Tag: cyber
-
SystemBC Malware Turns Windows Machines Into SOCKS5 Proxies for Ransomware Attacks
SystemBC (also tracked as Coroxy) remains a versatile and persistent Windows malware family that operators routinely deploy to convert compromised hosts into SOCKS5 proxy gateways and to maintain remote access for follow-on operations. First observed as a payload in exploit kits around 20182019, SystemBC has evolved into a widely traded commodity tool used by multiple…
-
Kali Linux 2026.2 Release With new Hacking Tool and With Updated Desktop Environments
Kali Linux 2026.2 arrives on schedule in the final week of Q2 with a pragmatic blend of desktop environment refreshes, infrastructure hardening, and practical usability refinements that will matter to both pentesters and platform maintainers. The release emphasizes polish and performance rather than headline-grabbing features: GNOME advances to version 50 and KDE Plasma to 6.6.…
-
Boss Scam Uses DLL Sideloading to Hijack WhatsApp Web and Defraud Enterprises
The new “Boss Scam” is a sharp escalation in CEO fraud: attackers now combine impersonation, Windows DLL sideloading, and WhatsApp Web session theft to turn trusted executive channels into fraud infrastructure. The campaign was highlighted in advisories tied to India’s I4C and NCTAU, which warned that attackers pose as regulators or senior bosses, deliver malicious…
-
UK Healthcare Sector Records Tenfold Increase in Cyber-Attacks
SonicWall records 264,000 events in first five months of 2026 as UK hospitals come under siege First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/uk-healthcare-tenfold-increase/
-
Japan Hotel Industry Targeted With TONResolver RAT and Guest Complaint Phishing Emails
Japan’s hotel sector is the latest target of a sophisticated phishing and remote-access trojan (RAT) campaign that leverages guest-complaint lures and an unusual resilience mechanism: a TON blockchainbased dead-drop resolver. Beginning in late May 2026, attackers sent highly targeted emails to Booking.com partner properties in Japan with subject lines such as “é‡è¦ï¼šã‚²ã‚¹ãƒˆæ»žåœ¨ãƒ¬ãƒ“ューä¾é ¼” (Important: Guest Stay…
-
Mustang Panda Targets India’s Government and Energy Sectors With ZOHOMURK and MINIRECON
Two concurrent espionage campaigns by Mustang Panda targeting Indian government and energy-sector organisations, deploying a novel malware suite that includes SHARDLOADER, MINIRECON and ZOHOMURK. The intrusions, observed in June 2026, focused on hydropower entities and government offices engaged in MOUs with Taiwanese institutions, using geopolitically themed lures and weaponised archives that sideload malicious DLLs via…
-
Malicious Chromium Extension Spoofs Perplexity AI to Hijack Browser Searches
A malicious Chromium extension that impersonated the Perplexity AI brand to intercept browser searches and capture keystrokes before delivering users to legitimate search results. The extension, listed as “Search for perplexity ai” (ID flkebkiofojicogddingbdmcmkpbplcd, version 2.2), used Manifest V3 capabilities, declarativeNetRequest (DNR) rules, and a typosquatted domain perplexity-ai[.]online to create a stealthy two”‘hop interception pipeline…
-
Mistic Malware Blends Into Microsoft Endpoint Components Using Malicious EndpointDlp.dll
A newly identified Windows backdoor, dubbed Mistic, that has been observed in intrusions since April 2026 and appears designed for stealthy, long-term access. The malware uses DLL sideloading, in-memory execution, and self-deletion to blend into enterprise environments and minimize forensic traces. Mistic is introduced via a DLL sideloading chain that abuses a legitimate executable named…
-
U.S. Targets Russian Cyber Spies With $10M Bounty Over Messaging App Attacks
The U.S. offers up to $10M for information on Russian hackers targeting Signal and WhatsApp accounts of officials and journalists. The U.S. government is offering rewards of up to $10 million for information leading to the identification of members of the Russian-linked groups UNC5792 and UNC4221. The hackers target government officials, military personnel, journalists, and…
-
Austria Urges Anthropic to Move to EU to Avoid US Controls
Mythos and Fable Export Controls Deprive EU of ‘Cutting-Edge Innovation,’ Security. Stung by the Trump administration’s export controls on Anthropic’s most powerful cyber-capable models, Mythos and Fable, the Austrian government wants Europe to tempt Anthropic into moving across the Atlantic. Austria told the EU sovereignty leader that we must act now. First seen on govinfosecurity.com…
-
British public won’t tolerate cyber disruption any more
The British public’s tolerance for cyber disruption, particularly at high-profile organisations such as retailers, is wearing thin, according to a TalkTalk Business study First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645293/British-public-wont-tolerate-cyber-disruption-any-more
-
US posts $10 million reward over Russian cyber campaign targeting Signal, WhatsApp
Russia-linked hacking groups tracked as UNC5792 and UNC4221 have socially engineered their way into the messaging accounts of government officials. First seen on therecord.media Jump to article: therecord.media/10million-reward-us-russian-hackers-unc4221-unc5792
-
Splunk Secure Gateway RCE Vulnerability Lets Low-Privileged Attackers Execute Arbitrary Code
A newly disclosed high-severity vulnerability in Splunk Secure Gateway (SSG) allows low-privileged authenticated users to achieve remote code execution (RCE) on affected systems, significantly increasing the attack surface for enterprise Splunk deployments. This vulnerability, tracked as CVE-2026-20251, has been assigned a CVSS score of 8.8. It arises from the unsafe deserialization of user-controlled data using…
-
Once, cyber-attacks required great skill. AI is changing that | Bruce Schneier
Modern AI systems are, in effect, a universal adviser to help people do harmful things. We’ll need to harness AI for defense, tooEarlier this week, national security agencies from the Five Eyes that’s the rich, English-language-speaking countries club jointly released a <a href=”https://www.nsa.gov/Press-Room/News-Highlights/Article/Article/4523810/five-eyes-cyber-security-agencies-statement/”>statement warning of the increasing cyber risks of AI models: in particular, their…
-
STOCKSTAY Malware Uses WebSocket C2, RSA Encryption, and Environmental Keying for Stealth
Analysis of a .NET backdoor tracked as STOCKSTAY exposes a mature, modular espionage implant actively developed and deployed by the Russia-linked Turla cluster since at least December 2022. STOCKSTAY demonstrates several operational techniques designed to maximize stealth and survivability: secure WebSocket-based C2, asymmetric encryption using a 4096-bit RSA keypair, inter-component IPC, and environment-based keying of…
-
Critical Hoppscotch Vulnerability Lets Attackers Overwrite JWT_SECRET and Forge Admin Tokens
A critical security vulnerability, identified as CVE-2026-50160, has been discovered in the self-hosted Hoppscotch backend. This vulnerability allows unauthenticated attackers to overwrite sensitive configuration values, including the JWT signing secret, which can ultimately lead to a complete administrative takeover of affected instances. The issue is documented in the GitHub advisory GHSA-j542-4rch-8hwf and impacts all versions…
-
Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse
A Russian advanced persistent threat (APT) group has continued to evolve and expand its malware arsenal as part of its ongoing cyber onslaught against Ukraine throughout 2025.Slovakian cybersecurity company ESET said it observed 35 distinct spear-phishing campaigns mounted by Gamaredon against new targets, with most of them taking place in the second half of the…
-
ClawHavoc Attack Hits ClawHub With 1,184 Malicious Skills and 247,000 Installations
The AI-agent ecosystem experienced its largest supply-chain compromise to date when ClawHavoc detonated across ClawHub, the official skill marketplace for OpenClaw. Our full AIG-powered scan of nearly 50,000 ClawHub Skills found 1,184 clearly malicious packages tied to 12 compromised publisher accounts and confirmed 247,693 installations. The campaign combined typosquatting, ranking manipulation, and multi-stage payload delivery…
-
SSU and FBI Uncover Russian Cyber Espionage Operation Against Officials and Military Personnel
Tags: cyber, data-breach, espionage, government, hacking, intelligence, military, russia, service, ukraineUkraine’s SSU and the FBI Just Confirmed Russian Intelligence Has Been Systematically Hacking Messenger Accounts for Years. The Security Service of Ukraine (SSU), working jointly with the FBI, has formally exposed a sustained Russian intelligence campaign targeting the messaging accounts of government officials, military personnel, politicians, and activists across Ukraine, Europe, and the United States.…
-
Langflow RCE Vulnerability Exploited to Deploy Monero Cryptominer on Exposed AI Servers
Tags: ai, cve, cyber, data-breach, exploit, Internet, rce, remote-code-execution, tactics, threat, vulnerabilityThreat actors are actively exploiting CVE-2026-33017, a critical unauthenticated remote code execution (RCE) vulnerability in Langflow, to compromise internet-exposed AI application servers and silently deploy a customized Monero (XMR) cryptominer. Tracked and documented by Trend Micro researchers Simon Dulude and John Zhang, the campaign marks a significant pivot in commodity cryptominer delivery tactics, from traditional…
-
New Windows Injection Technique Hijacks Win32k Callback Dispatch to Execute Shellcode
A newly documented injection technique abuses the kernel-to-user callback dispatch path used by the Windows graphical subsystem (win32k.sys) to achieve remote code execution while leaving the KernelCallbackTable structurally intact. Rather than replacing a KernelCallbackTable entry with a shellcode pointer, the operator resolves a legitimate callback target from the table and installs an inline detour inside…
-
Critical Dell Wyse Management Suite Vulnerabilities Let Attackers Execute Remote Code
Dell Technologies has disclosed several critical vulnerabilities in its Wyse Management Suite (WMS) that could enable remote attackers to execute arbitrary code and fully compromise affected systems. Identified under advisory DSA-2026-225, these flaws affect WMS versions prior to 5.5 HF1 and are rated from high to critical in severity, highlighting risks for enterprise environments that…
-
FBI and CISA Warn Russian Hackers Stealing Verification Codes and Account PINs From Signal Users
U.S. cybersecurity authorities have issued a new warning about Russian intelligence-linked threat actors targeting secure messaging platforms, specifically highlighting the increased risk for Signal users. These threat actors are employing sophisticated phishing campaigns designed to steal verification codes and account PINs. In a joint Public Service Announcement (PSA) published on June 26, 2026, the Cybersecurity…
-
Russian Hackers Accused of Destructive Cyber-Attack on Jaguar Land Rover
Experts warn the Jaguar Land Rover breach bears hallmarks of Kremlin-backed hackers, citing novel ransomware, strategic timing and efforts to obscure attribution First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/russian-hackers-destructive-jaguar/
-
AI-Generated Mythic Agents Challenge Static Signatures and Traditional Implant Detection
The emergence of LLM-driven >>disposable tooling<< is reshaping offensive tradecraft and forcing defenders to rethink detection models that rely on static signatures and known implant behaviors. Recent experiments demonstrating the automated generation of Mythic agents from prompt to deployment reveal a new threat class: ephemeral, single-use implants tailor-made by large language models and orchestration harnesses.…
-
Critical Google Gemini CLI Flaw Lets Attackers Execute Code on Headless CI Platforms
A critical vulnerability has been identified in Google’s Gemini CLI and the associated run-gemini-cli GitHub Action. This flaw exposes headless continuous integration (CI) platforms to potential host-level code execution when processing untrusted workspaces. It is tracked as CVE-2026-12537, with the advisory identifying it as GHSA-wpqr-6v78-jr5g. Rated at the maximum severity under CVSS v4, the issue…
-
Microsoft 365 Apps RCE Vulnerability Lets Attackers Execute Code via Malicious Excel Files
A newly disclosed remote code execution (RCE) vulnerability in Microsoft 365 Apps is raising concerns in enterprise environments. Attackers can exploit malicious Excel documents to execute arbitrary code on target systems. This vulnerability, tracked as CVE-2025-60727, arises from an out-of-bounds read condition (CWE-125) in Microsoft Excel’s file-parsing mechanism, allowing threat actors to trigger memory corruption…
-
Ghostwriter Hackers Use Real-Time WebSocket Relay to Bypass SMS and OTP MFA
UNC1151 tracked by many as Ghostwriter or FrostyNeighbor has advanced a credential-phishing technique that uses a real-time WebSocket relay to defeat SMS and OTP-based multi-factor authentication (MFA). The method was observed in a recent campaign that targeted Belarusian politician Yury Hubarevich and multiple Ukrainian portals, and Censys pivots show the infrastructure spans dozens of domains…
-
DOJ Seizes Nearly 400 Domains Used for Illegal World Cup Streaming and Malware Threats
The U.S. Department of Justice (DOJ) has announced the seizure of nearly 400 internet domains used to stream FIFA World Cup 2026 matches illegally. This operation represents one of the largest coordinated anti-piracy enforcement actions related to a global sporting event. Conducted under the title “Operation Offsides,” it targeted websites that were distributing real-time broadcasts…
-
DOJ Seizes Nearly 400 Domains Used for Illegal World Cup Streaming and Malware Threats
The U.S. Department of Justice (DOJ) has announced the seizure of nearly 400 internet domains used to stream FIFA World Cup 2026 matches illegally. This operation represents one of the largest coordinated anti-piracy enforcement actions related to a global sporting event. Conducted under the title “Operation Offsides,” it targeted websites that were distributing real-time broadcasts…

