Fake VPN installers are delivering a new backdoor to Afghan telecoms and South Asian infrastructure, with ties to APT36.
Infoblox tracks actors buying expired domains to inherit trust and traffic for malware, scams, and C2.
SAP Commerce Cloud's CVSS 10 flaw is under attack just three days after the patch shipped.
The UK criminal records office got a reprimand after attackers kept access to its CMS for seven months.
Ukraine's police shut 94 scam call centers and seized millions in cash and equipment.
Researchers prove commercial RISC-V chips are still vulnerable to Spectre attacks.
A contractor got two years for extorting Brightly Software with stolen payroll data.
XM Cyber chains four SCCM flaws to SYSTEM using a $58 certificate.
Researchers show Loongson cache flaws leak kernel keys across VM boundaries.
The extortion group linked to BlackFile successors says it stole nearly 1M files.
Malwarebytes finds a lookalike CCleaner site pushing a Chrome credential stealer.
A fresh round of Apple mercenary spyware warnings lands in 110 countries.
Group-IB links WindRelay and SpyNote in real-time card fraud across Europe.
Attackers are exploiting CVE-2026-65400 to drop Monero miners on exposed Macs.
France's DGFiP confirms a June intrusion that exposed taxpayer data.
ShinyHunters dumped account data after RingCentral refused an extortion demand.
Jamf Threat Labs details a three-stage Rust stealer that harvests macOS credentials and gives operators live, hidden control of the victim's browser.
A free archive with 7.3 million Chess.com records looks like large-scale scraping, though one internal-facing detail needs explaining.
watchTowr logged hundreds of exploitation probes against an unpatched GeoServer SQLi bug within hours of its disclosure.
Huntress says an Akira affiliate rebooted a victim into Safe Mode to kill EDR, then the encryptor crashed on the…
Sansec blocked the first exploits of CVE-2026-71362, an unauthenticated account takeover in Adobe Commerce rated 9.1.
Trellix found dark web services like APEX AI and MessiahGPT that lower the skill bar for ransomware-grade attacks.
A breach at shipping partner ShipMonk exposed names, emails and addresses for over 13,000 Trezor customers.
CERT-UA ties fake recruiter lures to Sandworm subgroup UAC-0145, which hides PowerShell execution inside a poisoned WireGuard client.
Sign in to your account