// 3 CRITICAL · 2 ZERO-DAY · 3 CVE · 3 EXPLOIT · 1 ADVISORY IN THE LAST 24H
malware

Android Malware Impersonates Indeed: Spyware and Anti-Uninstall via Accessibility

Malwarebytes analyzed fake Android apps impersonating Indeed for job interviews. The Trojan droppers install spyware, seize device con…

Aug 30, 2026views - 1.1k

malwareEXPLOIT

InstallFix Campaign Clones Claude Code to Spread Malware Without Exploits

Cybercriminals are using malvertising and cloned sites to distribute stealers and backdoors. The attack exploits no software vulnerabi…

Aug 30, 2026views - 1.2k

CYBERSEC

McKesson in ShinyHunters' Crosshairs: 284 Million Records and a $55 Million Ransom

McKesson disclosed a security incident involving unauthorized access to third-party applications. The ShinyHunters group claims to hav…

Aug 30, 2026views - 1.1k

cybersec

BlueDelta Refines HEADLACE: HOOKEDGE Backdoor Abuses Legitimate Webhook Services

The BlueDelta group has used macro-laced Word documents to distribute HOOKEDGE, a batch-script backdoor that leverages webhook.site fo…

Aug 28, 2026views - 1.2k

phishing

Bug in JavaScript Obfuscator Exposes Polymorphic Phishing Campaign

A server-side scope error in an obfuscator triggered infinite loops in 3.6% of variants, revealing a polymorphic evasion mechanism tha…

Aug 28, 2026views - 1.1k

CYBERSEC

Mirage2FA: AiTM Phishing Kit Hits 3,500 Organizations, Bypasses MFA on Microsoft 365

The Mirage2FA phishing-as-a-service kit, operated by LinX Coders, has targeted over 3,500 organizations using Adversary-in-the-Middle…

Aug 26, 2026views - 1.4k

malware

DOUBLECUP: The Fake Steganography That Exposes Criminal Payloads to a Simple grep

The DOUBLECUP loader promises advanced steganography but hides PowerShell code in plaintext after the PNG file. Extractable with FINDS…

Aug 25, 2026views - 825

CYBERSEC

Windows: Localized Filename Bug Steals NTLM Credentials with a Single Click

CVE-2026-50508: A flaw in Windows localized filenames enables NTLM hash theft simply by opening a file or visiting a web page. Microso…

Aug 25, 2026views - 1k

CYBERSEC

SilkParasite Exposes the Line Between AI-Assisted and AI-Generated Malware

Bitdefender uncovered SilkParasite, a cyber-espionage campaign using seven RAT families and AI-assisted development to target governme…

Aug 24, 2026views - 1.1k

malware

SynkLoader: The 'Kitchen Sink' Malware Attacking via Microsoft Teams

Expel researchers have uncovered SynkLoader, a modular, multi-language malware family that uses Microsoft Teams phishing to breach cor…

Aug 21, 2026views - 1k

CYBERSEC

North Korea’s Famous Chollima Behind 47% of State-Backed Tech Attacks

The North Korean group Famous Chollima carried out 47% of all state-sponsored attacks against the technology sector in one year, using…

Aug 21, 2026views - 1.2k

CYBERSEC

UNC6671: Personal Phones Become the Gateway to Steal SaaS Data

The UNC6671 group uses vishing on personal smartphones to bypass MFA and steal SaaS sessions. Google has tracked over $10 million in e…

Aug 19, 2026views - 1.2k