loader image
Infostealers Fuel Agentic Attack Chains

Infostealers fuel agentic attack chains as cybercriminals in 2025 turned to automation, significantly advancing their operations. Instead of relying on isolated incidents, attackers developed systems capable of executing complete intrusion cycles with little need for human intervention. According to data from criminal forums, this shift has empowered cybercriminals to operate more efficiently and on a […]

Android Malware Hits Pix Payments, Banks, Crypto

A wave of cyber threats has emerged as six Android malware families target Pix payments, banking apps, and cryptocurrency wallets. Cybersecurity experts have identified these new malicious software variants, which infiltrate devices to siphon critical data and orchestrate financial fraud. Among these threats are traditional banking trojans such as PixRevolution, TaxiSpy RAT, BeatBanker, Mirax, and […]

Microsoft Patches 2 Zero-Days, 79 Flaws

In its latest software update, Microsoft patches 2 zero-days as part of the March 2026 Patch Tuesday. This initiative addresses a total of 79 security vulnerabilities, marking a significant effort to enhance cybersecurity. The patch release includes fixes for two publicly disclosed zero-day vulnerabilities, among other issues, underscoring Microsoft’s ongoing commitment to fortifying its products […]

BlackSanta EDR Killer Targets HR Departments

A new cybersecurity threat, identified as the BlackSanta EDR killer, has been actively targeting human resource departments for over a year. This threat, attributed to a Russian-speaking group, utilizes sophisticated malware specifically designed to penetrate security systems commonly used by such departments. The malware’s primary function includes bypassing Endpoint Detection and Response (EDR) mechanisms, leaving […]

Ally Plugin’s SQL Flaw Threatens 400,000 Sites

A high-severity SQL Injection vulnerability has been discovered in a popular web accessibility and usability tool, leading to significant concerns. The issue within the Ally plugin’s SQL flaw jeopardizes the security of over 400,000 active WordPress sites. The flaw allows malicious actors to manipulate database queries, potentially accessing sensitive information or compromising site functionality. Experts […]

Azure Arc Flaw Lets Local Users Hijack Azure ID

A new security vulnerability, known as the Azure Arc flaw, poses a significant threat to Windows users. CVE-2026-26117 impacts Azure Arc on Windows, allowing a local privilege escalation with potentially severe consequences. Low-privileged users on any Arc-joined Windows host could exploit this flaw to gain higher access levels. Once elevated, they might abuse the Arc […]

Salesforce Sites Scanned by Custom AuraInspector

Threat actors are actively scanning Salesforce sites, particularly those utilizing Experience Cloud, using a modified AuraInspector tool. Salesforce’s Cybersecurity Operations Center warns that these adversaries aim to exploit misconfigurations and access sensitive data. AuraInspector, originally developed by Google/Mandiant, is an open-source auditing tool for Salesforce’s Aura and Experience Cloud applications. It evaluates exposure risks by […]

Lazarus Uses Fake LinkedIn to Target AllSecure CEO

Lazarus uses a fake LinkedIn profile to lure top executives in cyber-espionage schemes, with the latest target being the CEO of AllSecure. Exploiting the professional networking platform, the notorious North Korean hacking group masqueraded as a legitimate industry interviewer to deceive the executive. This audacious move highlights the growing sophistication and boldness of cyberthreats directed […]

Ericsson US Confirms Vendor Hack Exposed Data

Ericsson US confirms a data breach following a cyberattack on one of its service providers, which led to the exposure of sensitive information pertaining to employees and customers. On April 28, 2025, the service provider detected unusual activity suggesting unauthorized data access. To address the situation, they enlisted external cybersecurity experts and notified the FBI. […]

Poland Police Bust Teen DDoS Kit Sellers

Poland police busted a group of teenagers who allegedly sold software tools designed for launching distributed denial-of-service (DDoS) attacks. Authorities have accused these minors of profiting by providing resources that targeted and disrupted popular websites. The investigation revealed that these DDoS kits allowed buyers to flood specific websites with traffic, causing significant operational disruptions. Polish […]

Claude Code Lure Steals Developers’ Credentials

Cybercriminals are employing the Claude Code lure tactic to deceive developers and IT professionals. These attackers set up counterfeit download pages that imitate Claude Code, a legitimate AI coding assistant. Users, seeking official software, inadvertently download an infostealer malware. This exploit reflects a troubling trend where popular AI tools are leveraged to gain unwarranted trust. […]

Amazon’s AWS-LC Crypto Flaws Expose Cloud Risk

Cybersecurity experts have revealed critical vulnerabilities in Amazon’s AWS-LC, an open-source cryptographic library integral to Amazon’s cloud infrastructure. These amazon aws lc flaws raise significant concerns due to their potential threat to cloud-based operations. The vulnerabilities identified include CVE-2026-3338, CVE-2026-3337, CVE-2026-3336, and CVE-2026-2256, which present unauthenticated bypass risks that could compromise data security across Amazon […]