Compromised Ukrainian Websites Deliver Psychedelic Stealer Through Fake Cloudflare Verification
Published on September 24, 2026
Severity High Detail An active ClickFix campaign has compromised legitimate Ukrainian business websites and injected fake Cloudflare verification pages to trick visitors into executing a malicious Windows Installer command. The attack delivers a previously undocumented information stealer known as Psychedelic, which targets browser credentials, account tokens, and cryptocurrency wallet data. The compromised websites belonged to […]
Learn more » Hackers Exploit Check Point VPN RCE and Management Zero-Day in Attacks
Published on September 24, 2026
Detail Check Point has disclosed two critical vulnerabilities, CVE-2026-85102 and CVE-2026-93616, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.8 and can be exploited remotely without authentication. CVE-2026-85102 is an improper certificate-validation flaw affecting Check Point Security Gateway and Spark Firewall VPN deployments. Successful exploitation may allow an unauthenticated attacker to […]
Learn more » Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
Published on September 23, 2026
Severity High Detail Researchers from Volexity have identified a Chinese threat actor tracked as UTA0565 exploiting a Google Chrome and Microsoft Windows zero-day exploit chain through fake websites to deploy a previously undocumented malware family known as CLEANGULP. The activity was detected on September 3 and 4, 2026, targeting Asian government entities. The threat actor […]
Learn more » Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape
Published on September 23, 2026
Severity High Detail Security researchers from DepthFirst disclosed a Linux kernel vulnerability tracked as CVE-2026-80521, which can allow an attacker inside a container to escape the container boundary and obtain root-level privileges on the underlying host. The vulnerability is a use-after-free / race-condition flaw in the AF_UNIX socket subsystem of the Linux kernel. It affects […]
Learn more » SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE
Published on September 22, 2026
Severity High Detail Security researcher Dinh Ho Anh Khoa of Viettel Cyber Security has disclosed technical details for CVE-2026-65660, a Microsoft SharePoint Server vulnerability that was initially described by Microsoft as a spoofing issue but has since been shown to enable authenticated remote code execution (RCE). According to the published research, the flaw exists within […]
Learn more » PAYLOAD Ransomware Hijacks Active Directory Group Policy for Encryptionless Extortion
Published on September 21, 2026
Severity High Detail Researchers from Kaspersky’s Global Emergency Response Team have analyzed a ransomware operation known as PAYLOAD, which demonstrates a shift toward encryptionless extortion by abusing Microsoft Active Directory Group Policy Objects (GPOs) instead of deploying traditional ransomware encryptors. The incident, observed in April 2026 at a manufacturing organization in the Middle East, involved […]
Learn more » MSNightmare Releases New PoC for DoS Vulnerability in Windows Defender
Published on September 21, 2026
Severity Medium Detail Security researcher MSNightmare (Nightmare-Eclipse) has released BigDiskBuster, a proof-of-concept (PoC) tool designed to prevent Microsoft Defender Antivirus from successfully installing platform and security intelligence updates. The project is positioned as a successor to the previously released UnDefend tool and demonstrates how local system resources can be abused to interfere with Defender’s update […]
Learn more » BragJack attacks hijack AI browser agents through malicious extensions
Published on September 20, 2026
SeverityHigh Detail Security researcher Gal Weizman of Forever Security has disclosed a proof-of-concept attack technique named BragJack that can hijack AI assistants integrated into Chromium-based browsers through a single malicious browser extension. The technique was demonstrated against Google Chrome Gemini Live, Perplexity Comet, Microsoft Edge, Opera Neon, and Anthropic Claude in Chrome. The research resulted […]
Learn more » New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution
Published on September 19, 2026
Severity High Detail WordPress has released security updates addressing a vulnerability in its core software that can allow a specially crafted link opened by a logged-in administrator to automatically install and preview a theme from the official WordPress.org directory without the administrator manually clicking the Install button. Security researchers at pwn.ai named the attack chain […]
Learn more » Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer
Published on September 18, 2026
SeverityMedium Detail Security researchers have identified an ongoing malware campaign using SEO-optimized fake GitHub repositories to impersonate LastPass and at least 39 other software companies. The campaign delivers a previously undocumented information-stealing malware named Rapuncel along with a Microsoft-signed kernel driver capable of terminating security software. The campaign targets users searching for legitimate software downloads, […]
Learn more » Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents
Published on September 18, 2026
SeverityMedium Detail Security researchers have disclosed a zero-click remote code execution (RCE) vulnerability, dubbed Plugin4Shell, affecting four major AI coding agents: Anthropic Claude Code, OpenAI Codex, GitHub Copilot, and Google Gemini CLI. The vulnerability affects the way these AI coding agents verify plugins obtained from online repositories. Attackers who control a plugin’s source repository can […]
Learn more » Chinese Hackers Deploy SparroWocky Backdoor in Government Espionage Attacks
Published on September 17, 2026
SeverityMedium Detail The China-linked espionage group FamousSparrow has been using a new modular backdoor named SparroWocky in attacks against government organizations across Latin America. According to ESET researchers, the activity has been ongoing for more than a year, with SparroWocky replacing the group’s previously used SparrowDoor backdoor. SparroWocky was observed targeting government organizations in Argentina, […]
Learn more » Hackers Steal Active Directory Password Hashes Without Attacking Domain Controllers Directly
Published on September 10, 2026
Detail Threat actors are increasingly abusing Active Directory replication functionality to obtain password hashes and other credential material without directly compromising a Domain Controller. This technique, known as DCSync, abuses legitimate Active Directory replication mechanisms to make a compromised system appear as a legitimate replication partner. In a normal Active Directory environment, Domain Controllers synchronize […]
Learn more » Hackers Deploy Linux Rootkit on F5 BIG-IP APM Devices Hiding Web Shell in Memory
Published on September 9, 2026
SeverityMedium Detail Sophos researchers identified a Linux rootkit targeting compromised F5 BIG-IP APM devices that hide a web shell entirely in memory instead of writing the final web shell content to disk. F5 BIG-IP APM is used to enforce access policies for applications, APIs, and data, with deployments commonly found in enterprise, financial, government and […]
Learn more » ChatGPT Flaw Could Let Attackers Steal Gmail Data Across User Accounts
Published on September 9, 2026
SeverityMedium Detail Security researchers from Check Point Research, led by researcher Alexey Bukhteyev, discovered a flaw in ChatGPT’s isolation architecture that could have allowed attackers to access data from a victim’s connected applications and transfer it to a separate ChatGPT account through a hidden cross-account channel. Attackers could embed instructions within a shared ChatGPT conversation, […]
Learn more » Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours
Published on September 8, 2026
SeverityMedium Detail Google Threat Intelligence Group (GTIG) has reported a growing trend of threat actors using AI and autonomous agents to accelerate cyberattacks, including credential theft, vulnerability discovery, malware development, and cloud resource abuse. One financially motivated threat actor, TeamPCP, used an autonomous multi-agent framework to conduct a large-scale credential harvesting campaign, compromising thousands of […]
Learn more » Hackers Build AI Frameworks for Widescale Credential Theft
Published on September 8, 2026
SeverityMedium Detail Threat actors are increasingly moving from AI-powered coding assistants to multi-agent frameworks capable of automating multiple stages of cyberattacks. According to the Google Threat Intelligence Group (GTIG), threat actors have been observed using AI agents to coordinate attack tasks, troubleshoot failures, and adapt their activities with limited human intervention. GTIG observed that threat […]
Learn more » Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
Published on September 7, 2026
SeverityMedium Detail Threat hunters have identified a widespread data theft and extortion campaign targeting Microsoft 365 and other SaaS platforms through fake IT support calls, AitM phishing, MFA theft, and session-token replay. The activity, tracked as PREY-0058, primarily targets executives such as directors and vice presidents. Attackers impersonate internal IT or help desk staff and […]
Learn more » JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies
Published on September 7, 2026
SeverityMedium Detail Cybersecurity researchers have analyzed JSCeal, a sophisticated compiled V8 JavaScript malware capable of credential theft, surveillance, browser data collection, and web traffic interception. First documented by Check Point Research in July 2025, JSCeal has been distributed through malicious advertising campaigns that redirect victims to fake cryptocurrency trading websites impersonating legitimate services such as […]
Learn more » Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
Published on September 6, 2026
Severity Medium Detail A large-scale phishing campaign has been using invisible Unicode characters to disguise financial keywords and evade email security controls. Microsoft observed the campaign sending up to 2.37 million phishing messages per weekday, with activity reaching its highest volume on February 26, 2026. The technique, known as ASCII Smuggling, hides non-rendering Unicode characters […]
Learn more » Ransomware Hackers Use New TukTuk Malware to Steal Credentials and Disable Security Tools
Published on September 6, 2026
Severity Medium Detail Oasis Security researchers have uncovered a previously undocumented remote-control command-and-control (C2) framework dubbed TukTuk, linked to the Gentlemen ransomware operation. Discovered on an attacker-controlled server alongside EDR-disabling tools, DLL sideloading packages, and exfiltrated sensitive data from healthcare and defense-sector entities, TukTuk provides operators with a full-suite administration and surveillance platform. Featuring cross-platform […]
Learn more » APT28-Linked BlueDelta Deploys HOOKEDGE Backdoor in European Espionage Campaigns
Published on September 5, 2026
Severity Medium Detail A new espionage campaign attributed to the Russian-linked BlueDelta group has been targeting government, diplomatic, and defense organizations across Europe with a lightweight Windows backdoor known as HOOKEDGE. The campaign was observed against organizations in Romania, Spain, and Türkiye from late September 2025 through early April 2026. Newer HOOKEDGE variants identified in […]
Learn more » AI Agents Breach Company Network in Under 10 Hours and Steal Root Credentials
Published on September 5, 2026
Severity Medium Detail Palo Alto Networks’ Unit 42 has released an incident response report detailing a breach where a human operator armed with frontier AI models and agentic frameworks compromised an enterprise network and seized root credentials in under 10 hours—a timeline that typically takes human red teams two weeks. The adversary compressed over 50 […]
Learn more » NodeStealer Spyware Expands to Keylogging, Screenshot Capture and Facebook Data Theft
Published on September 4, 2026
Severity Medium Detail A new variant of the Python-based NodeStealer malware has expanded beyond its previous focus on Facebook account theft, adding spyware capabilities such as keylogging, clipboard monitoring, screenshot capture, and extensive Facebook data collection. The variant, identified in August 2026, also expands its ability to steal browser and local data while using a […]
Learn more » Hackers Weaponize ScreenConnect to Spread Worm-Like Malware Across Windows Systems
Published on September 4, 2026
Severity Medium Detail Huntress researchers have uncovered a campaign weaponizing modified ScreenConnect clients to spread malware laterally across Windows networks. Originating from tech-support scams and phishing lures, attackers trick users into installing rogue remote-support clients. Once deployed, the modified client automatically packages and pushes staged payloads to newly connected systems using ScreenConnect’s native file-transfer feature, […]
Learn more » The Gentlemen Ransomware Disables EDR and Backup Services Before Encrypting Networks in Under 24 Hours
Published on September 3, 2026
Severity High Detail Researchers have reported that the Gentlemen ransomware operation, tracked by Sophos as GOLD SHERWOOD, is conducting rapid ransomware attacks that can progress from initial compromise to full network encryption in less than 24 hours. The group operates under a Ransomware-as-a-Service (RaaS) model, allowing affiliates to conduct attacks using the ransomware platform against […]
Learn more » Fake IT Support Hackers Abuse Microsoft Teams and Quick Assist to Deploy Reverse Shell
Published on September 2, 2026
Severity High Detail Threat actors are using fake IT support requests through external Microsoft Teams chats to trick employees into granting remote access via Microsoft’s legitimate Quick Assist application. Once access is granted, attackers deploy a multi-stage reverse shell designed to blend into normal Windows activity and evade traditional security controls. Researchers Ofek Lahiani and […]
Learn more » New Windows Backdoor Stays Completely Silent Until Hackers Send a Secret Trigger
Published on September 1, 2026
Severity High Detail Security researchers at PolySwarm have identified a newly discovered Windows backdoor named SLEEPWALKER, designed to remain dormant on compromised systems until it receives a specially crafted network packet from an operator. SLEEPWALKER does not require routine outbound beaconing. Instead, it places available network interfaces into promiscuous mode and continuously monitors for traffic […]
Learn more » Public PoC Released for Microsoft Exchange Server Pre-auth RCE Vulnerability
Published on September 1, 2026
Severity High Detail A public proof-of-concept (PoC) exploit has been released for CVE-2026-62911, a Microsoft Exchange Server vulnerability associated with an authentication capture-and-replay weakness. While Microsoft classifies the vulnerability as an elevation-of-privilege issue, publicly available technical research describes an attack chain that can potentially result in unauthenticated remote code execution and SYSTEM-level compromise on vulnerable […]
Learn more » China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs
Published on August 31, 2026
Severity High Detail Sygnia researchers have disclosed details of an ongoing China-linked cyber espionage campaign tracked as Fire Ant, which has expanded from VMware virtualization environments to compromise Cisco IOS XR routers, TACACS servers, and Linux management hosts supporting high-value networks. The activity overlaps significantly with the tactics publicly attributed to UNC3886, a China-nexus espionage group known for targeting […]
Learn more » ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions
Published on August 31, 2026
Severity Medium Detail Kaspersky researchers have identified a campaign attributed to the China-linked threat actor Silver Fox, distributing the ValleyRAT backdoor, also tracked as Winos 4.0, disguised as a legitimate signed Chinese adware application. The attackers modified QN Wallpaper, a genuine Chinese desktop-wallpaper application that normally displays advertisements and bundles partner software. The malicious version abuses the application’s trusted […]
Learn more » Chinese Hackers Deploy PackClient RAT via Tax-Themed Phishing Attacks to Steal Data
Published on August 30, 2026
Severity Medium Detail Proofpoint threat researchers have disclosed details regarding PackClient, a commercial remote access trojan (RAT) framework deployed by Chinese-speaking threat actor TA4922. Marketed on Chinese-language Telegram channels, PackClient provides extensive initial-access and post-exploitation capabilities, including credential theft, surveillance, data exfiltration, and lateral movement. In campaigns observed between May and July 2026, TA4922 targeted […]
Learn more » Chrome Web Store extensions caught stealing crypto, browser data
Published on August 30, 2026
Severity Medium Detail Security researchers have identified 19 malicious extensions for Google Chrome and Microsoft Edge that deliver an extensible malware framework capable of stealing cryptocurrency, browser data, credentials, and session information. The campaign was uncovered by application security company Socket and may have been active since early 2024. The malicious extensions contain different modules […]
Learn more » Go Loader Uses Anti-Sandbox Techniques and SNOWLIGHT to Deliver Fileless VShell RAT
Published on August 29, 2026
Severity Medium Detail A Windows malware campaign is using a fake graduate-school resume to deliver the SNOWLIGHT stager and a fileless VShell remote-access trojan (RAT). The campaign appears to target users associated with Chinese academic and technical research environments. The attack relies on a custom 32-bit Go-based loader that checks the execution environment for signs […]
Learn more » Hackers Use Fake Cloudflare CAPTCHA to Deploy TerminalFix Reverse Tunnel
Published on August 29, 2026
Severity Medium Detail Microsoft has documented TerminalFix, a social engineering campaign that tricks users into executing malicious PowerShell commands via fake Cloudflare CAPTCHA prompts. Moving beyond basic ClickFix tactics, TerminalFix directs victims to paste code directly into Windows Terminal. By combining DLL sideloading, image steganography, and an embedded Python reverse tunnel, the campaign converts compromised […]
Learn more » Hackers Abuse Active Directory SPN Misconfigurations for Stealthy Kerberoasting Attacks
Published on August 28, 2026
Severity Medium Detail Security researchers have identified a technique known as “Ghost SPN”, which abuses Active Directory Service Principal Name (SPN) misconfigurations to conduct stealthy Kerberoasting attacks. The technique allows threat actors with delegated directory permissions to temporarily assign an SPN to a standard user account, request a Kerberos service ticket, and remove the SPN […]
Learn more » Ransomware Hacker Uses AI to Plan Cyberattacks Against More Than 20 Organizations
Published on August 27, 2026
Severity High Detail Researchers have uncovered an Aurora ransomware affiliate that leveraged an AI coding assistant to plan and refine cyberattacks against more than 20 organizations across nine countries between April and July 2026. The activity was exposed through a misconfigured server that provided investigators with visibility into the attacker’s tools, command history, credentials, AI […]
Learn more » Hackers Abuse npm Mirrors to Host Phishing Redirect Pages
Published on August 26, 2026
Severity Medium Detail Threat actors are abusing the npm package ecosystem and third-party npm mirrors to host malicious HTML pages that impersonate Cloudflare CAPTCHA verification screens and redirect users to attacker-controlled destinations. At the time of analysis, some redirect chains were observed leading to legitimate websites; however, researchers noted that the mechanism could be reconfigured […]
Learn more » SynkLoader Mimic as IT Support Personnel Attacking Users Via Microsoft Teams
Published on August 25, 2026
Severity Medium Detail Threat actors are increasingly abusing trusted enterprise collaboration platforms to bypass traditional email-centric security perimeters. ReliaQuest Threat Research recently identified a campaign deploying SynkLoader, a hash-gated PowerShell loader, using targeted Microsoft Teams impersonation and voice phishing (vishing). Operating under the guise of internal IT support, attackers deceive end users into executing a […]
Learn more » OpenClaw-Based Multi-Agent AI Framework Compromises Government Systems and Exfiltrates Thousands of Records
Published on August 25, 2026
Severity Medium Detail Cybersecurity researchers have uncovered a multi-agent AI framework that was used to compromise government organizations in Asia, crack employee credentials, and exfiltrate thousands of personnel records. The framework utilized Hermes and OpenClaw agents, according to Dream Research Labs. Researchers identified a 160 MB operational archive containing 1,395 files generated over approximately four […]
Learn more » Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor
Published on August 24, 2026
Severity Medium Detail Cybersecurity researchers have identified a cyber espionage campaign targeting organizations in Myanmar using fake graduation ceremony invitations to deliver a Go-based backdoor known as QUICAgent. The campaign, tracked as Operation QUICSILVER, has targeted government and information technology organizations, according to Seqrite Labs. The activity is assessed with moderate confidence to be linked […]
Learn more » ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud
Published on August 24, 2026
Severity Medium Detail Cybersecurity researchers have identified an updated version of ToxicPanda (TgToxic), an Android banking trojan with significantly expanded capabilities. The new variant contains 167 remote commands and has broadened its financial targeting to more than 140 banking and cryptocurrency applications, with overlay-based credential theft targeting 349 financial institutions across 16 countries. The malware […]
Learn more » StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data
Published on August 23, 2026
Severity Medium Detail StopAndProtect is a large-scale cybercrime campaign that has compromised thousands of vulnerable WordPress websites to distribute malware, steal data, and support ransomware operations. The campaign primarily targets Windows users through fake CAPTCHA pages and ClickFix social engineering. How? The attack begins with threat actors compromising vulnerable WordPress websites, many of which are […]
Learn more » Chinese Hacker Uses DeepSeek and Hermes Agent to Launch Autonomous Cyberattacks
Published on August 23, 2026
SeverityHigh Detail A Chinese-speaking threat actor has been observed using DeepSeek through the Hermes Agent framework to automate reconnaissance, vulnerability research, exploit acquisition and attack attempts against internet-facing infrastructure. According to Unit 42, the actor tracked under the aliases knaithe and KnYuan built an AI-assisted offensive environment combining DeepSeek’s reasoning capabilities with Hermes Agent’s terminal […]
Learn more » Trojanized npm Packages Deliver RedC2 4.0 Linux Backdoor with AI-Assisted
Published on August 22, 2026
SeverityHigh Detail Cybersecurity researchers have identified multiple trojanized npm packages that appear to provide legitimate calendar and streak utilities but are designed to secretly deliver an AI-powered Linux implant known as RedC2 4.0. When one of the affected modules is loaded, it locates a bundled binary, makes it executable, and launches it as a detached […]
Learn more » New SynkLoader Malware Distributed Through Microsoft Teams Phishing Campaigns
Published on August 22, 2026
SeverityMedium Detail A previously unknown malware family called SynkLoader is being distributed through Microsoft Teams phishing campaigns to steal Windows credentials using a fake lock screen. The attackers impersonate the target organization’s IT help desk, a tactic that has been increasingly observed in multi-stage attacks. Victims are directed to install a fake “PowerShell Cleaner” MSI […]
Learn more » Hackers Abuse FTP Server Banners to Deliver New Windows Malware
Published on August 21, 2026
SeverityMedium Detail Threat actors are abusing FTP server banners to conceal commands used to deliver two previously undocumented remote access trojans (RATs), named E4del and PINHOLE. MalwareHunterTeam observed the technique in July 2026 during an attack involving Windows shortcut files (.LNK) and FTP server banners used as dead-drop resolvers (DDR) to retrieve commands. SOCRadar subsequently […]
Learn more » Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices
Published on August 20, 2026
SeverityHigh Detail A new Android malware family named Manic has been observed targeting banking, cryptocurrency, government identity, messaging, and military-focused applications. The malware combines banking trojan and spyware capabilities with extensive device-control and surveillance features. Manic has been active since at least February 2026 and is distributed through phishing websites and malicious dropper applications disguised […]
Learn more » New CRLF Desync Attack Lets Hackers Steal HTTPOnly Cookies and Hijack Accounts
Published on August 20, 2026
Severity High Detail Security researchers Tom Stacey from PortSwigger and Tobia Righi from TurtleSec have identified a new class of HTTP request smuggling attacks called CRLF-Powered Desync Attacks. The technique abuses HTTP header injection weaknesses that can escalate into serious attacks, including account takeover, HTTPOnly cookie theft, response queue poisoning, and potentially self-propagating desync worms. […]
Learn more » Fake Gemini installer delivers Vidar infostealer via Google Colab lure
Published on August 20, 2026
SeverityHigh Detail Security researchers have identified a campaign using a fake Google Gemini installer to deliver the Vidar information-stealing malware to Windows users. The campaign abuses trusted Google services and AI-related search interest to make the malicious software appear legitimate. The activity was observed on a company network in the EMEA region. The attackers used […]
Learn more »