Skip to content

1010.cx

  • New GhostShell Hacking Group Targets Ukraine’s Drone Defense Sector

    ·

    Cyber Attack, Cyber-Attacks, cybersecurity, Drone, GhostShell, Russia, Security, Ukraine
    Researchers warn GhostShell is using fake drone documents to target Ukrainian defence teams, stealing passwords and sensitive data in a new cyber campaign.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Fake npm Packages Impersonate PostCSS Tool to Steal Chrome Passwords

    ·

    Chrome, Cyber Attack, cybersecurity, JFrog, Malware, npm, Password, PostCSS, RAT, SCAM, Security, Windows
    JFrog warns of malicious npm packages that mimic PostCSS tooling, drop a Windows RAT, and target Chrome-stored passwords through a staged infection setup route.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • ModeloRAT and Mistic Backdoor Activity Linked to Ransomware Initial Access Broker

    ·

    cyber security, Cyber Security News, Ransomware

    The Python-based remote access trojan ModeloRAT and a newly observed stealth backdoor, dubbed Backdoor.Mistic, to activity consistent with an initial access broker (IAB) operation that facilitates ransomware deployments. Mistic first seen in April 2026 and publicized by Zscaler as MLTBackdoor access appears optimized for long-term, low-visibility access and was discovered deployed in at least one […]

    The post ModeloRAT and Mistic Backdoor Activity Linked to Ransomware Initial Access Broker appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks

    ·

    Cybersecurity researchers have flagged a new class of CI/CD workflow weakness that allows attackers to hijack workflows and compromise open-source supply chains. The “critical exploitable pattern” has been codenamed Cordyceps by Novee Security. The issue can allow full attacker control of repositories at dozens of the largest organizations worldwide, including Microsoft, Google, Apache, and

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Android Malware Campaign Uses Fake Document Reader App with 100K Google Play Downloads

    ·

    Android, cyber security, Cyber Security News, Malware

    Android Malware Campaign Uses Fake Document Reader App with 100K Google Play Downloads tracks a fresh Anatsa campaign that abused trust in a seemingly useful document-reader app to reach a large install base before its payload was activated. The malicious app was published as a document reader and file utility, a category that normally attracts […]

    The post Android Malware Campaign Uses Fake Document Reader App with 100K Google Play Downloads appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Grafana Confirms TanStack npm Supply Chain Attack Led to GitHub Repository Cloning

    ·

    cyber security, Cyber Security News

    Grafana Labs has confirmed that a recent supply chain attack involving the TanStack npm ecosystem resulted in the cloning of its internal GitHub repositories. However, it did not compromise customer production systems or the Grafana Cloud platform. This disclosure follows a thorough internal investigation completed on May 27, 2026, as well as an independent forensic […]

    The post Grafana Confirms TanStack npm Supply Chain Attack Led to GitHub Repository Cloning appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • AEV, BAS, Or Pentesting: Which Security Validation Solution Is Right for You?

    ·

    Blogs
    This week in cybersecurity from the editors at Cybercrime Magazine

    Sausalito, Calif. – Jun. 24, 2026

    – Read the full story from BreackLock

    AEV, BAS, and penetration testing each answer a different security question.

    Adversarial Exposure Validation (AEV) maps which vulnerabilities are actually exploitable by real attackers and identifies the attack paths that could lead to critical assets.

    Breach and Attack Simulation (BAS) uses automated, continuous simulations to determine whether security controls are functioning as expected.

    Penetration testing uses human testers to find what is vulnerable in a system at a specific point in time. The three approaches are complementary rather than interchangeable.

    BreachLock takes readers for a deep dive into AEV, BAS, and pentesting, and then they answer another FAQ: Why is continuous security validation important for enterprise security programs?

    The short answer: Continuous security validation, delivered through approaches like BAS and AEV, ensures that security gaps are identified and surfaced as soon as they become relevant rather than waiting for the next scheduled engagement.

    BAS, AEV, and pentesting are offered through the BreachLock Unified Platform.

    Read the Full Story



    Cybercrime Magazine is Page ONE for Cybersecurity. Go to any of our sections to read the latest:

    • SCAM. The latest schemes, frauds, and social engineering attacks being launched on consumers globally.
    • NEWS. Breaking coverage on cyberattacks and data breaches, and the most recent privacy and security stories.
    • HACK. Another organization gets hacked every day. We tell you who, what, where, when, and why.
    • VC. Cybersecurity venture capital deal flow with the latest investment activity from various sources around the world.
    • M&A. Cybersecurity mergers and acquisitions including big tech, pure cyber, product vendors and professional services.
    • BLOG. What’s happening at Cybercrime Magazine. Plus the stories that don’t make headlines (but maybe they should).
    • PRESS. Cybersecurity industry news and press releases in real time from the editors at Business Wire.
    • PODCAST. New episodes daily on the Cybercrime Magazine Podcast feature victims, law enforcement, vendors, and cybersecurity experts.
    • RADIO. Tune into WCYB Digital Radio at Cybercrime.Radio, the first and only round-the-clock internet radio station devoted to cybersecurity.

    Contact us to send story tips, feedback and suggestions, and for sponsorship opportunities and custom media productions.

    The post AEV, BAS, Or Pentesting: Which Security Validation Solution Is Right for You? appeared first on Cybercrime Magazine.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Hackers Use Microsoft Teams-Themed Lures to Deploy Legitimate Remote Access Software

    ·

    cyber security, Cyber Security News, Microsoft

    An active phishing campaign that impersonates Microsoft Teams to trick victims into downloading a legitimately signed remote access tool (RAT) preconfigured for unauthorized access. Attackers deliver Teams-themed lures notifications about meeting transcripts, missed recordings, or “download transcript” prompts linking to convincing landing pages that mimic collaboration and productivity services. The offered downloads are pitched as […]

    The post Hackers Use Microsoft Teams-Themed Lures to Deploy Legitimate Remote Access Software appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Dawn of the Apex Agentic Adversary

    ·

    We are standing at the end of an era we never thought to mourn: the era of human-speed threats. For years, cybersecurity moved to a rhythm organizations could follow. A researcher found a bug, a CVE was cataloged, a vendor navigated a patch cycle, and weeks or even months later, a fix was deployed. In this era, dwell time was measured in days, sometimes weeks. We are now approaching an

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Payouts King Initial Access Broker Deploys Edgecution Malware Through Malicious Edge Extension

    ·

    cyber security, Cyber Security News, Malware

    A concerted campaign by an initial access broker with ties to the Payouts King ransomware ecosystem that leverages a novel browser-based delivery technique to establish persistent host-level control. The actor deploys a malicious Microsoft Edge extension dubbed “Edgecution” which abuses the Chrome native messaging protocol to reach a Python backdoor running on the endpoint, effectively […]

    The post Payouts King Initial Access Broker Deploys Edgecution Malware Through Malicious Edge Extension appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

1 2 3 … 891
Next Page

1010.cx

cybersecurity / defense / intelligence