-
ChocoShell is a PowerShell-based infostealer used in Microsoft’s newly disclosed “CaptiveCrunch” campaign to steal Microsoft 365 tokens, browser sessions, and Wi‑Fi credentials from travelers connecting to compromised hospitality networks worldwide. Th…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
NullReceiver is a lean, stealth-focused evolution of DPRK’s blockchain C2 tradecraft that hides a reusable attacker wallet behind ordinary-looking Ethereum transfers, while still exposing just enough bytes to resolve a live command server. Two trojaniz…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Telegram Messenger was temporarily removed from Apple’s App Store in several countries late Monday, preventing new users from downloading the messaging platform and blocking reinstalls for users who had previously deleted the app. This global d…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Thermo Fisher Scientific has released security updates for a high-severity flaw in its Applied Biosystems Human Identification (HID) software. This vulnerability could allow nearly undetectable manipulation of DNA test data files before analysis. The i…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Security researchers have revealed a series of attacks that could enable malware on a compromised Windows device to hijack accounts protected by Google-synced passkeys. This can occur without stealing a password, capturing a fingerprint, or requiring t…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
TP-Link has announced a high-severity security vulnerability in its TL-WR940N v6 wireless router that could allow an unauthenticated remote attacker to execute arbitrary code and potentially take full control of the affected device. This vulnerability …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
North Korea’s national antivirus appears to have quietly pivoted to ClamAV’s open‑source engine, recompiled it, and shipped it under four different domestic product names underscoring Pyongyang’s reliance on foreign code to secure tightly controlled ne…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
N-able has issued an urgent hotfix to address a critical authentication-bypass vulnerability in its N-central remote monitoring and management (RMM) platform, following confirmation of active exploitation. This vulnerability, tracked as CVE-2026-18577,…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A new Metasploit Framework module has been submitted for review, targeting the critical Ruby on Rails Active Storage vulnerability, tracked as CVE-2026-66066. This submission poses an increased risk to applications that utilize the Vips image-processin…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
CareCloud has reported a data security incident involving unauthorized access to its Amazon Web Services (AWS) environment that supports the CareCloud Health division. This incident disrupted one of the company’s electronic health record (EHR) systems….
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


