-
Corporate executives’ Social Security numbers (SSNs) are being sold on dark web identity marketplaces for as little as $0.25 per record. This creates a low-cost entry point for fraudsters looking to commit executive impersonation, business email …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A Windows malware campaign disguised as a graduate-school resume has been observed delivering the SNOWLIGHT stager and a fileless VShell remote-access trojan (RAT) to targets likely associated with Chinese academic and technical research environments. …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A cache of leaked internal records has exposed what appears to be a structured Russian military cyber-operator pipeline embedded inside Bauman Moscow State Technical University. The documents indicate that the university’s concealed Department No. 4 tr…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Dark Caracal-linked operators are using Ethereum smart contracts as a resilient fallback mechanism for a newly identified Go-based malware framework called GoCaracal. Arctic Wolf Labs uncovered the framework while investigating a targeted intrusion in …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
OpenAI has issued a warning that AI-enabled cyberattacks could become significantly more widespread and sophisticated within months. The organization urges industries, governments, technology providers, and critical infrastructure operators to work tog…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
PaperCut has issued an urgent security advisory after confirming the active exploitation of a vulnerability affecting all versions of its PaperCut NG and PaperCut MF print-management servers. Organizations with Application Servers exposed to the intern…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A critical vulnerability in cPanel/WHM could allow authenticated attackers to gain root-level code execution and take full control of vulnerable hosting servers, according to a security advisory published by cPanel on August 27, 2026. The vulnerability…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A common configuration error in Active Directory is assigning Service Principal Names (SPNs) to ordinary user accounts. This mistake can create an overlooked path for Kerberoasting attacks, allowing adversaries to obtain credentials without needing pri…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
AWS security teams can improve detection of multi-stage intrusions by correlating API activity in CloudTrail with network metadata in VPC Flow Logs and DNS activity in Route 53 Resolver query logs. The approach turns isolated alerts into an attack narr…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Suspected Chinese-speaking operators exploited the critical ownCloud flaw CVE-2023-49105 to steal nuclear material records, research reactor data, personnel files, and encryption key material from a Philippine nuclear research organization. Hunt.io dis…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


