-
Six federal agencies have updated a joint advisory warning that Iranian-affiliated advanced persistent threat (APT) actors are actively exploiting internet-exposed programmable logic controllers (PLCs) across U.S. critical infrastructure, manipulating …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A recently disclosed vulnerability in Foxit PDF Reader may allow a local attacker with existing code execution to elevate their privileges to NT AUTHORITY\SYSTEM. This issue, tracked as CVE-2026-57239, affects Foxit PDF Reader installations prior to ve…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Cl0p ransomware affiliates are actively exploiting internet-exposed PTC Windchill and FlexPLM deployments in a global data-theft campaign targeting high-value engineering environments. Observed post-exploitation activity includes filesystem enumeration…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
An Illinois man has pleaded guilty to a phishing and account-compromise scheme that targeted thousands of Snapchat users, leading to the theft of private images from numerous women. Federal prosecutors stated that Kyle Svara, 27, of Oswego, Illinois, a…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
SectopRAT is at the center of a highly targeted malvertising campaign abusing Anthropic’s Claude platform to deliver a stealthy, HVNC‑enabled RAT that gives attackers deep, persistent access to victims’ passwords, credit cards, cookies and corporate fi…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Golden Chickens, tracked as TAG-195 and also known as Venom Spider, has launched four new modular malware families designed to enhance credential theft, browser session hijacking, and post-exploitation flexibility. The newly identified families TinyEgg…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
SourTrade turns the browser itself into a malware build system, deliberately sidestepping the industry’s reliance on hash-based file fingerprints and traditional network-centric detection. SourTrade has been active since late 2024, abusing programmatic…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
JetBrains has addressed a series of security vulnerabilities affecting IntelliJ IDEA and TeamCity, including several critical flaws that could allow code execution or unauthorized actions in development and continuous integration environments. The upda…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Origin Energy Limited has confirmed a cybersecurity incident involving unauthorized access to and disclosure of customer data, representing a significant data security event for one of Australia’s largest energy providers. The company identified the br…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Apache Syncope has released versions 4.1.24.1, 4.1.24.1.2, and 4.0.74.0.7 to address six security vulnerabilities affecting the 4.1, 4.0, and 3.0 release branches. These vulnerabilities include a self-service privilege escalation bug, multiple post-aut…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


