-
Chinese-speaking threat actors are continuing to rely on Noodle RAT, a cross-platform remote access trojan designed to maintain covert access to compromised Windows workstations and Linux servers. Also tracked as ANGRYREBEL and Nood RAT, the malware ha…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A large-scale SMS phishing campaign linked to the Smishing Triad is using a sophisticated phishing kit dubbed JWR to harvest payment-card data, one-time passwords, online-banking credentials, identity information, and digital-wallet logins. Group-IB at…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
CenterPoint Energy has confirmed that an unauthorized third party accessed personal information belonging to some of its customers by compromising one of the utility provider’s external systems. The Houston-based energy company disclosed the incident i…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Acronis has released an urgent security update for a high-severity local privilege escalation vulnerability affecting its Backup plugin for cPanel & WHM on Linux. The company confirmed that attackers have already exploited this flaw in limited, tar…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly identified phishing operation tracked as PAPERMILL is abusing a legitimately signed Notepad++ executable, DLL sideloading, and layered in-memory loaders to install VenomRAT on Windows systems. The campaign uses tax-audit lures aimed at Indian r…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A public proof-of-concept exploit has been released for CVE-2026-23980, a SQL injection vulnerability affecting Apache Superset installations running versions earlier than 6.0.0. The Apache Superset project disclosed this issue in February. It classifi…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
China-aligned threat actors are concealing the PeckBirdy command-and-control framework inside low-quality Chinese-language casino and adult websites. Exploiting a vast and routinely ignored category of internet infrastructure to blend malware traffic i…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A shared message board turned isolated AI agents into an effective offensive collective during OpenAI’s July 2026 ExploitGym evaluations, enabling roughly 1,200 agents to exchange more than 70,000 messages and files. About 700 eventually participated i…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The National Institute of Standards and Technology (NIST) has published new implementation guidance to safeguard identity tokens, access tokens, and assertions used in single sign-on, cloud federation, and application programming interface (API) enviro…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Iranian state-linked cyber actors are using fake AI applications, antivirus tools and even fabricated MRI scan results to deliver CHOSEN BRICK, a Windows-focused spyware family designed to surveil dissidents, activists and journalists. A joint advisory…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


