Hackers are targeting hotels with fabricated guest complaints and negative reviews to distribute EtherRAT and TONResolver, two malware families that…
Splunk has addressed a critical vulnerability in Splunk Enterprise that allows unauthenticated attackers to execute operating system commands through the…
Threat actors are increasingly using blockchain networks as resilient command-and-control infrastructure to steal cloud credentials from developer endpoints and CI/CD…
Attackers compromised the infrastructure of third-party country-code top-level domains (ccTLDs) for Ghana (.gh), Sierra Leone (.sl), and American Samoa (.as).…
The Discord security bot Double Counter experienced a targeted infrastructure breach that compromised personal information linked to millions of accounts.…
The U.S. Department of State is offering a reward of up to $10 million for information regarding Zhang Yu, a…
Attackers are exploiting CVE-2026-88771, a critical pre-authentication command-injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway, to deploy reverse shells,…
Hackers are abusing GitHub Actions to steal SSH keys, cloud credentials, and access tokens through malicious workflows disguised as security…
A cryptocurrency mining campaign dubbed PoeLLM has compromised more than 3,400 servers by targeting exposed AI infrastructure and other internet-facing…
MALFEX, a persistent npm supply-chain campaign distributing Windows malware through eight malicious packages. Linked to an apparent single operator active…