Archive
All articles, newest first. Page 10.

Infostealer on Attacker Workstation Exposes Blind Eagle Campaign
An information stealer infection on a suspected threat actor's workstation has laid bare the full infrastructure of a phishing campaig…

KEV Beats CVSS: The Framework CISOs Use When Scores Lie
On August 31, 2026, vulnerability prioritization gained an official decision framework: CISA BOD 26-04 mandates four scoring variables…

Attacker's Own Infostealer Infection Exposes Full Arsenal of Colombian Blind Eagle Campaign
A consumer infostealer accidentally infected a threat actor's workstation, leaking browser history, local folders, credentials, and a…

AI AppSec: Scanners Agree on Just 5%, Triage Costs $128,000
Contrast Security's AppSec Overflow 2026 report reveals three AI scanners testing the same codebase agree on only 5% of findings, whil…

CSN ICT 2026 Report: Mediterranean Commercial Fleets Operating Under Digital Siege
The CSN ICT 2026 report finds Cyprus and Greece commercial fleets under sustained digital assault. Maritime cyber incidents doubled in…

PaperCut Issues Back-to-Back Emergency Patches for Actively Exploited Zero-Days
PaperCut released two emergency patches within 24 hours for CVE-2026-81578 and CVE-2026-82078. The first patch was bypassed, leaving t…
Beacon CRM Breached, Robert Burns Trust Warns Donors: The Risk
A cyberattack on Beacon CRM, a SaaS provider for the non-profit sector, exposed contact data for over 1,000 organizations. The Robert…

DOJ Corrects Record: NASA and Senate Were QTFY Targets, Not Victims
The U.S. Department of Justice revised its August 26 statement on August 29, 2026, clarifying that NASA, the U.S. Senate, and the Fede…

TheHatman and the 3.6 Million Azure Records: The Gap Between Claim and Confirmation
Threat actor TheHatman listed roughly 3.6 million records from the Azure directories of nine corporations for sale. Three companies de…

CareCloud Breach Exposes 3.75 Million Patient Records: The B2B Model Hides the Victims
CareCloud confirmed in March that an unauthorized actor accessed an AWS environment for six days, compromising 3,756,469 individuals.…

Rhysida Hits Berlin Government: Data Auction Launched, Ransom Refused
The Rhysida ransomware group claimed responsibility for a cyberattack on the Berlin state government on August 28, 2026, auctioning 5.…

ATF Confirms 'Major Incident' Without Confirming Who Caused It
The Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed the breach of a standalone system but stopped short of attributing i…

TA4922 Launches PackClient Campaigns in Asia: Modular RAT Bought on Telegram
Chinese threat group TA4922 deployed the PackClient RAT framework across China and India via tax-themed phishing between May and July…

'Superior' Campaign: 19 Extensions in Google and Microsoft Stores Turned Into Data-Theft Platforms
Socket identified 19 malicious extensions in the Chrome Web Store and Edge Add-ons Store. The modular framework hit nearly 80,000 user…

Anthropic: Infostealer Malware Steals Claude Sessions, Drains Usage Credits
Anthropic has warned Claude users that infostealer malware on compromised endpoints has stolen active sessions. Attackers are using th…

Ransomware Hits Norcross: A City’s Technical Silence After a Partial Takedown
The city of Norcross, Georgia, confirmed a ransomware attack identified on August 1, 2026. Most systems are back online, but the publi…

Android Malware Impersonates Indeed: Spyware and Anti-Uninstall via Accessibility
Malwarebytes analyzed fake Android apps impersonating Indeed for job interviews. The Trojan droppers install spyware, seize device con…

Crypto Theft on Firefox: Socket Uncovers 40 Malicious Extensions Out of 77
Security firm Socket has identified a campaign dubbed 'Offside Wallet Theft Factory' comprising 77 interconnected Firefox extensions,…

InstallFix Campaign Clones Claude Code to Spread Malware Without Exploits
Cybercriminals are using malvertising and cloned sites to distribute stealers and backdoors. The attack exploits no software vulnerabi…

Cosmos EVM: Bug Known Since April, $5.7M Exploit Across Six Chains
Cosmos Labs identified the critical vulnerability in the EVM module in April 2026. The decision to proceed with a public silent patch…

McKesson in ShinyHunters' Crosshairs: 284 Million Records and a $55 Million Ransom
McKesson disclosed a security incident involving unauthorized access to third-party applications. The ShinyHunters group claims to hav…

Five Critical Flaws Hit WordPress Plugins and Theme: The GiveWP Case
WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP contain CVSS 9.8–10.0 vulnerabilities enabling unauthenticated site takeov…

CVE-2026-65643: The Domain Parking Bug That Turns Any cPanel Account Into Root
cPanel patched a critical vulnerability in its domain parking module on August 27, 2026, that lets any authenticated user with basic a…

ZBT Routers Ship With Two Factory Firmware Implants Granting Unauthenticated Remote Root. No Patch Available
VulnCheck disclosed on August 27, 2026 that ZBT routers sold worldwide — including in Italy — contain two factory-installed implants,…