Latest Cyber Security NEWS

How legitimate cloud platforms enable phishers to bypass MFA
We cover a cloud-based AitM attack scenario leveraging service workers and Ultraviolet, and provide detailed phishing hosting statistics across platforms like Cloudflare Workers, Vercel, Netlify, GitHub Pages, and IPFS.
Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)
Read Full Article @
Date Published:

Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
Attacker-controlled instructions can make Atlassian's Rovo assistant collect Jira or Confluence data that a signed-in user can access, then send it to an outside server. Two security firms found that behavior independently, by different routes. Only one of those routes is confirmed closed.
PromptArmor, an AI security firm, hid the instructions in content Rovo reads. It said an uploaded file was
Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)
Read Full Article @
Date Published:

GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration
Two-phase attacks with the GoSerpent backdoor, Stowaway RAT, ThumbcacheService and other tools aim to steal data from government entities in Southeast Asia.
Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)
Read Full Article @
Date Published:

Toy Ghouls’ new toy: the GenieLocker ransomware
Kaspersky experts dissect GenieLocker: new custom ransomware variants for Windows, Linux, and ESXi systems. We found this family in attacks by Toy Ghouls, a financially motivated extortion group.
Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)
Read Full Article @
Date Published:

New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
New research shows content inside an email can escape its message boundary and interfere with the webmail interface.
Across attack chains spanning Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail, the techniques can capture passwords, take over third-party accounts, leak tokens, hijack trusted UI actions, and manipulate AI tools that read email.
PortSwigger researcher Gareth
Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)
Read Full Article @
Date Published:

HelloNet campaign: new malicious modules launched through the ViPNet update system
We identified targeted infection attempts against large Russian organizations using the ViPNet update system (a software suite for creating secure networks).
Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)
Read Full Article @
Date Published:

Twitter Whistleblower Complaint: The TL;DR Version
Twitter is blasted for security and privacy lapses by the company’s former head of security who alleges the social media giant’s actions amount to a national security risk.
Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)
Read Full Article @
Date Published:

UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
A recent wave of cyber attacks targeting financial services, private equity, and professional services has been attributed to a data extortion group known as UNC6671.
"UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT help desk staff facilitating mandatory, urgent security migrations. Significantly, the threat actor often contacts employees via
Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)
Read Full Article @
Date Published:

From Bobmojis to Bobbleheads: How the Democratic Party Built a Security-First Culture
Two former chief security officers of the Democratic National Committee explain that a strong security-first mindset requires executive support — and a dose of absurdity.
Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)
Read Full Article @
Date Published:

AI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent Hijacking
Attackers can take control of agents through malicious instructions hidden in content supplied to AI browsers, and there's no simple fix for the threat.
Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)
Read Full Article @
Date Published:

Researcher Claims Control of ChatGPT Secure Sandbox
A researcher demonstrated a proof-of-concept attack chain that provided C2-style influence over ChatGPT's isolated sandbox during a session at Black Hat USA 2026.
Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)
Read Full Article @
Date Published:

Growing Up The Hard Way
Open Source had a great childhood.
For two decades it got to be a kid. It ran around barefoot, gave everything away, trusted strangers, and never once thought about who was watching. It ran the kind of lemonade stand that took IOUs from anyone who wandered up — take what you need, pay me back whenever, no need to leave a name. It was idyllic. It was also, in retrospect, a little feral.
Then,
Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)
Read Full Article @
Date Published:

A new extortion cocktail: office printers, small ransoms, and BitLocker
We cover two recent cases of BitLocker extortion using RDP, MSSQL, RMM tools, web shells, and printers. The story includes TTPs and recommendations.
Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)
Read Full Article @
Date Published:

ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets
ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials.
The macOS-focused infection chain is designed to deliver a shell script that profiles the host and then fetches a macOS malware payload that's compatible with the computer's CPU architecture.
"
Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)
Read Full Article @
Date Published:

Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems.
"These packages appear to use AI slop squatted, or randomly generated typo-squatting package names, but all of them deliver a powerful RAT and infostealer payload," OpenSourceMalware researcher Paul
Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)
Read Full Article @
Date Published:

ShinyHunters called cancer diagnostics biz and tricked staffers into giving them access. Now they've dumped 10.9M email addresses
Cancer diagnostics breach spills personal and health info as extortion crew says healthcare giant ‘should’ve paid the ransom’
Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)
Read Full Article @
Date Published:

The Coordination Gap: How Attackers Are Outpacing Law Enforcement
The fight against cybercrime continues because threat actors have adapted their strategies to avoid deterrents, but law enforcement still operates in silos.
Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)
Read Full Article @
Date Published:

15 TP-Link Bugs Expose Risks in Zero-Trust Provisioning
Researchers are calling attention to the risks inherent in automated network device provisioning, using a world-leading device manufacturer as a case study.
Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)
Read Full Article @
Date Published:

An analysis of incidents at Brazilian educational institutions
Kaspersky expert provides statistics and details on several incident response cases at educational institutions in Brazil, as well as tips for schools and universities on how to stay safe.
Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)
Read Full Article @
Date Published:

Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild.
The vulnerability, tracked as CVE-2026-8037 (CVSS score: 9.6), is a command injection flaw that could be weaponized to achieve arbitrary
Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)
Read Full Article @
Date Published:

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day.
The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, enabling them to gain
Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)
Read Full Article @
Date Published:

Mirage Kitten targets Middle East and Africa region with new malware
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.
Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)
Read Full Article @
Date Published:

AI Sends Global Crime Syndicates Into Fraud Nirvana
Organized crime is convincingly scamming at scale, making billions thanks to AI-enabled voice cloning, deepfake real-time video overlays, LLM-driven persona management, and automated translation.
Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)
Read Full Article @
Date Published:

New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recovery
Kaspersky GReAT experts describe a new Project CAV3RN C2 module. It uses Outlook calendar for communication via Microsoft Graph and has a backup connection via DNS AAAA responses.
Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)
Read Full Article @
Date Published:

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. pwn.ai demonstrated how the flaw can be chained into PHP code execution on the server when a logged-in administrator interacts with an attacker-controlled page.
Tracked as CVE-2026-64638 (CVSS score: 8.9), the high-severity
Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)
Read Full Article @
Date Published:

OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia
Our experts discovered OctLurk and SilkLurk, backdoors operating primarily in memory, targeting Central Asia. They inject plugins to launch shells, scan networks, dump credentials, and keylogging.
Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)
Read Full Article @
Date Published:

N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist
N-able has released a fresh round of hotfixes for N‑central as part of its investigation into ongoing exploitation of a recently disclosed security flaw in the Remote Monitoring and Management (RMM) product.
"We are proactively expanding protections in response to ongoing monitoring of threat actors as they evolve their attack techniques," the company said.
"This is not a duplicate of our
Sat Aug 08 2026 13:35:09 GMT+0000 (Coordinated Universal Time)
Read Full Article @
Date Published:

