-
The Core Werewolf espionage cluster has introduced a previously undocumented remote access trojan dubbed CoreRAT in targeted attacks on Russian public-sector bodies and defense-industry organizations. The shift is notable because Core Werewolf, previou…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
WhatsApp has announced that over one billion people now use passkeys to secure their accounts, enhancing phishing-resistant authentication across one of the world’s largest messaging platforms. This update, revealed on August 25, introduces suppo…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
ToxNetV2, an AArch64 Linux peer-to-peer botnet, integrates a large language model into its controller workflow to turn botnet and host telemetry into proposed operational actions. The implementation connects NVIDIA NIM-hosted z-ai/glm-5.2 model output …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A multi-agent AI framework, utilizing Hermes and OpenClaw agents, was employed to compromise government entities in Asia, stealing thousands of personnel records, cracking employee credentials, and establishing persistent access to state infrastructure…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A cluster of fraudulent websites impersonating Microsoft is using fake “security scans” to pressure victims into uninstalling antivirus products, disclosing personal and banking information, and granting remote access to their computers. The sites, bra…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
ASOS has started notifying affected customers in the U.S. after detecting unauthorized access to accounts linked to login credentials obtained from outside its systems. According to a breach notification issued by ASOS US Sales LLC, unusual activity wa…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Zscaler has addressed several vulnerabilities in its Client Connector endpoint application that could allow an unauthenticated, unprivileged attacker to execute arbitrary code within the product’s context. This vulnerability, tracked as CVE-2026-59568,…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Broadcom has disclosed 91 Common Vulnerabilities and Exposures (CVEs) affecting the Spring Framework and related projects, triggering a software supply chain remediation event that Sonatype estimates impacts 209,569 software components. The advisory is…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
PavinLoader, a multi-stage .NET malware loader, operating across ClickFix, fake software-download, and malicious game campaigns. The activity shows how attackers are moving beyond a single delivery vector. A victim may be lured to a fake Cloudflare or …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Anthropic has expanded Claude Enterprise’s Model Context Protocol (MCP) security capabilities with enterprise-managed authorization, allowing organizations to centrally provision and govern connector access through their identity provider (IdP). The fe…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


