// 2 CRITICAL · 2 ZERO-DAY · 3 CVE · 2 EXPLOIT · 1 ADVISORY IN THE LAST 24H
malware

SourTrade: The Browser Becomes an In-Memory Malware Factory

The SourTrade malvertising campaign assembles malware directly in the victim's browser memory using legitimate web APIs. The technique…

Aug 02, 2026views - 1.1k

CYBERSEC

The Great Patching Isn't Enough Anymore: When Attackers Weaponize Your Own Tools

Cisco Talos IR's Q2 2026 report marks a turning point: phishing now drives over 50% of engagements, while authentication abuse surged…

Aug 02, 2026views - 1.1k

CYBERSEC

TransUnion, the SaaS Periphery Paradox: 4.4 Million SSNs Exposed via Third-Party OAuth App

Credit bureau TransUnion disclosed a data breach exposing 4,461,511 unredacted Social Security Numbers. The vector was not a direct in…

Aug 02, 2026views - 1.3k

phishing

Device Code Phishing: How Attackers Bypass MFA on Microsoft 365

Proofpoint documents threat clusters exploiting Microsoft's legitimate OAuth device authorization flow to compromise Microsoft 365 acc…

Aug 01, 2026views - 690

phishing

Kratos Dismantled: AiTM Code Remains in Hands of 1,800 Criminals

German and U.S. authorities seized over 200 servers linked to the Kratos phishing-as-a-service kit, but the source code still circulat…

Aug 01, 2026views - 663

CYBERSEC

Bank of Baroda Data Breach Traced to Compromised Email Account: The Limits of What We Know

India's Bank of Baroda confirms an employee email account was compromised, but insists core banking systems remain untouched. A threat…

Aug 01, 2026views - 523

CYBERSECZERO-DAY

OWAReaper: The Malware That Survives Device Reimaging

Russia-aligned APT Laundry Bear (TA488) exploited CVE-2026-42897, an XSS flaw in Outlook Web Access, to deploy OWAReaper — a browser-b…

Jul 30, 2026views - 1.2k

phishing

Kratos Phishing Kit Dismantled: 200 Servers Seized, but AiTM Code Remains in Circulation

German, U.S., and Indonesian authorities took down the Kratos phishing kit, seizing over 200 servers and arresting the alleged develop…

Jul 28, 2026views - 1.2k

CYBERSEC

Hotel Wi-Fi DNS Attacks Steal Microsoft 365 Accounts, Bypass MFA

Threat actors compromise hotel and conference center Wi-Fi captive portals to manipulate DNS and steal Microsoft 365 credentials, sess…

Jul 28, 2026views - 1.2k

malware

OctagonPanel Spyware Hides Behind Fake Bahrain Civil Defense Alert App

A counterfeit "BH Alert" app impersonating Bahrain's civil defense system delivers the OctagonPanel surveillance malware via a four-st…

Jul 27, 2026views - 1.1k

CYBERSECZERO-DAY

Russia Exploits Zimbra Zero-Day: Patching Alone Won't Evict the Spies

A zero-click XSS flaw in Zimbra Collaboration Suite let a Russian espionage group harvest emails, 2FA codes, and persistent app passwo…

Jul 26, 2026views - 1.1k

phishing

Misconfigured Server Exposes Three Evilginx Operations Targeting Microsoft 365

A phishing server with directory listing enabled exposed complete M365 phishing toolkits, two distinct MFA bypass techniques, and evid…

Jul 25, 2026views - 1.1k