Cyber News

128 Seconds to disruption: Microsoft Defender stops ransomware at QNET

128 Seconds to disruption: Microsoft Defender stops ransomware at QNET

Microsoft says Defender isolated a compromised QNET endpoint in 128 seconds, interrupting a multi-stage ransomware chain before the payload could…

Hackers breach TrueConf to trojanize client installers with backdoors

Hackers breach TrueConf to trojanize client installers with backdoors

The TrueConf compromise is not just a server-breach story. It is a reminder that update channels themselves become attack infrastructure…

Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

CISA added Progress Kemp LoadMaster flaw CVE-2026-8037 to the KEV catalog after repeated exploitation attempts, turning a load balancer bug…

Metabase SQLi zero-day exploited in customer data-theft attacks

Metabase SQLi zero-day exploited in customer data-theft attacks

Metabase confirmed active exploitation of a critical unauthenticated SQL injection flaw that can hand a remote attacker administrator access to…

New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes

New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes

CISA is telling federal agencies to move within three days on actively exploited flaws in IBM Langflow, N-able N-central, and…

AI Recommendation Poisoning: How “Ask AI” Buttons Silently Alter LLM Memory

AI Recommendation Poisoning: How “Ask AI” Buttons Silently Alter LLM Memory

A new class of prompt injection is spreading across commercial websites. It requires no malware, no stolen credentials, and no…

CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws

CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws

CISA is telling federal agencies to move within three days on actively exploited flaws in IBM Langflow, N-able N-central, and…

Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks

Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks

Unit 42 described three post-compromise attack paths against Chrome's Google Password Manager on Windows that could let malware bypass user-verification…

The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version

The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version

Analysis of XCSSET v40 reveals a macOS malware targeting developers via Xcode. Unit 42 used advanced pattern matching and AI…

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations…

New DOUBLECUP ClickFix service hides malware in browser cache images

New DOUBLECUP ClickFix service hides malware in browser cache images

A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims' browsers,…

INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws

INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws

The INC Ransomware operation has emerged as the "dominant threat actor" exploiting the recently disclosed security flaws in SonicWall Secure…

Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

Unit 42 described three post-compromise attack paths against Chrome's Google Password Manager on Windows that could let malware bypass user-verification…