Nimbus Manticore uses trojanized coding challenges to deploy NodeRabbit and PollCat RATs across Windows, Linux, and macOS.
Attackers stole a METR API key and consumed credits worth about $600,000, while a later campaign failed to access internal ...
North Korean workers are expanding remote-job fraud beyond IT into healthcare and sales, using false identities, proxies, and ...
This week’s cybersecurity recap covers AI agents breaching Hugging Face, Chinese spy proxies, router backdoors, PaperCut ...
ValleyRAT abuses signed QN Wallpaper software for DLL sideloading, disables Windows Defender, and runs inside a trusted ...
Aurora ransomware operators used Cursor Agent for hands-on exploitation against 10 targets after receiving credentials or an existing route.
Fire Ant compromises Cisco IOS XR routers and TACACS servers to capture traffic, harvest credentials, and suppress defensive ...
DoJ corrected its QTFY statement, saying several U.S. agencies were targets rather than confirmed victims of the China-linked ...
Microsoft says TerminalFix uses fake Cloudflare CAPTCHAs to trigger PowerShell and deploy a reverse-tunnel backdoor for internal network access.
Critical flaws in WPMU DEV, Avada, TranslatePress, Pods, and GiveWP can enable admin takeover or remote code execution.
Berlin confirms an extortion attempt after data theft from its state network, while the scope of the exfiltrated data remains ...
Cosmos Labs has warned that a critical balance-handling flaw in the shared Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and August 25, 2026. The vulnerability, ...