TASK#STOMP Windows backdoor uses PowerShell, scheduled tasks and runtime C# compilation to steal business documents and maintain remote access.
Tag: EN
Red Hat OpenShift Flaw Lets Attackers Poison Disconnected Registries With Malicious Releases
Red Hat disclosed an important OpenShift vulnerability that could let attackers bypass release-image signature checks and introduce malicious payloads…
Andorran Police joins Europol’s secure communication network
Through this connection, the Andorran Police will be able to securely share law enforcement information with Europol and a wide network of European and…
AI Drives Surge in Bot and API Threats
Akamai report warns of increase in bot traffic, API threats, chatbot leaks and other AI-related threats
How a Managed SOC works: What happens when a cyberattack begins?
Cyberattacks often begin in an inconspicuous way – for example, by clicking on an email attachment or a phishing link. Whether this leads to a serious…
Critical MaxKB AI Agent Flaw Lets Prompt Injection Execute System Commands
A critical vulnerability in the MaxKB AI knowledge-base platform could let attackers exploit prompt injection and run operating system commands on…
Attacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273)
A Chinese-speaking threat actor has exploited a vulnerability (CVE-2026-7273) in unpatched ZyXEL GS1900 Smart Managed Switches and has exfiltrated…
Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal
A malicious npm package named “indexed-btree” has been observed hiding its malicious behavior within application code rather than using lifecycle scripts,…
Linux BambooToken Malware Uses MQTT C2 for Remote Shell Access and File Exfiltration
A Linux variant of the BambooToken backdoor uses MQTT as its command-and-control channel, enabling operators to profile compromised hosts, execute shell…
Somewhere in your traffic logs, a bot is doing more than looking
Akamai has watched verified AI crawlers, ChatGPT among them, move from reading web pages to sending high-frequency POST requests. In a 30-day analysis of…
Rogue AI agents put trusted access under scrutiny
Two newly disclosed incidents involving rogue AI agents are raising questions about what happens when autonomous software operates through apparently…
WordPress Patches ‘Click2Shell’ Vulnerability
The bug lets attackers automatically install and preview themes and could lead to remote code execution.
Researchers used Claude to hack OpenAI
Claude helped researchers break into OpenAI in under 72 hours, and exposed how quickly AI is lowering the bar for sophisticated hacking.
U.S. CISA adds Zyxel flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zyxel flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and…
A New Tool Found Malware That’s Guided by an AI Hive Mind—No Humans in Sight
Cisco Talos researchers created a new framework for identifying malware and hacking tools that rely on AI chatbots—and quickly discovered something…
Top 10 Best Passwordless Authentication Solutions in 2026 [Ranked & Scored]
The password’s obituary has been written for a decade, but 2026 is the year the funeral actually gets scheduled: platform passkeys are mainstream,…
North Korean Hackers Hide Mac Backdoors in Fake Terraform Job Tests
North Korean hackers are using fake Terraform job tests to deploy macOS backdoors and target developer access to cloud infrastructure.
Texas utility CenterPoint confirms breach after attacker leaks customer data
Texas utility CenterPoint Energy has confirmed a data breach after a threat actor published customer information online and claimed to have stolen around…
CISA Warns of Zyxel GS1900 Switches Flaw Actively Exploited in Attacks
CISA added CVE-2026-7273, a critical stack-based buffer overflow in the CGI program of Zyxel GS1900 Series Switches, to its KEV catalog after confirming…
Orkes Conductor RCE Draws Nearly 7,000 Exploit Attempts
A critical Orkes Conductor flaw is under active attack, with 6,696 exploit attempts blocked in a week. Defenders should upgrade to version 3.30.2 or later.
