cybersec

#TitleDate
1Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain CampaignApr 23, 3:10 pm
2Regular Password Resets Aren’t as Safe as You ThinkApr 23, 3:10 pm
3Cosmetics giant Rituals discloses data breach affecting customersApr 23, 3:10 pm
4Microsoft: Some Teams users can’t join meetings after Edge updateApr 23, 2:10 pm
5Project Glasswing Proved AI Can Find the Bugs. Who's Going to Fix Them?Apr 23, 1:10 pm
6[Webinar] Mythos Reality Check: Beating Automated Exploitation at AI SpeedApr 23, 1:10 pm
7UK warns of Chinese hackers using proxy networks to evade detectionApr 23, 1:10 pm
8New GopherWhisper APT group abuses Outlook, Slack, Discord for commsApr 23, 12:10 pm
9Apple Fixes iOS Flaw That Let FBI Recover Deleted Signal MessagesApr 23, 11:10 am
10Apple Patches Exploited Notification Flaw, (Thu, Apr 23rd)Apr 23, 11:10 am
11CISA orders feds to patch BlueHammer flaw exploited as zero-dayApr 23, 11:10 am
12Vercel Finds More Compromised Accounts in Context.ai-Linked BreachApr 23, 10:10 am
13China-Linked GopherWhisper Infects 12 Mongolian Government Systems with Go BackdoorsApr 23, 10:10 am
14Apple Patches iOS Flaw That Stored Deleted Signal Notifications in FBI Forensic CaseApr 23, 9:10 am
15Apple fixes bug that let the FBI recover deleted Signal messagesApr 23, 6:10 am
16ISC Stormcast For Thursday, April 23rd, 2026 https://isc.sans.edu/podcastdetail/9904, (Thu, Apr 23rd)Apr 23, 2:10 am
17Apple fixes iOS bug that retained deleted notification dataApr 22, 9:10 pm
18New Mirai campaign exploits RCE flaw in EoL D-Link routersApr 22, 8:10 pm
19Malicious KICS Docker Images and VS Code Extensions Hit Checkmarx Supply ChainApr 22, 7:10 pm
20Kyber ransomware gang toys with post-quantum encryption on WindowsApr 22, 7:10 pm
21Self-Propagating Supply Chain Worm Hijacks npm Packages to Steal Developer TokensApr 22, 6:10 pm
22Harvester Deploys Linux GoGra Backdoor in South Asia Using Microsoft Graph APIApr 22, 4:10 pm
23Spain dismantles major $4.7M manga piracy platform, arrests fourApr 22, 3:10 pm
24Inside Caller-as-a-Service Fraud: The Scam Economy Has a Hiring ProcessApr 22, 2:10 pm
25Microsoft Teams to get efficiency mode on PCs with limited resourcesApr 22, 1:10 pm
26New npm supply-chain attack self-spreads to steal auth tokensApr 22, 1:10 pm
27Toxic Combinations: When Cross-App Permissions Stack into RiskApr 22, 12:10 pm
28Lotus Wiper Malware Targets Venezuelan Energy Systems in Destructive AttackApr 22, 12:10 pm
29Microsoft traces Universal Print issues to Graph API code changeApr 22, 11:10 am
30Microsoft Patches Critical ASP.NET Core CVE-2026-40372 Privilege Escalation BugApr 22, 10:10 am
31New GoGra malware for Linux uses Microsoft Graph API for commsApr 22, 10:10 am
32Cohere AI Terrarium Sandbox Flaw Enables Root Code Execution, Container EscapeApr 22, 9:10 am
33Mustang Panda’s New LOTUSLITE Variant Targets India Banks, South Korea Policy CirclesApr 22, 9:10 am
34Microsoft releases emergency patches for critical ASP.NET flawApr 22, 9:10 am
35Over 1,300 Microsoft SharePoint servers vulnerable to spoofing attacksApr 22, 7:10 am
36ISC Stormcast For Wednesday, April 22nd, 2026 https://isc.sans.edu/podcastdetail/9902, (Wed, Apr 22nd)Apr 22, 2:10 am
37[Guest Diary] Beyond Cryptojacking: Telegram tdata as a Credential Harvesting Vector, Lessons from a Honeypot Incident, (Wed, Apr 22nd)Apr 22, 12:10 am
38French govt agency confirms breach as hacker offers to sell dataApr 21, 10:10 pm
39SystemBC C2 Server Reveals 1,570+ Victims in The Gentlemen Ransomware OperationApr 21, 8:10 pm
40New Lotus data wiper used against Venezuelan energy, utility firmsApr 21, 7:10 pm
4122 BRIDGE:BREAK Flaws Expose Thousands of Lantronix and Silex Serial-to-IP ConvertersApr 21, 5:10 pm
4222 BRIDGE:BREAK Flaws Expose 20,000 Lantronix and Silex Serial-to-IP ConvertersApr 21, 4:10 pm
43Ransomware Negotiator Pleads Guilty to Aiding BlackCat Attacks in 2023Apr 21, 3:10 pm
44‘Scattered Spider’ Member ‘Tylerb’ Pleads GuiltyApr 21, 3:10 pm
455 Places where Mature SOCs Keep MTTR Fast and Others Waste TimeApr 21, 2:10 pm
46UK probes Telegram, teen chat sites over CSAM sharing concernsApr 21, 2:10 pm
47Stopping Fraud at Each Stage of the Customer Journey Without Adding FrictionApr 21, 2:10 pm
48CISA flags new SD-WAN flaw as actively exploited in attacksApr 21, 1:10 pm
49Google Patches Antigravity IDE Flaw Enabling Prompt Injection Code ExecutionApr 21, 12:10 pm
50NGate Campaign Targets Brazil, Trojanizes HandyPay to Steal NFC Data and PINsApr 21, 12:10 pm
51Actively exploited Apache ActiveMQ flaw impacts 6,400 serversApr 21, 12:10 pm
52No Exploit Needed: How Attackers Walk Through the Front Door via Identity-Based AttacksApr 21, 12:10 pm
53Former ransomware negotiator pleads guilty to BlackCat attacksApr 21, 11:10 am
54NGate Android malware uses HandyPay NFC app to steal card dataApr 21, 9:10 am
55A .WAV With A Payload, (Tue, Apr 21st)Apr 21, 8:10 am
56CISA Adds 8 Exploited Flaws to KEV, Sets April-May 2026 Federal DeadlinesApr 21, 7:10 am
57ISC Stormcast For Tuesday, April 21st, 2026 https://isc.sans.edu/podcastdetail/9900, (Tue, Apr 21st)Apr 21, 2:10 am
58KelpDAO suffers $290 million heist tied to Lazarus hackersApr 20, 11:10 pm
59China's Apple App Store infiltrated by crypto-stealing wallet appsApr 20, 10:10 pm
60The Gentlemen ransomware now uses SystemBC for bot-powered attacksApr 20, 8:10 pm
61SGLang CVE-2026-5760 (CVSS 9.8) Enables RCE via Malicious GGUF Model FilesApr 20, 7:10 pm
62Seiko USA website defaced as hacker claims customer data theftApr 20, 7:10 pm
63Microsoft: Teams increasingly abused in helpdesk impersonation attacksApr 20, 4:10 pm
64⚡ Weekly Recap: Vercel Hack, Push Fraud, QEMU Abused, New Android RATs Emerge & MoreApr 20, 3:10 pm
65British Scattered Spider hacker pleads guilty to crypto theft chargesApr 20, 2:10 pm
66The backup myth that is putting businesses at riskApr 20, 2:10 pm
67Why Most AI Deployments Stall After the DemoApr 20, 1:10 pm
68Microsoft tests Windows Explorer speed, performance improvementsApr 20, 1:10 pm
69Anthropic MCP Design Vulnerability Enables RCE, Threatening AI Supply ChainApr 20, 11:10 am
70Microsoft pulls service update causing Teams launch failuresApr 20, 10:10 am
71Researchers Detect ZionSiphon Malware Targeting Israeli Water, Desalination OT SystemsApr 20, 9:10 am
72Microsoft releases emergency updates to fix Windows Server issuesApr 20, 9:10 am
73Handling the CVE Flood With EPSS, (Mon, Apr 20th)Apr 20, 7:10 am
74Vercel Breach Tied to Context AI Hack Exposes Limited Customer CredentialsApr 20, 5:10 am
75ISC Stormcast For Monday, April 20th, 2026 https://isc.sans.edu/podcastdetail/9898, (Mon, Apr 20th)Apr 20, 2:10 am
76Vercel confirms breach as hackers claim to be selling stolen dataApr 19, 6:10 pm
77Apple account change alerts abused to send phishing emailsApr 19, 4:10 pm
78NIST to stop rating non-priority flaws due to volume increaseApr 19, 3:10 pm
79Critical flaw in Protobuf library enables JavaScript code executionApr 18, 4:10 pm
80Microsoft Teams right-click paste broken by Edge update bugApr 18, 3:10 pm
81NAKIVO v11.2: Ransomware Defense, Faster Replication, vSphere 9, and Proxmox VE 9.0 SupportApr 18, 2:10 pm
82$13.74M Hack Shuts Down Sanctioned Grinex Exchange After Intelligence ClaimsApr 18, 9:10 am
83[Webinar] Eliminate Ghost Identities Before They Expose Your Enterprise DataApr 18, 9:10 am
84Mirai Variant Nexcorium Exploits CVE-2024-3721 to Hijack TBK DVRs for DDoS BotnetApr 18, 7:10 am
85Payouts King ransomware uses QEMU VMs to bypass endpoint securityApr 17, 8:10 pm
86Inside an Underground Guide: How Threat Actors Vet Stolen Credit Card ShopsApr 17, 3:10 pm
87Grinex exchange blames "Western intelligence" for $13.7M crypto hackApr 17, 3:10 pm
88Three Microsoft Defender Zero-Days Actively Exploited; Two Still UnpatchedApr 17, 2:10 pm
89Webinar: From phishing to fallout — Why MSPs must rethink both security and recoveryApr 17, 1:10 pm
90Google Blocks 8.3B Policy-Violating Ads in 2025, Launches Android 17 Privacy OverhaulApr 17, 12:10 pm
91CISA flags Apache ActiveMQ flaw as actively exploited in attacksApr 17, 10:10 am
92Man gets 30 months for selling thousands of hacked DraftKings accountsApr 17, 8:10 am
93NIST Limits CVE Enrichment After 263% Surge in Vulnerability SubmissionsApr 17, 8:10 am
94Microsoft: Some Windows servers enter reboot loops after April patchesApr 17, 8:10 am
95Operation PowerOFF Seizes 53 DDoS Domains, Exposes 3 Million Criminal AccountsApr 17, 7:10 am
96Recently leaked Windows zero-days now exploited in attacksApr 17, 7:10 am
97Apache ActiveMQ CVE-2026-34197 Added to CISA KEV Amid Active ExploitationApr 17, 4:10 am
98ISC Stormcast For Friday, April 17th, 2026 https://isc.sans.edu/podcastdetail/9896, (Fri, Apr 17th)Apr 17, 2:10 am
99Lumma Stealer infection with Sectop RAT (ArechClient2), (Fri, Apr 17th)Apr 17, 1:10 am
100Operation PowerOFF identifies 75k DDoS users, takes down 53 domainsApr 16, 11:10 pm
101ZionSiphon malware designed to sabotage water treatment systemsApr 16, 10:10 pm
102New Microsoft Defender “RedSun” zero-day PoC grants SYSTEM privilegesApr 16, 9:10 pm
103Newly Discovered PowMix Botnet Hits Czech Workers Using Randomized C2 TrafficApr 16, 7:10 pm
104Hackers exploit Marimo flaw to deploy NKAbuse malware from Hugging FaceApr 16, 5:10 pm
105Google expands Gemini AI use to fight malicious ads on its platformApr 16, 4:10 pm
106ThreatsDay Bulletin: Defender 0-Day, SonicWall Brute-Force, 17-Year-Old Excel RCE and 15 More StoriesApr 16, 2:10 pm
107Most "AI SOCs" Are Just Faster Triage. That's Not Enough.Apr 16, 2:10 pm
108New ATHR vishing platform uses AI voice agents for automated attacksApr 16, 2:10 pm
109[Webinar] Find and Eliminate Orphaned Non-Human Identities in Your EnvironmentApr 16, 1:10 pm
110Hidden Passenger? How Taboola Routes Logged-In Banking Sessions to TemuApr 16, 12:10 pm
111Obsidian Plugin Abuse Delivers PHANTOMPULSE RAT in Targeted Finance, Crypto AttacksApr 16, 12:10 pm
112Cisco Patches Four Critical Identity Services, Webex Flaws Enabling Code ExecutionApr 16, 12:10 pm
113Cisco says critical Webex Services flaw requires customer actionApr 16, 12:10 pm
114Data breach at edtech giant McGraw Hill affects 13.5 million accountsApr 16, 11:10 am
115US nationals behind DPRK IT worker 'laptop farm' sent to prisonApr 16, 9:10 am
116Microsoft: April Windows Server 2025 update may fail to installApr 16, 8:10 am
117UAC-0247 Targets Ukrainian Clinics and Government in Data-Theft Malware CampaignApr 16, 7:10 am
118ISC Stormcast For Thursday, April 16th, 2026 https://isc.sans.edu/podcastdetail/9894, (Thu, Apr 16th)Apr 16, 2:10 am
119[Guest Diary] Compromised DVRs and Finding Them in the Wild, (Thu, Apr 16th)Apr 16, 12:10 am
120Critical Nginx UI auth bypass flaw now actively exploited in the wildApr 15, 11:10 pm
121New AgingFly malware used in attacks on Ukraine govt, hospitalsApr 15, 10:10 pm
122WordPress plugin suite hacked to push malware to thousands of sitesApr 15, 9:10 pm
123n8n Webhooks Abused Since October 2025 to Deliver Malware via Phishing EmailsApr 15, 6:10 pm
124Signed software abused to deploy antivirus-killing scriptsApr 15, 6:10 pm
125Microsoft pays $2.3M for cloud and AI flaws at Zero Day QuestApr 15, 5:10 pm
126CISA flags Windows Task Host vulnerability as exploited in attacksApr 15, 3:10 pm
127April Patch Tuesday Fixes Critical Flaws Across SAP, Adobe, Microsoft, Fortinet, and MoreApr 15, 2:10 pm
128Actively Exploited nginx-ui Flaw (CVE-2026-33032) Enables Full Nginx Server TakeoverApr 15, 2:10 pm
129Rolling Networks: Securing the Transportation SectorApr 15, 2:10 pm
130Deterministic + Agentic AI: The Architecture Exposure Validation RequiresApr 15, 1:10 pm
131Microsoft: April updates trigger BitLocker key prompts on some serversApr 15, 12:10 pm
132Microsoft fixes bug behind Windows Server 2025 automatic upgradesApr 15, 11:10 am
133Microsoft Issues Patches for SharePoint Zero-Day and 168 Other New VulnerabilitiesApr 15, 9:10 am
134OpenAI Launches GPT-5.4-Cyber with Expanded Access for Security TeamsApr 15, 6:10 am
135ISC Stormcast For Wednesday, April 15th, 2026 https://isc.sans.edu/podcastdetail/9892, (Wed, Apr 15th)Apr 15, 2:10 am
136Scanning for AI Models, (Tue, Apr 14th)Apr 15, 1:10 am
137Microsoft adds Windows protections for malicious Remote Desktop filesApr 14, 11:10 pm
138Over 100 Chrome Web Store extensions steal user accounts, dataApr 14, 10:10 pm
139Patch Tuesday, April 2026 EditionApr 14, 10:10 pm
140Crypto-exchange Kraken extorted by hackers after insider breachApr 14, 10:10 pm
141Over 100 Chrome extensions in Web Store target users accounts and dataApr 14, 9:10 pm
142Microsoft April 2026 Patch Tuesday fixes 167 flaws, 2 zero-daysApr 14, 6:10 pm
143Microsoft Patch Tuesday April 2026., (Tue, Apr 14th)Apr 14, 6:10 pm
144Windows 11 cumulative updates KB5083769 & KB5082052 releasedApr 14, 6:10 pm
145McGraw-Hill confirms data breach following extortion threatApr 14, 6:10 pm
146Microsoft releases Windows 10 KB5082200 extended security updateApr 14, 6:10 pm
147New PHP Composer Flaws Enable Arbitrary Command Execution — Patches ReleasedApr 14, 5:10 pm
148Fake Ledger Live app on Apple’s App Store stole $9.5M in cryptoApr 14, 5:10 pm
149AI-Driven Pushpaganda Scam Exploits Google Discover to Spread Scareware and Ad FraudApr 14, 4:10 pm
150Microsoft rolls out fast-track to reinstate Windows hardware dev accountsApr 14, 4:10 pm
1515 Ways Zero Trust Maximizes Identity SecurityApr 14, 3:10 pm
152Google Adds Rust-Based DNS Parser into Pixel 10 Modem to Enhance SecurityApr 14, 2:10 pm
153Mirax Android RAT Turns Devices into SOCKS5 Proxies, Reaching 220,000 via Meta AdsApr 14, 12:10 pm
154Analysis of 216M Security Findings Shows a 4x Increase In Critical Risk (2026 Report)Apr 14, 10:10 am
155108 Malicious Chrome Extensions Steal Google and Telegram Data, Affecting 20,000 UsersApr 14, 9:10 am
156CISA Adds 6 Known Exploited Flaws in Fortinet, Microsoft, and Adobe SoftwareApr 14, 7:10 am
157ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched ServersApr 14, 7:10 am
158ISC Stormcast For Tuesday, April 14th, 2026 https://isc.sans.edu/podcastdetail/9890, (Tue, Apr 14th)Apr 14, 2:10 am
159European Gym giant Basic-Fit data breach affects 1 million membersApr 13, 10:10 pm
160JanelaRAT Malware Targets Latin American Banks with 14,739 Attacks in Brazil in 2025Apr 13, 8:10 pm
161Critical flaw in wolfSSL library enables forged certificate useApr 13, 8:10 pm
162Stolen Rockstar Games analytics data leaked by extortion gangApr 13, 8:10 pm
163FBI takedown of W3LL phishing service leads to developer arrestApr 13, 7:10 pm
164New Booking.com data breach forces reservation PIN resetsApr 13, 6:10 pm
165OpenAI rotates macOS certs after Axios attack hit code-signing workflowApr 13, 6:10 pm
166FBI and Indonesian Police Dismantle W3LL Phishing Network Behind $20M Fraud AttemptsApr 13, 4:10 pm
167Adobe rolls out emergency fix for Acrobat, Reader zero-day flawApr 13, 4:10 pm
168⚡ Weekly Recap: Fiber Optic Spying, Windows Rootkit, AI Vulnerability Hunting and MoreApr 13, 2:10 pm
169The silent “Storm”: New infostealer hijacks sessions, decrypts server-sideApr 13, 2:10 pm
170Your MTTD Looks Great. Your Post-Alert Gap Doesn'tApr 13, 1:10 pm
171Scans for EncystPHP Webshell, (Mon, Apr 13th)Apr 13, 1:10 pm
172North Korea's APT37 Uses Facebook Social Engineering to Deliver RokRAT MalwareApr 13, 11:10 am
173OpenAI Revokes macOS App Certificate After Malicious Axios Supply Chain IncidentApr 13, 8:10 am
174ISC Stormcast For Monday, April 13th, 2026 https://isc.sans.edu/podcastdetail/9888, (Mon, Apr 13th)Apr 13, 2:10 am
175Critical Marimo pre-auth RCE flaw now under active exploitationApr 12, 3:10 pm
176Adobe Patches Actively Exploited Acrobat Reader Flaw CVE-2026-34621Apr 12, 6:10 am
177CPUID Breach Distributes STX RAT via Trojanized CPU-Z and HWMonitor DownloadsApr 12, 6:10 am
178Over 20,000 crypto fraud victims identified in international crackdownApr 11, 3:10 pm
179Citizen Lab: Law Enforcement Used Webloc to Track 500 Million Devices via Ad DataApr 11, 8:10 am
180ChatGPT rolls out new $100 Pro subscription to challenge ClaudeApr 11, 2:10 am
181CPUID hacked to deliver malware via CPU-Z, HWMonitor downloadsApr 10, 5:10 pm
182Nearly 4,000 US industrial devices exposed to Iranian cyberattacksApr 10, 4:10 pm
183Supply chain attack at CPUID pushes malware with CPU-Z/HWMonitorApr 10, 2:10 pm
184GlassWorm Campaign Uses Zig Dropper to Infect Multiple Developer IDEsApr 10, 2:10 pm
185Analysis of one billion CISA KEV remediation records exposes limits of human-scale securityApr 10, 2:10 pm
186Microsoft: Canadian employees targeted in payroll pirate attacksApr 10, 12:10 pm
187Marimo RCE Flaw CVE-2026-39987 Exploited Within 10 Hours of DisclosureApr 10, 11:10 am
188Google rolls out Gmail end-to-end encryption on mobile devicesApr 10, 11:10 am
189Browser Extensions Are the New AI Consumption Channel That No One Is Talking AboutApr 10, 11:10 am
190Google Rolls Out DBSC in Chrome 146 to Block Session Theft on WindowsApr 10, 9:10 am
191Backdoored Smart Slider 3 Pro Update Distributed via Compromised Nextend ServersApr 10, 8:10 am
192Obfuscated JavaScript or Nothing, (Thu, Apr 9th)Apr 10, 7:10 am
193EngageLab SDK Flaw Exposed 50M Android Users, Including 30M Crypto Wallet InstallsApr 10, 6:10 am
194New VENOM phishing attacks steal senior executives' Microsoft loginsApr 9, 10:10 pm
195New ‘LucidRook’ malware used in targeted attacks on NGOs, universitiesApr 9, 10:10 pm
196EngageLab SDK Flaw Exposed 50M Android Users, Including 30M Crypto WalletsApr 9, 8:10 pm
197Healthcare IT solutions provider ChipSoft hit by ransomware attackApr 9, 8:10 pm
198Google Chrome adds infostealer protection against session cookie theftApr 9, 7:10 pm
199Smart Slider updates hijacked to push malicious WordPress, Joomla versionsApr 9, 5:10 pm
200UAT-10362 Targets Taiwanese NGOs with LucidRook Malware in Spear-Phishing CampaignsApr 9, 5:10 pm
201When attackers already have the keys, MFA is just another door to openApr 9, 3:10 pm
202ThreatsDay Bulletin: Hybrid P2P Botnet, 13-Year-Old Apache RCE and 18 More StoriesApr 9, 2:10 pm
203Webinar: From noise to signal - What threat actors are targeting nextApr 9, 1:10 pm
204Bitter-Linked Hack-for-Hire Campaign Targets Journalists Across MENA RegionApr 9, 12:10 pm
205Adobe Reader Zero-Day Exploited via Malicious PDFs Since December 2025Apr 9, 12:10 pm
206The Hidden Security Risks of Shadow AI in EnterprisesApr 9, 12:10 pm
207Eurail says December data breach impacts 300,000 individualsApr 9, 11:10 am
208Hackers exploiting Acrobat Reader zero-day flaw since DecemberApr 9, 10:10 am
209Hackers steal $3.6 million from crypto ATM giant Bitcoin DepotApr 9, 8:10 am
210Microsoft suspends dev accounts for high-profile open source projectsApr 9, 7:10 am
211ISC Stormcast For Thursday, April 9th, 2026 https://isc.sans.edu/podcastdetail/9886, (Thu, Apr 9th)Apr 9, 2:10 am
212Number Usage in Passwords: Take Two, (Thu, Apr 9th)Apr 9, 1:10 am
213Hackers use pixel-large SVG trick to hide credit card stealerApr 8, 11:10 pm
214Google: New UNC6783 hackers steal corporate Zendesk support ticketsApr 8, 10:10 pm
215New Chaos Variant Targets Misconfigured Cloud Deployments, Adds SOCKS ProxyApr 8, 7:10 pm
216CISA orders feds to patch exploited Ivanti EPMM flaw by SundayApr 8, 7:10 pm
217New macOS stealer campaign uses Script Editor in ClickFix attackApr 8, 7:10 pm
218Masjesu Botnet Emerges as DDoS-for-Hire Service Targeting Global IoT DevicesApr 8, 6:10 pm
219TeamPCP Supply Chain Campaign: Update 007 - Cisco Source Code Stolen via Trivy-Linked Breach, Google GTIG Tracks TeamPCP as UNC6780, and CISA KEV Deadline Arrives with No Standalone Advisory, (Wed, Apr 8th)Apr 8, 6:10 pm
22013-year-old bug in ActiveMQ lets hackers remotely execute commandsApr 8, 6:10 pm
221APT28 Deploys PRISMEX Malware in Campaign Targeting Ukraine and NATO AlliesApr 8, 4:10 pm
222More Honeypot Fingerprinting Scans, (Wed, Apr 8th)Apr 8, 3:10 pm
223Is a $30,000 GPU Good at Password Cracking?Apr 8, 2:10 pm
224Shrinking the IAM Attack Surface through Identity Visibility and Intelligence Platforms (IVIP)Apr 8, 12:10 pm
225Anthropic's Claude Mythos Finds Thousands of Zero-Day Flaws Across Major SystemsApr 8, 10:10 am
226N. Korean Hackers Spread 1,700 Malicious Packages Across npm, PyPI, Go, RustApr 8, 9:10 am
227Microsoft rolls out fix for broken Windows Start Menu searchApr 8, 7:10 am
228Iran-Linked Hackers Disrupt U.S. Critical Infrastructure by Targeting Internet-Exposed PLCsApr 8, 6:10 am
229ISC Stormcast For Wednesday, April 8th, 2026 https://isc.sans.edu/podcastdetail/9884, (Wed, Apr 8th)Apr 8, 2:10 am
230Hackers exploit critical flaw in Ninja Forms WordPress pluginApr 7, 10:10 pm
231FBI: Americans lost a record $21 billion to cybercrime last yearApr 7, 9:10 pm
232Snowflake customers hit in data theft attacks after SaaS integrator breachApr 7, 8:10 pm
233A Little Bit Pivoting: What Web Shells are Attackers Looking for?, (Tue, Apr 7th)Apr 7, 7:10 pm
234Russian State-Linked APT28 Exploits SOHO Routers in Global DNS Hijacking CampaignApr 7, 6:10 pm
235Russia Hacked Routers to Steal Microsoft Office TokensApr 7, 6:10 pm
236US warns of Iranian hackers targeting critical infrastructureApr 7, 6:10 pm
237Max severity Flowise RCE vulnerability now exploited in attacksApr 7, 5:10 pm
238Docker CVE-2026-34040 Lets Attackers Bypass Authorization and Gain Host AccessApr 7, 4:10 pm
239Authorities disrupt router DNS hijacks used to steal Microsoft 365 loginsApr 7, 4:10 pm
240Over 1,000 Exposed ComfyUI Instances Targeted in Cryptomining Botnet CampaignApr 7, 2:10 pm
241Why Your Automated Pentesting Tool Just Hit a WallApr 7, 2:10 pm
242The Hidden Cost of Recurring Credential IncidentsApr 7, 1:10 pm
243[Webinar] How to Close Identity Gaps in 2026 Before AI Exploits Enterprise RiskApr 7, 1:10 pm
244New GPUBreach Attack Enables Full CPU Privilege Escalation via GDDR6 Bit-FlipsApr 7, 10:10 am
245China-Linked Storm-1175 Exploits Zero-Days to Rapidly Deploy Medusa RansomwareApr 7, 8:10 am
246Flowise AI Agent Builder Under Active CVSS 10.0 RCE Exploitation; 12,000+ Instances ExposedApr 7, 6:10 am
247German authorities identify REvil and GandCrab ransomware bossesApr 7, 4:10 am
248ISC Stormcast For Tuesday, April 7th, 2026 https://isc.sans.edu/podcastdetail/9882, (Tue, Apr 7th)Apr 7, 2:10 am
249German authorities identify REvil and GangCrab ransomware bossesApr 7, 12:10 am
250New GPUBreach attack enables system takeover via GPU rowhammerApr 6, 10:10 pm
251Iran-Linked Password-Spraying Campaign Targets 300+ Israeli Microsoft 365 OrganizationsApr 6, 8:10 pm
252Microsoft fixes Classic Outlook bug causing email delivery issuesApr 6, 8:10 pm
253Disgruntled researcher leaks “BlueHammer” Windows zero-day exploitApr 6, 8:10 pm
254DPRK-Linked Hackers Use GitHub as C2 in Multi-Stage Attacks Targeting South KoreaApr 6, 6:10 pm
255Microsoft removes Support and Recovery Assistant from WindowsApr 6, 6:10 pm
256CISA orders feds to patch exploited Fortinet EMS flaw by FridayApr 6, 5:10 pm
257Drift $280M crypto theft linked to 6-month in-person operationApr 6, 5:10 pm
258Microsoft links Medusa ransomware affiliate to zero-day attacksApr 6, 5:10 pm
259CISA orders feds to patch Fortinet flaw exploited in attacks by FridayApr 6, 4:10 pm
260⚡ Weekly Recap: Axios Hack, Chrome 0-Day, Fortinet Exploits, Paragon Spyware and MoreApr 6, 3:10 pm
261Multi-OS Cyberattacks: How SOCs Close a Critical Risk in 3 StepsApr 6, 3:10 pm
262Why Simple Breach Monitoring is No Longer EnoughApr 6, 2:10 pm
263How LiteLLM Turned Developer Machines Into Credential Vaults for AttackersApr 6, 1:10 pm
264Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR ToolsApr 6, 11:10 am
265How often are redirects used in phishing in 2026?, (Mon, Apr 6th)Apr 6, 9:10 am
266BKA Identifies REvil Leaders Behind 130 German Ransomware AttacksApr 6, 7:10 am
267Germany Doxes “UNKN,” Head of RU Ransomware Gangs REvil, GandCrabApr 6, 3:10 am
268ISC Stormcast For Monday, April 6th, 2026 https://isc.sans.edu/podcastdetail/9880, (Mon, Apr 6th)Apr 6, 2:10 am
269$285 Million Drift Hack Traced to Six-Month DPRK Social Engineering OperationApr 5, 8:10 pm
270Traffic violation scams switch to QR codes in new phishing textsApr 5, 8:10 pm
271New FortiClient EMS flaw exploited in attacks, emergency patch releasedApr 5, 7:10 pm
272Hackers exploit React2Shell in automated credential theft campaignApr 5, 3:10 pm
273Fortinet Patches Actively Exploited CVE-2026-35616 in FortiClient EMSApr 5, 6:10 am
27436 Malicious npm Packages Exploited Redis, PostgreSQL to Deploy Persistent ImplantsApr 5, 6:10 am
275Axios npm hack used fake Teams error fix to hijack maintainer accountApr 4, 9:10 pm
276LinkedIn secretly scans for 6,000+ Chrome extensions, collects dataApr 4, 3:10 pm
277Device code phishing attacks surge 37x as new kits spread onlineApr 4, 3:10 pm
278LinkedIn secretely scans for 6,000+ Chrome extensions, collects dataApr 3, 9:10 pm
279Microsoft Details Cookie-Controlled PHP Web Shells Persisting via Cron on Linux ServersApr 3, 6:10 pm
280China-Linked TA416 Targets European Governments with PlugX and OAuth-Based PhishingApr 3, 6:10 pm
281Hims & Hers warns of data breach after Zendesk support ticket breachApr 3, 6:10 pm
282Die Linke German political party confirms data stolen by Qilin ransomwareApr 3, 5:10 pm
283Evolution of Ransomware: Multi-Extortion Ransomware AttacksApr 3, 3:10 pm
284TeamPCP Supply Chain Campaign: Update 006 - CERT-EU Confirms European Commission Cloud Breach, Sportradar Details Emerge, and Mandiant Quantifies Campaign at 1,000+ SaaS Environments, (Fri, Apr 3rd)Apr 3, 2:10 pm
285Why Third-Party Risk Is the Biggest Gap in Your Clients' Security PostureApr 3, 1:10 pm
286UNC1069 Social Engineering of Axios Maintainer Led to npm Supply Chain AttackApr 3, 1:10 pm
287Microsoft still working to fix Exchange Online mailbox access issuesApr 3, 12:10 pm
288Drift Loses $285 Million in Durable Nonce Social Engineering Attack Linked to DPRKApr 3, 10:10 am
289New SparkCat Variant in iOS, Android Apps Steals Crypto Wallet Recovery Phrase ImagesApr 3, 10:10 am
290Man admits to locking thousands of Windows devices in extortion plotApr 3, 9:10 am
291Microsoft now force upgrades unmanaged Windows 11 24H2 PCsApr 3, 8:10 am
292CERT-EU: European Commission hack exposes data of 30 EU entitiesApr 3, 7:10 am
293Drift loses $280 million North Korean hackers seize Security Council powersApr 3, 6:10 am
294ISC Stormcast For Friday, April 3rd, 2026 https://isc.sans.edu/podcastdetail/9878, (Fri, Apr 3rd)Apr 3, 2:10 am
295Hackers Exploit CVE-2025-55182 to Breach 766 Next.js Hosts, Steal CredentialsApr 2, 9:10 pm
296Claude Code leak used to push infostealer malware on GitHubApr 2, 9:10 pm
297Drift loses $280 million as hackers seize Security Council powersApr 2, 7:10 pm
298Cisco Patches 9.8 CVSS IMC and SSM Flaws Allowing Remote System CompromiseApr 2, 5:10 pm
299Residential proxies evaded IP reputation checks in 78% of 4B sessionsApr 2, 4:10 pm
300Attempts to Exploit Exposed "Vite" Installs (CVE-2025-30208), (Thu, Apr 2nd)Apr 2, 3:10 pm
301ThreatsDay Bulletin: Pre-Auth Chains, Android Rootkits, CloudTrail Evasion & 10 More StoriesApr 2, 2:10 pm
302Medtech giant Stryker fully operational after data-wiping attackApr 2, 2:10 pm
303New Progress ShareFile flaws can be chained in pre-auth RCE attacksApr 2, 2:10 pm
304Adversaries Exploit Vacant Homes to Intercept Mail in Hybrid CybercrimeApr 2, 2:10 pm
305The State of Trusted Open Source ReportApr 2, 12:10 pm
306Researchers Uncover Mining Operation Using ISO Lures to Spread RATs and Crypto MinersApr 2, 12:10 pm
307WhatsApp Alerts 200 Users After Fake iOS App Installed Spyware; Italian Firm Faces ActionApr 2, 11:10 am
308Critical Cisco IMC auth bypass gives attackers Admin accessApr 2, 11:10 am
309Microsoft links Classic Outlook issue to email delivery problemsApr 2, 10:10 am
310Over 14,000 F5 BIG-IP APM instances still exposed to RCE attacksApr 2, 9:10 am
311Apple Expands iOS 18.7.7 Update to More Devices to Block DarkSword ExploitApr 2, 8:10 am
312ISC Stormcast For Thursday, April 2nd, 2026 https://isc.sans.edu/podcastdetail/9876, (Thu, Apr 2nd)Apr 2, 2:10 am
313New CrystalRAT malware adds RAT, stealer and prankware featuresApr 2, 12:10 am
314Hackers exploit TrueConf zero-day to push malicious software updatesApr 1, 10:10 pm
315Apple expands iOS 18 updates to more iPhones to block DarkSword attacksApr 1, 10:10 pm
316New EvilTokens service fuels Microsoft device code phishing attacksApr 1, 8:10 pm
317CERT-UA Impersonation Campaign Spread AGEWHEEZE Malware to 1 Million EmailsApr 1, 6:10 pm
318'NoVoice' Android malware on Google Play infected 2.3 million devicesApr 1, 6:10 pm
319Routine Access Is Powering Modern Intrusions, a New Threat Report FindsApr 1, 3:10 pm
320New Chrome Zero-Day CVE-2026-5281 Under Active Exploitation — Patch ReleasedApr 1, 2:10 pm
321Microsoft Warns of WhatsApp-Delivered VBS Malware Hijacking Windows via UAC BypassApr 1, 2:10 pm
322Casbaneiro Phishing Targets Latin America and Europe Using Dynamic PDF LuresApr 1, 2:10 pm
323Block the Prompt, Not the Work: The End of "Doctor No"Apr 1, 2:10 pm
324TeamPCP Supply Chain Campaign: Update 005 - First Confirmed Victim Disclosure, Post-Compromise Cloud Enumeration Documented, and Axios Attribution Narrows, (Wed, Apr 1st)Apr 1, 2:10 pm
3253 Reasons Attackers Are Using Your Trusted Tools Against You (And Why You Don’t See It Coming)Apr 1, 12:10 pm
326FBI warns against using Chinese mobile apps due to privacy risksApr 1, 12:10 pm
327Google fixes fourth Chrome zero-day exploited in attacks in 2026Apr 1, 11:10 am
328Malicious Script That Gets Rid of ADS, (Wed, Apr 1st)Apr 1, 11:10 am
329Google Attributes Axios npm Supply Chain Attack to North Korean Group UNC1069Apr 1, 8:10 am
330Claude Code Source Leaked via npm Packaging Error, Anthropic ConfirmsApr 1, 7:10 am
331Google Drive ransomware detection now on by default for paying usersApr 1, 7:10 am
332New Windows 11 emergency update fixes preview update install issuesApr 1, 6:10 am
333ISC Stormcast For Wednesday, April 1st, 2026 https://isc.sans.edu/podcastdetail/9874, (Wed, Apr 1st)Apr 1, 2:10 am
334Claude Code source code accidentally leaked in NPM packageApr 1, 1:10 am
335Google now allows you to change your @gmail.com addressApr 1, 12:10 am
336GIGABYTE Control Center vulnerable to arbitrary file write flawMar 31, 11:10 pm
337Proton launches new "Meet" privacy-focused conferencing platformMar 31, 11:10 pm
338Claude AI finds Vim, Emacs RCE bugs that trigger on file openMar 31, 10:10 pm
339Android Developer Verification Rollout Begins Ahead of September EnforcementMar 31, 8:10 pm
340Cisco source code stolen in Trivy-linked dev environment breachMar 31, 6:10 pm
341TrueConf Zero-Day Exploited in Attacks on Southeast Asian Government NetworksMar 31, 5:10 pm
342Vertex AI Vulnerability Exposes Google Cloud Data and Private ArtifactsMar 31, 2:10 pm
343Hackers compromise Axios npm package to drop cross-platform malwareMar 31, 2:10 pm
344How to Categorize AI Agents and Prioritize RiskMar 31, 2:10 pm
345The AI Arms Race – Why Unified Exposure Management Is Becoming a Boardroom PriorityMar 31, 1:10 pm
346Silver Fox Expands Asia Cyber Campaign with AtlasCross RAT and Fake DomainsMar 31, 1:10 pm
347Microsoft fixes Outlook Classic crashes caused by Teams Meeting add-inMar 31, 12:10 pm
348Hacker charged with stealing $53 million from Uranium crypto exchangeMar 31, 10:10 am
349Application Control Bypass for Data Exfiltration, (Tue, Mar 31st)Mar 31, 8:10 am
350Dutch Finance Ministry takes treasury banking portal offline after breachMar 31, 8:10 am
351Axios Supply Chain Attack Pushes Cross-Platform RAT via Compromised npm AccountMar 31, 7:10 am
352CISA orders feds to patch actively exploited Citrix flaw by ThursdayMar 31, 7:10 am
353ISC Stormcast For Tuesday, March 31st, 2026 https://isc.sans.edu/podcastdetail/9872, (Tue, Mar 31st)Mar 31, 2:10 am
354Healthcare tech firm CareCloud says hackers stole patient dataMar 30, 10:10 pm
355New RoadK1ll WebSocket implant used to pivot on breached networksMar 30, 9:10 pm
356OpenAI Patches ChatGPT Data Exfiltration Flaw and Codex GitHub Token VulnerabilityMar 30, 8:10 pm
357Critical Citrix NetScaler memory flaw actively exploited in attacksMar 30, 7:10 pm
358DeepLoad Malware Uses ClickFix and WMI Persistence to Steal Browser CredentialsMar 30, 5:10 pm
3593 SOC Process Fixes That Unlock Tier 1 ProductivityMar 30, 3:10 pm
360⚡ Weekly Recap: Telecom Sleeper Cells, LLM Jailbreaks, Apple Forces U.K. Age Checks and MoreMar 30, 3:10 pm
361How to Evaluate AI SOC Agents: 7 Questions Gartner Says You Should Be AskingMar 30, 3:10 pm
362Apple adds macOS Terminal warning to block ClickFix attacksMar 30, 3:10 pm
363TeamPCP Supply Chain Campaign: Update 004 - Databricks Investigating Alleged Compromise, TeamPCP Runs Dual Ransomware Operations, and AstraZeneca Data Released, (Mon, Mar 30th)Mar 30, 3:10 pm
364The State of Secrets Sprawl 2026: 9 Takeaways for CISOsMar 30, 12:10 pm
365Hackers now exploit critical F5 BIG-IP flaw in attacks, patch nowMar 30, 11:10 am
366Microsoft pulls KB5079391 Windows update over install issuesMar 30, 10:10 am
367Russian CTRL Toolkit Delivered via Malicious LNK Files Hijacks RDP via FRP TunnelsMar 30, 10:10 am
368Three China-Linked Clusters Target Southeast Asian Government in 2025 Cyber CampaignMar 30, 8:10 am
369Critical Fortinet Forticlient EMS flaw now exploited in attacksMar 30, 8:10 am
370European Commission confirms data breach after Europa.eu hackMar 30, 7:10 am
371ISC Stormcast For Monday, March 30th, 2026 https://isc.sans.edu/podcastdetail/9870, (Mon, Mar 30th)Mar 30, 2:10 am
372DShield (Cowrie) Honeypot Stats and When Sessions Disconnect, (Mon, Mar 30th)Mar 30, 12:10 am
373FBI confirms hack of Director Patel's personal email inboxMar 29, 9:10 pm
374File read flaw in Smart Slider plugin impacts 500K WordPress sitesMar 29, 3:10 pm
375Iran-Linked Hackers Breach FBI Director’s Personal Email, Hit Stryker With Wiper AttackMar 28, 5:10 pm
376TeamPCP Supply Chain Campaign: Update 003 - Operational Tempo Shift as Campaign Enters Monetization Phase With No New Compromises in 48 Hours, (Sat, Mar 28th)Mar 28, 4:10 pm
377New Infinity Stealer malware grabs macOS data via ClickFix luresMar 28, 3:10 pm
378Citrix NetScaler Under Active Recon for CVE-2026-3055 (CVSS 9.3) Memory Overread BugMar 28, 10:10 am
379TA446 Deploys DarkSword iOS Exploit Kit in Targeted Spear-Phishing CampaignMar 28, 9:10 am
380CISA Adds CVE-2025-53521 to KEV After Active F5 BIG-IP APM ExploitationMar 28, 8:10 am
381TA446 Deploys Leaked DarkSword iOS Exploit Kit in Targeted Spear-Phishing CampaignMar 28, 8:10 am
382Backdoored Telnyx PyPI package pushes malware hidden in WAV audioMar 27, 10:10 pm
383Apple Sends Lock Screen Alerts to Outdated iPhones Over Active Web-Based ExploitsMar 27, 7:10 pm
384TeamPCP Pushes Malicious Telnyx Versions to PyPI, Hides Stealer in WAV FilesMar 27, 6:10 pm
385European Commission investigating breach after Amazon cloud account hackMar 27, 5:10 pm
386Fake VS Code alerts on GitHub spread malware to developersMar 27, 5:10 pm
387Open VSX Bug Let Malicious VS Code Extensions Bypass Pre-Publish Security ChecksMar 27, 3:10 pm
388TeamPCP Supply Chain Campaign: Update 002 - Telnyx PyPI Compromise, Vect Ransomware Mass Affiliate Program, and First Named Victim Claim, (Fri, Mar 27th)Mar 27, 3:10 pm
389Agentic GRC: Teams Get the Tech. The Mindset Shift Is What's Missing.Mar 27, 2:10 pm
390Bearlyfy Hits Russian Firms with Custom GenieLocker RansomwareMar 27, 1:10 pm
391AitM Phishing Targets TikTok Business Accounts Using Cloudflare Turnstile EvasionMar 27, 1:10 pm
392European Commission investigating breach after Amazon cloud hackMar 27, 1:10 pm
393We Are At WarMar 27, 12:10 pm
394Anti-piracy coalition takes down AnimePlay app with 5 million usersMar 27, 11:10 am
395Windows 11 KB5079391 update rolls out Smart App Control improvementsMar 27, 10:10 am
396Bearlyfy Hits 70+ Russian Firms with Custom GenieLocker RansomwareMar 27, 10:10 am
397LangChain, LangGraph Flaws Expose Files, Secrets, Databases in Widely Used AI FrameworksMar 27, 9:10 am
398Dutch Police discloses security breach after phishing attackMar 27, 9:10 am
399ISC Stormcast For Friday, March 27th, 2026 https://isc.sans.edu/podcastdetail/9868, (Fri, Mar 27th)Mar 27, 2:10 am
400Ajax football club hack exposed fan data, enabled ticket hijackMar 26, 9:10 pm
401CISA: New Langflow flaw actively exploited to hijack AI workflowsMar 26, 8:10 pm
402China-Linked Red Menshen Uses Stealthy BPFDoor Implants to Spy via Telecom NetworksMar 26, 6:10 pm
403TeamPCP Supply Chain Campaign: Update 001 - Checkmarx Scope Wider Than Reported, CISA KEV Entry, and Detection Tools Available, (Thu, Mar 26th)Mar 26, 6:10 pm
404UK sanctions Xinbi marketplace linked to Asian scam centersMar 26, 4:10 pm
405ThreatsDay Bulletin: PQC Push, AI Vuln Hunting, Pirated Traps, Phishing Kits & 20 More StoriesMar 26, 2:10 pm
406Masters of Imitation: How Hackers and Art Forgers Perfect the Art of DeceptionMar 26, 2:10 pm
407Coruna iOS exploit framework linked to Triangulation attacksMar 26, 2:10 pm
408Claude Extension Flaw Enabled Zero-Click XSS Prompt Injection via Any WebsiteMar 26, 2:10 pm
409Inside a Modern Fraud Attack: From Bot Signups to Account TakeoversMar 26, 2:10 pm
410WhatsApp rolls out more AI features, iOS multi-account supportMar 26, 2:10 pm
411TikTok for Business accounts targeted in new phishing campaignMar 26, 2:10 pm
412Russia arrests suspected owner of LeakBase cybercrime forumMar 26, 1:10 pm
413[Webinar] Stop Guessing. Learn to Validate Your Defenses Against Real AttacksMar 26, 12:10 pm
414Coruna iOS Kit Reuses 2023 Triangulation Exploit Code in New Mass AttacksMar 26, 12:10 pm
415Suspected RedLine infostealer malware admin extradited to USMar 26, 12:10 pm
416WebRTC Skimmer Bypasses CSP to Steal Payment Data from E-Commerce SitesMar 26, 9:10 am
417ISC Stormcast For Thursday, March 26th, 2026 https://isc.sans.edu/podcastdetail/9866, (Thu, Mar 26th)Mar 26, 2:10 am
418GitHub adds AI-powered bug detection to expand security coverageMar 26, 12:10 am
419Apple Patches (almost) everything again. March 2026 edition., (Wed, Mar 25th)Mar 25, 10:10 pm
420PolyShell attacks target 56% of all vulnerable Magento storesMar 25, 10:10 pm
421Bubble AI app builder abused to steal Microsoft account credentialsMar 25, 8:10 pm
422New Torg Grabber infostealer malware targets 728 crypto walletsMar 25, 7:10 pm
423LeakBase Admin Arrested in Russia Over Massive Stolen Credential MarketplaceMar 25, 6:10 pm
424Citrix urges admins to patch NetScaler flaws as soon as possibleMar 25, 4:10 pm
425GlassWorm Malware Uses Solana Dead Drops to Deliver RAT and Steal Browser, Crypto DataMar 25, 3:10 pm
426Paid AI Accounts Are Now a Hot Underground CommodityMar 25, 2:10 pm
427Device Code Phishing Hits 340+ Microsoft 365 Orgs Across Five Countries via OAuth AbuseMar 25, 1:10 pm
428Russian Hacker Sentenced to 2 Years for TA551 Botnet-Driven Ransomware AttacksMar 25, 1:10 pm
429The Kill Chain Is Obsolete When Your AI Agent Is the ThreatMar 25, 1:10 pm
430Kali Linux 2026.1 released with 8 new tools, new BackTrack modeMar 25, 1:10 pm
431TP-Link warns users to patch critical router auth bypass flawMar 25, 12:10 pm
432Manager of botnet used in ransomware attacks gets 2 years in prisonMar 25, 9:10 am
433FCC Bans New Foreign-Made Routers Over Supply Chain and Cyber Risk ConcernsMar 25, 8:10 am
434TeamPCP Backdoors LiteLLM Versions 1.82.7–1.82.8 via Trivy CI/CD CompromiseMar 25, 7:10 am
435ISC Stormcast For Wednesday, March 25th, 2026 https://isc.sans.edu/podcastdetail/9864, (Wed, Mar 25th)Mar 25, 2:10 am
436SmartApeSG campaign pushes Remcos RAT, NetSupport RAT, StealC, and Sectop RAT (ArechClient2), (Wed, Mar 25th)Mar 25, 1:10 am
437Popular LiteLLM PyPI package backdoored to steal credentials, auth tokensMar 25, 12:10 am
438Popular LiteLLM PyPI package compromised in TeamPCP supply chain attackMar 24, 11:10 pm
439PTC warns of imminent threat from critical Windchill, FlexPLM RCE bugMar 24, 11:10 pm
440FCC bans new routers made outside the USA over security risksMar 24, 9:10 pm
441TeamPCP Backdoors LiteLLM Versions 1.82.7–1.82.8 Likely via Trivy CI/CD CompromiseMar 24, 8:10 pm
442Tax Search Ads Deliver ScreenConnect Malware Using Huawei Driver to Disable EDRMar 24, 6:10 pm
443Firefox now has a free built-in VPN with 50GB monthly data limitMar 24, 6:10 pm
444Hackers Use Fake Resumes to Steal Enterprise Credentials and Deploy Crypto MinerMar 24, 5:10 pm
445Microsoft fixes bug causing Classic Outlook sync issues with GmailMar 24, 4:10 pm
446Yanluowang ransomware access broker gets 81 months in prisonMar 24, 2:10 pm
447Infinite Campus warns of breach after ShinyHunters claims data theftMar 24, 2:10 pm
448Detecting IP KVMs, (Tue, Mar 24th)Mar 24, 2:10 pm
449HackerOne discloses employee data breach after Navia hackMar 24, 2:10 pm
450Zero Trust: Bridging the Gap Between Authentication and TrustMar 24, 2:10 pm
4515 Learnings from the First-Ever Gartner Market Guide for Guardian AgentsMar 24, 12:10 pm
452Ghost Campaign Uses 7 npm Packages to Steal Crypto Wallets and CredentialsMar 24, 12:10 pm
453Dutch Ministry of Finance discloses breach affecting employeesMar 24, 12:10 pm
454TeamPCP Hacks Checkmarx GitHub Actions Using Stolen CI CredentialsMar 24, 11:10 am
455The Hidden Cost of Cybersecurity Specialization: Losing Foundational SkillsMar 24, 11:10 am
456Citrix Urges Patching Critical NetScaler Flaw Allowing Unauthenticated Data LeaksMar 24, 8:10 am
457U.S. Sentences Russian Hacker to 6.75 Years for Role in $9M Ransomware DamageMar 24, 8:10 am
458ISC Stormcast For Tuesday, March 24th, 2026 https://isc.sans.edu/podcastdetail/9862, (Tue, Mar 24th)Mar 24, 2:10 am
459OpenAI rolls out ChatGPT Library to store your personal filesMar 24, 12:10 am
460Mazda discloses security breach exposing employee and partner dataMar 23, 11:10 pm
461Tycoon2FA phishing platform returns after recent police disruptionMar 23, 10:10 pm
462Tool updates: lots of security and logic fixes, (Mon, Mar 23rd)Mar 23, 9:10 pm
463North Korean Hackers Abuse VS Code Auto-Run Tasks to Deploy StoatWaffle MalwareMar 23, 8:10 pm
464Crunchyroll probes breach after hacker claims to steal 6.8M users' dataMar 23, 8:10 pm
465TeamPCP deploys Iran-targeted wiper in Kubernetes attacksMar 23, 8:10 pm
466Trivy supply-chain attack spreads to Docker, GitHub reposMar 23, 6:10 pm
467‘CanisterWorm’ Springs Wiper Attack Targeting IranMar 23, 4:10 pm
468Varonis Atlas: Securing AI and the Data That Powers ItMar 23, 3:10 pm
469We Found Eight Attack Vectors Inside AWS Bedrock. Here's What Attackers Can Do with ThemMar 23, 2:10 pm
470⚡ Weekly Recap: CI/CD Backdoor, FBI Buys Location Data, WhatsApp Ditches Numbers & MoreMar 23, 2:10 pm
471Microsoft Exchange Online service change causes email access issuesMar 23, 1:10 pm
472Microsoft Warns IRS Phishing Hits 29,000 Users, Deploys RMM MalwareMar 23, 12:10 pm
473FBI warns of Handala hackers using Telegram in malware attacksMar 23, 10:10 am
474Trivy Hack Spreads Infostealer via Docker, Triggers Worm and Kubernetes WiperMar 23, 9:10 am
475CISA orders feds to patch DarkSword iOS flaws exploited attacksMar 23, 9:10 am
476New KB5085516 emergency update fixes Microsoft account sign-inMar 23, 8:10 am
477Hackers Exploit CVE-2025-32975 (CVSS 10.0) to Hijack Unpatched Quest KACE SMA SystemsMar 23, 7:10 am
478ISC Stormcast For Monday, March 23rd, 2026 https://isc.sans.edu/podcastdetail/9860, (Mon, Mar 23rd)Mar 23, 2:10 am
479VoidStealer malware steals Chrome master key via debugger trickMar 22, 3:10 pm
480Trivy vulnerability scanner breach pushed infostealer via GitHub ActionsMar 21, 6:10 pm
481Microsoft Azure Monitor alerts abused for callback phishing attacksMar 21, 5:10 pm
482Microsoft Azure Monitor alerts abused in callback phishing campaignsMar 21, 3:10 pm
483Google adds ‘Advanced Flow’ for safe APK sideloading on AndroidMar 21, 3:10 pm
484FBI Warns Russian Hackers Target Signal, WhatsApp in Mass Phishing AttacksMar 21, 2:10 pm
485Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity ManagerMar 21, 11:10 am
486CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026Mar 21, 9:10 am
487Trivy Supply Chain Attack Triggers Self-Spreading CanisterWorm Across 47 npm PackagesMar 21, 8:10 am
488FBI links Signal phishing attacks to Russian intelligence servicesMar 20, 9:10 pm
489Trivy Security Scanner GitHub Actions Breached, 75 Tags Hijacked to Steal CI/CD SecretsMar 20, 7:10 pm
490Oracle pushes emergency fix for critical Identity Manager RCE flawMar 20, 7:10 pm
491Police take down 373,000 fake CSAM sites in Operation AliceMar 20, 6:10 pm
492Critical Langflow Flaw CVE-2026-33017 Triggers Attacks within 20 Hours of DisclosureMar 20, 5:10 pm
493CISA orders feds to patch max-severity Cisco flaw by SundayMar 20, 3:10 pm
494How CISOs Can Survive the Era of Geopolitical CyberattacksMar 20, 2:10 pm
495Magento PolyShell Flaw Enables Unauthenticated Uploads, RCE and Account TakeoverMar 20, 1:10 pm
496Google Adds 24-Hour Wait for Unverified App Sideloading to Reduce Malware and ScamsMar 20, 12:10 pm
497The Importance of Behavioral Analytics in AI-Enabled Cyber AttacksMar 20, 11:10 am
498Musician admits to $10M streaming royalty fraud using AI botsMar 20, 10:10 am
499GSocket Backdoor Delivered Through Bash Script, (Fri, Mar 20th)Mar 20, 9:10 am
500Microsoft: March Windows updates break Teams, OneDrive sign-insMar 20, 8:10 am
AI Testing

Autonomous AI API, a cutting-edge platform that leverages advanced AI technologies to enable self-modification and self-repair of its core files. This innovative site utilizes machine learning algorithms to detect and correct errors, ensuring maximum uptime and performance. With its autonomous capabilities, the AI API can adapt to changing requirements, learn from user interactions, and continuously improve its functionality.