-
A highly convincing malvertising campaign is targeting macOS users searching for “how to install Claude Code on Mac,” delivering the MacSync infostealer through a trusted-looking workflow that abuses legitimate infrastructure rather than exploiting sof…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The takedown of the Kratos phishing-as-a-service (PhaaS) platform in July 2026 has done little to slow the broader threat landscape. As security researchers warn that its leaked techniques and infrastructure patterns are already being repurposed in ong…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A significant evolution in the CastleLoader malware ecosystem, with new campaigns deploying the NeedleStealer framework to harvest cryptocurrency wallet seed phrases and hijack browser sessions. The findings expand on earlier research by Huntress and L…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
JetBrains has announced a critical vulnerability in TeamCity On-Premises, identified as CVE-2026-63077. This vulnerability allows unauthenticated remote attackers to execute arbitrary operating system commands on affected servers. The issue impacts eve…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Chinese state-linked hackers are increasingly relying on a covert multi-hop infrastructure dubbed RedRelay (also known as ORBWEAVER) to mask the origins of global cyber operations, with evidence pointing to little-known Guangdong Chanming as a key enab…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A researcher recently disclosed an AI-assisted Linux kernel zero-day vulnerability, tracked as CVE-2026-53264, which allows local privilege escalation to root on affected systems. This flaw is found in the Linux packet scheduling subsystem (net/sched) …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Tengu, a newly observed Mirai-derived botnet, is demonstrating how modern IoT malware is rapidly evolving beyond traditional distributed denial-of-service (DDoS) operations by integrating persistence, evasion, and multi-functional attack capabilities. …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Fake ShinyHunters-themed sextortion emails are abusing data from recent ShinyHunters leaks to threaten victims with the release of fabricated “webcam recordings” unless a 2,000 dollar Bitcoin ransom is paid within 48 hours. Despite the technical-soundi…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
LegacyHive is a newly discovered proof-of-concept (PoC) for Windows that exploits profile initialization and offline registry hive manipulation to redirect user-level registry paths, potentially allowing access to resources associated with another acco…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
PortSwigger has launched Burp AT, an agentic AI system that allows penetration testers to delegate web security investigation tasks while maintaining direct control over the testing scope, approvals, and final conclusions. The public beta is currently …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


