-
Threat actors are actively exploiting two newly disclosed remote code execution vulnerabilities affecting Langflow and Ruby on Rails. These campaigns focus on cloud credential theft, host reconnaissance, and the establishment of command-and-control (C2…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A coordinated social-engineering campaign dubbed Spring Ring used external Microsoft Teams accounts to impersonate corporate IT help desk staff and target more than 150 employees across at least 10 organizations between January and April 2026. The oper…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Five Venezuelan nationals have pleaded guilty in a federal case involving attempts to deploy ATM jackpotting malware against cash machines in Kansas. This case highlights a growing cyber-physical threat targeting financial institutions across the Unite…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Threat actors are abusing legitimate ChatGPT shared-conversation URLs to host social-engineering lures that steer victims into a ClickFix-style infection chain, ultimately delivering a NetSupport remote-access tool (RAT). The observed chain begins with…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A sophisticated cryptocurrency-focused information stealer that hides its malicious logic inside compiled V8 JavaScript bytecode. JSCeal, also tracked by some vendors as WEEVILPROXY or MeadowLocust, is not delivered as readable JavaScript. Instead, ope…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Security researchers have issued warnings that attackers are actively exploiting a critical authentication bypass vulnerability in JFrog Artifactory, tracked as CVE-2026-82329. This vulnerability allows the generation of administrator-level access toke…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Boston Scientific is working to restore its manufacturing, order processing, and distribution capabilities following a cybersecurity incident that caused a network outage across certain internal IT systems. In an August 30 update, the medical device ma…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
BraZetsu, a Python-based Windows malware framework allegedly operated by the Brazilian threat actor Exilware to identify, profile, and monetize compromised corporate systems. Rather than behaving like a conventional infostealer, BraZetsu appears design…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Threat actors are impersonating AI web crawlers from organizations such as OpenAI, Anthropic, DeepSeek, Google, Perplexity, and Amazon to scan internet-facing servers for exposed secrets, according to a GreyNoise research report published on August 28,…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly analyzed Windows backdoor named SLEEPWALKER uses a passive command-and-control model designed to evade conventional beaconing-based detections. Raw-packet activation, DNS-based tasking support, VMware VMCI communications, named-pipe capabilitie…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


