Social engineering, compromised software updates, insider misuse, and AI-assisted fraud continue to create opportunities for unauthorized access, data…
Category: EN
Smishing Hackers Can Watch Every Keystroke as Victims Enter Card Details and OTPs
A new SMS phishing campaign turns a routine payment check into a live fraud session. Victims who tap a link reach convincing pages seeking card details,…
CISA and NIST Issue Guidance to Protect Cloud Identity Tokens
CISA and NIST issued final guidance to help protect cloud identity tokens and assertions
Critical HPE Vulnerabilities Allow Remote Attackers to Achieve Complete System Compromise
Hewlett Packard Enterprise has released security updates for HPE Networking EdgeConnect SD-WAN Gateways and SD-WAN Orchestrator after identifying dozens…
Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
Mandiant says an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider and later spread Shai-Hulud across…
Hackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems
Noodle RAT is a remote-access trojan that gives attackers control of compromised computers and servers. Its renewed visibility matters because it runs on…
HBO Max Reddit Account Hacked: 108 Malicious Ads Push ClickFix Malware
Attackers reportedly hijacked HBO Max’s verified Reddit account to run 108 malicious ads delivering ClickFix malware to Windows and Mac users.
Apple Adds New Parental Controls to iPhone, iPad and Mac: Here’s What Changes
Apple is rolling out new parental controls for iPhone, iPad and Mac, including website approvals, Screen Time changes and expanded safety tools.
AIUC Raises $40 Million to Certify Enterprise AI Agents
The company provides a standard for AI systems, testing them against risks such as jailbreaks, prompt injections, and unauthorized actions.
GhostCode Abuses Microsoft Entra Device Enrollment to Maintain Access After Token Revocation
A newly identified device-code phishing kit dubbed GhostCode exploits Microsoft Entra device enrollment to maintain access after stolen tokens are…
Google Patches Pixel Modem Zero-Day Exploited in Targeted Attacks
Google has patched a high-severity zero-day in the Pixel cellular modem after finding evidence that the vulnerability was exploited in limited, targeted…
Scammers Are Watching Airline Complaints and Posing as Customer Support
Check Point uncovers thousands of fake support accounts, with hundreds more appearing every day A delayed flight. Missing luggage. A refund that never…
Microsoft Issues Out-of-Band Windows Update After September Patch Breaks Remote Desktop, Hyper-V
Microsoft released an out-of-band Windows update to fix Remote Desktop, Hyper-V Linux sharing, and USB audio issues caused by its September patch.
Revolut Data Leak May Trace Back to Compromised Italian Government Accounts
A suspected compromise of an Italian government PEC account may have allowed threat actors to impersonate law enforcement and obtain sensitive data from…
Scattered Spider Social Engineering Attacks on UK Retailers
A wave of cyberattacks against major UK retailers in April 2025 has highlighted the continuing effectiveness of social engineering tactics employed by the…
Pixel Modem Zero-Day Exploited in Targeted Attacks
Google announced patches for the exploited privilege escalation vulnerability (CVE-2026-58704) on September 15.
Top 30 Cybersecurity Interview Questions And Answers For 2026
By HOC Team | Updated: September 2026 Read time: ~24 min Cybersecurity hiring in 2026 is both…
VectraRAT Malware-as-a-Service Lets Hackers Bypass UAC and Hijack Windows Systems
VectraRAT, a previously undocumented Malware-as-a-Service platform that combines remote-access trojan capabilities with automated credential theft and a…
Microsoft warns of cloud storage and financial fraud campaign
Microsoft has warned customers about two sophisticated social engineering campaigns targeting corporate accounts and financial systems.
PAPERMILL Hackers Abuse Signed Notepad++ to Deploy VenomRAT in Tax Audit Attacks
A phishing campaign using a fake tax-audit notice is deploying VenomRAT through a signed copy of Notepad++. The operation, tracked as PAPERMILL, uses an…
