-
Bluekit Phishing Kit is a new PhaaS tool that targets major platforms, using AiTM techniques to steal session data and bypass MFA protections.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Cybersecurity researchers are sounding the alarm about a new supply chain attack campaign targeting SAP-related npm Packages with credential-stealing malware. According to reports from Aikido Security, SafeDep, Socket, StepSecurity, and Google-owned Wiz, the campaign – calling itself the mini Shai-Hulud – has affected the following packages associated with SAP’s JavaScript and cloud application
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A hacker using the alias “Xorcat” claims to have breached Polymarket using API flaws, but research suggests the leak could be just data scraping incident.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Lt. Gen. Douglas Schiess is likely to be nominated by President Donald Trump to serve as the Space Force’s next top uniformed leader, Defense One has learned.
Schiess currently serves as the deputy chief of space operations for operations at the Pentagon. If confirmed by the Senate, the three-star general will replace Gen. Chance Saltzman—who has served as the service’s top military leader since September 2022. Two defense insiders confirmed to Defense One that Schiess was the likely nominee.
A Space Force spokesperson declined to comment on the presumptive nominee. White House officials did not immediately return a request for comment on Wednesday afternoon.
If confirmed, Schiess would be the third Chief of Space Operations in the service’s six-year history. Earlier this month, Saltzman addressed reporters and attendees at the Space Symposium conference in Colorado and acknowledged it would likely be one of his last public engagements ahead of his retirement, which is expected later this year.
Like both of his predecessors, Scheiss is a career space operator, as distinct from an acquisitions specialist—the service’s other large officer community..
Schiess served as the Space Forces–Space commander and U.S. Space Command’s vice commander, according to his biography. Earlier in his career, he directed the space forces component of Air Forces Central Command at Al Udeid Air Base in Qatar and commanded the 45th Operations Group at Cape Canaveral in Florida. Like Saltzman, he began his career as an Air Force intercontinental ballistic missile operator.
Saltzman, during his time as the service’s chief of space operations, encouraged the Space Force to embrace a warfighting identity and pushed to expand its mission sets. Under his tenure, the Space Force budget grew from $26 billion to a record-breaking $72 billion funding request this year. It’s also expanded to nearly 11,000 service members today.
“I'm not sad,” Saltzman told reporters. “This is so exciting…We're starting to marry up resourcing and processes and guardian talent; the joint force is recognizing how important this is. I think our messaging is getting through.” The Space Force also received some of its first public recognition from the top Pentagon brass for providing necessary support for joint operations in Iran and Venezuela.
]]>¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Cybersecurity researchers have discovered malicious code in an npm package after a malicious package as a dependency to the project by Anthropic’s Claude Opus large language model (LLM). The package in question is “@validate-sdk/v2,” which is listed on npm as a utility software development kit (SDK) for hashing, validation, encoding/decoding, and secure random generation. However, its real
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Lazarus Group is abusing “ClickFix” social engineering to push a new macOS malware kit dubbed “Mach-O Man,” giving attackers a direct path to credentials, Keychain secrets, and corporate access in fintech and crypto environments. This research is authored by Mauro Eldritch, an offensive security expert and founder of BCA LTD, a company focused on threat intelligence and […]
The post Lazarus Targets macOS Users With New “Mach-O Man” Malware Kit appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
This week in cybersecurity from the editors at Cybercrime Magazine
Sausalito, Calif. – Apr. 29, 2026Executive risk management has evolved far beyond physical protection and travel security. Today, the most pressing threats to leadership come from digital exposure, where publicly available data creates direct pathways for threat actors to exploit, according to VanishID, developers of agentic AI-powered digital executive protection.
A single executive’s digital footprint can influence not only their personal safety but also the financial stability, operational continuity, and reputation of the entire organization.
As impersonation attacks, financial fraud, and targeted social engineering continue to rise, executives have become high-value entry points. Their visibility, authority, and access make them uniquely vulnerable.
For modern enterprises, executive risk is no longer a niche concern. It is a strategic priority that demands structured, ongoing digital protection at scale.
Last year, VanishID announced the launch of a new CEO Protection offering designed specifically to protect Chief Executives and their families from the unique digital privacy and security risks.
The company also announced a $10 million investment led by Dell Technologies Capital and joined by Mark McLaughlin, former CEO and Chairman of Palo Alto Networks, with participation from Crosslink Capital, Rally Ventures, Energy Impact Partners, Bright Pixel, and LockStep Ventures.
Since then, VanishID, trusted by more than 100 client organizations, has garnered interest around its digital executive protection, as well as solutions for workforce protection, family office protection, and public sector protection.
Matt Polak, founder and CEO at VanishID, explains why digital executive protection is critically important to organizations in a new 2-minute video produced by Cybercrime Magazine.
Cybercrime Magazine is Page ONE for Cybersecurity. Go to any of our sections to read the latest:
- SCAM. The latest schemes, frauds, and social engineering attacks being launched on consumers globally.
- NEWS. Breaking coverage on cyberattacks and data breaches, and the most recent privacy and security stories.
- HACK. Another organization gets hacked every day. We tell you who, what, where, when, and why.
- VC. Cybersecurity venture capital deal flow with the latest investment activity from various sources around the world.
- M&A. Cybersecurity mergers and acquisitions including big tech, pure cyber, product vendors and professional services.
- BLOG. What’s happening at Cybercrime Magazine. Plus the stories that don’t make headlines (but maybe they should).
- PRESS. Cybersecurity industry news and press releases in real time from the editors at Business Wire.
- PODCAST. New episodes daily on the Cybercrime Magazine Podcast feature victims, law enforcement, vendors, and cybersecurity experts.
- RADIO. Tune into WCYB Digital Radio at Cybercrime.Radio, the first and only round-the-clock internet radio station devoted to cybersecurity.
Contact us to send story tips, feedback and suggestions, and for sponsorship opportunities and custom media productions.
The post VanishID: Agentic AI-Powered Cybersecurity Protects C-Suite Executives appeared first on Cybercrime Magazine.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
WILMINGTON, Delaware, 29th April 2026, CyberNewswire
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Security researchers at LayerX have uncovered a high-severity vulnerability in the popular AI-powered development environment, Cursor. Dubbed “CursorJacking,” this flaw carries a CVSS score of 8.2 and exposes developers to immediate credential theft. Any installed extension can silently access a user’s API keys and session tokens without requiring special permissions or user interaction. Standard security […]
The post Cursor AI Extension Flaw Exposes Developer Tokens to Credential Theft appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
In February 2026, researchers uncovered a shift that completely changed the game: threat actors are now using custom AI setups to automate attacks directly into the kill chain. We aren’t just talking about AI writing better phishing emails anymore. We’re talking about autonomous agents mapping Active Directory and seizing Domain Admin credentials in minutes. The problem? Most defensive workflows
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


