Attackers reportedly hijacked HBO Max’s verified Reddit account to run 108 malicious ads delivering ClickFix malware to Windows and Mac users.
Category: eSecurity Planet
Cisco Secure Email Gateway Zero-Day Exploited for Root Command Execution
Cisco Secure Email Gateway flaw CVE-2026-76461 is under active exploitation, with no workaround and urgent patching required for affected AsyncOS systems.
Zero-Days, AI Agents, and Massive Data Leaks Define the Week
Weekly summary of Cybersecurity Insider newsletters
36,769 Self-Hosted AI Services Exposed Online — What Security Teams Should Check
A new scan found 36,769 self-hosted AI endpoints reachable online, highlighting gaps in access controls, patching, and monitoring.
CISA Warns Attackers Are Exploiting Acronis Backup Flaw on Linux Servers
CISA added CVE-2026-87886 to its KEV catalog after confirmed exploitation of an Acronis Backup flaw affecting Linux hosting environments.
Researchers Find OAuth Token Exposure in Twitch Extension Used by 30K
Researchers found a Twitch extension used by 30,000 Chrome users transmitting OAuth tokens, potentially exposing authenticated account access.
1.8M Android APKs Scanned for Hardcoded Secrets in Automated Attack
Attackers scanned 1.8 million Android APKs for hardcoded secrets, showing why developers need stronger credential management and production-build security.
Fake MRI Scans Deliver CHOSEN BRICK Spyware to Windows PCs
Iranian state-linked attackers are using fake MRI scans and software lures to deploy CHOSEN BRICK spyware on Windows PCs.
HBO Max Reddit Account Hacked: 108 Malicious Ads Push ClickFix Malware
Attackers reportedly hijacked HBO Max’s verified Reddit account to run 108 malicious ads delivering ClickFix malware to Windows and Mac users.
Cisco Secure Email Gateway Zero-Day Exploited for Root Command Execution
Cisco Secure Email Gateway flaw CVE-2026-76461 is under active exploitation, with no workaround and urgent patching required for affected AsyncOS systems.
36,769 Self-Hosted AI Services Exposed Online — What Security Teams Should Check
A new scan found 36,769 self-hosted AI endpoints reachable online, highlighting gaps in access controls, patching, and monitoring.
Cisco FMC Flaws Give Ransomware and APTs a Path Into Internal Networks
Cisco Talos says attackers are exploiting FMC flaws to steal credentials, tunnel into internal networks, and deploy Qilin ransomware.
CISA Warns of Active GitLab Exploitation as Attackers Target Server Files
CISA warns attackers are exploiting a critical GitLab flaw that exposes server files, credentials and development pipelines. Learn how to respond.
Researchers Find OAuth Token Exposure in Twitch Extension Used by 30K
Researchers found a Twitch extension used by 30,000 Chrome users transmitting OAuth tokens, potentially exposing authenticated account access.
1.8M Android APKs Scanned for Hardcoded Secrets in Automated Attack
Attackers scanned 1.8 million Android APKs for hardcoded secrets, showing why developers need stronger credential management and production-build security.
Brevo Breach Sends Trezor Phishing Email to 347,000 Subscribers
A Brevo breach allowed attackers to send Trezor phishing emails to 347,000 subscribers, exposing security risks created by trusted third-party vendors.
AI Slowdown Debate Leaves Security Teams With a Bigger Problem
As AI leaders debate slowing development, security teams must secure the agents already operating in their environments.
Japan Government Network Breach Puts 246,000 People at Risk
A vulnerability in Japan’s shared government network may have exposed personal information tied to 246,000 workers across 23 organizations.
Microsoft 365 Passkey Phishing Turns Login Into a Cloud Breach
Microsoft warns that passkey-themed phishing is hijacking Microsoft 365 accounts, adding rogue MFA methods, and slowly stealing business cloud data.
Mantax Otax Targets Android Phones With Spyware and Ransomware
Mantax Otax Android malware steals messages, PINs, and files, monitors screens, and uses ransomware and harassment to pressure victims into paying.
