deploy adaptive honeypot systems.

aptvulnerabilityexploitationwindowslinux
Cisco Talos / 2026-04-29T10:00:42+00:00Read Intel
criticalvulnerabilitysource excerpt

CISA Adds Actively Exploited ConnectWise and Windows Flaws to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added two security flaws impacting ConnectWise ScreenConnect and Microsoft Windows to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.

vulnerabilitycvewindows
The Hacker News / 2026-04-29T08:46:00+00:00Read Intel
criticalvulnerabilitysource excerpt

LiteLLM CVE-2026-42208 SQL Injection Exploited within 36 Hours of Disclosure

In yet another instance of threat actors quickly jumping on the exploitation bandwagon, a newly disclosed critical security flaw in BerriAI's LiteLLM Python package has come under active exploitation in the wild within 36 hours of the bug becoming public knowledge.

vulnerabilitycve
The Hacker News / 2026-04-29T05:34:00+00:00Read Intel
criticalvulnerabilitysource excerpt

Hackers are exploiting a critical LiteLLM pre-auth SQLi flaw

Hackers are targeting sensitive information stored in the LiteLLM open-source large-language model (LLM) gateway by exploiting a critical vulnerability tracked as CVE-2026-42208.

vulnerabilitycvenetwork
BleepingComputer / 2026-04-28T21:07:23+00:00Read Intel
lowmalwaresource excerpt

Brazilian LofyGang Resurfaces After Three Years With Minecraft LofyStealer Campaign

A cybercrime group of Brazilian origin has resurfaced after more than three years to orchestrate a campaign that targets Minecraft players with a new stealer called LofyStealer (aka GrabBot). "The malware disguises itself as a Minecraft hack called 'Slinky,'" Brazil-based cybersecurity company ZenoX said in a technical report.

malware
The Hacker News / 2026-04-28T17:39:00+00:00Read Intel
criticalransomwaresource excerpt

VECT 2.0 Ransomware Irreversibly Destroys Files Over 131KB on Windows, Linux, ESXi

Threat hunters are warning that the cybercriminal operation known as VECT 2.0 acts more like a wiper than a ransomware due to a critical flaw in its encryption implementation across Windows, Linux, and ESXi variants that renders recovery impossible even for the threat actors.

ransomwarewindowslinux
The Hacker News / 2026-04-28T14:01:00+00:00Read Intel
criticalransomwaresource excerpt

Five defender priorities from the Talos Year in Review

With attackers moving faster than ever, it’s easy to feel overwhelmed. This blog breaks down five practical priorities from the Cisco Talos 2025 Year in Review to help defenders focus and prioritize, amidst all the noise.

ransomwarewindowsidentity
Cisco Talos / 2026-04-28T13:23:20+00:00Read Intel
lowadvisorysource excerpt

Simplifying AWS defense with Microsoft Sentinel UEBA

Learn how Microsoft Sentinel UEBA helps defenders distinguish benign AWS activity from attacker behavior by enriching raw CloudTrail logs with clear, binary behavioral signals derived from baseline user, peer, and device behavior patterns. The post Simplifying AWS defense with Microsoft Sentinel UEBA appeared first on Microsoft Security Blog .

detectioncloudidentity
Microsoft Security Blog / 2026-04-28T13:00:00+00:00Read Intel
lowvulnerabilitysource excerpt

After Mythos: New Playbooks For a Zero-Window Era

When patching isn’t fast enough, NDR helps contain the next era of threats. If you’ve been tracking advancements in AI, you know the exploit window, the short buffer that organizations relied on to patch and protect after a vulnerability disclosure, is closing fast.

vulnerabilityexploitation
The Hacker News / 2026-04-28T10:30:00+00:00Read Intel
criticalvulnerabilitysource excerpt

Microsoft Confirms Active Exploitation of Windows Shell CVE-2026-32202

Microsoft on Monday revised its advisory for a now-patched, high-severity security flaw impacting Windows Shell to acknowledge that it has been actively exploited in the wild. The vulnerability in question is CVE-2026-32202 (CVSS score: 4.3), a spoofing vulnerability that could allow an attacker to access sensitive information.

vulnerabilitycvewindowsemail
The Hacker News / 2026-04-28T05:50:00+00:00Read Intel
lowadvisorysource excerpt

Robinhood account creation flaw abused to send phishing emails

Online trading platform Robinhood's account creation process was exploited by threat actors to inject phishing messages into legitimate emails, tricking users into believing their accounts had suspicious activity.

tradecraftemail
BleepingComputer / 2026-04-27T23:11:01+00:00Read Intel
lowadvisorysource excerpt

Webinar: Spotting cyberattacks before they begin

On Thursday, April 30 at 2:00 PM ET, BleepingComputer will host a live webinar with threat intelligence company Flare and threat intelligence researcher Tammy Harper, exploring how security teams can identify early warning signs of attacks before they escalate into incidents.

BleepingComputer / 2026-04-27T14:25:35+00:00Read Intel
highvulnerability

TeamPCP Supply Chain Campaign: Update 008 - 26-Day Pause Ends with Three Concurrent Compromises (Checkmarx KICS, Bitwarden CLI Cascade, xinference PyPI), CanisterSprawl npm Worm Identified, and Tier 1 Coverage Returns, (Mon, Apr 27th)

This update succeeds&&#x23&#x3b;x26&#x3b;&#x23&#x3b;xc2&#x3b;&&#x23&#x3b;x26&#x3b;&#x23&#x3b;xa0&#x3b;TeamPCP Supply Chain Campaign Update 007, published April 8, 2026, which left the campaign in credential-monetization mode following the Cisco source code theft via Trivy-linked credentials, Google GTIG&&#x23&#x3b;x26&#x3b;&#x23&#x3b;39&#x3b;s formal designation of the operators as UNC6780 (with their credential

malwarevulnerabilitycve
SANS ISC / 2026-04-27T14:01:17+00:00Read Intel
lowmalwaresource excerpt

⚡ Weekly Recap: Fast16 Malware, XChat Launch, Federal Backdoor, AI Employee Tracking & More

Everything is dumb again. This week feels broken in a very familiar way. Old tricks are back. New tools are doing shady crap. Supply chains got hit. Fake help desks worked. Weird research showed how easy some attacks still are. Most of it feels like stuff we should have fixed years ago. Bad extensions. Stolen creds. Remote tools are getting abused. Malware hides in places people trust.

malware
The Hacker News / 2026-04-27T13:30:00+00:00Read Intel
lowvulnerabilitysource excerpt

Mythos Changed the Math on Vulnerability Discovery. Most Teams Aren't Ready for the Remediation Side

Anthropic’s Claude Mythos Preview has dominated security discussions since its April 7 announcement. Early reporting describes a powerful cybersecurity-focused AI system capable of identifying vulnerabilities at scale and raising serious questions about how quickly organizations can validate, prioritize, and remediate what it finds.

vulnerability
The Hacker News / 2026-04-27T11:58:00+00:00Read Intel
lowmalwaresource excerpt

Researchers Uncover 73 Fake VS Code Extensions Delivering GlassWorm v2 Malware

Cybersecurity researchers have flagged dozens of Microsoft Visual Studio Code (VS Code) extensions on the Open VSX repository that are linked to a persistent information-stealing campaign dubbed GlassWorm. The cluster of 73 extensions has been identified as cloned versions of their legitimate counterparts.

malware
The Hacker News / 2026-04-27T11:23:00+00:00Read Intel
mediumvulnerabilitysource excerpt

CISA Adds 4 Exploited Flaws to KEV, Sets May 2026 Federal Deadline

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added four vulnerabilities impacting SimpleHelp, Samsung MagicINFO 9 Server, and D-Link DIR-823X series routers to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

vulnerabilitycve
The Hacker News / 2026-04-25T05:08:00+00:00Read Intel
lowtradecraftsource excerpt

The npm Threat Landscape: Attack Surface and Mitigations

Unit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and more. The post The npm Threat Landscape: Attack Surface and Mitigations appeared first on Unit 42 .

malwaretradecraft
Unit 42 / 2026-04-24T21:40:33+00:00Read Intel
lowmalwaresource excerpt

Firestarter malware survives Cisco firewall updates, security patches

Cybersecurity agencies in the U.S. and U.K. are warning about a custom malware called Firestarter persisting on Cisco Firepower and Secure Firewall devices running Adaptive Security Appliance (ASA) or Firepower Threat Defense (FTD) software.

malwarenetwork
BleepingComputer / 2026-04-24T20:34:08+00:00Read Intel
lowadvisorysource excerpt

Tropic Trooper Uses Trojanized SumatraPDF and GitHub to Deploy AdaptixC2

Chinese-speaking individuals are the target of a new campaign that uses a trojanized version of SumatraPDF reader to deploy the AdaptixC2 Beacon post-exploitation agent and ultimately facilitate the abuse of Microsoft Visual Studio Code (VS Code) tunnels for remote access.

The Hacker News / 2026-04-24T09:29:00+00:00Read Intel
mediumvulnerabilitysource excerpt

LMDeploy CVE-2026-33626 Flaw Exploited Within 13 Hours of Disclosure

A high-severity security flaw in LMDeploy, an open-source toolkit for compressing, deploying, and serving LLMs, has come under active exploitation in the wild less than 13 hours after its public disclosure. The vulnerability, tracked as CVE-2026-33626 (CVSS score: 7.5), relates to a Server-Side Request Forgery (SSRF) vulnerability that could be exploited to access sensitive data.

vulnerabilitycve
The Hacker News / 2026-04-24T07:24:00+00:00Read Intel
highransomwaresource excerpt

It pays to be a forever student

In this newsletter, Joe discusses why understanding other disciplines can often flow back into the macro and micro of cybersecurity, especially in a world of AI.

ransomwareaptot
Cisco Talos / 2026-04-23T18:00:22+00:00Read Intel
highaptsource excerpt

UAT-4356's Targeting of Cisco Firepower Devices

Cisco Talos is aware of UAT-4356's continued active targeting of Cisco Firepower devices’ Firepower eXtensible Operating System (FXOS). UAT-4356 exploited n-day vulnerabilities (CVE-2025-20333 and CVE-2025-20362) to gain unauthorized access to vulnerable devices.

aptmalwarevulnerabilitycvetradecraftdetection
Cisco Talos / 2026-04-23T15:10:57+00:00Read Intel
lowvulnerabilitysource excerpt

Bad Memories Still Haunt AI Agents

Cisco found and fixed a significant vulnerability in the way Anthropic handles memories, but experts warn that mishandled memory files will continue threaten AI systems.

vulnerability
Dark Reading / 2026-04-23T14:30:31+00:00Read Intel
lowadvisorysource excerpt

Regular Password Resets Aren’t as Safe as You Think

Password resets are one of the easiest ways for attackers to bypass security controls. Specops Software shows how helpdesk social engineering turns a seemingly legitimate reset request into full account compromise.

BleepingComputer / 2026-04-23T14:10:20+00:00Read Intel
lowaptsource excerpt

Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite

Written by: JP Glab, Tufail Ahmed, Josh Kelley, Muhammad Umair Introduction Google Threat Intelligence Group (GTIG) identified a multistage intrusion campaign by a newly tracked threat group, UNC6692, that leveraged persistent social engineering, a custom modular malware suite, and deft pivoting inside the victim’s environment to achieve deep network penetration.

aptmalwaretradecraftcloudemail
Mandiant / 2026-04-23T14:00:00+00:00Read Intel
lowadvisorysource excerpt

Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign

Bitwarden CLI has been compromised as part of the newly discovered and ongoing Checkmarx supply chain campaign, according to new findings from Socket. "The affected package version appears to be @bitwarden/cli@2026.4.0, and the malicious code was published in 'bw1.js,' a file included in the package contents," the application security company said.

The Hacker News / 2026-04-23T13:42:00+00:00Read Intel
lowadvisorysource excerpt

ThreatsDay Bulletin: $290M DeFi Hack, macOS LotL Abuse, ProxySmart SIM Farms +25 New Stories

You scroll past one incident and see another that feels familiar, like it should have been fixed years ago, but it still works with small changes. Same bugs. Same mistakes. The supply chain is messy. Packages you did not check are stealing data, adding backdoors, and spreading. Attacking the systems behind apps is easier than breaking the apps themselves.

The Hacker News / 2026-04-23T13:17:00+00:00Read Intel
lowvulnerabilitysource excerpt

[Webinar] Mythos Reality Check: Beating Automated Exploitation at AI Speed

Imagine a world where hackers don't sleep, don't take breaks, and find weak spots in your systems instantly. Well, that world is already here. Thanks to AI, attackers are now launching automated, large-scale exploits faster than ever before. The time you have to fix a vulnerability before it gets attacked is shrinking to zero.

vulnerabilityexploitation
The Hacker News / 2026-04-23T12:03:00+00:00Read Intel
mediumvulnerabilitysource excerpt

Apple Patches iOS Flaw That Stored Deleted Signal Notifications in FBI Forensic Case

Apple has rolled out a software fix for iOS and iPadOS to address a Notification Services flaw that stored notifications marked for deletion on the device. The vulnerability, tracked as CVE-2026-28950 (CVSS score: N/A), has been described as a logging issue that has been addressed with improved data redaction.

vulnerabilitycve
The Hacker News / 2026-04-23T08:06:00+00:00Read Intel
mediumvulnerabilitysource excerpt

New Mirai campaign exploits RCE flaw in EoL D-Link routers

A new Mirai-based malware campaign is actively exploiting CVE-2025-29635, a high-severity command-injection vulnerability affecting D-Link DIR-823X routers, to enlist devices into the botnet.

malwarevulnerabilitycve
BleepingComputer / 2026-04-22T20:04:46+00:00Read Intel
lowvulnerabilitysource excerpt

AI-powered defense for an AI-accelerated threat landscape

Read how Microsoft is partnering with Anthropic and broader industry to use leading models, paired with our platforms and expertise, to turn AI-driven discovery into protection at scale. The post AI-powered defense for an AI-accelerated threat landscape appeared first on Microsoft Security Blog .

vulnerabilitydetection
Microsoft Security Blog / 2026-04-22T17:00:00+00:00Read Intel
lowadvisorysource excerpt

Electricity Is a Growing Area of Cyber Risk

IT has long been concerned about ensuring systems receive the right amount of electricity. Cyberattackers are realizing they can manipulate voltage fluctuations for their purposes, too.

Dark Reading / 2026-04-22T14:25:07+00:00Read Intel
lowmalwaresource excerpt

Lotus Wiper Malware Targets Venezuelan Energy Systems in Destructive Attack

Cybersecurity researchers have discovered a previously undocumented data wiper that has been used in attacks targeting Venezuela at the end of last year and the start of 2026. Dubbed Lotus Wiper, the novel file wiper has been used in a destructive campaign targeting the energy and utilities sector in Venezuela, per findings from Kaspersky.

malware
The Hacker News / 2026-04-22T10:55:00+00:00Read Intel
criticalvulnerabilitysource excerpt

Microsoft Patches Critical ASP.NET Core CVE-2026-40372 Privilege Escalation Bug

Microsoft has released out-of-band updates to address a security vulnerability in ASP.NET Core that could allow an attacker to escalate privileges. The vulnerability, tracked as CVE-2026-40372, carries a CVSS score of 9.1 out of 10.0. It's rated Important in severity. An anonymous researcher has been credited with discovering and reporting the flaw.

vulnerabilitycve
The Hacker News / 2026-04-22T09:29:00+00:00Read Intel
highransomwaresource excerpt

SystemBC C2 Server Reveals 1,570+ Victims in The Gentlemen Ransomware Operation

Threat actors associated with The Gentlemen ransomware‑as‑a‑service (RaaS) operation have been observed attempting to deploy a known proxy malware called SystemBC. According to new research published by Check Point, the command-and-control (C2 or C&C) server linked to SystemBC has led to the discovery of a botnet of more than 1,570 victims.

ransomwaremalware
The Hacker News / 2026-04-21T18:18:00+00:00Read Intel
mediumaptsource excerpt

Detection strategies across cloud and identities against infiltrating IT workers

The shift to remote and hybrid work since the pandemic expanded global hiring and accelerated digital onboarding, increasing reliance on online identity verification and remote access. The post Detection strategies across cloud and identities against infiltrating IT workers appeared first on Microsoft Security Blog .

aptexploitationdetectionwindowscloudidentity
Microsoft Security Blog / 2026-04-21T16:03:09+00:00Read Intel
highransomwaresource excerpt

Ransomware Negotiator Pleads Guilty to Aiding BlackCat Attacks in 2023

A third individual who was employed as a ransomware negotiator has pleaded guilty to conducting ransomware attacks against U.S. companies in 2023. Angelo Martino, 41, of Land O'Lakes, Florida, teamed up with the operators of the BlackCat ransomware starting in April 2023 to assist the e-crime gang in extracting higher amounts as ransoms.

ransomware
The Hacker News / 2026-04-21T14:31:00+00:00Read Intel
lowadvisorysource excerpt

Phishing and MFA exploitation: Targeting the keys to the kingdom

In 2025, attackers increasingly targeted weaknesses in multi-factor authentication (MFA) workflows, and phishing attacks leveraged valid, compromised credentials to launch lures from trusted accounts. The trends focused entirely on trust, or the lack thereof, in everyday business operations.

tradecraftidentityemail
Cisco Talos / 2026-04-21T12:00:08+00:00Read Intel
lowadvisorysource excerpt

No Exploit Needed: How Attackers Walk Through the Front Door via Identity-Based Attacks

The cybersecurity industry has spent the last several years chasing sophisticated threats like zero-days, supply chain compromises, and AI-generated exploits. However, the most reliable entry point for attackers still hasn't changed: stolen credentials. Identity-based attacks remain a dominant initial access vector in breaches today.

exploitationidentity
The Hacker News / 2026-04-21T11:30:00+00:00Read Intel
highvulnerabilitysource excerpt

Actively exploited Apache ActiveMQ flaw impacts 6,400 servers

Nonprofit security organization Shadowserver found that over 6,400 Apache ActiveMQ servers exposed online are vulnerable to ongoing attacks exploiting a high-severity code injection vulnerability.

vulnerability
BleepingComputer / 2026-04-21T11:17:51+00:00Read Intel
mediumvulnerabilitysource excerpt

CISA Adds 8 Exploited Flaws to KEV, Sets April-May 2026 Federal Deadlines

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added eight new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including three flaws impacting Cisco Catalyst SD-WAN Manager, citing evidence of active exploitation.

vulnerabilitycve
The Hacker News / 2026-04-21T06:23:00+00:00Read Intel
criticalvulnerabilitysource excerpt

SGLang CVE-2026-5760 (CVSS 9.8) Enables RCE via Malicious GGUF Model Files

A critical security vulnerability has been disclosed in SGLang that, if successfully exploited, could result in remote code execution on susceptible systems. The vulnerability, tracked as CVE-2026-5760, carries a CVSS score of 9.8 out of 10.0. It has been described as a case of command injection leading to the execution of arbitrary code.

vulnerabilitycve
The Hacker News / 2026-04-20T17:14:00+00:00Read Intel
criticaladvisorysource excerpt

Making opportunistic cyberattacks harder by design

How Microsoft secures Dynamics 365 and Power Platform by removing credentials, reducing attack surfaces, and using platform engineering to block opportunistic threats. The post Making opportunistic cyberattacks harder by design appeared first on Microsoft Security Blog .

cloudidentity
Microsoft Security Blog / 2026-04-20T16:00:00+00:00Read Intel
lowadvisorysource excerpt

WhatsApp Leaks User Metadata to Attackers

Strangers can infer limited info about you without knowing or messaging you, which could theoretically aid certain kinds of malicious activity.

Dark Reading / 2026-04-20T14:33:35+00:00Read Intel
highransomwaresource excerpt

The backup myth that is putting businesses at risk

Backups protect data, but don't keep your business running during downtime. Datto shows why BCDR is essential to keep operations running during ransomware and outages.

ransomware
BleepingComputer / 2026-04-20T14:01:11+00:00Read Intel
lowmalwaresource excerpt

⚡ Weekly Recap: Vercel Hack, Push Fraud, QEMU Abused, New Android RATs Emerge & More

Monday’s recap shows the same pattern in different places. A third-party tool becomes a way in, then leads to internal access. A trusted download path is briefly swapped to deliver malware. Browser extensions act normally while pulling data and running code. Even update channels are used to push payloads. It’s not breaking systems—it’s bending trust. There’s also a shift in how attacks run.

malware
The Hacker News / 2026-04-20T13:41:00+00:00Read Intel
criticalvulnerabilitysource excerpt

Anthropic MCP Design Vulnerability Enables RCE, Threatening AI Supply Chain

Cybersecurity researchers have discovered a critical "by design" weakness in the Model Context Protocol's (MCP) architecture that could pave the way for remote code execution and have a cascading effect on the artificial intelligence (AI) supply chain.

vulnerability
The Hacker News / 2026-04-20T10:42:00+00:00Read Intel
lowvulnerabilitysource excerpt

Fracturing Software Security With Frontier AI Models

Unit 42 finds frontier AI models enhance vulnerability discovery, acting as full-spectrum security researchers. They enable autonomous zero-day discovery and faster N-day patching. The post Fracturing Software Security With Frontier AI Models appeared first on Unit 42 .

vulnerability
Unit 42 / 2026-04-20T10:00:14+00:00Read Intel
lowotsource excerpt

Researchers Detect ZionSiphon Malware Targeting Israeli Water, Desalination OT Systems

Cybersecurity researchers have flagged a new malware called ZionSiphon that appears to be specifically designed to target Israeli water treatment and desalination systems. The malware has been codenamed ZionSiphon by Darktrace, highlighting its ability to set up persistence, tamper with local configuration files, and scan for operational technology (OT)-relevant services on the local subnet.

malwaretradecraftot
The Hacker News / 2026-04-20T07:34:00+00:00Read Intel
lowvulnerabilitysource excerpt

Handling the CVE Flood With EPSS, (Mon, Apr 20th)

Every morning, security people around the world face the same ritual: opening their vulnerability feed to find a lot of new CVE entries that appeared overnight. Over the past decade, this flood has become a defining challenge of modern defensive security.

vulnerability
SANS ISC / 2026-04-20T06:43:22+00:00Read Intel
lowadvisorysource excerpt

Vercel Breach Tied to Context AI Hack Exposes Limited Customer Credentials

Web infrastructure provider Vercel has disclosed a security breach that allows bad actors to gain unauthorized access to "certain" internal Vercel systems. The incident stemmed from the compromise of Context.ai, a third-party artificial intelligence (AI) tool, that was used by an employee at the company.

The Hacker News / 2026-04-20T03:35:00+00:00Read Intel
lowtradecraftsource excerpt

Cross‑tenant helpdesk impersonation to data exfiltration: A human-operated intrusion playbook

Threat actors are abusing external Microsoft Teams collaboration to impersonate IT helpdesk staff and convince users to grant remote access. Once inside, attackers can abuse legitimate tools and standard admin protocols to move laterally and exfiltrate data while appearing as routine IT support—activity Microsoft Defender helps detect across Teams, endpoint, and identity telemetry.

malwaretradecraftwindowscloudidentityemail
Microsoft Security Blog / 2026-04-18T12:55:45+00:00Read Intel
lowadvisorysource excerpt

$13.74M Hack Shuts Down Sanctioned Grinex Exchange After Intelligence Claims

Grinex, a Kyrgyzstan-incorporated cryptocurrency exchange sanctioned by the U.K. and the U.S. last year, said it's suspending operations after it blamed Western intelligence agencies for a $13.74 million hack. The exchange said it fell victim to what it described as a large-scale cyber attack that bore hallmarks of foreign intelligence agency involvement.

The Hacker News / 2026-04-18T07:59:00+00:00Read Intel
criticalransomwaresource excerpt

Containing a domain compromise: How predictive shielding shut down lateral movement

Domain compromise accelerates fast. Predictive shielding slowed it down. This real-world attack shows how exposure-based containment stopped credential abuse and broke the threat actor's momentum. The post Containing a domain compromise: How predictive shielding shut down lateral movement appeared first on Microsoft Security Blog .

ransomwareapttradecraftwindowsidentity
Microsoft Security Blog / 2026-04-17T14:51:01+00:00Read Intel
lowvulnerabilitysource excerpt

NIST Limits CVE Enrichment After 263% Surge in Vulnerability Submissions

The National Institute of Standards and Technology (NIST) has announced changes to the way it handles cybersecurity vulnerabilities and exposures (CVEs) listed in its National Vulnerability Database (NVD), stating it will only enrich those that fulfil certain conditions owing to an explosion in CVE submissions.

vulnerability
The Hacker News / 2026-04-17T07:14:00+00:00Read Intel
mediumvulnerabilitysource excerpt

A Deep Dive Into Attempted Exploitation of CVE-2023-33538

CVE-2023-33538 allows for command injection in TP-Link routers. We discuss exploitation attempts with payloads characteristic of Mirai botnet malware. The post A Deep Dive Into Attempted Exploitation of CVE-2023-33538 appeared first on Unit 42 .

malwarevulnerabilitycve
Unit 42 / 2026-04-16T22:00:13+00:00Read Intel
lowvulnerabilitysource excerpt

New Microsoft Defender “RedSun” zero-day PoC grants SYSTEM privileges

A researcher known as "Chaotic Eclipse" has published a proof-of-concept exploit for a second Microsoft Defender zero-day, dubbed "RedSun," in the past two weeks, protesting how the company works with cybersecurity researchers.

vulnerabilityexploitationwindows
BleepingComputer / 2026-04-16T20:19:31+00:00Read Intel
mediumvulnerability

Foxit, LibRaw vulnerabilities

Cisco Talos’ Vulnerability Discovery & Research team recently disclosed one Foxit Reader vulnerability, and six LibRaw file reader vulnerabilities. The vulnerabilities mentioned in this blog post have been patched by their respective vendors, all in adherence to Cisco’s third-party vulnerability disclosure policy .     For

vulnerabilitycvedetection
Cisco Talos / 2026-04-16T19:00:24+00:00Read Intel
lowvulnerabilitysource excerpt

The Q1 vulnerability pulse

Thor provides an overview of the Q1 2026 vulnerability statistics, highlighting key trends in legacy CVEs and the evolving impact of AI on the threat landscape.

vulnerabilitydetectionnetwork
Cisco Talos / 2026-04-16T18:00:31+00:00Read Intel
criticaladvisorysource excerpt

Building your cryptographic inventory: A customer strategy for cryptographic posture management

Learn how to build a comprehensive cryptographic inventory and strengthen quantum‑safe readiness using Microsoft Security tools, best‑practice lifecycle models, and partner solutions. The post Building your cryptographic inventory: A customer strategy for cryptographic posture management appeared first on Microsoft Security Blog .

cloud
Microsoft Security Blog / 2026-04-16T16:00:00+00:00Read Intel
criticalaptsource excerpt

Dissecting Sapphire Sleet’s macOS intrusion from lure to compromise

The Microsoft Defender Security Research Team uncovered a sophisticated macOS intrusion campaign attributed to the North Korean threat actor Sapphire Sleet that abuses user driven execution and social engineering to bypass macOS security protections and steal credentials, cryptocurrency assets, and sensitive data.

aptmalwaretradecraftdetectionwindows
Microsoft Security Blog / 2026-04-16T15:00:00+00:00Read Intel
criticalvulnerabilitysource excerpt

Defending Your Enterprise When AI Models Can Find Vulnerabilities Faster Than Ever

Introduction Advances in AI model-powered exploitation have demonstrated that general-purpose AI models can excel at vulnerability discovery, even without being purpose-built for the task. Eventually, capabilities such as these will be integrated directly into the development cycle, and code will be more difficult to exploit than ever; however, this transition creates a critical window of risk.

vulnerabilityexploitationcloud
Mandiant / 2026-04-16T14:00:00+00:00Read Intel
mediumvulnerabilitysource excerpt

ThreatsDay Bulletin: Defender 0-Day, SonicWall Brute-Force, 17-Year-Old Excel RCE and 15 More Stories

You know that feeling when you open your feed on a Thursday morning and it's just... a lot? Yeah. This week delivered. We've got hackers getting creative in ways that are almost impressive if you ignore the whole "crime" part, ancient vulnerabilities somehow still ruining people's days, and enough supply chain drama to fill a season of television nobody asked for. Not all bad though.

vulnerabilitywindows
The Hacker News / 2026-04-16T13:05:00+00:00Read Intel
lowmalwaresource excerpt

Obsidian Plugin Abuse Delivers PHANTOMPULSE RAT in Targeted Finance, Crypto Attacks

A "novel" social engineering campaign has been observed abusing Obsidian, a cross-platform note-taking application, as an initial access vector to distribute a previously undocumented Windows remote access trojan called PHANTOMPULSE in attacks targeting individuals in the financial and cryptocurrency sectors.

malwarewindows
The Hacker News / 2026-04-16T11:02:00+00:00Read Intel
lowtradecraftsource excerpt

PowMix botnet targets Czech workforce

Cisco Talos discovered an ongoing malicious campaign, operating since at least December 2025, affecting a broader workforce in the Czech Republic with a previously undocumented botnet we call

malwaretradecraftwindowscloud
Cisco Talos / 2026-04-16T10:00:33+00:00Read Intel
lowmalwaresource excerpt

UAC-0247 Targets Ukrainian Clinics and Government in Data-Theft Malware Campaign

The Computer Emergencies Response Team of Ukraine (CERT-UA) has disclosed details of a new campaign that has targeted governments and municipal healthcare institutions, mainly clinics and emergency hospitals, to deliver malware capable of stealing sensitive data from Chromium-based web browsers and WhatsApp.

malware
The Hacker News / 2026-04-16T06:20:00+00:00Read Intel
lowadvisorysource excerpt

Incident response for AI: Same fire, different fuel

AI changes how incidents unfold and how we respond. Learn which IR practices still apply and where new telemetry, tools, and skills are needed. The post Incident response for AI: Same fire, different fuel appeared first on Microsoft Security Blog .

windows
Microsoft Security Blog / 2026-04-15T16:00:45+00:00Read Intel
lowadvisorysource excerpt

Rolling Networks: Securing the Transportation Sector

Modern trucks are rolling networks packed with sensors, connectivity, and attack surfaces, creating new cyber risks. NMFTA's Cybersecurity Conference brings industry leaders together to tackle emerging threats in transportation.

BleepingComputer / 2026-04-15T14:00:10+00:00Read Intel
criticalvulnerabilitysource excerpt

Actively Exploited nginx-ui Flaw (CVE-2026-33032) Enables Full Nginx Server Takeover

A recently disclosed critical security flaw impacting nginx-ui, an open-source, web-based Nginx management tool, has come under active exploitation in the wild. The vulnerability in question is CVE-2026-33032 (CVSS score: 9.8), an authentication bypass vulnerability that enables threat actors to seize control of the Nginx service. It has been codenamed MCPwn by Pluto Security.

vulnerabilitycve
The Hacker News / 2026-04-15T12:56:00+00:00Read Intel
highmalwaresource excerpt

The n8n n8mare: How threat actors are misusing AI workflow automation

Cisco Talos research has uncovered agentic AI workflow automation platform abuse in emails. Recently, we identified an increase in the number of emails that abuse n8n, one of these platforms, from as early as October 2025 through March 2026.

malwareexploitationtradecraftcloudemail
Cisco Talos / 2026-04-15T10:00:52+00:00Read Intel
criticalvulnerabilitysource excerpt

Microsoft Issues Patches for SharePoint Zero-Day and 168 Other New Vulnerabilities

Microsoft on Tuesday released updates to address a record 169 security flaws across its product portfolio, including one vulnerability that has been actively exploited in the wild. Of these 169 vulnerabilities, 157 are rated Important, eight are rated Critical, three are rated Moderate, and one is rated Low in severity.

vulnerability
The Hacker News / 2026-04-15T08:40:00+00:00Read Intel
mediumvulnerabilitysource excerpt

New PHP Composer Flaws Enable Arbitrary Command Execution — Patches Released

Two high-severity security vulnerabilities have been disclosed in Composer, a package manager for PHP, that, if successfully exploited, could result in arbitrary command execution. The vulnerabilities have been described as command injection flaws affecting the Perforce VCS (version control software) driver.

vulnerabilitycve
The Hacker News / 2026-04-14T15:57:00+00:00Read Intel
lowadvisorysource excerpt

AI-Driven Pushpaganda Scam Exploits Google Discover to Spread Scareware and Ad Fraud

Cybersecurity researchers have unmasked a novel ad fraud scheme that has been found to leverage search engine poisoning (SEO) techniques and artificial intelligence (AI)-generated content to push deceptive news stories into Google's Discover feed and trick users into enabling persistent browser notifications that lead to scareware and financial scams.

The Hacker News / 2026-04-14T14:30:00+00:00Read Intel
mediumtradecraftsource excerpt

5 Ways Zero Trust Maximizes Identity Security

Stolen credentials remain a top breach vector, often leading to unchecked privilege escalation. Specops explains how identity-first Zero Trust limits access, enforces device trust, and blocks lateral movement.

vulnerabilitytradecraftidentity
BleepingComputer / 2026-04-14T14:02:12+00:00Read Intel
criticalvulnerabilitysource excerpt

ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers

A critical security vulnerability impacting ShowDoc, a document management and collaboration service popular in China, has come under active exploitation in the wild. The vulnerability in question is CVE-2025-0520 (aka CNVD-2020-26585), which carries a CVSS score of 9.4 out of 10.0.

vulnerabilitycve
The Hacker News / 2026-04-14T05:50:00+00:00Read Intel
lowvulnerabilitysource excerpt

CSA: CISOs Should Prepare for Post-Mythos Exploit Storm

Security experts warn of an "AI vulnerability storm" triggered by the introduction of Anthropic's Claude Mythos in a new paper from the Cloud Security Alliance (CSA).

vulnerabilityexploitationcloud
Dark Reading / 2026-04-13T21:29:31+00:00Read Intel
criticalvulnerabilitysource excerpt

Critical flaw in wolfSSL library enables forged certificate use

A critical vulnerability in the wolfSSL SSL/TLS library can weaken security via improper verification of the hash algorithm or its size when checking Elliptic Curve Digital Signature Algorithm (ECDSA) signatures.

vulnerability
BleepingComputer / 2026-04-13T19:56:03+00:00Read Intel
lowadvisorysource excerpt

FBI takedown of W3LL phishing service leads to developer arrest

The FBI Atlanta Field Office and Indonesian authorities have dismantled the "W3LL" global phishing platform, seizing infrastructure and arresting the alleged developer in what is described as the first coordinated enforcement action between the United States and Indonesia targeting a phishing kit developer.

tradecraftemail
BleepingComputer / 2026-04-13T18:55:50+00:00Read Intel
lowmalwaresource excerpt

JanelaRAT Malware Targets Latin American Banks with 14,739 Attacks in Brazil in 2025

Banks and financial institutions in Latin American countries like Brazil and Mexico have continued to be the target of a malware family called JanelaRAT. A modified version of BX RAT, JanelaRAT is known to steal financial and cryptocurrency data associated with specific financial entities, as well as track mouse inputs, log keystrokes, take screenshots, and collect system metadata.

malware
The Hacker News / 2026-04-13T17:15:00+00:00Read Intel
lowadvisorysource excerpt

FBI, Indonesia take down W3LL phishing tool

A widely used phishing tool that allowed hackers to create fake websites that looked like legitimate login portals for just $500 was disrupted by the FBI and law enforcement agencies in Indonesia.

tradecraftemail
The Record / 2026-04-13T16:45:00+00:00Read Intel
lowadvisory

Scans for EncystPHP Webshell, (Mon, Apr 13th)

Last week, I wrote about attackers scanning for various webshells, hoping to find some that do not require authentication or others that use well-known credentials. But some attackers are paying attention and are deploying webshells with more difficult-to-guess credentials. Today, I noticed some scans for what appears to be the "EncystPHP" web shell. Fortinet wrote about this webshell back in January.

SANS ISC / 2026-04-13T13:02:50+00:00Read Intel
lowvulnerabilitysource excerpt

Your MTTD Looks Great. Your Post-Alert Gap Doesn't

Anthropic restricted its Mythos Preview model last week after it autonomously found and exploited zero-day vulnerabilities in every major operating system and browser. Palo Alto Networks' Wendi Whitmorewarned that similar capabilities are weeks or months from proliferation. CrowdStrike's 2026 Global Threat Report puts average eCrime breakout time at 29 minutes.

vulnerability
The Hacker News / 2026-04-13T11:41:00+00:00Read Intel
lowaptsource excerpt

North Korea's APT37 Uses Facebook Social Engineering to Deliver RokRAT Malware

The North Korean hacking group tracked as APT37 (aka ScarCruft) has been attributed to a fresh multi-stage, social engineering campaign in which threat actors approached targets on Facebook and added them as friends on the social media platform, turning the trust-building exercise into a delivery channel for a remote access trojan called RokRAT.

aptmalware
The Hacker News / 2026-04-13T09:15:00+00:00Read Intel
criticalvulnerabilitysource excerpt

Adobe Patches Actively Exploited Acrobat Reader Flaw CVE-2026-34621

Adobe has released emergency updates to fix a critical security flaw in Acrobat Reader that has come under active exploitation in the wild. The vulnerability, assigned the CVE identifier CVE-2026-34621, carries a CVSS score of 8.6 out of 10.0. Successful exploitation of the flaw could allow an attacker to run malicious code on affected installations.

vulnerabilitycve
The Hacker News / 2026-04-12T04:25:00+00:00Read Intel
lowadvisorysource excerpt

What’s new with Google Cloud

Want to know the latest from Google Cloud? Find it here in one handy location. Check back regularly for our newest updates, announcements, resources, events, learning opportunities, and more. Tip : Not sure where to find what you’re looking for on the Google Cloud blog? Start here: Google Cloud blog 101: Full list of topics, links, and resources .

cloud
Mandiant / 2026-04-10T16:00:00+00:00Read Intel
criticaladvisorysource excerpt

Nearly 4,000 US industrial devices exposed to Iranian cyberattacks

The attack surface targeted by Iranian-linked hackers in cyberattacks against U.S. critical infrastructure networks includes thousands of Internet-exposed programmable logic controllers (PLCs) manufactured by Rockwell Automation.

ot
BleepingComputer / 2026-04-10T15:52:45+00:00Read Intel
highvulnerability

[Video] The TTP Ep. 22: The Collapse of the Patch Window

In this episode of The Talos Threat Perspective, we discuss how vulnerability exploitation is accelerating, and why attacker speed, AI, and exposed systems are affecting the patch window.

vulnerabilityexploitationtradecraft
Cisco Talos / 2026-04-10T15:29:39+00:00Read Intel
lowadvisorysource excerpt

FCC proposes new rule to further crackdown on illegal robocalls

The rule would force originating providers to gather more information from customers before they allow calls, verify the provided data more carefully and be assessed steeper penalties when they fail to stop illegal robocalls from being made on their networks.

detection
The Record / 2026-04-09T19:57:00+00:00Read Intel
lowtradecraftsource excerpt

The agentic SOC—Rethinking SecOps for the next decade

In the SOC of the future, autonomous defense moves at machine speed, agents add context and coordination, and humans focus on judgment, risk, and outcomes. The post The agentic SOC—Rethinking SecOps for the next decade appeared first on Microsoft Security Blog .

malwaretradecraftdetectioncloudidentityemail
Microsoft Security Blog / 2026-04-09T19:00:00+00:00Read Intel
lowvulnerabilitysource excerpt

The threat hunter’s gambit

Bill discusses why obsessing over strategy games is actually a secret weapon to outsmart threat actors.

vulnerability
Cisco Talos / 2026-04-09T18:00:20+00:00Read Intel
lowaptsource excerpt

Investigating Storm-2755: “Payroll pirate” attacks targeting Canadian employees

Microsoft Incident Response – Detection and Response Team (DART) researchers observed an emerging, financially motivated threat actor, tracked as Storm-2755, compromising Canadian employee accounts to gain unauthorized access to employee profiles and divert salary payments to attacker-controlled accounts.

apttradecraftdetectionwindowsidentityemail
Microsoft Security Blog / 2026-04-09T15:00:00+00:00Read Intel
mediumvulnerabilitysource excerpt

ThreatsDay Bulletin: Hybrid P2P Botnet, 13-Year-Old Apache RCE and 18 More Stories

Thursday. Another week, another batch of things that probably should've been caught sooner but weren't. This one's got some range — old vulnerabilities getting new life, a few "why was that even possible" moments, attackers leaning on platforms and tools you'd normally trust without thinking twice.

vulnerability
The Hacker News / 2026-04-09T12:57:00+00:00Read Intel
lowadvisorysource excerpt

Webinar: From noise to signal - What threat actors are targeting next

Threat actors often signal their intentions before launching attacks, from dark web chatter to access-broker listings and credential requests. Join our upcoming webinar with Flare Systems to learn how to turn those early warning signs into proactive defensive action before an intrusion begins.

BleepingComputer / 2026-04-09T12:20:28+00:00Read Intel
lowvulnerabilitysource excerpt

Adobe Reader Zero-Day Exploited via Malicious PDFs Since December 2025

Threat actors have been exploiting a previously unknown zero-day vulnerability in Adobe Reader using maliciously crafted PDF documents since at least December 2025. The finding, detailed by EXPMON's Haifei Li, has been described as a highly-sophisticated PDF exploit. The artifact ("Invoice540.pdf") first appeared on the VirusTotal platform on November 28, 2025.

vulnerabilityexploitation
The Hacker News / 2026-04-09T11:15:00+00:00Read Intel
lowadvisorysource excerpt

Microsoft suspends dev accounts for high-profile open source projects

Microsoft has suspended developer accounts used to maintain multiple high-profile open-source projects without proper notification and no way to quickly reinstate them, effectively blocking them from publishing new software builds and security patches for Windows users.

windows
BleepingComputer / 2026-04-09T06:46:26+00:00Read Intel
criticalvulnerability

Docker CVE-2026-34040: Authorization Bypass Leading to Host Access

A critical vulnerability (CVE-2026-34040) in Docker Engine allows attackers to bypass authorization plugins and gain host access, stemming from an incomplete fix for a previous vulnerability.

dockercveauthorization bypasscontainer securityhost access
The Hacker News / 2026-04-09T03:44:38.789178ZRead Intel
highapt

Stealthy Phishing Campaign Targets Industrial Organizations

A sophisticated phishing campaign is targeting industrial organizations, employing advanced techniques for victim profiling and stealthy payload delivery to achieve deeper network access. The campaign's low-volume, deliberate approach poses a significant challenge for detection and response.

phishingindustrial control systemscredential harvestingstealthapt
External Source / 2026-04-09T02:13:26.494785ZRead Intel
highdetection

Multi-OS Cyberattacks Require Unified SOC Workflows

Attackers are increasingly targeting diverse operating systems within enterprise environments, exploiting fragmented Security Operations Center (SOC) workflows. This report outlines the challenges and provides a three-step approach for SOCs to close critical risks by unifying their cross-platform defense strategies.

soccross-platformthreat detectionincident responseattack surface
The Hacker News / 2026-04-09T02:12:53.113262ZRead Intel
highdetection

Cross-Platform Attack Campaigns Expose SOC Workflow Gaps

Attackers are increasingly targeting diverse operating systems within enterprise environments, exploiting fragmented Security Operations Center (SOC) workflows that remain siloed by platform. This report outlines the challenge and provides a framework for SOCs to address this critical risk.

cross-platformsocattack surfacethreat detectionincident response
External Source / 2026-04-09T02:12:45.431681ZRead Intel
highapt

Iran-Linked Threat Actor Conducts Widespread Password-Spraying Campaign Against Microsoft 365

An Iran-nexus threat actor has been observed conducting a large-scale password-spraying campaign targeting over 300 Israeli Microsoft 365 organizations, with additional activity noted in the UAE and other regions. This campaign, occurring in multiple waves, leverages common passwords against numerous accounts to bypass security measures and gain initial access, potentially for data exfiltration.

password sprayingmicrosoft 365iranaptespionage
External Source / 2026-04-09T02:12:41.021897ZRead Intel
highapt

Authorities Disrupt FrostArmada Campaign Hijacking Routers for Microsoft 365 Credential Theft

An international law enforcement operation, in collaboration with private cybersecurity firms, has successfully dismantled FrostArmada, a sophisticated campaign orchestrated by APT28. This operation targeted MikroTik and TP-Link routers, exploiting their DNS resolution capabilities to redirect users to fake Microsoft 365 login pages, thereby harvesting sensitive credentials.

apt28frostarmadarouterdnsmicrosoft 365credential theft
BleepingComputer / 2026-04-09T02:12:29.968864ZRead Intel
criticalvulnerability

Windows Zero-Day 'BlueHammer' Exploit Leaked

A zero-day exploit for a Windows privilege escalation vulnerability, dubbed 'BlueHammer', has been publicly released after a researcher allegedly leaked it due to dissatisfaction with Microsoft's handling of the disclosure. The exploit allows attackers to gain SYSTEM-level privileges.

windowszero-dayprivilege escalationexploitbluehammer
External Source / 2026-04-09T02:12:17.479231ZRead Intel
highvulnerability

Automated Credential Theft Campaign Exploits React2Shell Vulnerability in Next.js Applications

A large-scale automated campaign is actively exploiting the React2Shell vulnerability (CVE-2025-55182) in Next.js applications to steal sensitive credentials, including API keys, SSH private keys, and cloud credentials. The operation, attributed to threat cluster UAT-10608, utilizes a framework called NEXUS Listener to exfiltrate data from at least 766 compromised hosts.

react2shellnext.jscredential theftnexus listenercve-2025-55182
External Source / 2026-04-09T02:11:02.415251ZRead Intel
highvulnerability

Docker CVE-2026-34040: Authorization Bypass Leading to Host Access

A critical vulnerability (CVE-2026-34040) in Docker Engine allows attackers to bypass authorization plugins and gain host access, stemming from an incomplete fix for a previous vulnerability.

dockercveauthorizationhost accesscontainer security
The Hacker News / 2026-04-09T02:10:54.928485ZRead Intel
mediumdetection

Multi-OS Cyberattacks Require Unified SOC Workflows

Attackers are increasingly targeting diverse operating systems within enterprise environments, exploiting fragmented Security Operations Center (SOC) workflows. This report outlines how SOCs can adapt to this evolving threat landscape by unifying their approach across Windows, macOS, Linux, and mobile devices.

socmulti-oscyberattackdetectionworkflow
The Hacker News / 2026-04-09T02:10:50.938514ZRead Intel
highdetection

Cross-Platform Attack Campaigns Expose SOC Workflow Gaps

Attackers are increasingly targeting diverse operating systems within enterprise environments, exploiting fragmented Security Operations Center (SOC) workflows that remain siloed by platform. This multi-OS approach creates significant blind spots and risks for organizations.

cross-platformsocattack surfacethreat detectionendpoint security
External Source / 2026-04-09T02:10:46.691768ZRead Intel
highapt

Iran-Linked Threat Actors Conduct Password-Spraying and Ransomware Attacks

This report details a coordinated cyber campaign linked to Iran, involving widespread password-spraying attacks against Microsoft 365 environments and renewed activity from the Pay2Key ransomware group. The campaign highlights the evolving tactics of state-sponsored actors in the Middle East.

iranpassword sprayingmicrosoft 365ransomwarepay2key
External Source / 2026-04-09T02:10:42.172921ZRead Intel
mediumadvisory

CISA to Host Town Halls on Critical Infrastructure Cyber Incident Reporting

CISA is launching a series of town hall meetings to gather feedback from critical infrastructure stakeholders regarding the implementation of new cyber incident reporting requirements. These sessions aim to foster collaboration and ensure effective communication as these regulations take shape.

cisacritical infrastructurereportingregulationstakeholder engagement
External Source / 2026-04-09T02:10:36.952111ZRead Intel
criticalvulnerability

Disgruntled Researcher Leaks "BlueHammer" Windows Zero-Day Exploit

An unpatched Windows privilege escalation zero-day exploit, codenamed "BlueHammer," has been publicly leaked by a disgruntled researcher, enabling attackers to achieve SYSTEM or elevated administrator privileges.

windowszero-dayprivilege escalationexploitbluehammer
BleepingComputer / 2026-04-09T02:10:26.059379ZRead Intel
criticalvulnerability

Windows Zero-Day 'BlueHammer' Exploit Leaked, Enabling Privilege Escalation

A zero-day exploit for a Windows privilege escalation vulnerability, codenamed 'BlueHammer', has been publicly released. The exploit allows unauthenticated attackers to gain SYSTEM-level privileges on affected Windows systems.

windowszero-dayprivilege escalationexploitbluehammer
External Source / 2026-04-09T02:10:23.056297ZRead Intel
mediumadvisorysource excerpt

Cracks in the Bedrock: Agent God Mode

Unit 42 reveals "Agent God Mode" in Amazon Bedrock AgentCore. Broad IAM permissions lead to privilege escalation and data exfiltration risks. The post Cracks in the Bedrock: Agent God Mode appeared first on Unit 42 .

vulnerabilityexploitationcloud
Unit 42 / 2026-04-08T22:00:51+00:00Read Intel
criticalvulnerabilitysource excerpt

CISA orders feds to patch exploited Ivanti EPMM flaw by Sunday

CISA has given U.S. government agencies four days to secure their systems against a critical-severity vulnerability in Ivanti Endpoint Manager Mobile (EPMM) that has been exploited in attacks since January.

vulnerability
BleepingComputer / 2026-04-08T18:15:27+00:00Read Intel
lowmalwaresource excerpt

New Chaos Variant Targets Misconfigured Cloud Deployments, Adds SOCKS Proxy

Cybersecurity researchers have flagged a new variant ofmalware called Chaosthat'scapable of hitting misconfigured cloud deployments, marking an expansion of the botnet's targeting infrastructure. "Chaos malware is increasingly targeting misconfigured cloud deployments, expanding beyond its traditional focus on routers and edge devices," Darktrace said in a new report.

malwarecloud
The Hacker News / 2026-04-08T17:51:00+00:00Read Intel
lowadvisory

TeamPCP Supply Chain Campaign: Update 007 - Cisco Source Code Stolen via Trivy-Linked Breach, Google GTIG Tracks TeamPCP as UNC6780, and CISA KEV Deadline Arrives with No Standalone Advisory, (Wed, Apr 8th)

This is the seventh update to the TeamPCP supply chain campaign threat intelligence report,&&#x23&#x3b;x26&#x3b;&#x23&#x3b;xc2&#x3b;&&#x23&#x3b;x26&#x3b;&#x23&#x3b;xa0&#x3b;"When the Security Scanner Became the Weapon"&&#x23&#x3b;x26&#x3b;&#x23&#x3b;xc2&#x3b;&&#x23&#x3b;x26&#x3b;&#x23&#x3b;xa0&#x3b;(v3.0, March 25, 2026).&&#x23&#x3b;x26&#x3b;&#x23&#x3b;xc2&#x3b;&&#x23&#x3b;x26&#x3b;&#x23&#x3b;xa0&#x3b;Update

SANS ISC / 2026-04-08T17:15:05+00:00Read Intel
lowadvisorysource excerpt

Masjesu Botnet Emerges as DDoS-for-Hire Service Targeting Global IoT Devices

Cybersecurity researchers have lifted the curtain on a stealthy botnet that's designed for distributed denial-of-service (DDoS) attacks. Called Masjesu, the botnet has been advertised via Telegram as a DDoS-for-hire service since it first surfaced in 2023. It's capable of targeting a wide range of IoT devices, such as routers and gateways, spanning multiple architectures.

The Hacker News / 2026-04-08T16:30:00+00:00Read Intel
lowadvisorysource excerpt

Is a $30,000 GPU Good at Password Cracking?

A $30,000 AI GPU doesn't outperform consumer GPUs at password cracking. Specops explains why attackers don't need exotic hardware to break weak passwords.

BleepingComputer / 2026-04-08T14:00:10+00:00Read Intel
lowtradecraftsource excerpt

Financial cyberthreats in 2025 and the outlook for 2026

In this report, Kaspersky experts share their insights into the 2025 financial threat landscape, including regional statistics and trends in phishing, PC malware, and infostealers.

malwareexploitationtradecraftidentityemail
Securelist / 2026-04-08T09:00:37+00:00Read Intel
criticalvulnerabilitysource excerpt

Hackers exploit critical flaw in Ninja Forms WordPress plugin

A critical vulnerability in the Ninja Forms File Uploads premium add-on for WordPress allows uploading arbitrary files without authentication, which can lead to remote code execution.

vulnerabilityexploitation
BleepingComputer / 2026-04-07T22:03:01+00:00Read Intel
lowtradecraft

A Little Bit Pivoting: What Web Shells are Attackers Looking for?, (Tue, Apr 7th)

Webshells remain a popular method for attackers to maintain persistence on a compromised web server. Many "arbitrary file write" and "remote code execution" vulnerabilities are used to drop small files on systems for later execution of additional payloads. The names of these files keep changing and are often chosen to "fit in" with other files.

malwaretradecraft
SANS ISC / 2026-04-07T18:28:16+00:00Read Intel
lowaptsource excerpt

Russian State-Linked APT28 Exploits SOHO Routers in Global DNS Hijacking Campaign

The Russia-linked threat actor known as APT28 (aka Forest Blizzard) has been linked to a new campaign that has compromised insecure MikroTik and TP-Link routers and modified their settings to turn them into malicious infrastructure under their control as part of a cyber espionage campaign since at least May 2025.

apt
The Hacker News / 2026-04-07T16:48:00+00:00Read Intel
lowadvisorysource excerpt

[Webinar] How to Close Identity Gaps in 2026 Before AI Exploits Enterprise Risk

In the rapid evolution of the 2026 threat landscape, a frustrating paradox has emerged for CISOs and security leaders: Identity programs are maturing, yet the risk is actually increasing. According to new research from the Ponemon Institute, hundreds of applications within the typical enterprise remain disconnected from centralized identity systems.

identity
The Hacker News / 2026-04-07T16:29:00+00:00Read Intel
mediumvulnerabilitysource excerpt

Docker CVE-2026-34040 Lets Attackers Bypass Authorization and Gain Host Access

A high-severity security vulnerability has been disclosed in Docker Engine that could permit an attacker to bypass authorization plugins (AuthZ) under specific circumstances. The vulnerability, tracked as CVE-2026-34040 (CVSS score: 8.8), stems from an incomplete fix for CVE-2024-41110, a maximum-severity vulnerability in the same component that came to light in July 2024.

vulnerabilitycve
The Hacker News / 2026-04-07T15:15:00+00:00Read Intel
lowadvisorysource excerpt

Why Your Automated Pentesting Tool Just Hit a Wall

Automated pentesting tools deliver strong early results, then quickly plateau. Picus Security explains how the "PoC cliff" leaves major attack surfaces untested and creates a dangerous validation gap.

exploitation
BleepingComputer / 2026-04-07T14:01:11+00:00Read Intel
lowaptsource excerpt

SOHO router compromise leads to DNS hijacking and adversary-in-the-middle attacks

Executive summary Forest Blizzard, a threat actor linked to the Russian military, has been compromising insecure home and small-office internet equipment like routers, then modifying their settings in ways that turn them into part of the actor’s malicious infrastructure. The post SOHO router compromise leads to DNS hijacking and adversary-in-the-middle attacks appeared first on Microsoft Security Blog .

apttradecraftdetectionwindowscloudnetwork
Microsoft Security Blog / 2026-04-07T14:00:00+00:00Read Intel
highvulnerabilitysource excerpt

Year in Review: Vulnerabilities old and new and something React2

The year was characterized by an unending beat-down on infrastructure that relied on older enmeshed dependencies (e.g., Log4j and PHPUnit), while React2Shell rocketed to the highest percentage of attacks for the entire year within the last three weeks of 2025.

vulnerabilityexploitationwindowsidentity
Cisco Talos / 2026-04-07T10:00:11+00:00Read Intel
mediumadvisorysource excerpt

New GPUBreach Attack Enables Full CPU Privilege Escalation via GDDR6 Bit-Flips

New academic research has identified multiple RowHammer attacks against high-performance graphics processing units (GPUs) that could be exploited to escalate privileges and, in some cases, even take full control of a host. The efforts have been codenamed GPUBreach, GDDRHammer, and GeForge.

vulnerability
The Hacker News / 2026-04-07T08:38:00+00:00Read Intel
mediumvulnerabilitysource excerpt

Flowise AI Agent Builder Under Active CVSS 10.0 RCE Exploitation; 12,000+ Instances Exposed

Threat actors are exploiting a maximum-severity security flaw in Flowise, an open-source artificial intelligence (AI) platform, according to new findings from VulnCheck. The vulnerability in question is CVE-2025-59528 (CVSS score: 10.0), a code injection vulnerability that could result in remote code execution.

vulnerabilitycve
The Hacker News / 2026-04-07T05:56:00+00:00Read Intel
criticaladvisorysource excerpt

Understanding Current Threats to Kubernetes Environments

Unit 42 uncovers escalating Kubernetes attacks, detailing how threat actors exploit identities and critical vulnerabilities to compromise cloud environments. The post Understanding Current Threats to Kubernetes Environments appeared first on Unit 42 .

exploitationcloud
Unit 42 / 2026-04-06T22:00:08+00:00Read Intel
lowaptsource excerpt

AI-Assisted Supply Chain Attack Targets GitHub

PRT-scan is the second campaign in recent months where a threat actor appears to have leveraged AI for automated targeting of a widespread GitHub misconfiguration.

apt
Dark Reading / 2026-04-06T21:38:53+00:00Read Intel
lowaptsource excerpt

Iran-Linked Password-Spraying Campaign Targets 300+ Israeli Microsoft 365 Organizations

An Iran-nexus threat actor is suspected to be behind a password-spraying campaign targeting Microsoft 365 environments in Israel and the U.A.E. amid ongoing conflict in the Middle East. The activity, assessed to be ongoing, was carried out in three distinct attack waves that took place on March 3, March 13, and March 23, 2026, per Check Point.

apt
The Hacker News / 2026-04-06T18:37:00+00:00Read Intel
highransomwaresource excerpt

Microsoft links Medusa ransomware affiliate to zero-day attacks

Microsoft says that Storm-1175, a China-based financially motivated cybercriminal group known for deploying Medusa ransomware payloads, has been deploying n-day and zero-day exploits in high-velocity attacks.

ransomwarevulnerability
BleepingComputer / 2026-04-06T16:56:01+00:00Read Intel
lowaptsource excerpt

Inside an AI‑enabled device code phishing campaign

A new wave of device code phishing shows how threat actors are scaling account compromise using AI and end‑to‑end automation. This campaign goes beyond traditional phishing by generating live authentication codes on demand, enabling higher success rates and sustained post‑compromise access. The post Inside an AI‑enabled device code phishing campaign appeared first on Microsoft Security Blog .

apttradecraftdetectionwindowsemail
Microsoft Security Blog / 2026-04-06T16:34:17+00:00Read Intel
highvulnerabilitysource excerpt

CISA orders feds to patch exploited Fortinet EMS flaw by Friday

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered federal agencies to secure FortiClient Enterprise Management Server (EMS) instances against an actively exploited vulnerability by Friday.

vulnerability
BleepingComputer / 2026-04-06T16:02:14+00:00Read Intel
criticalransomwaresource excerpt

Storm-1175 focuses gaze on vulnerable web-facing assets in high-tempo Medusa ransomware operations

The financially motivated cybercriminal threat actor Storm-1175 operates high-velocity ransomware campaigns that weaponize recently disclosed vulnerabilities to obtain initial access, exfiltrate data, and deploy Medusa ransomware. The post Storm-1175 focuses gaze on vulnerable web-facing assets in high-tempo Medusa ransomware operations appeared first on Microsoft Security Blog .

ransomwareaptvulnerabilitycvetradecraftwindows
Microsoft Security Blog / 2026-04-06T16:00:00+00:00Read Intel
criticaladvisorysource excerpt

Multi-OS Cyberattacks: How SOCs Close a Critical Risk in 3 Steps

Your attack surface no longer lives on one operating system, and neither do the campaigns targeting it. In enterprise environments, attackers move across Windows endpoints, executive MacBooks, Linux infrastructure, and mobile devices, taking advantage of the fact that many SOC workflows are still fragmented by platform.

windowslinux
The Hacker News / 2026-04-06T13:00:00+00:00Read Intel
lowadvisorysource excerpt

⚡ Weekly Recap: Axios Hack, Chrome 0-Day, Fortinet Exploits, Paragon Spyware and More

This week had real hits. The key software got tampered with. Active bugs showed up in the tools people use every day. Some attacks didn’t even need much effort because the path was already there. One weak spot now spreads wider than before. What starts small can reach a lot of systems fast. New bugs, faster use, less time to react. That’s this week.

The Hacker News / 2026-04-06T12:46:00+00:00Read Intel
lowadvisorysource excerpt

How LiteLLM Turned Developer Machines Into Credential Vaults for Attackers

The most active piece of enterprise infrastructure in the company is the developer workstation. That laptop is where credentials are created, tested, cached, copied, and reused across services, bots, build tools, and now local AI agents. In March 2026, the TeamPCP threat actor proved just how valuable developer machines are.

The Hacker News / 2026-04-06T11:45:00+00:00Read Intel
highransomwaresource excerpt

Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR Tools

Threat actors associated with Qilin and Warlock ransomware operations have been observed using the bring your own vulnerable driver (BYOVD) technique to silence security tools running on compromised hosts, according to findings from Cisco Talos and Trend Micro.

ransomwaretradecraft
The Hacker News / 2026-04-06T10:07:00+00:00Read Intel
highransomwaresource excerpt

BKA Identifies REvil Leaders Behind 130 German Ransomware Attacks

Germany's Federal Criminal Police Office (aka BKA or the Bundeskriminalamt) has unmasked the real identities of two of the key figures associated with the now-defunct REvil (aka Sodinokibi) ransomware-as-a-service (RaaS) operation.

ransomware
The Hacker News / 2026-04-06T06:59:00+00:00Read Intel
lowadvisorysource excerpt

$285 Million Drift Hack Traced to Six-Month DPRK Social Engineering Operation

Drift has revealed that the April 1, 2026, attack that led to the theft of $285 million was the culmination of a months-long targeted and meticulously planned social engineering operation undertaken by the Democratic People's Republic of Korea (DPRK) that began in the fall of 2025.

The Hacker News / 2026-04-05T18:25:00+00:00Read Intel
criticalvulnerabilitysource excerpt

Fortinet Patches Actively Exploited CVE-2026-35616 in FortiClient EMS

Fortinet has released out-of-band patches for a critical security flaw impacting FortiClient EMS that it said has been exploited in the wild. The vulnerability, tracked as CVE-2026-35616 (CVSS score: 9.1), has been described as a pre-authentication API access bypass leading to privilege escalation.

vulnerabilitycve
The Hacker News / 2026-04-05T04:32:00+00:00Read Intel
highvulnerabilitysource excerpt

Do not get high(jacked) off your own supply (chain)

In the span of just a few weeks, we have observed a dizzying array of major supply chain attacks. If we are all building on such shaky foundation, what can we do to keep safe?

vulnerabilityexploitation
Cisco Talos / 2026-04-03T17:31:42+00:00Read Intel
lowmalwaresource excerpt

Axios NPM supply chain incident

Overview of the recent Axios NPM supply chain incident including details of the payloads delivered from actor-controlled infrastructure.

malwarewindowslinux
Cisco Talos / 2026-04-03T17:00:22+00:00Read Intel
lowadvisorysource excerpt

Why Third-Party Risk Is the Biggest Gap in Your Clients' Security Posture

The next major breach hitting your clients probably won't come from inside their walls. It'll come through a vendor they trust, a SaaS tool their finance team signed up for, or a subcontractor nobody in IT knows about. That's the new attack surface, and most organizations are underprepared for it.

The Hacker News / 2026-04-03T11:00:00+00:00Read Intel
mediumvulnerabilitysource excerpt

Hackers Exploit CVE-2025-55182 to Breach 766 Next.js Hosts, Steal Credentials

A large-scale credential harvesting operation has been observed exploiting the React2Shell vulnerability as an initial infection vector to steal database credentials, SSH private keys, Amazon Web Services (AWS) secrets, shell command history, Stripe API keys, and GitHub tokens at scale.

vulnerabilitycveexploitationcloud
The Hacker News / 2026-04-02T19:30:00+00:00Read Intel
criticalaptsource excerpt

Threat actor abuse of AI accelerates from tool to cyberattack surface

Generative AI is upgrading cyberattacks, from 450% higher phishing click‑through rates to industrialized MFA bypass. The post Threat actor abuse of AI accelerates from tool to cyberattack surface appeared first on Microsoft Security Blog .

aptmalwaretradecraftotwindowsidentity
Microsoft Security Blog / 2026-04-02T16:00:00+00:00Read Intel
lowaptsource excerpt

Cookie-controlled PHP webshells: A stealthy tradecraft in Linux hosting environments

Cookie-gated PHP webshells use obfuscation, php-fpm execution, and cron-based persistence to evade detection in Linux hosting environments. This post examines how this tradecraft conceals execution behind specially crafted HTTP cookies. The post Cookie-controlled PHP webshells: A stealthy tradecraft in Linux hosting environments appeared first on Microsoft Security Blog .

aptmalwaretradecraftdetectionwindowslinux
Microsoft Security Blog / 2026-04-02T15:37:22+00:00Read Intel
criticalvulnerabilitysource excerpt

Cisco Patches 9.8 CVSS IMC and SSM Flaws Allowing Remote System Compromise

Cisco has released updates to address a critical security flaw in the Integrated Management Controller (IMC) that, if successfully exploited, could allow an unauthenticated, remote attacker to bypass authentication and gain access to the system with elevated privileges. The vulnerability, tracked as CVE-2026-20093, carries a CVSS score of 9.8 out of a maximum of 10.0.

vulnerabilitycve
The Hacker News / 2026-04-02T15:21:00+00:00Read Intel
criticalvulnerabilitysource excerpt

vSphere and BRICKSTORM Malware: A Defender's Guide

Written by: Stuart Carrera Introduction Building on recent BRICKSTORM research from Google Threat Intelligence Group (GTIG), this post explores the evolving threats facing virtualized environments. These operations directly target the VMware vSphere ecosystem, specifically the vCenter Server Appliance (VCSA) and ESXi hypervisors.

malwarevulnerabilitytradecraftdetectionwindowslinux
Mandiant / 2026-04-02T14:00:00+00:00Read Intel
lowtradecraftsource excerpt

[Video] The TTP Ep 21: When Attackers Become Trusted Users

An episode of the Talos Threat Perspective on the 2025 Year in Review trends. We explore how identity is being used to gain, extend, and maintain access inside environments.

exploitationtradecraftidentityemail
Cisco Talos / 2026-04-02T13:06:45+00:00Read Intel
lowadvisorysource excerpt

The State of Trusted Open Source Report

In December 2025, we shared the first-ever The State of Trusted Open Source report, featuring insights from our product data and customer base on open source consumption across our catalog of container image projects, versions, images, language libraries, and builds.

cloud
The Hacker News / 2026-04-02T11:30:00+00:00Read Intel
highransomwaresource excerpt

Qilin EDR killer infection chain

This blog provides an in-depth analysis of the malicious “msimg32.dll” used in Qilin ransomware attacks, which is a multi-stage infection chain targeting EDR systems.

ransomwaremalwaredetectionwindows
Cisco Talos / 2026-04-02T10:00:56+00:00Read Intel
lowaptsource excerpt

Mitigating the Axios npm supply chain compromise

On March 31, 2026, the popular HTTP client Axios experienced a supply chain attack, causing two newly published npm packages for version updates to download from command and control (C2) that Microsoft Threat Intelligence has attributed to the North Korean state actor Sapphire Sleet.

aptmalwarewindowslinux
Microsoft Security Blog / 2026-04-01T21:00:00+00:00Read Intel
lowtradecraft

Malicious Script That Gets Rid of ADS, (Wed, Apr 1st)

Today, most malware are called “fileless” because they try to reduce their footprint on the infected computer filesystem to the bare minimum. But they need to write something… think about persistence. They can use the registry as an alternative storage location.

malwaretradecraft
SANS ISC / 2026-04-01T20:09:43+00:00Read Intel
lowtradecraftsource excerpt

Microsoft Warns of WhatsApp-Delivered VBS Malware Hijacking Windows via UAC Bypass

Microsoft is calling attention to a new campaign that has leveraged WhatsApp messages to distribute malicious Visual Basic Script (VBS) files. The activity, beginning in late February 2026, leverages these scripts to initiate a multi-stage infection chain for establishing persistence and enabling remote access.

malwaretradecraftwindows
The Hacker News / 2026-04-01T14:10:00+00:00Read Intel
lowaptsource excerpt

Casbaneiro Phishing Targets Latin America and Europe Using Dynamic PDF Lures

A multi-pronged phishing campaign is targeting Spanish-speaking users in organizations across Latin America and Europe to deliver Windows banking trojans like Casbaneiro (aka Metamorfo) via another malware called Horabot. The activity has been attributed to a Brazilian cybercrime threat actor tracked as Augmented Marauder and Water Saci.

aptmalwaretradecraftwindowsemail
The Hacker News / 2026-04-01T12:36:00+00:00Read Intel
highvulnerabilitysource excerpt

New Chrome Zero-Day CVE-2026-5281 Under Active Exploitation — Patch Released

Google on Thursday released security updates for its Chrome web browser to address 21 vulnerabilities, including a zero-day flaw that it said has been exploited in the wild. The high-severity vulnerability, CVE-2026-5281 (CVSS score: N/A), concerns a use-after-free bug in Dawn, an open-source and cross-platform implementation of the WebGPU standard.

vulnerabilitycve
The Hacker News / 2026-04-01T11:42:00+00:00Read Intel
lowmalwaresource excerpt

3 Reasons Attackers Are Using Your Trusted Tools Against You (And Why You Don’t See It Coming)

For years, cybersecurity has followed a familiar model: block malware, stop the attack. Now, attackers are moving on to what’s next. Threat actors now use malware less frequently in favor of what’s already inside your environment, including abusing trusted tools, native binaries, and legitimate admin utilities to move laterally, escalate privileges, and persist without raising alarms.

malware
The Hacker News / 2026-04-01T10:58:00+00:00Read Intel
lowadvisorysource excerpt

Are We Training AI Too Late?

Ask the Expert: Cybersecurity teams need to expand their field of view to include new, unique threat sources, rather than relying on past, proven threat actors.

Dark Reading / 2026-04-01T10:40:13+00:00Read Intel
lowaptsource excerpt

Google Attributes Axios npm Supply Chain Attack to North Korean Group UNC1069

Google has formally attributed the supply chain compromise of the popular Axios npm package to a financially motivated North Korean threat activity cluster tracked as UNC1069. "We have attributed the attack to a suspected North Korean threat actor we track as UNC1069," John Hultquist, chief analyst at Google Threat Intelligence Group (GTIG), told The Hacker News in a statement.

apt
The Hacker News / 2026-04-01T07:44:00+00:00Read Intel
lowadvisorysource excerpt

Claude Code Source Leaked via npm Packaging Error, Anthropic Confirms

Anthropic on Tuesday confirmed that internal code for its popular artificial intelligence (AI) coding assistant, Claude Code, had been inadvertently released due to a human error. "No sensitive customer data or credentials were involved or exposed," an Anthropic spokesperson said in a statement shared with CNBC News.

The Hacker News / 2026-04-01T06:12:00+00:00Read Intel
lowadvisorysource excerpt

Android Developer Verification Rollout Begins Ahead of September Enforcement

Google on Monday said it's officially rolling out Android developer verification to all developers to combat the problem of bad actors distributing harmful apps while "hiding behind anonymity." The development comes ahead of a planned verification mandate that goes into effect in Brazil, Indonesia, Singapore, and Thailand this September, before it expands globally next year.

The Hacker News / 2026-03-31T18:28:00+00:00Read Intel
criticalotsource excerpt

The threat to critical infrastructure has changed. Has your readiness?

Five facts critical infrastructure (CI) leaders need to act on in 2026, grounded in what Microsoft Threat Intelligence is observing across sectors right now. The post The threat to critical infrastructure has changed. Has your readiness? appeared first on Microsoft Security Blog .

otcloudidentity
Microsoft Security Blog / 2026-03-31T17:00:00+00:00Read Intel
lowadvisorysource excerpt

Applying security fundamentals to AI: Practical advice for CISOs

Read actionable advice for CISOs on securing AI, managing risk, and applying core security principles in today’s AI‑powered environment. The post Applying security fundamentals to AI: Practical advice for CISOs appeared first on Microsoft Security Blog .

identity
Microsoft Security Blog / 2026-03-31T16:00:00+00:00Read Intel
lowaptsource excerpt

North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack

Written by: Austin Larsen, Dima Lenz, Adrian Hernandez, Tyler McLellan, Christopher Gardner, Ashley Zaya, Michael Rudden, Mon Liclican Introduction Google Threat Intelligence Group (GTIG) is tracking an active software supply chain attack targeting the popular Node Package Manager (NPM) package " axios ."

aptmalwarewindowslinuxcloudemail
Mandiant / 2026-03-31T14:00:00+00:00Read Intel
lowaptsource excerpt

WhatsApp malware campaign delivers VBScript and MSI backdoors

A malware campaign uses WhatsApp messages to deliver VBS scripts that initiate a multi-stage infection chain. The attack leverages renamed Windows tools and cloud-hosted payloads to install MSI backdoors and maintain persistent access to compromised systems. The post WhatsApp malware campaign delivers VBScript and MSI backdoors appeared first on Microsoft Security Blog .

aptmalwaretradecraftdetectionwindowscloud
Microsoft Security Blog / 2026-03-31T13:43:05+00:00Read Intel
highvulnerabilitysource excerpt

Vertex AI Vulnerability Exposes Google Cloud Data and Private Artifacts

Cybersecurity researchers have disclosed a security "blind spot" in Google Cloud's Vertex AI platform that could allow artificial intelligence (AI) agents to be weaponized by an attacker to gain unauthorized access to sensitive data and compromise an organization's cloud environment.

vulnerabilityexploitationcloud
The Hacker News / 2026-03-31T13:09:00+00:00Read Intel
lowadvisorysource excerpt

The AI Arms Race – Why Unified Exposure Management Is Becoming a Boardroom Priority

The cybersecurity landscape is accelerating at an unprecedented rate. What is emerging is not simply a rise in the number of vulnerabilities or tools, but a dramatic increase in speed. Speed of attack, speed of exploitation, and speed of change across modern environments. This is the defining challenge of the new era of digital warfare: the weaponization of Artificial Intelligence.

The Hacker News / 2026-03-31T11:50:00+00:00Read Intel
highransomwaresource excerpt

Ransomware in 2025: Blending in is the strategy

A summary of the top ransomware trends from the Talos 2025 Year in Review, with a focus on identity, attacker tactics, and practical defenses.

ransomwaretradecraftwindowsidentityemail
Cisco Talos / 2026-03-31T10:00:02+00:00Read Intel
lowmalwaresource excerpt

Axios Supply Chain Attack Pushes Cross-Platform RAT via Compromised npm Account

The popular HTTP client known as Axios has suffered a supply chain attack after two newly published versions of the npm package introduced a malicious dependency that delivers a trojan capable of targeting Windows, macOS, and Linux systems. Versions 1.14.1 and 0.30.4 of Axios have been found to inject "plain-crypto-js" version 4.2.1 as a fake dependency.

malwarewindowslinux
The Hacker News / 2026-03-31T06:08:00+00:00Read Intel
lowadvisorysource excerpt

Addressing the OWASP Top 10 Risks in Agentic AI with Microsoft Copilot Studio

Agentic AI introduces new security risks. Learn how the OWASP Top 10 Risks for Agentic Applications maps to real mitigations in Microsoft Copilot Studio. The post Addressing the OWASP Top 10 Risks in Agentic AI with Microsoft Copilot Studio appeared first on Microsoft Security Blog .

identity
Microsoft Security Blog / 2026-03-30T16:00:00+00:00Read Intel
criticalvulnerabilitysource excerpt

Storm Brews Over Critical, No-Click Telegram Flaw

The vulnerability, which is allegedly triggered by a corrupted sticker in the messaging app, received a 9.8 CVSS score, but Telegram denies it exists.

vulnerability
Dark Reading / 2026-03-30T15:01:59+00:00Read Intel
criticalvulnerabilitysource excerpt

Critical Flaw in Langflow AI Platform Under Attack

Threats actors pounced on the code injection vulnerability within hours of its disclosure, demonstrating that organizations have little time to address critical bugs.

vulnerability
Dark Reading / 2026-03-26T19:14:05+00:00Read Intel
mediumvulnerabilitysource excerpt

TP-Link, Canva, HikVision vulnerabilities

Cisco Talos’ Vulnerability Discovery & Research team recently disclosed a vulnerability in HikVision, as well as 10 in TP-Link, and 19 in Canva. The vulnerabilities mentioned in this blog post have been patched by their respective vendors, all in adherence to Cisco’s third-party vulnerability disclosure policy .

vulnerabilitycveexploitationdetection
Cisco Talos / 2026-03-26T18:34:26+00:00Read Intel
lowadvisorysource excerpt

A puppet made me cry and all I got was this t-shirt

In this week's newsletter, Amy draws parallels between the collaborative themes of "Project Hail Mary" and the massive team effort behind the newly released Talos Year in Review report.

Cisco Talos / 2026-03-26T18:00:44+00:00Read Intel
lowmalwaresource excerpt

An AI gateway designed to steal your data

Dissecting the supply chain attack on LiteLLM, a multifunctional gateway used in many AI agents. Explaining the dangers of the malicious code and how to protect yourself.

malwarecloudnetwork
Securelist / 2026-03-26T11:01:38+00:00Read Intel
mediumvulnerabilitysource excerpt

Coruna: the framework used in Operation Triangulation

Kaspersky GReAT experts look into the Coruna exploit kit targeting iPhones. We discovered that the kernel exploit for CVE-2023-32434 and CVE-2023-38606 is an updated version of the Operation Triangulation exploit.

vulnerabilitycveexploitation
Securelist / 2026-03-26T08:00:19+00:00Read Intel
lowadvisorysource excerpt

Anatomy of a Cyber World Global Report 2026

The Kaspersky Security Services report describes cyberattack trends and statistics revealed by the Managed Detection and Response service. The report also includes Incident Response findings based on real-world cases identified and mitigated in 2025.

detectionot
Securelist / 2026-03-25T11:00:56+00:00Read Intel
lowtradecraftsource excerpt

M-Trends 2026: Data, Insights, and Strategies From the Frontlines

Every year, the cyber threat landscape forces defenders to adapt to evolving adversary tactics, techniques, and procedures (TTPs). In 2025, Mandiant observed a clear divergence in adversary pacing that closely aligns with the trends we have been documenting for defenders over the past year. On one end of the spectrum, cyber criminal groups optimized for immediate impact and deliberate recovery denial.

tradecraftdetectioncloud
Mandiant / 2026-03-23T14:00:00+00:00Read Intel
lowmalwaresource excerpt

Analyzing the Current State of AI Use in Malware

Unit 42 research explores how AI is currently used in malware, from superficial integrations to advanced decision-making, and its future impact. The post Analyzing the Current State of AI Use in Malware appeared first on Unit 42 .

malware
Unit 42 / 2026-03-19T10:00:01+00:00Read Intel
lowvulnerabilitysource excerpt

The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors

Introduction Google Threat Intelligence Group (GTIG) has identified a new iOS full-chain exploit that leveraged multiple zero-day vulnerabilities to fully compromise devices. Based on toolmarks in recovered payloads, we believe the exploit chain to be called DarkSword.

aptmalwarevulnerabilityexploitationcloud
Mandiant / 2026-03-18T14:00:00+00:00Read Intel
lowmalwaresource excerpt

Boggy Serpens Threat Assessment

Iranian threat group Boggy Serpens' cyberespionage evolves with AI-enhanced malware and refined social engineering. Unit 42 details their persistent targeting. The post Boggy Serpens Threat Assessment appeared first on Unit 42 .

malware
Unit 42 / 2026-03-16T22:00:57+00:00Read Intel
criticalransomwaresource excerpt

Ransomware Under Pressure: Tactics, Techniques, and Procedures in a Shifting Threat Landscape

Written by: Bavi Sadayappan, Zach Riddle, Ioana Teaca, Kimberly Goody, Genevieve Stark Introduction Since 2018, when many financially motivated threat actors began shifting their monetization strategy to post-compromise ransomware deployments, ransomware has become one of the most pervasive threats to organizations across almost every industry vertical and region.

ransomwarecloud
Mandiant / 2026-03-16T14:00:00+00:00Read Intel
lowtradecraftsource excerpt

Free real estate: GoPix, the banking Trojan living off your memory

Kaspersky GReAT experts describe the unprecedentedly complex Brazilian banking Trojan GoPix that employs memory-only implants, Proxy AutoConfig (PAC) files for man-in-the-middle attacks, and malvertising via Google Ads.

malwaretradecraftdetectionwindows
Securelist / 2026-03-16T11:00:25+00:00Read Intel
lowaptsource excerpt

BeatBanker: A dual‑mode Android Trojan

Kaspersky researchers identified a new Android Trojan dubbed BeatBanker targeting Brazil, posing as government apps and Google Play Store, and capable of both crypto mining and stealing banking data.

aptmalwaretradecraftemail
Securelist / 2026-03-10T10:00:44+00:00Read Intel
highransomwaresource excerpt

Proactive Preparation and Hardening Against Destructive Attacks: 2026 Edition

Written by: Matthew McWhirt, Bhavesh Dhake, Emilio Oropeza, Gautam Krishnan, Stuart Carrera, Greg Blaum, Michael Rudden UPDATE (March 13): Added guidance around abuse or misuse of endpoint / MDM platforms . Background Threat actors leverage destructive malware to destroy data, eliminate evidence of malicious activity, or manipulate systems in a way that renders them inoperable.

ransomwareaptmalwaredetectioncloud
Mandiant / 2026-03-06T14:00:00+00:00Read Intel
criticalvulnerabilitysource excerpt

Exploits and vulnerabilities in Q4 2025

This report provides statistical data on published vulnerabilities and exploits we researched during Q4 2025. It also includes summary data on the use of C2 frameworks in APT attacks.

vulnerabilitywindowslinux
Securelist / 2026-03-06T10:00:22+00:00Read Intel
lowvulnerabilitysource excerpt

Look What You Made Us Patch: 2025 Zero-Days in Review

Written by: Casey Charrier, James Sadowski, Zander Work, Clement Lecigne, Benoît Sevens, Fred Plan Executive Summary Google Threat Intelligence Group (GTIG) tracked 90 zero-day vulnerabilities exploited in-the-wild in 2025.

aptmalwarevulnerabilityexploitationcloud
Mandiant / 2026-03-05T14:00:00+00:00Read Intel
lowmalwaresource excerpt

Mobile malware evolution in 2025

Statistics on Android malware and the most notable mobile threats of 2025: preinstalled backdoors Keenadu and Triada, spyware Trojans, the Kimwolf IoT botnet, and Mamont banking Trojans.

malware
Securelist / 2026-03-04T10:00:46+00:00Read Intel
lowaptsource excerpt

Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit

Introduction Google Threat Intelligence Group (GTIG) has identified a new and powerful exploit kit targeting Apple iPhone models running iOS version 13.0 (released in September 2019) up to version 17.2.1 (released in December 2023) . The exploit kit, named “Coruna” by its developers, contained five full iOS exploit chains and a total of 23 exploits.

aptvulnerabilityexploitationcloud
Mandiant / 2026-03-03T14:00:00+00:00Read Intel
lowaptsource excerpt

Exposing the Undercurrent: Disrupting the GRIDTIDE Global Cyber Espionage Campaign

Introduction Last week, Google Threat Intelligence Group (GTIG), Mandiant, and partners took action to disrupt a global espionage campaign targeting telecommunications and government organizations in dozens of nations across four continents. The threat actor, UNC2814, is a suspected People's Republic of China (PRC)-nexus cyber espionage group that GTIG has tracked since 2017.

aptmalwarevulnerabilitycloud
Mandiant / 2026-02-25T14:00:00+00:00Read Intel
lowmalwaresource excerpt

Arkanix Stealer: a C++ & Python infostealer

Kaspersky researchers analyze a C++ and Python stealer dubbed "Arkanix Stealer", which was active for several months, targeted wide range of data, was distributed as MaaS and offered referral program to its partners.

malware
Securelist / 2026-02-19T11:00:49+00:00Read Intel
highvulnerabilitysource excerpt

From BRICKSTORM to GRIMBOLT: UNC6201 Exploiting a Dell RecoverPoint for Virtual Machines Zero-Day

Written by: Peter Ukhanov, Daniel Sislo, Nick Harbour, John Scarbrough, Fernando Tomlinson, Jr., Rich Reece Introduction Mandiant and Google Threat Intelligence Group (GTIG) have identified the zero-day exploitation of a high-risk vulnerability in Dell RecoverPoint for Virtual Machines , tracked as CVE-2026-22769 , with a CVSSv3.1 score of 10.0 .

malwarevulnerabilitycvecloudnetwork
Mandiant / 2026-02-17T14:00:00+00:00Read Intel
lowapt

GTIG AI Threat Tracker: Distillation, Experimentation, and (Continued) Integration of AI for Adversarial Use

Introduction In the final quarter of 2025, Google Threat Intelligence Group (GTIG) observed threat actors increasingly integrating artificial intelligence (AI) to accelerate the attack lifecycle, achieving productivity gains in reconnaissance, social engineering, and malware development. This report serves as an update to our November 2025 findings regarding the advances in threat actor usage of AI tools.

aptmalwaretradecraftcloudemail
Mandiant / 2026-02-12T14:00:00+00:00Read Intel
lowadvisorysource excerpt

Beyond the Battlefield: Threats to the Defense Industrial Base

Introduction In modern warfare, the front lines are no longer confined to the battlefield; they extend directly into the servers and supply chains of the industry that safeguards the nation. Today, the defense sector faces a relentless barrage of cyber operations conducted by state-sponsored actors and criminal groups alike.

aptotcloudemail
Mandiant / 2026-02-10T14:00:00+00:00Read Intel
lowaptsource excerpt

UNC1069 Targets Cryptocurrency Sector with New Tooling and AI-Enabled Social Engineering

Written by: Ross Inman, Adrian Hernandez Introduction North Korean threat actors continue to evolve their tradecraft to target the cryptocurrency and decentralized finance (DeFi) verticals. Mandiant recently investigated an intrusion targeting a FinTech entity within this sector, attributed to UNC1069 , a financially motivated threat actor active since at least 2018.

aptmalwarecloud
Mandiant / 2026-02-09T14:00:00+00:00Read Intel
criticalvulnerabilitysource excerpt

Diverse Threat Actors Exploiting Critical WinRAR Vulnerability CVE-2025-8088

Introduction The Google Threat Intelligence Group (GTIG) has identified widespread, active exploitation of the critical vulnerability CVE-2025-8088 in WinRAR, a popular file archiver tool for Windows, to establish initial access and deliver diverse payloads.

aptvulnerabilitycveexploitationtradecraftwindows
Mandiant / 2026-01-27T14:00:00+00:00Read Intel
criticaladvisorysource excerpt

Closing the Door on Net-NTLMv1: Releasing Rainbow Tables to Accelerate Protocol Deprecation

Written by: Nic Losby Introduction Mandiant is publicly releasing a comprehensive dataset of Net-NTLMv1 rainbow tables to underscore the urgency of migrating away from this outdated protocol. Despite Net-NTLMv1 being deprecated and known to be insecure for over two decades—with cryptanalysis dating back to 1999—Mandiant consultants continue to identify its use in active environments.

exploitationcloud
Mandiant / 2026-01-15T14:00:00+00:00Read Intel
lowadvisorysource excerpt

AuraInspector: Auditing Salesforce Aura for Data Exposure

Written by: Amine Ismail, Anirudha Kanodia Introduction Mandiant is releasing AuraInspector, a new open-source tool designed to help defenders identify and audit access control misconfigurations within the Salesforce Aura framework .

tradecraftdetectioncloudidentity
Mandiant / 2026-01-12T14:00:00+00:00Read Intel
criticalvulnerabilitysource excerpt

Multiple Threat Actors Exploit React2Shell (CVE-2025-55182)

Written by: Aragorn Tseng, Robert Weiner, Casey Charrier, Zander Work, Genevieve Stark, Austin Larsen Introduction On Dec. 3, 2025, a critical unauthenticated remote code execution (RCE) vulnerability in React Server Components, tracked as CVE-2025-55182 (aka "React2Shell"), was publicly disclosed.

malwarevulnerabilitycveexploitationcloud
Mandiant / 2025-12-12T14:00:00+00:00Read Intel
lowadvisory

Five generative AI use cases for the financial services industry

Generative AI has the potential to revolutionize the way we live, work, bank, and invest. Its impact could be as significant as the advent of the internet or the mobile device. Indeed, 82% of organizations considering or currently using gen AI believe it will either significantly change or transform their industry (source: Google Cloud Gen AI Benchmarking Study, July 2023).

cloud
Mandiant / 2023-10-03T13:00:00+00:00Read Intel
lowadvisorysource excerpt

Cloud Load Balancing enhancements improve security and distributed application support

At Google Cloud Next ‘23 , the Cloud Networking Load Balancing team announced multiple enhancements that unlock new use cases and increase your value when using Google Cloud Load Balancing. The four of the marquee features we introduced are: mTLS support adds client-side authentication during TLS negotiation on global external Application Load Balancers.

cloudidentity
Mandiant / 2023-09-20T16:00:00+00:00Read Intel
lowadvisorysource excerpt

Education turns out for Google Cloud Next ‘23

Educators, researchers, IT professionals, student developers, and C-suite leaders showed up in full force in August for Google Cloud Next , our global showcase for the latest cloud technologies and success stories.

cloud
Mandiant / 2023-09-19T18:00:00+00:00Read Intel
lowadvisorysource excerpt

Confidential VMs on Intel CPUs: Your new intelligent defense

Editor’s note : As of September 2024, Confidential VM with Intel TDX is generally available on the general purpose C3 machine series. For organizations who want to bring and process their most sensitive compute workloads in the cloud without any code changes, we offer Confidential virtual machines (VMs) that leverage the latest hardware-based security technology.

cloudidentity
Mandiant / 2023-09-19T16:00:00+00:00Read Intel
criticaladvisorysource excerpt

Introducing the unified Chronicle Security Operations platform

At Google Cloud, our mission is to help organizations transform cybersecurity with frontline intelligence, expertise, and AI-powered innovation. Nowhere is this needed more than in security operations (SecOps), where understaffed and overwhelmed security teams struggle to defend against a threat landscape that is growing in volume and sophistication, often with tools that were designed in the pre-cloud era.

detectioncloudidentity
Mandiant / 2023-09-18T12:00:00+00:00Read Intel
lowadvisory

Expanding your Bigtable architecture with change streams

Engineers use Bigtable to hold vast amounts of transactional and analytical information as part of their data workflow. We are excited about the release of Bigtable change streams that will enhance these data workflows for event-based architectures and offline processing. In this article, we will cover the new feature and a few example applications that incorporate change streams.

cloud
Mandiant / 2023-09-15T16:00:00+00:00Read Intel