A malicious RubyGems campaign has turned seemingly useful developer packages into tools for hidden cryptocurrency mining. The poisoned packages can consume a machine’s computing power, slow down development work, and quietly generate Monero for the attackers. The campaign also goes…
Category: Cyber Security News
Hackers Allegedly Claim Breach of Decathlon Customer Database With 160 Million Records
A threat actor is allegedly claiming to possess and sell a Decathlon customer database containing approximately 160 million records. The database was advertised on a cybercrime forum, where the seller stated that payment would be accepted through cryptocurrency. The alleged…
Chaos Ransomware Turns Your Chrome and Edge Web Browser Into an Invisible Malware Command Channel
Chaos ransomware has introduced a new way to hide attacker activity inside everyday web browsing. The group’s msaRAT remote-access tool turns Chrome or Microsoft Edge into a covert channel for receiving commands and moving data. This approach mirrors the stealth…
Hackers Abuse Notepad++ Plugins to Compromise Your System Silently
A stealthy new campaign in which the UAC-0099 threat cluster hijacks a legitimate Notepad++ plugin to quietly plant malware on victim machines, marking a significant evolution in the group’s tactics since mid-summer 2026. Uncovered by Ukraine’s CERT-UA, the infection begins…
Fake Bahrain Civil Defense App Deploys Android RAT to Steal PINs, OTPs, and Banking Credentials
A sophisticated Android malware campaign is exploiting heightened geopolitical tensions in the Gulf region by masquerading as an official Bahrain Civil Defense emergency alert application. Security researchers have uncovered a fake “BH Alert” app that delivers a multi-stage Remote Access…
Hackers Abuse GitHub Actions to Exploit cPanel and WHM Servers and Steal Cloud Credentials
A large-scale cyber campaign is abusing GitHub Actions to turn trusted open source projects into weapons against web hosting servers. Attackers plant malicious workflow files inside compromised repositories and use free GitHub compute power to scan the public internet for…
Exim Directory Traversal Vulnerability Enables Privilege Escalation Attacks
A newly disclosed high-severity vulnerability in the Exim mail transfer agent allows local attackers to exploit a directory traversal flaw to escalate privileges on affected systems. Tracked as EXIM-Security-2026-06-22.1 and assigned GCVE-25-2026-07-45-1, the issue impacts Exim versions from 4.88 through…
Next.js Patches Nine Security Flaws Enabling SSRF, Authentication Bypass, and DoS Attacks
Vercel has disclosed and patched nine security vulnerabilities in Next.js, the widely used React framework, addressing flaws that could enable server-side request forgery (SSRF), middleware authentication bypass, denial-of-service (DoS) attacks, and sensitive data exposure. All nine advisories were published two…
Hackers’ OPSEC Mistake Exposed a Global Espionage Campaign and Its New TriBack Malware
A simple mistake by cyber spies has pulled back the curtain on a wide ranging espionage effort. It reached hospitals, government offices, and schools across several continents in early 2026. In mid April, operators left a staging server open with…
TrickBot Turns Ordinary DNS Traffic Into a Hidden Channel for Malware Commands
TrickBot has quietly evolved into a more covert threat by turning everyday DNS traffic into a stealth channel for malware commands, making its activity harder to spot on busy enterprise networks. In a recent campaign, a new variant was seen…
Microsoft Defender for Office 365 Adds New Prompt Injection Protection
Microsoft has introduced a new capability in Defender for Office 365 to protect against prompt injection attacks, which target AI-powered email workflows, such as Microsoft 365 Copilot. This update reflects the evolving threat landscape, where attackers increasingly attempt to manipulate…
Ubuntu snap-confine Race Condition Enables Local Privilege Escalation to Root
Ubuntu systems are at risk from a new local privilege escalation vulnerability in snap-confine, which could enable any local user to gain full root access on certain desktop installations. Qualys researchers discovered a race condition in snap-confine, the helper program…
Google Launches CodeMender AI Agent to Find, Validate, and Patch Vulnerabilities
Google has introduced CodeMender, a new AI-powered code security agent designed to find, validate automatically, and patch vulnerabilities at machine speed, as organizations face a surge in AI-driven cyber threats targeting software supply chains. The launch marks a shift from…
New Dolphin X Malware Steals Credentials From 300+ Apps and Profiles Victims With AI
A newly identified Windows malware called Dolphin X is raising concerns because it can steal far more than browser passwords. The tool is marketed to criminals as both an information stealer and a remote access trojan, giving operators a broad…
Hackers Breach South Korea’s Diplomatic Academy and Expose Foreign Ministry Staff Data
South Korea’s diplomatic community is facing a serious security incident after hackers breached the Korea National Diplomatic Academy’s online education system and accessed data on Ministry of Foreign Affairs staff and overseas personnel. The attack quietly unfolded over many months,…
CISA Warns of Check Point Authentication Vulnerability Actively Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning about a critical authentication vulnerability in Check Point SmartConsole that is actively being exploited in the wild, prompting organizations to take immediate defensive action. Tracked as CVE-2026-16232,…
CISA Warns Iran-Linked Hackers Exploit Rockwell PLCs to Disrupt U.S. Critical Infrastructure
Iran-linked hackers are targeting internet-connected industrial controllers used across U.S. critical infrastructure. The campaign has disrupted programmable logic controllers, or PLCs, in government, water, wastewater, and energy facilities. Some victims suffered operational disruption and financial losses after attackers altered the…
Chick-fil-A Urges Customers to Change Chick-fil-A One Passwords After Unauthorized Access
Chick-fil-A has warned customers to update their Chick-fil-A One passwords after detecting unauthorized access to a subset of loyalty accounts during a credential stuffing attack in June 2026. After conducting an internal investigation, the company confirmed that attackers used an…
July 2026 InfraTrust Report Flags 26 Unauthenticated Vulnerabilities and Exploited SonicWall Flaws
A new infrastructure security review has exposed a busy month for defenders. Fourteen infrastructure vendors issued 61 relevant advisories worldwide during the 30 days ending July 17, including 26 flaws that attackers can reach remotely without logging in. Six advisories…
Bluetooth Vulnerability Exposes 2.2 Million Cars to Remote Unlock and Immobilization Attacks
A recently disclosed Bluetooth vulnerability in the aftermarket KARR Security System exposes approximately 2.2 million vehicles to remote attacks that could allow unauthorized door unlocking, alarm control, and vehicle immobilization. This issue, uncovered by researchers at the University of California,…
