A maximum-severity vulnerability in SAP Commerce Cloud is reportedly facing exploitation attempts only days after SAP released a security update. Tracked…
Tag: EN
Apple macOS Flaw Exploited in the Wild to Install Monero Cryptominers
A critical vulnerability in the recently updated Apple macOS has been weaponized by threat actors to mine Monero cryptocurrency, according to the…
Evooo1Bot Hijacks Linux Routers for Proxying, Credential Theft and DDoS Attacks
A new Linux botnet named Evooo1Bot is turning internet-facing routers and other gateway devices into SOCKS5 traffic relay nodes, giving attackers a way to…
Active Directory Security: Hardening Guide and Common Attack Paths (2026)
By HOC Team | Last updated: August 2026 | Read time: ~25 min When the NotPetya malware spread…
Cloud Penetration Testing: Methodology, Tools and Legal Requirements (2026)
By HOC Team | Last updated: August 2026 | Read time: ~24 min A financial services company commissioned…
Trezor Data Breach Exposes Personal Information of Nearly 14,000 Customers
Hardware cryptocurrency wallet maker Trezor has disclosed a data breach involving the personal information of nearly 14,000 customers, after an…
Stopping a cyberattack while walking your dog – defensive AI security CEO says it’s not ruff to do
Corma CEO tells The Reg it’s building ‘One ring to rule them all, for the defenders to have this power’
Security Affairs newsletter Round 590 by Pierluigi Paganini – INTERNATIONAL EDITION
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email…
Sophisticated Cyberattack Exposes Data of 678,000 French Taxpayers
France’s tax agency says hackers stole data on 678,000 taxpayers, including income and tax details, in a sophisticated cyberattack. A threat actor claimed…
Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-day
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: GitHub Dependabot malware alerts now cover eight…
APT36 Suspected in PATCHCORD Espionage Campaign Using Google Sheets C2
Acronis uncovered PATCHCORD, a stealthy backdoor targeting Afghan telecom and South Asian infrastructure via fake VPN tools and Google Sheets C2.…
Google Confirms Gmail Was Not Breached After Reports of 183 Million Password Leak
Google says Gmail was not breached, despite reports claiming that 183 million Gmail passwords had leaked. Thank you for being a Ghacks reader.
Encrypted AI Reasoning Flaw Exposed Secrets Across Major LLM APIs
A newly reported security weakness in the systems used by OpenAI, Anthropic and Google to preserve hidden AI reasoning between API calls has allowed…
Meccha Chameleon Players Urged to Update Game After Malicious Workshop Maps Infect PCs
Players of indie game Meccha Chameleon have been advised to install the latest update and avoid the game’s original Discord community after malicious…
Anthropic AI Discovery Pushes HAWK Out of US Post-Quantum Cryptography Race
A post-quantum cryptography algorithm that was being evaluated for possible adoption as a US standard has been withdrawn after Anthropic’s AI security…
GrapheneOS Foundation Defends Privacy Features Amid US Case Involving User
The US Department of Justice’s recent case against GrapheneOS user Sam Tunick has renewed discussions about mobile privacy, digital security and the…
Parents take on Meta, TikTok, Google, and Snap in 3,000 youth safety lawsuits
It’s the biggest legal challenge yet to addictive social media design and its impact on children.
Dissecting the JWR phishing framework
Cisco Talos recently identified an undocumented phishing framework, internally branded “JWR” by its developer, built to convincingly impersonate checkout…
CBP Workers Allegedly Used Government Databases to Spy on Exes, Crushes, and Colleagues
Records obtained by WIRED detail hundreds of allegations of Customs and Border Protection workers misusing internal tools to look up romantic interests…
Akira Affiliate Crashes Ransomware After Attempting EDR Evasion
Huntress documents how a ransomware affiliate sabotaged its own attack with an anti-EDR effort
