The Dutch Police announced the arrest of multiple individuals suspected of being part of an international investment fraud scheme estimated to have t…
Zoom is warning of a critical vulnerability in its desktop client and software development kit for Windows that could be exploited by an unauthentica…
The Gold Eagle program will allowe industry, critical infrastructure operators and the government to use artificial intelligence to rapidly detect, p…
Microsoft’s July 2026 Patch Tuesday is the largest in the company’s history, addressing 622 CVEs across Windows, Office, Azure, SharePoint, Exchange,…
Although experts had already warned of an impending “tsunami of vulnerabilities” back in April, immediately following the announcement of the Mythos …
Our July hunt uncovered 2,417 newly-compromised repos, pushing confirmed footprint to 4,367 poisoned repos across 2,152 owners
Cybersecurity researchers have disclosed details of a previously unreported Internet-of-Things (IoT) botnet framework dubbed TuxBot v3 Evolution that…
A Russian-speaking threat actor known as "bandcampro" used Google's open-source Gemini CLI AI tool as a hacking agent and to operate a small-scale bo…
A coalition of 42 state attorneys general reached an $18 million settlement with 23andMe for cybersecurity failings that led to a data breach.
Key Findings LegacyHive is a registry hive loading primitive in the Windows User Profile Service (ProfSvc). It is a public proof-of-concept that forc…
OverviewOn July 14, 2026, SonicWall published a security advisory addressing two vulnerabilities affecting SMA1000 Series remote access appliances, i…
Five malicious versions of AsyncAPI packages were published to the Node Package Manager (npm) in a supply-chain attack that delivered a remote access…
A malware framework called OkoBot has been running on Windows machines since April 2025, and one of its modules is built to con hardware wallet owner…
The US Cybersecurity and Infrastructure Security Agency (CISA) has urged all organizations running SharePoint to harden their defenses after the disc…
Six-month phishing campaign used seasonal eCard lures to plant legitimate RMM tools on victims
LabubaRAT, a previously undocumented Rust-based remote access tool (RAT) masquerading as NVIDIA software that enables post-compromise operations on W…
An attacker can create a malicious repository containing a git.exe in the project root, and Cursor executes it automatically. The post Unpatched Curs…
First reported in May, ClaudeBleed is basically a “fake remote control” problem. A sneaky browser extension can pretend to be Claude’s own website an…
Authorities said Wednesday that the group operated like a legitimate international business since at least 2021, running about two dozen call centers…
Three vulnerabilities are actively exploited in attacks, including two that have been targeted as zero-days. The post CISA Urges Immediate Patching o…
Eleven forgotten Microsoft-signed UEFI shims can bypass Secure Boot on almost any machine
Written by: Corné de Jong Introduction Mandiant security assessments frequently identify publicly exposed serverless applications that lack authentic…
A financially motivated threat actor is impersonating hundreds of brands on GitHub and pushing a smash-and-grab infostealer masquerading as legitimat…
Patch Tuesday was followed by Oopsie Wednesday for some Dell customers, with Microsoft slamming on the update brakes after the hardware maker reporte…
Mozilla has released updates to address two critical flaws in Firefox for which it warned that exploit code has been published. The vulnerabilities a…
Bitdefender researchers show how Windows bind links can create conflicting filesystem views to hide malware from endpoint security products. The post…
The Los Angeles Police Department is the latest U.S. municipal agency to rethink its relationship to ALPR company Flock Safety.
Microsoft’s worst nightmare - a prolific zero-day vulnerability hunter who calls themselves Nightmare Eclipse - published yet another zero-day on Tue…
A crafted cursor:// link installs an attacker-controlled MCP server that executes unsandboxed commands under your account. The install dialog is supp…
Research of incidents by Sophos finds that phishing, brute force attacks and other identity-based threats have surpassed software vulnerabilities as …
Just one month ago, June 2026 Patch Tuesday broke Microsoft’s previous record with 206 CVEs and three zero‐days. July now triples that count, reinfor…
Vulnerability counts have been surging this year, and Microsoft's mammoth disclosure this week of 622 bugs is larger than the three previous months c…
Progress has restored access to its ShareFile Storage Zones Controller after a four-day suspension triggered by a credible external security threat
The suspects and their companies were previously sanctioned by the United States and its allies. The post US Charges Russian Individuals and Firms fo…
Spanish National Police have dismantled a cybercrime network accused of stealing and laundering about €140 million through fake investment platforms,…
Security researcher Chaotic Eclipse (aka Nightmare-Eclipse) has released a new proof-of-concept (PoC) exploit called LegacyHive. It has been describe…
Amazing: Researchers from ETH Zurich in Switzerland, however, managed to create a new type of pixel that can simultaneously do both. This hypercharge…
A critical security defect in the ServiceNow AI platform could allow remote attackers to execute arbitrary code. The post Vulnerabilities Patched by …
Key Findings • A targeted cyber-espionage operation against Bangladesh's military and defence establishment. • Initial access: a spear-phished RTF we…
Open a repository in Cursor on Windows and, if a file named git.exe is sitting in the project root, Cursor runs it. No click, no approval dialog, no …
Insights from 2,158 IT and cybersecurity leaders across 17 countries whose organizations were hit by ransomware in the past year.
ClickFix has moved from a one-off social engineering trick into an industrialized attack ecosystem that is outpacing conventional antivirus and endpo…
Microsoft has released patches for 570+ vulnerabilities on July 2026 Patch Tuesday, including two that are being leveraged by attackers (CVE-2026-561…
The new program stems from an AI-focused Executive Order signed by President Trump on June 2. The post White House Launches AI-Driven ‘Gold Eagle’ Vu…
TuxBot v3 Evolution, an IoT botnet framework built with LLMs. Read our analysis of its cross-compiled binaries, C2 architecture and bugs. The post Tu…
Introduction In January 2026, we identified multiple attacks involving unknown malware that captures the contents of cryptocurrency wallet windows. D…
Four years after Symantec first uncovered Daxin, the most advanced malware we had seen from a China-linked actor, it has been found running inside a …
The company has rolled out a fix and is restoring access for Storage Zones Controller customers who apply it. The post Progress Confirms Zero-Day Vul…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned Tuesday that attackers are actively exploiting three vulnerabilities to hack …
Microsoft released fixes for a record 570 CVEs in its July Patch Tuesday update, as experts warn AI is dramatically accelerating vulnerability discov…
The industrial giants fixed dozens of vulnerabilities across their ICS products, with advisories also released by CISA and VDE CERT. The post ICS Pat…
Four compromised npm packages in the @asyncapi namespace have been observed distributing a multi-stage botnet loader, according to findings from OX S…
The UK government is warning of the potential impact of catastrophic cyber-attacks
CrashStealer is a new macOS infostealer that masquerades as Apple’s CrashReporter component, uses an Apple‐notarized installer to slip past Gatekeepe…
U.S. federal prosecutors have unsealed charges against three Russian nationals, accusing them of providing bulletproof hosting (BPH) services to rans…
Public exploit code targeting the Firefox flaws exists, but no in-the-wild exploitation has been observed. The post Critical Vulnerabilities Patched …
SonicWall has warned of active exploitation of two zero-day vulnerabilities impacting Secure Mobile Access (SMA) 1000 series appliances, one of which…
SonicWall SMA1000 zero-day vulnerabilities CVE-2026-15409 and CVE-2026-15410 can be exploited for remote code execution. The post SonicWall Issues Ur…
By: Marie Mamaril, Intelligence TeamFinance-themed phishing campaigns are evolving toward process-oriented messaging tactics, in which email subject …
Robots that read the world through cameras now lean on large vision-language models to interpret what they see and decide what to do next. These mode…