<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <updated>2026-09-29T11:24:56Z</updated>
  <generator>https://njump.me</generator>

  <title>Nostr notes by The Hacker News (RSS Feed)</title>
  <author>
    <name>The Hacker News (RSS Feed)</name>
  </author>
  <link rel="self" type="application/atom+xml" href="https://njump.me/npub1fx99usanjk37advhnypevpsdmczpwjj3vunzkw3xc7kxym9nvrmszlxeqn.rss" />
  <link href="https://njump.me/npub1fx99usanjk37advhnypevpsdmczpwjj3vunzkw3xc7kxym9nvrmszlxeqn" />
  <id>https://njump.me/npub1fx99usanjk37advhnypevpsdmczpwjj3vunzkw3xc7kxym9nvrmszlxeqn</id>
  <icon>https://feeds.feedburner.com/icon.svg</icon>
  <logo>https://feeds.feedburner.com/icon.svg</logo>




  <entry>
    <id>https://njump.me/nevent1qqspxte6t28enkq7y4dn2psry07d9m493kpn6ftkzfphpv7dm2n3jmgzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w8mn5pq</id>
    
      <title type="html">ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqspxte6t28enkq7y4dn2psry07d9m493kpn6ftkzfphpv7dm2n3jmgzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w8mn5pq" />
    <content type="html">
      ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure&lt;br/&gt;&lt;br/&gt;Threat actors are leveraging ClickFix-like lures to deliver a previously undocumented remote access trojan (RAT) called ChainScript.&lt;br/&gt;&lt;br/&gt;&amp;#34;ChainScript has appeared under multiple build names, including ComponentTask33, UpdateDigital, HostShared, and OrchidViolet66, while presenting itself as Spotify, Zoom Workplace, and Microsoft Teams software,&amp;#34; Blackpoint Adversary Pursuit Group (APG)&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi-cgmwQRZh142Z19A3s7K7tpaXtsyy6Imy9cYGM7nFP1DAZoSK9gDw8T0dGXlkFWOGDFShJWMNjC7jbwoSvLokr1pX27u2B1SABpBL-aWtaXj2hYYrqVwTE7LpEDn_iIbRYCro8sH2hzAEsjHLGkpFqTjEKlFHi2o2pgacFJQvYkPDCKVEhkJgW8OWhpZA/s1600/poly.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/09/clickfix-lures-deploy-chainscript-rat.html&#34;&gt;https://thehackernews.com/2026/09/clickfix-lures-deploy-chainscript-rat.html&lt;/a&gt;
    </content>
    <updated>2026-09-21T08:39:38Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqsrn6y75n3exyjyhghfagzk0y009xsw06x7kr297htp2rte4uxetjczypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0why8ss5</id>
    
      <title type="html">Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqsrn6y75n3exyjyhghfagzk0y009xsw06x7kr297htp2rte4uxetjczypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0why8ss5" />
    <content type="html">
      Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors&lt;br/&gt;&lt;br/&gt;The North Korean threat actor known as Jade Sleet has been attributed to the compromise of an India-based &amp;#34;much smaller organization&amp;#34; in the information technology (IT) services industry, once again highlighting how the adversary continues to target developers to breach target networks.&lt;br/&gt;&lt;br/&gt;Cybersecurity company SentinelOne, which disclosed details of the activity, said it involved the use of Apple&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi-xFiujwBJLdl6_4wZSMCWdeyCgev2EqszOLkIJ5I9Kbanu6YNmQ36nM615XmLQ-sq2aqldOHfl47jaMNRtDd80RT8k5f6I7eQuszf7wsIg49sEdMW36hsEKUtVUkZabRlGvvDxn7H7COmRCV8qP2pzQm9LNo5QKRnnptxmxTlJ8BMcPxuiqdaMjn-are0/s1600/it-services.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/09/jade-sleet-linked-to-indian-it-provider.html&#34;&gt;https://thehackernews.com/2026/09/jade-sleet-linked-to-indian-it-provider.html&lt;/a&gt;
    </content>
    <updated>2026-09-21T06:06:44Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqswz99m5fnkppj0wuy25xm07qsn3y2xh7zfe6vsrvg93xpmpaqw4pgzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wlmpsc4</id>
    
      <title type="html">WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqswz99m5fnkppj0wuy25xm07qsn3y2xh7zfe6vsrvg93xpmpaqw4pgzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wlmpsc4" />
    <content type="html">
      WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage&lt;br/&gt;&lt;br/&gt;Cybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit.&lt;br/&gt;&lt;br/&gt;The new malware family, per OpenSourceMalware, exhibits functional overlaps with two malware strains associated with the Democratic People&amp;#39;s Republic of Korea&amp;#39;s (DPRK) Contagious Interview campaign: BeaverTail and&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhZypkEn_5V1qllBxmH8UMxTPyA9qoXxQtKpBpJlFq2rtHgMM1wnknkyq4Vmmy0NiCHn2IjS0nyvtmiZpJ-vYOd6VxMFBexh_p6GXuq3Cjda-YfjDOUE5u5V5HfBBAQzEm5DLX3jg_ZrIfEBFlpcBod65T3Q0pXVR7vERfitlS6cBHYVG2K7ek5ivweYTRq/s1600/npm-chrome.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/09/weaselbiscuit-stealer-spreads-via-13.html&#34;&gt;https://thehackernews.com/2026/09/weaselbiscuit-stealer-spreads-via-13.html&lt;/a&gt;
    </content>
    <updated>2026-09-18T10:40:06Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqsfyzf790hukxncg8ndjfay2wmel3etyudksucxj47d73cs2lda94czypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wz68h4q</id>
    
      <title type="html">RatHat Android Malware Abuses ADB to Retain Shell Access After ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqsfyzf790hukxncg8ndjfay2wmel3etyudksucxj47d73cs2lda94czypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wz68h4q" />
    <content type="html">
      RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall&lt;br/&gt;&lt;br/&gt;Cybersecurity researchers have flagged a new Android malware called RatHat that&amp;#39;s assessed to be operated by China-based threat actors and features an artificial intelligence (AI)-powered system to navigate and control compromised devices.&lt;br/&gt;&lt;br/&gt;&amp;#34;Distributed primarily via targeted smishing (SMS/text phishing) and malvertising campaigns leading to deceptive third-party download portals, RatHat uses&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj5Psm8tS3JWb6ev7nZoz7YQDPIgoHj9gwbNjgjxbokxICdzRIUb5YJI-XfDx0NQgm8afhayc-Zd51hjuxqi7Sk_XxCNXoTNt7nIZWpxCBcDMLjSm3uW38HRciOu3WNtaUT0a-2NSsOX91GbXpCScryNirImMMC4lkuVysHku58maTbm9XvAwJ0-X6O_wDE/s1600/1000109602.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/09/rathat-android-malware-abuses-adb-to.html&#34;&gt;https://thehackernews.com/2026/09/rathat-android-malware-abuses-adb-to.html&lt;/a&gt;
    </content>
    <updated>2026-09-18T06:17:25Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqsvxgld0cyrdmsfx6lvtr5hm3q3caujat7fd37p9j2a2eep6dp8daszypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w7q72tg</id>
    
      <title type="html">KREMLIN Banking Malware Hijacks Chrome and Edge to Steal ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqsvxgld0cyrdmsfx6lvtr5hm3q3caujat7fd37p9j2a2eep6dp8daszypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w7q72tg" />
    <content type="html">
      KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens&lt;br/&gt;&lt;br/&gt;Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN.&lt;br/&gt;&lt;br/&gt;Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiPTs6qupSdjinGg233zkoldOvlD4cva51loWufV3l9GrlDopNRIKsV9yluCDjbGELBAAvVGx_h4R-sjx4jvDp290Znzhv6j546sq5JB0NJUShGVV3w0gKU7nu4dBVCosaPeKW-Pr1_WHn4FV26aEJRgEo7oSJsgUE5_ZGCMKWPPBdZ7NMh5XRr04Cs6qTh/s1600/browser-malware.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html&#34;&gt;https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html&lt;/a&gt;
    </content>
    <updated>2026-09-15T18:54:14Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqs9xr7u68jzm9kg2409qpczhavyjusvspkhet802n9xsa7ceccqjhqzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wkv37te</id>
    
      <title type="html">Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqs9xr7u68jzm9kg2409qpczhavyjusvspkhet802n9xsa7ceccqjhqzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wkv37te" />
    <content type="html">
      Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data&lt;br/&gt;&lt;br/&gt;Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments.&lt;br/&gt;&lt;br/&gt;The first campaign, per the tech giant, involved sending over a million scam emails between August 3 and 5, 2026, by masquerading as chief executive officers&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiZ2E2hmYwxfZ25xw5iPhCHaSDENcuEyEIaha9e_rIJCf68srth31FtjIiIlnOcEiSQDDuk2Vg-dQdNLfR753ePSoDntP3BS-MGbEH2DS8Ch5ihzhpiDZZm5UIzKCbL1vNJSwSABCYst8oG6Oa-7iBWaSF6WSTEkCJBAi9YEEwAmVEdGYvu-JWZnxwEX9ni/s1600/ms-outlook.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html&#34;&gt;https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html&lt;/a&gt;
    </content>
    <updated>2026-09-13T10:11:48Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqsxlmzqsc83xaq9z3772nhdyemdjqfl48vle2fag4ugzvde60f68lczypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w46w24j</id>
    
      <title type="html">Google Play Early Access Abused to Push Thousands of Deceptive ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqsxlmzqsc83xaq9z3772nhdyemdjqfl48vle2fag4ugzvde60f68lczypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w46w24j" />
    <content type="html">
      Google Play Early Access Abused to Push Thousands of Deceptive Android Apps&lt;br/&gt;&lt;br/&gt;Bad actors are misusing Google Play&amp;#39;s Early Access program to push deceptive apps that claim to offer money, rewards, casino winnings, and premium content.&lt;br/&gt;&lt;br/&gt;Early Access apps are apps that haven&amp;#39;t been released on the official Android app marketplace. The main idea behind the program is for developers to solicit user feedback for new applications or features they may be working on before their&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh4vbRDTWaQnxiILexae9P_rAk0hzx-re0czK2tM_WNQcoVDPlKblD4M5qOy8FZ9hHJBDLGjHHAyYutmaiacI54o5q1SH5qSbsptviRF16T2r6i8Iywvzk4GJprCm60p12qrK7t3R8h_ZR7CUoG47YfdeOb0iKY0WRapDeObI8_poWklMtKXrmr421Scjzi/s1600/play.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/09/google-play-early-access-abused-to-push.html&#34;&gt;https://thehackernews.com/2026/09/google-play-early-access-abused-to-push.html&lt;/a&gt;
    </content>
    <updated>2026-09-10T14:36:47Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqs25a0y8kq4kpw3qxdj3mrjvf4zvh420cujf7vv39es85tgpqtyvcqzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wtkrqch</id>
    
      <title type="html">Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqs25a0y8kq4kpw3qxdj3mrjvf4zvh420cujf7vv39es85tgpqtyvcqzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wtkrqch" />
    <content type="html">
      Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA&lt;br/&gt;&lt;br/&gt;Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create &amp;#34;stolen keys&amp;#34; that grant illicit access to tools from model providers like Google, Anthropic, and others. &lt;br/&gt;&lt;br/&gt;Information stealers like Lumma Stealer or Vidar are equipped to harvest a wide range of data from compromised systems. This can include credential, session tokens, and API&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiYP_zrhRTZRWnPPcDkUrE7dBh2Bf5eaQmlBxyl7euTRGjS0C8boQppnrmjY0CIVjGrS_PF13V1W3BPVI3RDPZY59s_7xIkI8LnFkg3Tn_Q0x7_tbCs_sMkvhZMREtFLW3IOJSNNmQrKCDI88FCWhfymdWkEWtdMMRzivv3lZXImjreAz0d74VXt2K80ipH/s1600/tokens.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/09/infostealer-logs-expose-replayable-ai.html&#34;&gt;https://thehackernews.com/2026/09/infostealer-logs-expose-replayable-ai.html&lt;/a&gt;
    </content>
    <updated>2026-09-09T14:23:55Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqstgrmwhltkmt436ntrt0p79m8hfwdva6wjr0d9j9evet7fs95pccqzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wu99s28</id>
    
      <title type="html">Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqstgrmwhltkmt436ntrt0p79m8hfwdva6wjr0d9j9evet7fs95pccqzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wu99s28" />
    <content type="html">
      Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox&lt;br/&gt;&lt;br/&gt;Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild.&lt;br/&gt;&lt;br/&gt;The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome&amp;#39;s JavaScript and WebAssembly engine.&lt;br/&gt;&lt;br/&gt;&amp;#34;Out-of-bounds write in V8 in Google Chrome prior to&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgZvl2DE9GFM-4rdFgtQOOp1Dk3Xgp7xWysUv5zKTFwxqWYTurcgXgE-PDMn3_2AAIihh4YeiRvmwpb6GVDB1-8kxqasUWwX-FFa4mA41kXpFbzdt9hOvzW4xcyKBFttqIzbFSl-1SSSO0P_URv3Sy9QamkQZ55qzX5Y9Kmv5NdBCBHXCcUziiO6mfrqURE/s1600/chrome-zeroday.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/09/chrome-v8-zero-day-exploited-in-wild.html&#34;&gt;https://thehackernews.com/2026/09/chrome-v8-zero-day-exploited-in-wild.html&lt;/a&gt;
    </content>
    <updated>2026-09-09T09:11:03Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqs9c84e5l60rh7qg3y6nj69zngrug24mf6y4xh3zgglsf78zw5lyegzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wgrazst</id>
    
      <title type="html">FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqs9c84e5l60rh7qg3y6nj69zngrug24mf6y4xh3zgglsf78zw5lyegzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wgrazst" />
    <content type="html">
      FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials&lt;br/&gt;&lt;br/&gt;A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group, Red Hat says.&lt;br/&gt;&lt;br/&gt;FreeIPA is the system that determines who may log in across a Linux domain and maintains all identities in a 389 Directory Server database accessed via LDAP. The attack needs a second flaw in that database software.&lt;br/&gt;&lt;br/&gt;The&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiSKAVaHcAsULrGXPVkGXRyf94eoG7Kv3X0wwK2lRC64l3Em-S4_H5iE8-poK04yzrAC18tuHqpZyHhJvFTgliu_z8jo4QR78Mi4ghhCA-cUVL4oj2zjoLGiWKmD16oV4i44VfY45DYll0Uij_Exf4U2JMSLJEyH8jZk_xXKq7O_7D73q7vTYCCc4hrTnQ/s1600/freeipa.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/09/freeipa-flaw-chain-lets-anonymous.html&#34;&gt;https://thehackernews.com/2026/09/freeipa-flaw-chain-lets-anonymous.html&lt;/a&gt;
    </content>
    <updated>2026-09-08T11:22:07Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqsvsfz80dcj4wkyqh87knaalu0srpwr7554gmymazf8we623v3r3pqzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wkm7h68</id>
    
      <title type="html">Fake IT Calls Target Executives in Microsoft 365 Data Theft and ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqsvsfz80dcj4wkyqh87knaalu0srpwr7554gmymazf8we623v3r3pqzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wkm7h68" />
    <content type="html">
      Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks&lt;br/&gt;&lt;br/&gt;Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that&amp;#39;s targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins.&lt;br/&gt;&lt;br/&gt;The activity, which mainly singles out directors, vice presidents, and other executive staff&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjg-Zo4zgxCrVcz6-00WV2qAPHSD-av2Ed5hgRmR-2vUzkr9jVeph0NNb6gGsQfwSkFyuRfRcSsaISSpfysl_Xx5F48IM7HdBpO4F3CaVuLhk1v0a4vcH5xK_bxX6BxIjkfAjhDaNGcLG7_R9IcTjVGlFcW7y1ZV64imACHi9528LOjH1Flhk-cy9LFgrMv/s1600/phish-ms.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/09/microsoft-365-attackers-use-help-desk.html&#34;&gt;https://thehackernews.com/2026/09/microsoft-365-attackers-use-help-desk.html&lt;/a&gt;
    </content>
    <updated>2026-09-07T15:51:56Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqsthez0z8f7ng9hardkrvfm9630fdzzgjtjzpumxyegex29f79t2ugzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wgraf2k</id>
    
      <title type="html">Attackers Breached JetBrains Cadence via Unpatched TeamCity, ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqsthez0z8f7ng9hardkrvfm9630fdzzgjtjzpumxyegex29f79t2ugzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wgraf2k" />
    <content type="html">
      Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials&lt;br/&gt;&lt;br/&gt;JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment.&lt;br/&gt;&lt;br/&gt;&amp;#34;Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions,&amp;#34; JetBrains said.&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjH4sbUEhtXF9n1_8s2f6ChnKMmjUv4Ht-DvEtZyLDPuSNhKFoi41aNlu3-u5kJLXUva81rNFwlsprMXE11cnbXc_es968eO-ANvWm0j1Cyi9SaoVUfneQqNINCR7lRs3qkkYdsSoyMu34Mgxs7B4pKclAt4atPw8B-RCFOTChtgeji9NTes_NEdZ2KKu2_/s1600/jet.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/09/attackers-breached-jetbrains-cadence.html&#34;&gt;https://thehackernews.com/2026/09/attackers-breached-jetbrains-cadence.html&lt;/a&gt;
    </content>
    <updated>2026-09-05T16:52:33Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqs8wxmhp8wgj9r4w7rgh07k5z9wz6k6e4tstfwwkx9qgfelk65xa0szypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wnzh2zl</id>
    
      <title type="html">Phishing Campaign Sends Millions of Emails Using Invisible ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqs8wxmhp8wgj9r4w7rgh07k5z9wz6k6e4tstfwwkx9qgfelk65xa0szypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wnzh2zl" />
    <content type="html">
      Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters&lt;br/&gt;&lt;br/&gt;Microsoft is alerting of a &amp;#34;high-volume phishing campaign&amp;#34; that&amp;#39;s using invisible Unicode tag characters to bypass email filters.&lt;br/&gt;&lt;br/&gt;&amp;#34;Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as &amp;#39;funding&amp;#39; to prevent email filters from parsing them,&amp;#34; the Microsoft Security Research team said.&lt;br/&gt;&lt;br/&gt;The&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjoD4eMYuhLT8HvcHbYe8A4hkhmDH1f4pIWTIm5AXKueqdpY1NS8yNiTtlzS4mdIS8PLY8_zM1uQDNpO1U49HCUoJT8nn2Bpb6krpcYpOSQ3H3Z6fUsm-UkoFvj8fk8oShK0eUhO6px8hox_ZzlnX8tu0pJKpJ3UAF2Vcb3XyBXjCt_8uD8OOkMMgUjv8Pc/s1600/emails.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/09/phishing-campaign-sends-millions-of.html&#34;&gt;https://thehackernews.com/2026/09/phishing-campaign-sends-millions-of.html&lt;/a&gt;
    </content>
    <updated>2026-09-04T15:57:15Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqsqsdygkc0w2zjqw0479sqddjzamqh3p7y9k9r0889gl0wf8qg0zqczypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w33ac7p</id>
    
      <title type="html">Malicious .git Configs Can Make Claude, Codex, Cursor, and Other ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqsqsdygkc0w2zjqw0479sqddjzamqh3p7y9k9r0889gl0wf8qg0zqczypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w33ac7p" />
    <content type="html">
      Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code&lt;br/&gt;&lt;br/&gt;Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository&amp;#39;s own Git configuration names a command that the agent runs on the developer&amp;#39;s machine, four of them still unpatched at publication.&lt;br/&gt;&lt;br/&gt;The command executes as the user, outside the agent&amp;#39;s sandbox and without an approval prompt, and exploitation requires the repository to arrive&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhlrspu4otI5zjtu2q78NDrwnqfbTv4jzqXhH-txAo8pCjXDPRJjLvfWpRyHvbimqVvAOZWI0pMVmu2jWVdETbh2csa2UkMHx0M2uu9cJkB0_E4x1mjjs_1F9RYZjozZQvIYN5Xux43DX1u0jCQE_Pk19yE8BnR_RxXN-QXmP5jf74ZQgE9uQVUONJoQKQ/s1600/aix.gif&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/09/malicious-git-configs-can-make-claude.html&#34;&gt;https://thehackernews.com/2026/09/malicious-git-configs-can-make-claude.html&lt;/a&gt;
    </content>
    <updated>2026-09-02T14:06:59Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqszey80tsf4ejs6uy6e7p97dc0fxx3jhjx42vvgkcs4dcayss8e0vczypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wpk4par</id>
    
      <title type="html">Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqszey80tsf4ejs6uy6e7p97dc0fxx3jhjx42vvgkcs4dcayss8e0vczypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wpk4par" />
    <content type="html">
      Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain&lt;br/&gt;&lt;br/&gt;SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day attacks.&lt;br/&gt;&lt;br/&gt;The vulnerabilities, discovered internally by SonicWall&amp;#39;s William Perry and Adam Babis, are listed below -&lt;br/&gt;&lt;br/&gt;  CVE-2026-83548 (CVSS score: 10.0) -  A pre-authentication SSRF vulnerability in the Appliance&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhHkRZMEpG9dgsbvSzYfaPZC5u0gmzUw-5NHDTcsQ-MQtxr6pqNrngG2LsyMJ0KKxA364L3Lq4xhGAxCTRQ3C8szlo9aLJeWXw37C6hsAD5YbYCJF8KuQyuWMIPNCNDXX8-1HN76xxYhxffeenDDyWobOpA4AXC76hFcdh1vnqpjI_pLF2YuxiAwu87cHwC/s1600/sonicwall.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/09/attackers-exploit-two-sonicwall-sma.html&#34;&gt;https://thehackernews.com/2026/09/attackers-exploit-two-sonicwall-sma.html&lt;/a&gt;
    </content>
    <updated>2026-09-02T10:53:49Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqs9mex0fk3cz7wpd8s2lcgpfm4rr5hggjxmurqmml7w53nk4a6ag5gzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wyuhq7n</id>
    
      <title type="html">Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqs9mex0fk3cz7wpd8s2lcgpfm4rr5hggjxmurqmml7w53nk4a6ag5gzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wyuhq7n" />
    <content type="html">
      Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another&lt;br/&gt;&lt;br/&gt;Forescout Research - Vedere Labs said it used Anthropic&amp;#39;s Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another, executing attacker-supplied ARM shellcode on live hardware.&lt;br/&gt;&lt;br/&gt;The exploit targets CVE-2021-31886, a stack-based buffer overflow in the Nucleus FTP server&amp;#39;s handling of the USER command&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhlWf4d2lnMsRXbG_XpDaQ8uxTM9SD8QBArFea3LdD93t2xnpO4Bw2K_iBewRfrscbj2Kfe6DSkFozbxWnHwMeR5p1cx2XksAyZD5_avLwxqx5L6tvTf_Z807niMu_uqzbslMMgMx8M1IVY9y20gbuDwbWAco96weFLycq2JCQMQ2hpcTnd2yanypqsj4k/s1600/claude.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/09/researchers-use-claude-to-port-pre-auth.html&#34;&gt;https://thehackernews.com/2026/09/researchers-use-claude-to-port-pre-auth.html&lt;/a&gt;
    </content>
    <updated>2026-09-02T07:47:13Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqs0tza2x2g6y9qzq4sagcz0vtl7zk2vyk2n02g5a283yl9znzdkjhqzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w7glen8</id>
    
      <title type="html">Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqs0tza2x2g6y9qzq4sagcz0vtl7zk2vyk2n02g5a283yl9znzdkjhqzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w7glen8" />
    <content type="html">
      Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests&lt;br/&gt;&lt;br/&gt;The Iranian Nimbus Manticore hacking group has been attributed to two previously undocumented malware families that highlight the continued evolution of its toolset and likely expand its targeting footprint to infect Linux and Apple macOS systems using cross-platform remote access trojans (RATs) developed using Node.js and JavaScript.&lt;br/&gt;&lt;br/&gt;Russian cybersecurity company Kaspersky is tracking the&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhm2I0vj1ygDfFQ8UzazaxECq0aAP3UJ_VRMzeCN0MgTkWk4yLEUbKKU9dE0pIyXZIfJ0MgxjYEqAqWLAXAtuATDCdFZPI9WGkgwz04Mdd7LChIfMrWk-vhGfaHDGtySDkbIXgzBcNfh5qcobm-bz8QWuyVCcH7z9CM_RNZusA2rPEHV5g2WJ2tU6Llrdnu/s1600/iran-hacking.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/09/iranian-hackers-pose-as-recruiters-to.html&#34;&gt;https://thehackernews.com/2026/09/iranian-hackers-pose-as-recruiters-to.html&lt;/a&gt;
    </content>
    <updated>2026-09-01T13:08:58Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqs25mqygp9guclk0xs5yfy57g80mu5r0zh62wx9w9r236086xljghgzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wxa74m3</id>
    
      <title type="html">CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqs25mqygp9guclk0xs5yfy57g80mu5r0zh62wx9w9r236086xljghgzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wxa74m3" />
    <content type="html">
      CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs&lt;br/&gt;&lt;br/&gt;The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway, citing evidence of active exploitation.&lt;br/&gt;&lt;br/&gt;The vulnerabilities are listed below -&lt;br/&gt;&lt;br/&gt;  CVE-2019-1068 - A remote code execution vulnerability in&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjsOm0ydTRNpwfiKMNN7TGZyoellV9LHrcra7ES8hU8PvT6haNsS-QQ5IlystrzP1eq5jiIRfyykIZyB5JKrya5K4ryBRp9gKAmsoVW7OMis-YT4T6jnpbN11M8mUnPn-2yY-caG31-iXmDAhJ9CTbRg8r1UPWWqCob_S8St7McsKCM-4I36jD_xqE8D3BS/s1600/cisa-flaws.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/08/cisa-adds-six-exploited-flaws-to-kev.html&#34;&gt;https://thehackernews.com/2026/08/cisa-adds-six-exploited-flaws-to-kev.html&lt;/a&gt;
    </content>
    <updated>2026-08-27T07:05:28Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqszjv5ksf4v7xeu3qvtsqt7z684eqvc0k92z49lv5nd8pqpnwxxdtqzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wg5f784</id>
    
      <title type="html">Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqszjv5ksf4v7xeu3qvtsqt7z684eqvc0k92z49lv5nd8pqpnwxxdtqzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wg5f784" />
    <content type="html">
      Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users&amp;#39; Reservations in Tests&lt;br/&gt;&lt;br/&gt;Aikido Security has published research that recreates the Australian gym-booking incident in a synthetic environment, finding that Claude Opus 4.6, running on the OpenClaw agent harness, exploited a client-side-only booking restriction in 9 of 10 runs.&lt;br/&gt;&lt;br/&gt;The original incident was first reported by ABC News on August 10, based on chat logs and screenshots the user supplied. He had asked an&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiiLH7AlxOwnKOlTs4Zi3D7tyko_H-564oFmjcBu-YP4_YR7HMgRvWhGB9r0NhXwpVoqVk82yjCt9XjEcDfo7-iSoAVduYsjNndt3gU2fHqJ7PlwnFCjRaHJSYEMuZMAZOn6M_yGZ24JuUUjVCs1hTXes8h-q4OLFj2liDETlKzvCRAqKa-jX2Yrh-iErI/s1600/claude-gym.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/08/claude-opus-46-bypasses-gym-booking.html&#34;&gt;https://thehackernews.com/2026/08/claude-opus-46-bypasses-gym-booking.html&lt;/a&gt;
    </content>
    <updated>2026-08-26T10:27:23Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqstqpsr2dvx074qchuamx8t065pl995ytrx7ca8sfygk3vw37qlu6czypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wcrypt7</id>
    
      <title type="html">Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqstqpsr2dvx074qchuamx8t065pl995ytrx7ca8sfygk3vw37qlu6czypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wcrypt7" />
    <content type="html">
      Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code&lt;br/&gt;&lt;br/&gt;Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remote code execution.&lt;br/&gt;&lt;br/&gt;The vulnerability, tracked as CVE-2026-32475, carries a CVSS score of 9.0 out of 10.0. It has been described as a case of unrestricted upload of a file with a dangerous type.&lt;br/&gt;&lt;br/&gt;&amp;#34;The flaw lives in the Forms module&amp;#39;s File&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEitKWjeNJOL_DEahUmMAYpH9qh94s2iFi8igtfSlAzOVWiUBU-EIM0MWMsFYPmA5NDL6Rs9E-w9vvCmw3Cc6Og0q-TDt87Q2hwYIePNAQ0xQ3OJYHzgCizDFm-YK9SxW4ncWnuVLaOzgb3SPO7Qpx17zHMaFzBQfYllgz5IP-p1jMALgWlasRkj1nV3Tq3G/s1600/wordpress.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/08/elementor-pro-flaw-could-let.html&#34;&gt;https://thehackernews.com/2026/08/elementor-pro-flaw-could-let.html&lt;/a&gt;
    </content>
    <updated>2026-08-20T06:04:34Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqst4r7hf6z23f7yp7ku3cjjgl03y4088v4au6tuq5ngjy89488r98szypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w40efkz</id>
    
      <title type="html">StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqst4r7hf6z23f7yp7ku3cjjgl03y4088v4au6tuq5ngjy89488r98szypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w40efkz" />
    <content type="html">
      StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data&lt;br/&gt;&lt;br/&gt;Cybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to disseminate malware, commandeer infected hosts, store stolen documents, screenshots, and activity logs created to track the status of the activity.&lt;br/&gt;&lt;br/&gt;&amp;#34;The operation doesn&amp;#39;t rely on a single piece of malware, but on a whole toolkit of criminal software&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiHtWFBMa_xYpIkK39I2gvAJrksqJBAkRSnEZ-WjwpQtbV9mgfPRzWp3qtdhk_v1yOG67pAZ5H3DAFRVv7rEzbns9IuAa4_DV-MUBDIb6fuWzLyRvFXyC1fOaTUPbwxdoY4cykbPy3wXEn3HvlnbjbqH37vkLKMSJA799pVeD50RqMGlJJztFJZcFzR2xTf/s1600/wordpress-hacks.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/08/stopandprotect-uses-nearly-2000-hacked.html&#34;&gt;https://thehackernews.com/2026/08/stopandprotect-uses-nearly-2000-hacked.html&lt;/a&gt;
    </content>
    <updated>2026-08-19T11:25:28Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqsrlegz0m3n23dc67k8exxr2vd00l9cejf2j5l75wt3902qldcj4pgzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w8p9669</id>
    
      <title type="html">16 Typosquatted RubyGems Packages Steal Browser Credentials and ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqsrlegz0m3n23dc67k8exxr2vd00l9cejf2j5l75wt3902qldcj4pgzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w8p9669" />
    <content type="html">
      16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets&lt;br/&gt;&lt;br/&gt;Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer.&lt;br/&gt;&lt;br/&gt;OpenSourceMalware, which discovered the activity on August 15, 2026, is tracking the threat under the moniker StubMaker. The complete list of packages published as part of the campaign is below -&lt;br/&gt;&lt;br/&gt;  ubnuler&lt;br/&gt;  ubnlder&lt;br/&gt;  ri18nr&lt;br/&gt;  reaker&lt;br/&gt;  rakier&lt;br/&gt;  orakw&lt;br/&gt;  joxn&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi9BsXf9I7m4IoC0hb3fSwYiBJsaB1_vSj9kGhfi0HsWGeR0xVl_W1O_Z0bd6IxvQ-vUQP5FDsj5mpiwUjv72JG3vNdViDwAKDG1uswOPDfb84xN_n8AgafhIP2sCx8x1Jd4L0mptrXuzCCGze-safV0V13WiWsFbKrKYvIC6CPBncYuhwgaDafyqSJx9Kv/s1600/ruby.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/08/16-typosquatted-rubygems-packages-steal.html&#34;&gt;https://thehackernews.com/2026/08/16-typosquatted-rubygems-packages-steal.html&lt;/a&gt;
    </content>
    <updated>2026-08-18T11:40:06Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqsdmqhdszm6trr4rg6ktc72vs8qrlzet83ae9w73yqjhwjkf40rudqzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w5yhhar</id>
    
      <title type="html">SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqsdmqhdszm6trr4rg6ktc72vs8qrlzet83ae9w73yqjhwjkf40rudqzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w5yhhar" />
    <content type="html">
      SafePal Hardware Wallet Maker Says Flaw Exposed Data of Nearly 40,000 Customers&lt;br/&gt;&lt;br/&gt;SafePal has disclosed that an authorization flaw in an order-tracking plug-in exposed the names, email addresses, shipping addresses, phone numbers, and purchase details of approximately 39,798 customers.&lt;br/&gt;&lt;br/&gt;The hardware wallet maker said all affected customers were notified individually by email on August 16 from security@safepal.com, with the subject line &amp;#34;[Important] Your SafePal Order&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiFTKWlpW6A2F_jXpwDsCbJmaJ7-TnZPoCNsW0BG5pa4F8X8I1zzCRAMefU00NEQHKlqdqGchFbSTQ_aADgjlJeIHpUKswwnwNiP7WnbAftpciT_4FAFzPKi5NYnBtI0R0VEhP4JIHXFpm6hhyQFASu7IP1kFP2FmlLVejJDiG3Tgxf2ofz-J0Aq02AoF8/s1600/safe.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/08/safepal-hardware-wallet-maker-says-flaw.html&#34;&gt;https://thehackernews.com/2026/08/safepal-hardware-wallet-maker-says-flaw.html&lt;/a&gt;
    </content>
    <updated>2026-08-18T09:10:45Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqstdhuwddmhg4wcy3qvs4rfl2yjakuecjpn5pfv2tw5fp9mtrv9z7czypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0ww8c4dk</id>
    
      <title type="html">Attackers Compile khunt Inside Oracle to Turn SQL Injection Into ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqstdhuwddmhg4wcy3qvs4rfl2yjakuecjpn5pfv2tw5fp9mtrv9z7czypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0ww8c4dk" />
    <content type="html">
      Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access&lt;br/&gt;&lt;br/&gt;Attackers broke into an organization&amp;#39;s Oracle database through a SQL injection flaw in a public-facing web application, then installed a post-exploitation toolkit without writing an executable to disk. They fed Java source code to the database, let Oracle compile it into stored schema objects, and ran commands from inside the database engine.&lt;br/&gt;&lt;br/&gt;Huntress, which tracks the toolkit as khunt,&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgWGMHYrRkDGf3XV_lOoUbE1UCSjvcN9x-XNpNGpX_f45JqZzd2FrxJ-metvu-U5VyDqH2PGNaY9MiSeShhH-YVN3O4ryN5lh4ICsuXtz0-DuCSAgnywXUifDOf_qZS81AtjRGNQWgs1QnL4Eu54icswla_ZK7qGoZqWDaVzPX46pmcTrvj_ec0yQwrt9k/s1600/oracle-root.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/08/attackers-compile-khunt-inside-oracle.html&#34;&gt;https://thehackernews.com/2026/08/attackers-compile-khunt-inside-oracle.html&lt;/a&gt;
    </content>
    <updated>2026-08-06T09:19:23Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqsrudxp4rvxsul8tw5x7ulx5t6fm0h37ec64gdzq0zhtwxepnc58rszypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w7yz70q</id>
    
      <title type="html">Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqsrudxp4rvxsul8tw5x7ulx5t6fm0h37ec64gdzq0zhtwxepnc58rszypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w7yz70q" />
    <content type="html">
      Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens&lt;br/&gt;&lt;br/&gt;The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and seize control of user accounts.&lt;br/&gt;&lt;br/&gt;&amp;#34;Greatness supports AiTM [adversary-in-the-middle] credential and&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi8YRyOCSodUbPpWMicgOiuGbEQWDBmu_W-47PAUFkS7yKEQe4Do6svH4cQb-U0tC53C9mqq8ijjlG9gwuzyqYfNwtS61WxvNxIgk1dVC7wX598rncb_MgQ5t4yxc8NUYVdb6PT5cu7ZXJ7w3KaYG_7vtU5xixHel1jSADbtR-GC1bmngZPArXw-NjkTH1x/s1600/Greatness.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/08/greatness-phaas-adds-device-code.html&#34;&gt;https://thehackernews.com/2026/08/greatness-phaas-adds-device-code.html&lt;/a&gt;
    </content>
    <updated>2026-08-04T17:27:39Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqst9n6d39jd22y3uwvtye8kfpt4aj8c6melf0h6z2jsgwkvmp2lzaqzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wjsp4tu</id>
    
      <title type="html">Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqst9n6d39jd22y3uwvtye8kfpt4aj8c6melf0h6z2jsgwkvmp2lzaqzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wjsp4tu" />
    <content type="html">
      Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS&lt;br/&gt;&lt;br/&gt;An unknown Chinese-threat actor has been observed running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the DarkSword exploit kit.&lt;br/&gt;&lt;br/&gt;Attack surface management platform Censys said it identified the threat actor running more than 100 web properties, most of which are fake Amazon Web Services (AWS) sign-in pages on a domain that also hosts the exploit toolkit.&lt;br/&gt;&lt;br/&gt;&amp;#34;&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgvbg0AbgcDL8IouGo4deahk3vOuegzB-hxhUxAok05EuI5uuYJUDP-mUVS1w-gr9Oedf6JzF9qEB3l8MWVnsFGkmZ4ZorInHavwKWrQ7toTmv64uc4EnJdoFDqGlDPQsgcTwnJo8rlZyfG9yFu60fNE51Di00aVdZoiv5YMIvobc6xuWZhT_cKDk3ikV-P/s1600/apple.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/08/chinese-threat-actor-uses-leaked.html&#34;&gt;https://thehackernews.com/2026/08/chinese-threat-actor-uses-leaked.html&lt;/a&gt;
    </content>
    <updated>2026-08-03T10:49:06Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqsr3tv5y5scdy40gfyznmgrskcqwg8xq3exek7gvu46a86ze3h6u2gzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wp85jny</id>
    
      <title type="html">Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqsr3tv5y5scdy40gfyznmgrskcqwg8xq3exek7gvu46a86ze3h6u2gzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wp85jny" />
    <content type="html">
      Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory&lt;br/&gt;&lt;br/&gt;Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution.&lt;br/&gt;&lt;br/&gt;The vulnerability, tracked as CVE-2026-59726 (CVSS score: 10.0), impacts all versions of the project before version 3.16.3. It has been codenamed RufRoot by Noma Security&amp;#39;s&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhCgiIKxPiETcU1yIlU2RFsHgjXg2uLgbzaJ-98y7sPuujYarFbc0FdMqSRLIKJ1hYrsGLCZTCf5k40RtQ2PgwmA2L6tLAidOymHNIduXN3vtU0u0BsI37PLgWK8gwla3oTYkdD8ggssjMfF_5PuC9-exVYpBcqjg9tvscJ7XNAaHJxeUmCj-WP8VttRSgy/s1600/mcp.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/07/ruflo-mcp-flaw-lets-unauthenticated.html&#34;&gt;https://thehackernews.com/2026/07/ruflo-mcp-flaw-lets-unauthenticated.html&lt;/a&gt;
    </content>
    <updated>2026-07-29T15:39:30Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqs0jdmrc4wtd3twyerqvv0dyp0gjszvsydfgag0sw7pexa20t9gslczypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wwgnhlr</id>
    
      <title type="html">The Federal Security Service of the Russian Federation (FSB) on ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqs0jdmrc4wtd3twyerqvv0dyp0gjszvsydfgag0sw7pexa20t9gslczypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wwgnhlr" />
    <content type="html">
      The Federal Security Service of the Russian Federation (FSB) on Wednesday said it charged Telegram founder Pavel Durov for allegedly facilitating terrorist activities and for failing to remove prohibited information in violation of Russian law.&lt;br/&gt;&lt;br/&gt;The principal security agency said the instant messaging platform &amp;#34;failed to remove numerous channels, chats, and bots on the platform that are&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjMUnFYtFjTBTc4gylDAEu-XkRP-crArKjOPCGhPhdX7S3Of7UKlVyAbHVb9CyAStiVaXJkXjUgXssYTKSJNnQvJvxdn_diL69NGa-2lhE_6GJCBFp0qMshbqCPnCksje_5yYMqhqh43Np9-CEkjJDa_gs6Axq0lxbi12SlPKqPWf-s6_Roin-zR0DIBjvy/s1600/x-post-telegram.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/07/russia-charges-telegram-founder-pavel.html&#34;&gt;https://thehackernews.com/2026/07/russia-charges-telegram-founder-pavel.html&lt;/a&gt;
    </content>
    <updated>2026-07-29T11:00:00Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqs97xlxha0890a3fqhkp3xetcvj8mdn6ysxsuk462myghsr59rwauczypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0waevwrj</id>
    
      <title type="html">Public PoC Released for Exploited Check Point SmartConsole ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqs97xlxha0890a3fqhkp3xetcvj8mdn6ysxsuk462myghsr59rwauczypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0waevwrj" />
    <content type="html">
      Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass&lt;br/&gt;&lt;br/&gt;Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Management Server and Multi-Domain Security Management Server (MDS) that has come under active exploitation in the wild.&lt;br/&gt;&lt;br/&gt;The vulnerability, tracked as CVE-2026-16232 (CVSS score: 9.3), is an authentication bypass in the SmartConsole login process that&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiIxq_zUC231fexQTfY9VPvqP7FWVRurT9fbUUS3YMpMX2SRmJu9eXIlH7v6fnvqJGtirQwXJVjs1h-hbUM7j-R6DlfpW7M4kt28q9EoxMt7jJFjUjaAoVsuTWSsBZOFcDj99U8ApvFR4B4sDQ37QHYeWXjJsowFBP3n8-TBfzcKB2Rl-de-OluIkzbJIYb/s1600/cp-poc.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/07/rapid7-releases-poc-for-exploited-check.html&#34;&gt;https://thehackernews.com/2026/07/rapid7-releases-poc-for-exploited-check.html&lt;/a&gt;
    </content>
    <updated>2026-07-29T08:58:27Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqsxrnq8xdmg58wsgtjlhtdfnq0pawmxgy2ghtxutpm5rj3pjpxhnaszypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wzth7qh</id>
    
      <title type="html">Two Compromised joyfill npm Packages Run RAT When Imported Into ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqsxrnq8xdmg58wsgtjlhtdfnq0pawmxgy2ghtxutpm5rj3pjpxhnaszypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wzth7qh" />
    <content type="html">
      Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js&lt;br/&gt;&lt;br/&gt;Beta release versions of two npm packages in the @joyfill namespace have been compromised to deliver a remote access trojan (RAT) associated with the DEV#POPPER malware family.&lt;br/&gt;&lt;br/&gt;The list of affected packages is as follows -&lt;br/&gt;&lt;br/&gt;  @joyfill/layouts@0.1.2-2773.beta.0&lt;br/&gt;  @joyfill/components@4.0.0-rc24-2773-beta.4&lt;br/&gt;&lt;br/&gt;The two packages &amp;#34;contain an import-time JavaScript implant that resolves encrypted code&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjbnnos_l5g9tfmBH7efqHHPJs-C6Ti9zjG9iifZXs0QLLoUn7L1BwkunpqbD55rRvqSiJx0R_DTAl12TBnL9MN0DkDtzhwnm8Xgbsbu8LZuKyRDnVtq3cbeMlEmNJEmZgXy3BeOILj2kM24GojxXfDJDr93XsEiORhP9q1sYo814jzq4UsQCS0RRZmhp5k/s1600/npm-hack.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/07/two-compromised-joyfill-npm-packages.html&#34;&gt;https://thehackernews.com/2026/07/two-compromised-joyfill-npm-packages.html&lt;/a&gt;
    </content>
    <updated>2026-07-29T04:20:57Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqsfk7v3y48yvw8kfnljq2qvgg4tk5xv0xl2u669eld00ay48j2t2gszypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wq7vvqs</id>
    
      <title type="html">Researcher Publishes GitLab RCE PoC Letting Authenticated Users ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqsfk7v3y48yvw8kfnljq2qvgg4tk5xv0xl2u669eld00ay48j2t2gszypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wq7vvqs" />
    <content type="html">
      Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git&lt;br/&gt;&lt;br/&gt;Security researcher Yuhang Wu at depthfirst has published a working proof-of-concept (PoC) exploit that executes commands as git on an unpatched self-managed GitLab 18.11.3 server.&lt;br/&gt;&lt;br/&gt;An ordinary authenticated user triggers it by committing two crafted Jupyter notebooks and requesting their diff. The chain needs no administrator rights, continuous integration (CI) runner access, victim interaction&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgRIN1sheAdScq7AX9pLc07esRzQ18-0vBJ7hz9DlVhggVAImXrhYM_zxN0N6hJ2inDkBCnzRCXHR3Kv3I0QwyiVWkAMu7p949JSjgK611r48deMbrSN8iDD78aJdfxEeO_Jy6JFwOfPL_8M0RKEBl1RFO7ufvop1XG9-tdms7VRyvONXoteuCYp9Rg-FM/s1600/gitlab.gif&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/07/researcher-publishes-gitlab-rce-poc.html&#34;&gt;https://thehackernews.com/2026/07/researcher-publishes-gitlab-rce-poc.html&lt;/a&gt;
    </content>
    <updated>2026-07-25T08:34:15Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqsgg4wv3r57qddv6lqtkjzxaqxh4sp89v4nwvj8nlhrpv32g9d4s3gzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wsps4hw</id>
    
      <title type="html">Seeing AI Agents Is Not Enough. Security Teams Must Enforce What ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqsgg4wv3r57qddv6lqtkjzxaqxh4sp89v4nwvj8nlhrpv32g9d4s3gzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wsps4hw" />
    <content type="html">
      Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do&lt;br/&gt;&lt;br/&gt;AI agent security is moving through a familiar maturity curve: adoption, then visibility, and finally, control. But what we&amp;#39;ve collectively discovered is that enforcing least privilege for AI agents is harder than we ever imagined. This is why there are so many approaches, from prompt filtering to identity-layer access controls. Where we&amp;#39;ve collectively landed is that understanding the intent of&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhrpwR_tXhzpbt7F1FuALLW8MYrTuwWibwuWjsRDROepxJKdbvSNlbcZLHbL54SmyG_Q_oYFTjI5fqkudKNtfJkg68jAz4STq0xXHEOXnMeOq7fxPz2UslZesQBy_pWKn3IKYNEbltVsjbZDypkqi56JOeznD5hcGEKO6yB-qS2l5cPHlcX0cli_WOHNGM/s1600/pixer.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/07/seeing-ai-agents-is-not-enough-security.html&#34;&gt;https://thehackernews.com/2026/07/seeing-ai-agents-is-not-enough-security.html&lt;/a&gt;
    </content>
    <updated>2026-07-24T11:30:00Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqsv7dh8hc9g8wnwvsvuufay370jz38jug0rkayysp4qh93mjd284fszypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0ws8ktu3</id>
    
      <title type="html">Fake Notepad&#43;&#43; Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqsv7dh8hc9g8wnwvsvuufay370jz38jug0rkayysp4qh93mjd284fszypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0ws8ktu3" />
    <content type="html">
      Fake Notepad&#43;&#43; Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks&lt;br/&gt;&lt;br/&gt;The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious program that&amp;#39;s dressed up as a Notepad&#43;&#43; plugin to compromise Windows systems.&lt;br/&gt;&lt;br/&gt;The activity has been attributed by the agency to a threat cluster it tracks as UAC-0099, a Russia-aligned group that has previously observed weaponizing security flaws in WinRAR software to&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiCA0-yh9EAnhFa2V3NzQVw2m-sLgbCNVQ8GVMBX4Y6vUNwPXE-vHzdJLFKXVi3rdGXhx5RawHTwox7cd9ph20u5qn_H8TJUOKG8nITccTkzqfiyBKStdCgcrJOgAeGf9Mkzr1g8iCB0HrpuonkIQQTx15L2P53RPX9GeMYVIuvl51jJ2hn1jn0PcQARQaj/s1600/notepad-malware-code.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/07/fake-notepad-plugin-delivers.html&#34;&gt;https://thehackernews.com/2026/07/fake-notepad-plugin-delivers.html&lt;/a&gt;
    </content>
    <updated>2026-07-24T06:50:57Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqsfyezjn7p47pwcacw78t37azgvt4r4nhhf9q5p3cedlmdtc46juxszypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wnyczhs</id>
    
      <title type="html">Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqsfyezjn7p47pwcacw78t37azgvt4r4nhhf9q5p3cedlmdtc46juxszypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wnyczhs" />
    <content type="html">
      Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes&lt;br/&gt;&lt;br/&gt;A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra&amp;#39;s webmail client.&lt;br/&gt;&lt;br/&gt;The payload goes after the last 90 days of email, the organization&amp;#39;s entire email directory, the password saved in the browser and the codes kept for two-factor recovery. Opening the message was enough to start it.&lt;br/&gt;&lt;br/&gt;The NSA, CISA and partner agencies published&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjzlA3Ln3fk8yzrfLwR9egB99u67BL7NlRui9XkKviyXhFmZ3sYVTF5laSjHTwyphN51YvL39R0irNNPn2hDpVcn6EFi_NmuuSH3XTS9I71aPdZvgZRTOxXczmyqbSkcpqSy2TgOzSSJ0RzAyeQA4YXED73kIChZFtiuZ1fIVzCFvDJK4bEJ5M6Sj-qPeI/s1600/zimbra-email.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/07/russian-espionage-group-exploited.html&#34;&gt;https://thehackernews.com/2026/07/russian-espionage-group-exploited.html&lt;/a&gt;
    </content>
    <updated>2026-07-23T18:36:08Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqsz9eprw50e7mzwg7nzwmk4g26mv5rru3947654l47xcz30lvq04wqzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wvcxdzt</id>
    
      <title type="html">Why Modern SOCs Need Multi-Layered Detections The cycle is over. ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqsz9eprw50e7mzwg7nzwmk4g26mv5rru3947654l47xcz30lvq04wqzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wvcxdzt" />
    <content type="html">
      Why Modern SOCs Need Multi-Layered Detections&lt;br/&gt;&lt;br/&gt;The cycle is over. For years, cybersecurity followed a familiar pattern: defenses improved, attackers adapted, and the back-and-forth continued. Today, AI-equipped attackers are simply outpacing defenses. Most intrusions now bypass endpoint and malware-based detection entirely.&lt;br/&gt;&lt;br/&gt;The CrowdStrike Global Threat Report estimates around 79% of attacks are malware-free, as threat actors rely on&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgA_BCT5VYzHAi2ZYmYF84NAe3JitSR-U0uk4JZeuJf-hgHgwMXRj1_44z0DfwmtHqFZMxeEYGHR4AlvuIe-_4oAGvQlVnCm9peV1-H0nZ__XbPIcKlz_7RxoPuR7C2IMBZ7B27ABzkk9Zv08DOaKAefwt72n8H0WBP8Z8TBajQwEzBt10hFwE3-70o0A5V/s1600/corelight.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/07/why-modern-socs-need-multi-layered.html&#34;&gt;https://thehackernews.com/2026/07/why-modern-socs-need-multi-layered.html&lt;/a&gt;
    </content>
    <updated>2026-07-22T11:25:35Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqswmljtfq6fjpy9y6germjglgapcurkg8daks3qmarc8whkgzcc52czypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wna3rnx</id>
    
      <title type="html">Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqswmljtfq6fjpy9y6germjglgapcurkg8daks3qmarc8whkgzcc52czypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wna3rnx" />
    <content type="html">
      Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access&lt;br/&gt;&lt;br/&gt;Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments.&lt;br/&gt;&lt;br/&gt;Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with the exploitation of CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgP1HNhUk3hMm0HOAQBAVExGT5-PQfrxeAtKrKRpG_eaXz5qEtVKiuH4-nOVMVdbtZ5XVzfk-hM-eFwpS0IAZNpGkp2DmE4wiNauEA3GT-t1UtLNGjtyVuDRPezJSyj4jEw8zeNgoPnyloZe_6K_vM1-nfYYoehFdoWRgVzVnmJUF3wwfamG0BgDdN1BvMJ/s1600/ransomware-attack.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/07/qilin-ransomware-attackers-exploit-pan.html&#34;&gt;https://thehackernews.com/2026/07/qilin-ransomware-attackers-exploit-pan.html&lt;/a&gt;
    </content>
    <updated>2026-07-21T14:04:57Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqs0kczy8x25ug78uevekgq05v892dzque5v0hg4f6tzr0pq4w5rp7szypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wwhmlyx</id>
    
      <title type="html">WordPress wp2shell Exploitation Grows as Public Exploit Fuels ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqs0kczy8x25ug78uevekgq05v892dzque5v0hg4f6tzr0pq4w5rp7szypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wwhmlyx" />
    <content type="html">
      WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning&lt;br/&gt;&lt;br/&gt;Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites.&lt;br/&gt;&lt;br/&gt;The two security flaws, tracked as CVE-2026-63030 and CVE-2026-60137, have been codenamed wp2shell.&lt;br/&gt;&lt;br/&gt;&amp;#34;By the early hours of Saturday morning (UTC), successful exploitation was already well&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh4qOga3YGcLZ3JclK_mkOkQ-pRmQowUUqu6Hp3fj1QTmsNuuhkSj4OiFqgAtL7e6yeGkv-K1jC0v4bRayI40oDQ8UMeYishuNzRap3E5RYmIEbjRbmq-uAk4iWKWwIfMdNi6owJrVWE_3fcWzj5lZgVm9P96ddcqghwnp3rGx3pM3N6hck6UiaFUgVRbtC/s1600/wordpress-ex.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/07/wordpress-wp2shell-exploitation-grows.html&#34;&gt;https://thehackernews.com/2026/07/wordpress-wp2shell-exploitation-grows.html&lt;/a&gt;
    </content>
    <updated>2026-07-21T08:59:30Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqsxeyay6380pw4lanxwysgs7mupunp9yzdfz942uff6vf3a3smzg9gzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wwm745n</id>
    
      <title type="html">New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqsxeyay6380pw4lanxwysgs7mupunp9yzdfz942uff6vf3a3smzg9gzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wwm745n" />
    <content type="html">
      New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack&lt;br/&gt;&lt;br/&gt;Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator it first documented earlier this month.&lt;br/&gt;&lt;br/&gt;The same operator has now been spotted deploying ENCFORGE, a new compiled Go ransomware designed to encrypt model weights, vector indexes, training datasets, and other AI infrastructure files across the host filesystem.&lt;br/&gt;&lt;br/&gt;The entry&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjDTNXJkg3w9ziG7euHnlaoQkTjogtjIhtwE-ZudPv_9wOpJUCUNVc-i_BtBkDTCflKzRSfUOEp5xHyRWAOcQWv18pf2kv9-yuI75SOM52X3akV3VrguZf6GDH9MZejxFG7FoJGMIgARuiWyncCOmNznSofFT8Fn9Zu2ZGmk0V_Ni3niha2I9qAO59VKHw/s1600/ransomware-ai.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/07/new-encforge-ransomware-targets-ai.html&#34;&gt;https://thehackernews.com/2026/07/new-encforge-ransomware-targets-ai.html&lt;/a&gt;
    </content>
    <updated>2026-07-21T07:34:32Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqszmp5l306w9qejln6aa90vn4waacxh4uyuwk2hjz66nr7uwrqus5czypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0ws5rv90</id>
    
      <title type="html">Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqszmp5l306w9qejln6aa90vn4waacxh4uyuwk2hjz66nr7uwrqus5czypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0ws5rv90" />
    <content type="html">
      Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution&lt;br/&gt;&lt;br/&gt;Open a repository in Cursor on Windows and, if a file named git.exe is sitting in the project root, Cursor runs it. No click, no approval dialog, no warning that anything in the folder is about to execute.&lt;br/&gt;&lt;br/&gt;Whatever that binary does, it does as you, with your source, your SSH keys and your cloud tokens. Cursor keeps re-running it for as long as the project stays open.&lt;br/&gt;&lt;br/&gt;No prompt&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjyFnrtjbcXdDBTEYOhVnUpFO4CSqhCGj5xdvaYlhih4oUCd3phzBQTjjMogZeFDlYqTiO8Xt2jaHevba5peaV76dT417Vq9W-DZFSpu2_cEbAMtGwz-mqKZJcYgAAXmZT_Rnkdc0f3jAW-eANKWd6XZZJvYfYCt6l5Pp-2ZKjlnn4zG7G6gS7ivWruzeU/s1600/git.png&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/07/cursor-flaw-lets-malicious-cloned.html&#34;&gt;https://thehackernews.com/2026/07/cursor-flaw-lets-malicious-cloned.html&lt;/a&gt;
    </content>
    <updated>2026-07-15T10:55:22Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqs0ws4vxmxdscvawrj29p6csv57j3lmflml7gs92jupplm0gghpxqczypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w9arxwc</id>
    
      <title type="html">⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqs0ws4vxmxdscvawrj29p6csv57j3lmflml7gs92jupplm0gghpxqczypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w9arxwc" />
    <content type="html">
      ⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More&lt;br/&gt;&lt;br/&gt;Somewhere right now, a security tool is quietly finding bugs faster than any human can fix them. That&amp;#39;s supposed to be the good news. The catch is that the attackers have the same tools, pointed the other way, and they don&amp;#39;t file tickets.&lt;br/&gt;&lt;br/&gt;That&amp;#39;s the shape of this week. Trusted code turns on the people who installed it. Old bugs from last year are still landing because the fix sat in a queue too&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjuCIplQpj7CGra4jEeX4qO6DfR9_OazwL_c55clD60cy9pWK42qAsCmqrwe0YBUmPq0cg_6Gt52VlqoOGuigf4qwI8lazIdogbl8pjBDfprTbktGn96fxMbtCh06kyGFF9qCXg9PgMhSXu8V02QBxTmBArc-84ZI3jXwmoDQdj-SCp-_JY7z5XqrQR2IlP/s1600/monday-recap.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/07/weekly-recap-sharefile-threat-citrix.html&#34;&gt;https://thehackernews.com/2026/07/weekly-recap-sharefile-threat-citrix.html&lt;/a&gt;
    </content>
    <updated>2026-07-13T15:05:57Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqst4ng24ps6xcs8artd5axp9g8rd5vcgg2npztjzqfen39dr4ghpmgzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0weghajf</id>
    
      <title type="html">Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqst4ng24ps6xcs8artd5axp9g8rd5vcgg2npztjzqfen39dr4ghpmgzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0weghajf" />
    <content type="html">
      Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers&lt;br/&gt;&lt;br/&gt;A single wrong variable on one line in XQUIC, Alibaba&amp;#39;s QUIC and HTTP/3 library, lets any remote client crash the server with a short burst of completely legal traffic. There is no patch.&lt;br/&gt;&lt;br/&gt;FoxIO researcher Sébastien Féry disclosed the flaw on July 8 and nicknamed it XRING. He says it needs no login and no malformed packets: about 260 bytes of ordinary QPACK traffic takes the server&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjQHphr7bXE4J4-EmYSWy0cjHarUBibR2JrXpFbwDKMZnsWbiUsC9UE7g3x2r8WFDLB7BBZlH2kDJ3I9QqF8IIGLPiZda93wKUaDqJC8Nv11yrd7VPm9RmBOky0yRXGRhhcDqbwNCZvHiGTkKRb06XAwFiGl0juzUeFBn3LUDwFfxZVNlInVmXTNI4cMLI/s1600/XQUIC-demo.gif&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/07/unpatched-xring-flaw-in-xquic-lets.html&#34;&gt;https://thehackernews.com/2026/07/unpatched-xring-flaw-in-xquic-lets.html&lt;/a&gt;
    </content>
    <updated>2026-07-10T11:47:43Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqsdy03t932fj55h23gs7mwf3a33yfewvdrg8eqr6u7utdf9zrmwsdqzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wj6cjd9</id>
    
      <title type="html">Dormant GitHub Accounts Help Attackers Blend In While Mapping ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqsdy03t932fj55h23gs7mwf3a33yfewvdrg8eqr6u7utdf9zrmwsdqzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wj6cjd9" />
    <content type="html">
      Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs&lt;br/&gt;&lt;br/&gt;Datadog Security Labs is warning of &amp;#34;several overlapping campaigns&amp;#34; that are systematically enumerating corporate GitHub organizations, repositories, and user accounts through the GitHub API.&lt;br/&gt;&lt;br/&gt;&amp;#34;Operators rely on automated scraping tooling with custom or legitimate-sounding user agents, leveraging GitHub &amp;#39;ghost&amp;#39; accounts that are often years old, or compromised OAuth tokens and personal&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiDslymdYqhkFwIm3ZeaXVZweYVT_R1d6LCQhIm799y9-5hQ3C45cumIStxGYheFbwosbd_JtrB6FgOthR2KJgfe8PYs0k47eGV7263ATac5UR0t7OOaqOUGOf5DHAR4b0IaKTozk0UEiHJz5-nze3b1ureycPGqdPVlqrImWreOWwMpGxC8kgBvONCLGbH/s1600/github-ghost.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/07/dormant-github-accounts-help-attackers.html&#34;&gt;https://thehackernews.com/2026/07/dormant-github-accounts-help-attackers.html&lt;/a&gt;
    </content>
    <updated>2026-07-09T18:38:49Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqs8gwpk4tr62qkgt2nmw0xtfh7mk07keupj5tzfv66xxyw2ghv3q3czypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w63w5zv</id>
    
      <title type="html">15-Year-Old GhostLock Flaw Enables Root and Container Escape on ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqs8gwpk4tr62qkgt2nmw0xtfh7mk07keupj5tzfv66xxyw2ghv3q3czypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w63w5zv" />
    <content type="html">
      15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros&lt;br/&gt;&lt;br/&gt;Researchers at Nebula Security have disclosed GhostLock (CVE-2026-43499), a 15-year-old Linux kernel flaw that lets any logged-in user take full root control of a machine that has not been patched.&lt;br/&gt;&lt;br/&gt;The vulnerable code has shipped by default in essentially every mainstream distribution since 2011. The flaw needs no special permission, no unusual settings, and no network&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEid8ZRwAprNDN6zAPixm22IlrKWp03FJdQF0TxCV5v_jxckPLkOHRSzHQERbDNw_FZdnyluuhyphenhyphenGZ7pSX51cjBl-S8PrqhgARlAe8VfWPabk7t4hAy37ZSrRu6oXfRYlXP7s1x1OBYW9WHmgWobGS0wiC0mrO42xHWHrSI3ICLM5OFzsOA3tVCcs4_N1yPU/s1600/linux-root.gif&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/07/15-year-old-ghostlock-flaw-enables-root.html&#34;&gt;https://thehackernews.com/2026/07/15-year-old-ghostlock-flaw-enables-root.html&lt;/a&gt;
    </content>
    <updated>2026-07-08T06:16:44Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqsqdfnpre73x9p99tnyhh43cz7ajz9xpvdm6gewellcmrunenl7auqzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w867dg3</id>
    
      <title type="html">⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqsqdfnpre73x9p99tnyhh43cz7ajz9xpvdm6gewellcmrunenl7auqzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w867dg3" />
    <content type="html">
      ⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More&lt;br/&gt;&lt;br/&gt;A streaming box should not need a threat model. Neither should a username field, a demo repo, a reset flow, or a browser permission prompt. That is the irritating part this week: the risky pieces were ordinary.&lt;br/&gt;&lt;br/&gt;Home devices became a routing cover. Clean code pulled dirt from a dependency. Identity shortcuts aged badly. AI systems trusted the wrong instructions. Same soft spot throughout: trust&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjLyTSo2j_jLDBALDaJ6S4gpQf2xkxgGWRslJKuVLIrY-J7nsEG-zNgi02OKeABO5BNXCI1C05oTO1TdYYMtzjCHE7ugevubBOybwilFTXFY6wgXDBVkzMV3-cyYyZUfd-sfXmlfTtgyouay2kJYwxfclTk2M6PPOaLWdR-26P3TYuIm1l5wjQfoPVzk-ca/s1600/recapss.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/07/monday-recap-proxy-botnets-browser.html&#34;&gt;https://thehackernews.com/2026/07/monday-recap-proxy-botnets-browser.html&lt;/a&gt;
    </content>
    <updated>2026-07-06T13:01:14Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqs9pa4554xttewtl7apsu8nkhyel6vky084lfaqkgywft6x258rrsszypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w2gyjme</id>
    
      <title type="html">New TrojPix Attack Leaks Data From Air-Gapped Systems via Video ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqs9pa4554xttewtl7apsu8nkhyel6vky084lfaqkgywft6x258rrsszypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w2gyjme" />
    <content type="html">
      New TrojPix Attack Leaks Data From Air-Gapped Systems via Video Cable Emissions&lt;br/&gt;&lt;br/&gt;Researchers at Shandong University have shown a fast new way to pull data off computers that are cut off from every network. The technique, called TrojPix, tweaks on-screen pixels in ways the eye cannot see, so that the video cable carrying them radiates a faint radio signal a nearby receiver can decode.&lt;br/&gt;&lt;br/&gt;But TrojPix works only once malware is already on the target machine, so it&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhLYJDaMKVJEwbsJA1eYJaguihQzJv2dpnIl512z5xBuWojpidgE7mvbGWz27QN-Dnwx74qvCYOYGQNY4h2K00TzF_hz8D6M9gNxWALh2f2bz6jrzwuKvTuuLsb6kwU1O72qPUIjQYHtRwGPCCUYt-TDFJEZ7frhvxvsQa4vWP7HkLRPtXCi0ovIACzurMP/s1600/TrojPix-attack.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/07/new-trojpix-attack-leaks-data-from-air.html&#34;&gt;https://thehackernews.com/2026/07/new-trojpix-attack-leaks-data-from-air.html&lt;/a&gt;
    </content>
    <updated>2026-07-06T08:50:54Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqswcadw5xkr2xanugpcy07x7sau54m3uprf95m4x27s47e2jgz29xszypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w828zed</id>
    
      <title type="html">Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqswcadw5xkr2xanugpcy07x7sau54m3uprf95m4x27s47e2jgz29xszypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w828zed" />
    <content type="html">
      Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer&lt;br/&gt;&lt;br/&gt;An unknown threat actor has been observed exploiting a recently disclosed maximum-severity security flaw in SimpleHelp to deliver two previously unreported malware families, TaskWeaver and Djinn Stealer.&lt;br/&gt;&lt;br/&gt;The intrusion involves the exploitation of CVE-2026-48558 (CVSS score: 10.0), a critical authentication bypass vulnerability impacting the OpenID Connect (OIDC) flow that an unauthenticated&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgEid1CxvsX2dPrKoA1VzJ6PUhwrXxvSC4ehRmgyaRRCJlP_MFSeOxvwrT2ODJSbQx3E-7bBwBG4YpP3CQGLzojfXEveOgwZgUlcCSf-trk_G0k0Q1_nz4rb1nbRfhXgijfZ9eLDT8v_ATsmqz5AnbNgBuGX7UIc3YwAw1hYZwvzp5Z0eopWNRqTs4W3bP3/s1600/help-hackers.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/06/attackers-exploit-simplehelp-cve-2026.html&#34;&gt;https://thehackernews.com/2026/06/attackers-exploit-simplehelp-cve-2026.html&lt;/a&gt;
    </content>
    <updated>2026-06-30T11:18:47Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqsda9ztlqphzqnfjwpdedfp3k9ew69vy63g28axypschrx0y5g43fczypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w20p8j7</id>
    
      <title type="html">Apple Patches 30&#43; iOS, macOS, Safari Flaws, Including ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqsda9ztlqphzqnfjwpdedfp3k9ew69vy63g28axypschrx0y5g43fczypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w20p8j7" />
    <content type="html">
      Apple Patches 30&#43; iOS, macOS, Safari Flaws, Including AI-Discovered WebKit Bugs&lt;br/&gt;&lt;br/&gt;Apple on Monday released security updates for iOS, macOS, and the Safari web browser to address over three dozen flaws, including four vulnerabilities in WebKit that were discovered using artificial intelligence (AI) tools like Anthropic Claude and OpenAI Codex Security.&lt;br/&gt;&lt;br/&gt;The WebKit vulnerabilities are listed below -&lt;br/&gt;&lt;br/&gt;  CVE-2026-43707 - A memory corruption issue that could result in an&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjgEWbrJH-z_uAL6GFaOqplYF1ewSOBvFpaKD24W74VEBaSO-pW3sy0I0e57Bmc9yBKV4vb6zWYaVjd-oTSy2sSQNSubgQHcmFav_bp3HnySXcSGR-ocRiUfYcXgUXm44XZyrdNnIq2JqJxZQG5bnbui12eVoG3GPgVnGy9AE6vfDp3km5TTtf6rjPv6FZV/s1600/apple-updates-ai.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/06/apple-patches-30-ios-macos-safari-flaws.html&#34;&gt;https://thehackernews.com/2026/06/apple-patches-30-ios-macos-safari-flaws.html&lt;/a&gt;
    </content>
    <updated>2026-06-30T07:15:07Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqstm2ac95e226kasarxzzz9mjcmfgxeg2w2vymg2e2a5wakcyvpw0czypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wh20qfk</id>
    
      <title type="html">OpenAI Previews GPT-5.6 Sol With Restricted Access and Stronger ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqstm2ac95e226kasarxzzz9mjcmfgxeg2w2vymg2e2a5wakcyvpw0czypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wh20qfk" />
    <content type="html">
      OpenAI Previews GPT-5.6 Sol With Restricted Access and Stronger Cyber Safeguards&lt;br/&gt;&lt;br/&gt;OpenAI on Friday released three versions of GPT-5.6, called Sol, Terra, and Luna, as a limited preview to a small number of companies as part of an ongoing engagement with the U.S. government.&lt;br/&gt;&lt;br/&gt;While Sol is the latest flagship model and the most powerful, Terra strikes a balance between efficiency and power, and Luna is fine-tuned for speed and affordability.&lt;br/&gt;&lt;br/&gt;&amp;#34;GPT‑5.6 Sol launches with our most&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiweorWxmIvPG8uskOe44fLur9F5OJvqVdFLV1ejFqQozXruk70nzMhRaY58n4BuMhW1sbsdSvhTrlSxM8U5SLwPdaeRWNi4eQMUjEsFgmGV-37gTdnqk1NXLT4Ixadu4sq_pm0l_HVzuGHaIgcDnV_y092aZ1gCKkZ6lh2bp24PUBUfgsCSgvjlZiKRLMH/s1600/gpt.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/06/openai-limits-gpt-56-rollout-as-sol.html&#34;&gt;https://thehackernews.com/2026/06/openai-limits-gpt-56-rollout-as-sol.html&lt;/a&gt;
    </content>
    <updated>2026-06-27T12:19:37Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqsx0z2msc5j9pgvz4mhjm5r0wtmv8jawajvv295w8tak6xfaczfznszypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w07cgk3</id>
    
      <title type="html">New Linux pedit COW Exploit Enables Root Access by Poisoning ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqsx0z2msc5j9pgvz4mhjm5r0wtmv8jawajvv295w8tak6xfaczfznszypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w07cgk3" />
    <content type="html">
      New Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries&lt;br/&gt;&lt;br/&gt;A flaw in the Linux kernel&amp;#39;s traffic-control subsystem can let a local unprivileged user gain root on affected systems.&lt;br/&gt;&lt;br/&gt;CVE-2026-46331, nicknamed &amp;#34;pedit COW,&amp;#34; is an out-of-bounds write in the packet-editing action (act_pedit) that corrupts shared page-cache memory. A public, working exploit appeared within a day of the CVE assignment on June 16. Red Hat rates the flaw as&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj0PC1aWOiorYx2AGD7fl-IVefJBKPJvjy7sMo5MURoMlaq492QcSdpSqqdGZRZk3u3e6BMS7qVzrJXBuWk-kH4oRqQy1cHTxkvHBLMMbllF9R_rNqL618rz5zEV_FfOvE0_YQgI-VVWbVX772Bc72qSphwMK-TtOAoZ5A9swYpvSNYsFfdR17i8AAXXzDZ/s1600/linux-hack.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/06/new-linux-pedit-cow-exploit-enables.html&#34;&gt;https://thehackernews.com/2026/06/new-linux-pedit-cow-exploit-enables.html&lt;/a&gt;
    </content>
    <updated>2026-06-26T13:00:41Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqs0pmjpwedp8tme9pfh02tsh476rp6lluv6wq9shjpr4fzr5dhkjyqzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wvqtqsp</id>
    
      <title type="html">Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqs0pmjpwedp8tme9pfh02tsh476rp6lluv6wq9shjpr4fzr5dhkjyqzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wvqtqsp" />
    <content type="html">
      Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root Access&lt;br/&gt;&lt;br/&gt;An unknown threat actor exploited a recently disclosed high-severity security flaw impacting Cisco Catalyst SD-WAN as a zero-day at least two months before it was publicly disclosed, according to new findings from Google-owned Mandiant.&lt;br/&gt;&lt;br/&gt;The vulnerability, tracked as CVE-2026-20245 (CVSS score: 7.8), allows an authenticated, local attacker to execute arbitrary commands with elevated privileges&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg3UeGaI_Ej8KFu7-vQHTOuoohYdx04xIdI3W2B6JjCdaTSR6m-y1PAZ-aes-tH9nxtPGO2sFUiu1NwYkwT5s8bDPaHpG8nyN4t_mbZfVjf0nU8L11XujdqERtFUQlMZ85NV_nG6ZhqIQbGdAtyi8p1Oqq7TsBRs1IDn8HvOOnUPFEaL9_2cXrh9eovvaYz/s1600/cisco-20245.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/06/cisco-catalyst-sd-wan-zero-day-cve-2026.html&#34;&gt;https://thehackernews.com/2026/06/cisco-catalyst-sd-wan-zero-day-cve-2026.html&lt;/a&gt;
    </content>
    <updated>2026-06-25T05:46:54Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqs8zljpcf0p8laflqln74sr8gy0j0xfn46nlzjwjsmwdfsfqzclskczypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wjwydjw</id>
    
      <title type="html">GitHub Updates actions/checkout to Block Common Pwn Request ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqs8zljpcf0p8laflqln74sr8gy0j0xfn46nlzjwjsmwdfsfqzclskczypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wjwydjw" />
    <content type="html">
      GitHub Updates actions/checkout to Block Common Pwn Request Attack Patterns&lt;br/&gt;&lt;br/&gt;GitHub is moving to strengthen software supply chain security by updating &amp;#34;actions/checkout&amp;#34; to block pwn request attacks that exploit the risky use of the &amp;#34;pull_request_target workflow&amp;#34; trigger to run malicious code with the workflow&amp;#39;s full privileges.&lt;br/&gt;&lt;br/&gt;Effective June 18, 2026, the latest version of &amp;#34;actions/checkout,&amp;#34; the official GitHub action for checking out a repository into the&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjcacTEKD_LZFda1wwX5aClbAVOb6mwah2lVUY-jUZwNsrSZGDOFL18LP5zYLX3M2DwKng0qknZ5qo_hMk4q-NExgZv1ozhCy7DJuZwvviZE0sv36PQ2k8Y2emv1KMDFplakFwVzulOFPteWkmVoLO6Le912KAbJGFW0nkqKWHEkwJQLbsGhz5npWO3aJaR/s1600/github-actions.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/06/github-updates-actionscheckout-to-block.html&#34;&gt;https://thehackernews.com/2026/06/github-updates-actionscheckout-to-block.html&lt;/a&gt;
    </content>
    <updated>2026-06-23T14:22:03Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqsfjqtf0zlz64gm305a6yfwmgprp54409zrn7lel24tr6hszvtrk3qzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wj7lp99</id>
    
      <title type="html">ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqsfjqtf0zlz64gm305a6yfwmgprp54409zrn7lel24tr6hszvtrk3qzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wj7lp99" />
    <content type="html">
      ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack&lt;br/&gt;&lt;br/&gt;Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack after unknown threat actors managed to tamper with the official release channels and push backdoor code.&lt;br/&gt;&lt;br/&gt;&amp;#34;Attackers compromised the vendor&amp;#39;s build and distribution pipeline, injecting backdoor code into Pro plugin releases distributed through official licensed update channels,&amp;#34; Wordfence said in an analysis&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgd4DchiVkQLBMvGHgWrojoZUdyk2SwEhEj5q6cOYzKCUWF1Lz3Mxeizurg1O-SLVi2jg319ib4SJsSoVWixAkl5WLPu4rL1cMoYXUM6EziOVyt42ESt1zmMo_iLEfHx9XSAXpsDd1FEtRSgKk4AhDzA7DjJN8c__pUgogxTQgaGjsxM04WNiesgRnbEVHN/s1600/wordpress-plugin.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/06/shapedplugin-wordpress-pro-plugins.html&#34;&gt;https://thehackernews.com/2026/06/shapedplugin-wordpress-pro-plugins.html&lt;/a&gt;
    </content>
    <updated>2026-06-22T18:00:48Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqsd8jge7ydj9lment6q5uf7nmn878hearlnjyxse0a8aueny625rtszypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w6v30f8</id>
    
      <title type="html">29-Year-Old Squid Proxy Bug &amp;#39;Squidbleed&amp;#39; Can Leak ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqsd8jge7ydj9lment6q5uf7nmn878hearlnjyxse0a8aueny625rtszypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w6v30f8" />
    <content type="html">
      29-Year-Old Squid Proxy Bug &amp;#39;Squidbleed&amp;#39; Can Leak Cleartext HTTP Requests&lt;br/&gt;&lt;br/&gt;A heap over-read in the Squid web proxy can leak another user&amp;#39;s cleartext HTTP request, including any credentials or session tokens it carries, to anyone already allowed to send traffic through the same proxy.&lt;br/&gt;&lt;br/&gt;The bug traces to a 1997 FTP-parsing change and is still live in Squid&amp;#39;s default configuration. Researchers at Calif.io disclosed it in June and named it Squidbleed (&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiA4IfKMjQxVhpOYdrcCC4ty0vlGBDg_qCZuuvSTvyVWXYPXQlli7qyCZkPdHHuGJp-HVH1s-HGmf_Zqn97o2Qz5JOHaZ-Mk1mecm4W4yUBiCaejJL5guczISx2Q8ZH7RvS_4fXiNdHemr1aWKwz0CcyBJI_4_jFjQhY5JedBz_-pSiSQ1eQCF_BPYEbRs/s1600/sq.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/06/29-year-old-squid-proxy-bug-squidbleed.html&#34;&gt;https://thehackernews.com/2026/06/29-year-old-squid-proxy-bug-squidbleed.html&lt;/a&gt;
    </content>
    <updated>2026-06-22T14:29:46Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqszrwd6jmmvr9l56ukjd0tysxnnfxcvz5k4jw3p6c3xssd7j03l26gzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w2ugtk3</id>
    
      <title type="html">New OXLOADER Loader Uses Malicious Google Ads to Deliver ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqszrwd6jmmvr9l56ukjd0tysxnnfxcvz5k4jw3p6c3xssd7j03l26gzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w2ugtk3" />
    <content type="html">
      New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer&lt;br/&gt;&lt;br/&gt;Cybersecurity researchers have disclosed details of a new campaign that delivers CastleStealer by means of a previously unreported malware loader dubbed OXLOADER.&lt;br/&gt;&lt;br/&gt;According to Elastic Security Labs, the campaign leverages malicious Google Ads as a starting point to distribute the malware. Evidence indicates that the threat actor is likely Russian-speaking and financially motivated, owing to the&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi8sz7SHbQd4E8HNEKbvGGSYhPpJrUydP_gCRt_mWYYTr6QHLmChyphenhyphenca6BXhLBXA4OyKw-eS9xbqRqpKcYWFqDp4HoLBYKjVdWzhF0K1pqjX2bPtB91y1P1PZ8gh5r7Bpp-PIeUJVi_Hki91Qf6YjFAtFmf-qh7V9gNzmbEh_A2lISCvCDnNMALAuiqAlkL_/s1600/loader.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/06/new-oxloader-loader-uses-malicious.html&#34;&gt;https://thehackernews.com/2026/06/new-oxloader-loader-uses-malicious.html&lt;/a&gt;
    </content>
    <updated>2026-06-22T13:20:12Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqszqgr7d6m5wdxu6p7ml06vpwzkv6e78ntlcnnw9ukljv2rkzdj4lgzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wphe7dc</id>
    
      <title type="html">INTERPOL Warns Phishing, Ransomware, and AI Scams Are Rising ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqszqgr7d6m5wdxu6p7ml06vpwzkv6e78ntlcnnw9ukljv2rkzdj4lgzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wphe7dc" />
    <content type="html">
      INTERPOL Warns Phishing, Ransomware, and AI Scams Are Rising Across Asia-Pacific&lt;br/&gt;&lt;br/&gt;A new report from INTERPOL has revealed a &amp;#34;dramatic increase&amp;#34; in cybercrime in Asia and the South Pacific, fueled by rapid digitalization, internet penetration, new technologies, organized criminal networks, and a disparity in cybersecurity maturity.&lt;br/&gt;&lt;br/&gt;According to INTERPOL&amp;#39;s 2025/2026 Asia and South Pacific Cyberthreat Assessment Report, phishing has emerged as the most widespread and&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiCZyCo0qR6bFgeSdNHxD4d56tgq1YYTWI2aMHnDz63YlOYGrMbPnbpAumvGLNyZxxfLVTYEi7VBiVscqTpCC2sgfMtX-YFVAvy_flQZTKinHhT6qtKIc6boJfuGC4sbpNl9qYfblyZZizkaDRkMIScE3upxa-vBcGYeL6YqTBufD1ro3t0Mpwa6O8Ag4iU/s1600/asia.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/06/interpol-warns-phishing-ransomware-and.html&#34;&gt;https://thehackernews.com/2026/06/interpol-warns-phishing-ransomware-and.html&lt;/a&gt;
    </content>
    <updated>2026-06-22T06:06:53Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqsvpwgtx3ha4cl2c8sy0znn2208g3jsuy3z0lrsc378v23e80l9qnqzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wezd9zg</id>
    
      <title type="html">Malicious JetBrains Plugins Steal AI API Keys as Chrome ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqsvpwgtx3ha4cl2c8sy0znn2208g3jsuy3z0lrsc378v23e80l9qnqzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wezd9zg" />
    <content type="html">
      Malicious JetBrains Plugins Steal AI API Keys as Chrome Extensions Capture Chatbot Chats&lt;br/&gt;&lt;br/&gt;Cybersecurity researchers have flagged a &amp;#34;coordinated malware campaign&amp;#34; on the JetBrains Marketplace that has published no less than 15 malicious plugins capable of exfiltrating artificial intelligence (AI) provider keys.&lt;br/&gt;&lt;br/&gt;&amp;#34;Every plugin poses as an AI coding assistant built on DeepSeek and other large language models, offering chat, commit messages, code review, bug finding, and unit tests,&amp;#34;&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg2aRb82ydrk_lAXr6Yy-GmrPfQSaIuCNYTtB8dFm02DZWhJVj3bmjB3WLhWDUtiFmrGC3lHdeLfA2NtC6oHKJDAdW7ot4f3HQDyLw2Ep3q49BnOkuBWOPP2OuN1I1HNFknxPyQNpEZEnEt-8KhV2nx_HcaEiBm8Rdh7blevc3I1GjuBMLL1xOpJThFuJpE/s1600/hi.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/06/malicious-jetbrains-plugins-steal-ai.html&#34;&gt;https://thehackernews.com/2026/06/malicious-jetbrains-plugins-steal-ai.html&lt;/a&gt;
    </content>
    <updated>2026-06-17T09:38:46Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqs0hgjhwc8szt9q2tp60r070ruyzm9ern9zt38074akjjtqlnxkjgszypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0ws3a9q9</id>
    
      <title type="html">144 Mastra npm Packages Compromised via Hijacked Contributor ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqs0hgjhwc8szt9q2tp60r070ruyzm9ern9zt38074akjjtqlnxkjgszypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0ws3a9q9" />
    <content type="html">
      144 Mastra npm Packages Compromised via Hijacked Contributor Account&lt;br/&gt;&lt;br/&gt;As many as 144 npm packages associated with the Mastra namespace (&amp;#34;@mastra/*&amp;#34;), a popular open-source JavaScript and TypeScript framework for building artificial intelligence (AI) applications, have been compromised as part of a software supply chain attack codenamed easy-day-js, per findings from JFrog, SafeDep, Socket, and StepSecurity.&lt;br/&gt;&lt;br/&gt;&amp;#34;A single npm account (ehindero) mass-published more&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiKLWn0zHFuJ8rkb2bqILIyAGxt_-VJ13Ytmv1TRWtGJkI6Rva5Oag5LdLasE2rmenokuRvoEI2wH0Ayfe_P4_5q1Qc5FQ2MrQgUHrgD9wY6DTlYugAtj8CP7Fh0OPjKkU5LbeRKWvPEh0Ol0CmLTe4QVayeZiNlVFvU7MO5tWl-b8Lbn80hKd45q9Z1yOd/s1600/npms.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/06/144-mastra-npm-packages-compromised-via.html&#34;&gt;https://thehackernews.com/2026/06/144-mastra-npm-packages-compromised-via.html&lt;/a&gt;
    </content>
    <updated>2026-06-17T07:38:24Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqszyrepqs7zehg8hhhvzq83ztgd50qrxe7gcv3kazkkq67lyhvhy4czypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wqk4snt</id>
    
      <title type="html">Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqszyrepqs7zehg8hhhvzq83ztgd50qrxe7gcv3kazkkq67lyhvhy4czypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wqk4snt" />
    <content type="html">
      Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week&lt;br/&gt;&lt;br/&gt;Bad actors are exploiting multiple security vulnerabilities in Fortinet FortiSandbox, according to threat intelligence firm Defused Cyber.&lt;br/&gt;&lt;br/&gt;In a post shared on X, the company said it has observed exploitation of CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089 over the past 24 hours.&lt;br/&gt;&lt;br/&gt;CVE-2026-39813 (CVSS score: 9.1) refers to a path traversal vulnerability in FortiSandbox JRPC API that could&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEisozpc0YfCvHjGAyEZf7c1G10iEOgszA-mkIIrhG3A4VYcq8_Hih8U0hO66iBoDPPJZhfq7Dc3fGTsMLDiFiGSk6-xS7ltGORLe0_sC8VyhZHlfIkeGpOkMTcbQ0R7BeDtDmZFb-VB_GF3le8p0mx2ZMD-CLZb5eWlMJPiBhdu9ljzlh_E01hIon9dA-Y3/s1600/Fortinet.png&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/06/attackers-exploit-three-fortinet.html&#34;&gt;https://thehackernews.com/2026/06/attackers-exploit-three-fortinet.html&lt;/a&gt;
    </content>
    <updated>2026-06-16T10:30:41Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqsqmw32zhq0j5uceeww77gam9g6wkmg3yepfpthrya7zj6e4n3fa6czypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wr9p84g</id>
    
      <title type="html">Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqsqmw32zhq0j5uceeww77gam9g6wkmg3yepfpthrya7zj6e4n3fa6czypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wr9p84g" />
    <content type="html">
      Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware&lt;br/&gt;&lt;br/&gt;The North Korean state-sponsored hacking group known as ScarCruft (aka APT37) has been observed using spear-phishing messages impersonating Microsoft Account security notifications to deliver malware called NarwhalRAT.&lt;br/&gt;&lt;br/&gt;&amp;#34;The attack email contained a message impersonating an MS account security alert,&amp;#34; the Genians Security Center (GSC) said. &amp;#34;It was designed to create concern over possible&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg3Lf-lxaztGp4Ov5_hu7TmA6AEoqhh2oBADVLVEbA1HTzmsAyX9ePZtZvvBlBzNym1RiifCmOnb-pf604J7plqPdarQxnW-m6Ds0Wi-kT1Ytqm1KlGsf4hWmL8YPa17MXv4yxcEN0CwkA_9qwbEGn74XdX4Y0J4t1rR3oflfW5cpy2tXo65kVMFI3oRFxr/s1600/ms-alert.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/06/fake-microsoft-alerts-used-to-deploy.html&#34;&gt;https://thehackernews.com/2026/06/fake-microsoft-alerts-used-to-deploy.html&lt;/a&gt;
    </content>
    <updated>2026-06-16T08:14:55Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqsxyq7gfpsm79gm4cw3z5al9xh2wxpmq5e4cssa0tv8phjt4v3rkpgzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wy6ulcx</id>
    
      <title type="html">North Korean Hackers Are Turning Developer Tools Into Malware ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqsxyq7gfpsm79gm4cw3z5al9xh2wxpmq5e4cssa0tv8phjt4v3rkpgzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wy6ulcx" />
    <content type="html">
      North Korean Hackers Are Turning Developer Tools Into Malware Delivery Channels&lt;br/&gt;&lt;br/&gt;Cybersecurity researchers have flagged two malicious cyber campaigns that exhibit similarities with a persistent North Korean threat cluster known as Contagious Interview (aka Famous Chollima, HexagonalRodent, and Void Dokkaebi).&lt;br/&gt;&lt;br/&gt;According to a report published by Proofpoint, the threat actor has been found orchestrating phishing campaigns using developer role recruitment or code review themes&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiaqLMLYAQa1ICXVdOhmxnFqqoh_YonevmQPjEtYbmqLsdFC7JJnGc_F7K1no96DjZhTicVxI7sJUO04JM3e64Ko2eh1X6NlEqpKO2Nc1MKCzDPdqlmPZzTphhJlL7ibJ1CLRsIaVBZZvWtm7mv_jXLT53iwjlRVjBnyKCypFigPA0mZzFew-02Xp_aKu9o/s1600/northkorea.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/06/north-korean-hackers-are-turning.html&#34;&gt;https://thehackernews.com/2026/06/north-korean-hackers-are-turning.html&lt;/a&gt;
    </content>
    <updated>2026-06-15T19:32:52Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqsgyt62z2g0t8fuktulq48p259zq46gnl25eeeh82acqqrxf0eh7xszypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wc0cjhg</id>
    
      <title type="html">Agentjacking Attack Tricks AI Coding Agents Into Running ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqsgyt62z2g0t8fuktulq48p259zq46gnl25eeeh82acqqrxf0eh7xszypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wc0cjhg" />
    <content type="html">
      Agentjacking Attack Tricks AI Coding Agents Into Running Malicious Code&lt;br/&gt;&lt;br/&gt;Cybersecurity researchers have described what they say is a new class of attack that can trick artificial intelligence (AI) coding agents into running arbitrary code on developer machines.&lt;br/&gt;&lt;br/&gt;Called Agentjacking by Tenet Security, the attack can be triggered by means of a fake error report crafted using Sentry, an open-source error-tracking and performance-monitoring platform.&lt;br/&gt;&lt;br/&gt;&amp;#34;The attack&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhs-B-d2AZdbTGExalcZiBwa9fNa999-EQ1GrAeytHP6tpnC3WmKL4IcKV5voUs-MRq5WGVwwf2NFPyJxdJUPlgzBL8huaGFqRbXgR_qPOSh-5Ef2oZz8E2H38ZMjVipV7XyXpefY2PgDlWomgJ4RW6YJ4Z3tYMGRQh2z8xwpvOa9_LQWHT706ZCvKpaBxP/s1600/Agentjacking.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/06/agentjacking-attack-tricks-ai-coding.html&#34;&gt;https://thehackernews.com/2026/06/agentjacking-attack-tricks-ai-coding.html&lt;/a&gt;
    </content>
    <updated>2026-06-12T12:04:33Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqsfc3heswhdtn5k3fja5hy9fshkq842xzutdlyxgfgzwzj2h85ysxszypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wx3tmrh</id>
    
      <title type="html">Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqsfc3heswhdtn5k3fja5hy9fshkq842xzutdlyxgfgzwzj2h85ysxszypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wx3tmrh" />
    <content type="html">
      Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS&lt;br/&gt;&lt;br/&gt;Cybersecurity researchers have flagged half a dozen vulnerabilities in protobuf.js, a JavaScript and TypeScript implementation of Protocol Buffers (Protobuf), that, if successfully exploited, could result in remote code execution (RCE) and denial-of-service (DoS) attacks.&lt;br/&gt;&lt;br/&gt;&amp;#34;In affected environments, a single malicious protobuf schema, descriptor, or crafted payload could be enough to trigger&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiJXkAy-j0jwPWQiC9bJinbwINT6pxRmO7CJ_df4bkbAP3VD-xU8oblGB5ZBBR1oLMN0uqf_lBb5al4KSR82lU1kZsXu14TAMaXi6kIjcp5xxk5yLKnOCTloqgZd6w_PuzPxTxNROksgp9pld0D9HoxceBwprkC5cDXEvoSP64bzC_UZyZthInrECAReAeH/s1600/protobuf.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/06/six-proto6-vulnerabilities-in.html&#34;&gt;https://thehackernews.com/2026/06/six-proto6-vulnerabilities-in.html&lt;/a&gt;
    </content>
    <updated>2026-06-10T05:08:35Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqsdl4rcyvtyvlyjwnw9zugv53qnupf2ms40yeq3vqfwwah8mj4jq7qzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w7cr2ud</id>
    
      <title type="html">Microsoft Restores Some GitHub Repos, Keeps Others Offline as ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqsdl4rcyvtyvlyjwnw9zugv53qnupf2ms40yeq3vqfwwah8mj4jq7qzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w7cr2ud" />
    <content type="html">
      Microsoft Restores Some GitHub Repos, Keeps Others Offline as Miasma Probe Continues&lt;br/&gt;&lt;br/&gt;Microsoft on Monday confirmed that it temporarily removed some GitHub repositories in response to a recent security incident that led to 73 of its open-source projects being compromised to inject an information stealer into the code.&lt;br/&gt;&lt;br/&gt;&amp;#34;Our priority is to protect customers and the broader ecosystem,&amp;#34; a Microsoft spokesperson told The Hacker News via email. &amp;#34;We temporarily removed some&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhS-7rxJRihxTgaEj0a_mk4hVtMdwpHB8Gfd5ZgctcXcjOdEnSEJr9Qao5B5kpk2QBpumULMvNi1ZPptGJnA3NhAres2k9CGwhCQTfMciEcl2otHHvKxU9j9AkTyAgANeYS_CCY9WOip8lBCi6cq8JgPr_oqnuw-lpp53u881dYUrH8KzU8xLNPK6Lube-x/s1600/ms-worm.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/06/microsoft-restores-some-github-repos.html&#34;&gt;https://thehackernews.com/2026/06/microsoft-restores-some-github-repos.html&lt;/a&gt;
    </content>
    <updated>2026-06-09T16:34:52Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqsdykzf0uyhthjmaes8uvmvurr5m2ccgag824qespclwfckssv6cpszypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wrycfy2</id>
    
      <title type="html">The Hidden Security Risk in Modern Networks: The Work Between ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqsdykzf0uyhthjmaes8uvmvurr5m2ccgag824qespclwfckssv6cpszypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wrycfy2" />
    <content type="html">
      The Hidden Security Risk in Modern Networks: The Work Between Tools&lt;br/&gt;&lt;br/&gt;Organizations have more visibility than ever. Growing tech stacks provide greater coverage, and network security teams are increasingly adopting AI and automation to help with routine tasks and reduce manual effort.&lt;br/&gt;&lt;br/&gt;But the same challenges persist. Outages still last hours, causing significant financial losses, operational disruption, and reputational impact. Threat response and mean time to&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjJqeGTf-8XwdqkhtSdYoCT3HhGAP5pxBuBeA1ngKoX7BfGUcJMwqGhtf8Eh5TVXaN8-p-Ggk8Uiz4DhtmfT8GkKggOPmqRoh5j6XEumgw9aT7kwo4YcNAi_JrqIhSJU-_7gsyBXfwxAi7YfOS1_6CuDSen29PlEk5O4yA80Ob8_WNh81sExm8vgWSVnsY/s1600/tines.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/06/the-hidden-security-risk-in-modern.html&#34;&gt;https://thehackernews.com/2026/06/the-hidden-security-risk-in-modern.html&lt;/a&gt;
    </content>
    <updated>2026-06-09T11:30:00Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqsyeld345vzt8k5q082cxs722rd6tq6xtme2kskdn0uw5wcgyl7tpqzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wehc3pp</id>
    
      <title type="html">AI Phishing Is Crushing SOCs with Alert Volume: How to Reduce ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqsyeld345vzt8k5q082cxs722rd6tq6xtme2kskdn0uw5wcgyl7tpqzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wehc3pp" />
    <content type="html">
      AI Phishing Is Crushing SOCs with Alert Volume: How to Reduce Tier 1 Overload&lt;br/&gt;&lt;br/&gt;Phishing has always been a numbers game. AI has turned it into a volume machine.&lt;br/&gt;&lt;br/&gt;Attackers can now create convincing emails, fake login pages, and tailored lures in minutes. Every polished message adds another case for Tier 1 to review, another link to inspect, and another alert that cannot be dismissed at a glance.&lt;br/&gt;&lt;br/&gt;As the queue grows, a credential theft attempt or malware delivery can easily&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgWmg0GCTB3fe3Y57Wr_PMrbYUetN1SDu243ddq7AdKP-gwIbOdVDhXhuWtapmSuA6gDYWwk8ydavt33ZAoWzHmG4Imu4dqiiPaksZKDYK5AEX1XBPr2iz2JflFZoH4uy0_I35Gm6zpJo9wyGttsjdtDwLM_00VOg9qVka3vYjk62LAD3HGSbnE7ov9TMU/s1600/ai-threats.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/06/ai-phishing-is-crushing-socs-with-alert.html&#34;&gt;https://thehackernews.com/2026/06/ai-phishing-is-crushing-socs-with-alert.html&lt;/a&gt;
    </content>
    <updated>2026-06-08T13:00:00Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqs0ugcn8e53aw3cpqfrwpf80qa4ped6veuzx0r9gz2n2wt6d7e60yczypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wnu4tpd</id>
    
      <title type="html">Claude Code GitHub Action Flaw Let One Malicious Issue Hijack ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqs0ugcn8e53aw3cpqfrwpf80qa4ped6veuzx0r9gz2n2wt6d7e60yczypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wnu4tpd" />
    <content type="html">
      Claude Code GitHub Action Flaw Let One Malicious Issue Hijack Repositories&lt;br/&gt;&lt;br/&gt;A security researcher found a flaw in Anthropic&amp;#39;s Claude Code GitHub Action that let an attacker take over vulnerable public repositories running it, with nothing more than a single opened GitHub issue. Because Anthropic&amp;#39;s own action repo used the same workflow, a working attack could have pushed malicious code into the action itself and onto the projects downstream that pull it.&lt;br/&gt;&lt;br/&gt;RyotaK of GMO&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhiaBF9jAklPh1ncr_eVPGnV229BSTNgAjkScVm-yTXAn4IcBjjZoLIglasRdu1XEPafCxJhqVZrC3zkNWilyAhN-6Ox8z2HBRjNg2D4aqJsDiRDg02BgAy4zgwU2100ZLIO8yTOtarI0Vxa3AGUQk0GZq1_zKSFQOhNiNoyVsP2AldJZoW8ZJ1rY936ZI/s1600/claude-code-hack.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/06/claude-code-github-action-flaw-let-one.html&#34;&gt;https://thehackernews.com/2026/06/claude-code-github-action-flaw-let-one.html&lt;/a&gt;
    </content>
    <updated>2026-06-04T15:15:26Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqs009nx9kneu7cwzalx5g9szz5365wx3kav2aptp6w4flrnw0k9klszypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wzlapdq</id>
    
      <title type="html">China-Linked TA4922 Expands Phishing Attacks to UK, Germany, ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqs009nx9kneu7cwzalx5g9szz5365wx3kav2aptp6w4flrnw0k9klszypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wzlapdq" />
    <content type="html">
      China-Linked TA4922 Expands Phishing Attacks to UK, Germany, Italy, and South Africa&lt;br/&gt;&lt;br/&gt;A new China-linked cybercrime group known as TA4922 has expanded its targeting focus to target European organizations in the U.K., Germany, Italy, and South Africa.&lt;br/&gt;&lt;br/&gt;These efforts have been complemented by a &amp;#34;rapid operational tempo&amp;#34; and a continually evolving malware arsenal comprising known families like ValleyRAT (aka Winos 4.0) and Atlas RAT (aka AtlasCross RAT), as well as previously&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhq_JkP80d1IA8rz-SoYEBmuGqK_K7OpGrqiki4vB1ShMW5mFBVSMvl8H5MnYylZMl3AWeqdAmp19oZIL_7amYErNxBGiUAJqrOqGO0zjHH2jxCKCNdiGH_nqjHlksD9dlu4QGCq9KzMRfnWAi7YnPQQ86pnCypNupFDn_h-hSJdfhWT0Y4s01w6Cw-s6Od/s1600/phishing-hook.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/06/china-linked-ta4922-expands-phishing.html&#34;&gt;https://thehackernews.com/2026/06/china-linked-ta4922-expands-phishing.html&lt;/a&gt;
    </content>
    <updated>2026-06-04T12:22:25Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqswleensszt84wksla6gfjke7h72h6z36r24zkkxgeysd4mv7ydppczypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wn33hwh</id>
    
      <title type="html">AI-Driven Exploitation is Destroying Vulnerability Management. ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqswleensszt84wksla6gfjke7h72h6z36r24zkkxgeysd4mv7ydppczypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wn33hwh" />
    <content type="html">
      AI-Driven Exploitation is Destroying Vulnerability Management. Here’s How to Handle It.&lt;br/&gt;&lt;br/&gt;AI-driven exploitation timelines are rapidly shrinking, and they are not going to stop shrinking. Vulnerabilities are being discovered, reproduced, and weaponized faster than ever in the history of enterprise security. As a result, the window between a vulnerability being disclosed and indiscriminate exploitation observed across the internet is now measured in hours, not days.&lt;br/&gt;&lt;br/&gt;The industry&amp;#39;s&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjgC5W9v8FZkEWo3lLXfVm96RBtE2mlXcUmv-T0KxRiUVUsBhQOMm8MG6G-IExq0SIu3KlkO309v-a63s4dCkLdR6CCZ3Mf-XK-qi3a7T-Lp_mJB2jio7dLxMAnvAqxlh4J0-F7fUr7uiSeWOk7ldmBLNki4ORg2A_Y5yJ-tk0b9V6iJjjf7U4CRwD9eAA/s1600/watch.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/06/ai-driven-exploitation-is-destroying.html&#34;&gt;https://thehackernews.com/2026/06/ai-driven-exploitation-is-destroying.html&lt;/a&gt;
    </content>
    <updated>2026-06-02T11:58:00Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqs8w3dfvxlfq25cdpm2qt54txfkshvnxcc68xdjeg20xf7jlxdj0ngzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w7l00nm</id>
    
      <title type="html">⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqs8w3dfvxlfq25cdpm2qt54txfkshvnxcc68xdjeg20xf7jlxdj0ngzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w7l00nm" />
    <content type="html">
      ⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More&lt;br/&gt;&lt;br/&gt;Monday hit like a cron job with anger issues.&lt;br/&gt;&lt;br/&gt;A busted auth path here, a repo-side faceplant there, some &amp;#34;patched-ish&amp;#34; thing already getting chewed on in the wild, and then the usual bonus round: poisoned dev tools, sketchy forum chatter, phishing kits pretending to be productivity, and AI lowering the bar for people who already thought &amp;#39;curl | sh&amp;#39; had a personality.&lt;br/&gt;&lt;br/&gt;The vibe is simple: old&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiV-leTG-MQremNN5Ju342L6LQMn36xeD4jiS4YWT7EdYluHOtFDqIN8y3bQuV-A0D0wtsO5sRpG3Bpy5xdHhMs_sO_w3WoiiJzCd7o-7Hxw736ERxQs4WDd71EQEBIHLzT_UNFMwCDvC8Nij-gDNpMhsRnpsqoDHkuxUWLUEZSSTfDc4aXpx2qlpsaqlgH/s1600/cyberrecap.png&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/06/weekly-recap-new-linux-flaw-pan-os.html&#34;&gt;https://thehackernews.com/2026/06/weekly-recap-new-linux-flaw-pan-os.html&lt;/a&gt;
    </content>
    <updated>2026-06-01T13:59:54Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqs9szz3m3cddqmss5469mhzk4c80w2w4hhwfgcsj2namx9uqyjy9sqzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w0y7g8x</id>
    
      <title type="html">AI Chatbot Recommendations Redirect Users to Cryptojacking ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqs9szz3m3cddqmss5469mhzk4c80w2w4hhwfgcsj2namx9uqyjy9sqzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w0y7g8x" />
    <content type="html">
      AI Chatbot Recommendations Redirect Users to Cryptojacking Malware Sites&lt;br/&gt;&lt;br/&gt;Microsoft has warned of an active cryptojacking campaign that makes use of artificial intelligence (AI) chatbot interactions as a mechanism for surfacing malicious download sites.&lt;br/&gt;&lt;br/&gt;&amp;#34;This emerging delivery technique extends social engineering beyond conventional search results and increases the visibility of malicious software recommendations,&amp;#34; Microsoft Defender Experts and the Microsoft&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhqt5LC8yrEqRzxRxEUTh3yZSnXovvZU0R11suWWfP1FEKvC5ZOpPnLHpdDjAzUADZarX1C3XucsG5OOXN3Zj4-esPhUnz4DBnAdDxkZw3aEqdH_HHPn4N5Eu03Y-tG_kEmPOxKyMH14wpiOYs9w8jh7U6MlHjHqiS4nNxLH_NpS47oR-mRW5GfuDvX9VFo/s1600/ai-tools.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/05/ai-chatbot-recommendations-redirect.html&#34;&gt;https://thehackernews.com/2026/05/ai-chatbot-recommendations-redirect.html&lt;/a&gt;
    </content>
    <updated>2026-05-27T07:45:52Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqs8zpy79hvhka5mu3ngjecaqaynfnfkp6vgc28275w9w4vvnp4euzczypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wqe7505</id>
    
      <title type="html">New AI DDoS Attacks Are Smarter. Learn How to Fight Back in This ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqs8zpy79hvhka5mu3ngjecaqaynfnfkp6vgc28275w9w4vvnp4euzczypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wqe7505" />
    <content type="html">
      New AI DDoS Attacks Are Smarter. Learn How to Fight Back in This Webinar&lt;br/&gt;&lt;br/&gt;Every single day, hackers are finding new ways to crash websites and steal data.&lt;br/&gt;&lt;br/&gt;But right now, something has changed. Hackers are no longer working alone. They are now using powerful Artificial Intelligence (AI) tools to make their attacks faster, stronger, and much harder to stop.&lt;br/&gt;&lt;br/&gt;According to recent updates from The Hacker News, bad actors are using AI to find weak spots in systems and&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg-Jzce1sDI3eaFwGE2RPtOHh63Itg1gN7ay6XupD8AzHxmOlIY4BCsjavyHIHk9DsFNbFBtFn8sGxY5pIQ9zA0vsTz-BfoJZsSND0sZHCx09DNvj_m2Ik4v-lXpcyLPKUrDyYO7T1pSYPpOB2CdBogBXKkWbzx97I26hxNNtrFBhLRBaj0xc-yNq89mC1d/s1600/ddoss.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/05/new-ai-ddos-attacks-are-smarter-learn.html&#34;&gt;https://thehackernews.com/2026/05/new-ai-ddos-attacks-are-smarter-learn.html&lt;/a&gt;
    </content>
    <updated>2026-05-26T11:58:00Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqsx79v430eljpezvhht30gddwen2qp7qmk5pqef6fsn7a5sdnkct0czypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wglgn0s</id>
    
      <title type="html">Ghost CMS CVE-2026-26980 Exploited to Hijack 700&#43; Sites for ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqsx79v430eljpezvhht30gddwen2qp7qmk5pqef6fsn7a5sdnkct0czypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wglgn0s" />
    <content type="html">
      Ghost CMS CVE-2026-26980 Exploited to Hijack 700&#43; Sites for ClickFix Attacks&lt;br/&gt;&lt;br/&gt;Threat actors are exploiting a recently disclosed critical security flaw in Ghost CMS to inject malicious JavaScript code with an aim to fuel ClickFix attacks.&lt;br/&gt;&lt;br/&gt;According to QiAnXin XLab, the activity involves the exploitation of CVE-2026-26980 (CVSS score: 9.4), an SQL injection vulnerability in Ghost&amp;#39;s Content API that could allow an unauthenticated attacker to read arbitrary data from the&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg5bYCvN_MmCGXVH5raR8wqJQv52CST3mK7UBfLXVnqRRL_rHkhJpSOBjdPyR5oXmPsSB-X3-Sib6-eVToqi4UXB218ESR2uFdczESGAM5i4ZkxQyE7AkQteCFCasknPz262ceUOFccS3xcUbaQdvUGoRw0kJE7QQMSbeP2OAQVfY9lFYTj7ZhzCL_GdkuM/s1600/check-cf.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/05/ghost-cms-cve-2026-26980-exploited-to.html&#34;&gt;https://thehackernews.com/2026/05/ghost-cms-cve-2026-26980-exploited-to.html&lt;/a&gt;
    </content>
    <updated>2026-05-25T12:02:46Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqszz5cum526a9yydq55duvsc5tt65rnqpm9jyxyak3ez0ja7z48taczypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wnefucc</id>
    
      <title type="html">Microsoft Open-Sources RAMPART and Clarity to Secure AI Agents ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqszz5cum526a9yydq55duvsc5tt65rnqpm9jyxyak3ez0ja7z48taczypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wnefucc" />
    <content type="html">
      Microsoft Open-Sources RAMPART and Clarity to Secure AI Agents During Development&lt;br/&gt;&lt;br/&gt;Microsoft has unveiled two new open-source tools called RAMPART and Clarity to assist developers in better testing the security of artificial intelligence (AI) agents.&lt;br/&gt;&lt;br/&gt;RAMPART, short for Risk Assessment and Measurement Platform for Agentic Red Teaming, functions as a Pytest-native safety and security testing framework for writing and running safety and security tests for AI agents, covering&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjPuhFp_KGzG3yZEzqIYh-at7Dm3vg4_QX97ilaSXDjsUbfhU7KCmRS-uQ2UrV9D855Nvy8HcBDKe25VMT63dfyzh-B2bzSx649SJQSQhL3bfm4Eitv4KLW4PhzRfE1HvoFOFDu2bB4alNLTFzvr6_IkKWjqxShcuWytNgDR4b3wR1xGE6z06xSyWo6NVg3/s1600/ms-tools.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/05/microsoft-open-sources-rampart-and.html&#34;&gt;https://thehackernews.com/2026/05/microsoft-open-sources-rampart-and.html&lt;/a&gt;
    </content>
    <updated>2026-05-20T17:06:54Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqs2kdpy7m9xrwaq6xktxcaaz0vdxwul294e8f3t9w87l2wj43r8a9gzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wktsufh</id>
    
      <title type="html">DirtyDecrypt PoC Released for Linux Kernel CVE-2026-31635 LPE ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqs2kdpy7m9xrwaq6xktxcaaz0vdxwul294e8f3t9w87l2wj43r8a9gzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wktsufh" />
    <content type="html">
      DirtyDecrypt PoC Released for Linux Kernel CVE-2026-31635 LPE Vulnerability&lt;br/&gt;&lt;br/&gt;Proof-of-concept (PoC) exploit code has now been released for a recently patched security flaw in the Linux kernel that could allow for local privilege escalation (LPE).&lt;br/&gt;Dubbed DirtyDecrypt (aka DirtyCBC), the vulnerability was discovered and reported by the Zellic and V12 security team on May 9, 2026, only to be informed by the maintainers that it was a duplicate of a vulnerability that had&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgecVdZ_vIxfMWdiQkn7dC_SCueSRLBHaU01aHrtW1lUsx3_5gwbM6fG5NyV-VUhnDxvolk_tzMNWgINg06cwjKL1xIeDIFMiFH56IUO_zwZwJqiLnMp-VJcIWFjhulk1AHnlZ_ETgH3vg6Q6SHS4Ae-teRmaLDY4XZhONjoz4MeKvQLyzJ_YdckL8lk3fe/s1600/linux-poc.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/05/dirtydecrypt-poc-released-for-linux.html&#34;&gt;https://thehackernews.com/2026/05/dirtydecrypt-poc-released-for-linux.html&lt;/a&gt;
    </content>
    <updated>2026-05-19T14:56:26Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqspuep405tdvksrgzhpazw4y74hnummx5fqhcls6nfge9ztzxw884szypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wkha6fu</id>
    
      <title type="html">GitHub Actions Supply Chain Attack Redirects Tags to Steal CI/CD ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqspuep405tdvksrgzhpazw4y74hnummx5fqhcls6nfge9ztzxw884szypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wkha6fu" />
    <content type="html">
      GitHub Actions Supply Chain Attack Redirects Tags to Steal CI/CD Credentials&lt;br/&gt;&lt;br/&gt;In yet another software supply chain attack, threat actors have compromised the popular GitHub Actions workflow, actions-cool/issues-helper, to run malicious code that harvests sensitive credentials and exfiltrates them to an attacker-controlled server.&lt;br/&gt;&lt;br/&gt;&amp;#34;Every existing tag in the repository has been moved to point to an imposter commit that does not appear in the action&amp;#39;s normal commit history,&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgc7jpVO6HhBuEBTjkwmNjYhKlFmhhmytOqNZHYuGP-dNWrf3AoyE68yoKj77elddOX4Ps2x9jSuwhi5sE-QjK_oEjLXgQW9e6EHx6W0G7qTqYTM3fZh1AQTyrgm2o-PFBeD9ryHnC6fDmK5MYKUzBjU_pJibTilnm1d99WSQkJux6PXXRydkYW5d15Ada-/s1600/step.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/05/github-actions-supply-chain-attack.html&#34;&gt;https://thehackernews.com/2026/05/github-actions-supply-chain-attack.html&lt;/a&gt;
    </content>
    <updated>2026-05-19T05:28:06Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqsvz3juqeunakuvdkyq3sh773gucr3mwcpdepgf74xg0cuxsvdftfqzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0whsxmln</id>
    
      <title type="html">Developer Workstations Are Now Part of the Software Supply Chain ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqsvz3juqeunakuvdkyq3sh773gucr3mwcpdepgf74xg0cuxsvdftfqzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0whsxmln" />
    <content type="html">
      Developer Workstations Are Now Part of the Software Supply Chain&lt;br/&gt;&lt;br/&gt;Supply chain attackers are not only trying to slip malicious code into trusted software. They are trying to steal the access that makes trusted software possible. Recently, three separate campaigns hit npm, PyPI, and Docker Hub in a 48-hour window, and all three targeted secrets from developer environments and CI/CD pipelines, including API keys, cloud credentials, SSH keys, and tokens. This is&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjylLL25uQ3uU6RshKkTv9isR22Y_6_b4uJJ4koE1MqtmGs4IWdz88_aH8up_7WDxghA7-GeMbm6gpoKUXRw99Cm1ljO03H8bdcv91vvO_ch313e_JAwtYH-CewZJF2WkNrYWtcp-acMiPTvSs5aan7v2DLpEjVSBuEarfJ-eCLEHCL2WK9zjxOho_gj3k/s1600/git.gif&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/05/developer-workstations-are-now-part-of.html&#34;&gt;https://thehackernews.com/2026/05/developer-workstations-are-now-part-of.html&lt;/a&gt;
    </content>
    <updated>2026-05-18T11:23:41Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqs2fwdyu92ys838udns8mg4kxpnwe427l58vy74np734u2mnkkcejszypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w3f5mlm</id>
    
      <title type="html">CISA Adds Cisco SD-WAN CVE-2026-20182 to KEV After Admin Access ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqs2fwdyu92ys838udns8mg4kxpnwe427l58vy74np734u2mnkkcejszypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w3f5mlm" />
    <content type="html">
      CISA Adds Cisco SD-WAN CVE-2026-20182 to KEV After Admin Access Exploits&lt;br/&gt;&lt;br/&gt;The U.S.Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly disclosed vulnerability impacting Cisco Catalyst SD-WAN Controller to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to remediate the issue by May 17, 2026.&lt;br/&gt;The vulnerability is a critical authentication bypass tracked as CVE-2026-20182. It&amp;#39;s&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg4XG5z00sF3uL0ZbhtZNiergQ9QVaZJydwP1pXEdPh2o29mwvTS2nPKRbxHftwnEJ1pvxMQS9TQknWqbovk-vW7BRPHUSsBhN4yL2iOwJnlmK7lzCdW9tJbKtKLbnfSZSWgfGlWQ6HO807gjR6dP61VylH1zxWtvfo3c7ui8aBecSjVz5miCG0jHoa8rUA/s1600/cisa-exploit.png&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/05/cisa-adds-cisco-sd-wan-cve-2026-20182.html&#34;&gt;https://thehackernews.com/2026/05/cisa-adds-cisco-sd-wan-cve-2026-20182.html&lt;/a&gt;
    </content>
    <updated>2026-05-15T05:28:03Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqszgs3nneygmp9wx8e63qgn0n4nf6nsrdn5aa9z92t99q6xeqceelczypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w8rt3x8</id>
    
      <title type="html">Microsoft&amp;#39;s MDASH AI System Finds 16 Windows Flaws Fixed in ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqszgs3nneygmp9wx8e63qgn0n4nf6nsrdn5aa9z92t99q6xeqceelczypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w8rt3x8" />
    <content type="html">
      Microsoft&amp;#39;s MDASH AI System Finds 16 Windows Flaws Fixed in Patch Tuesday&lt;br/&gt;&lt;br/&gt;Microsoft has unveiled a new multi-model artificial intelligence (AI)-driven system called MDASH to facilitate vulnerability discovery and remediation at scale, adding that it&amp;#39;s being tested by some customers as part of a limited private preview.&lt;br/&gt;MDASH, short for multi-model agentic scanning harness, is designed as a model-agnostic system that uses bespoke AI agents for different vulnerability&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg1Iq16GS3jdGiIU24GHBkwg6unk05ctdgYwXO5df8zRu1qko95_XhszCjq6jlEIRozLsrtZHgi5GqDZnS1Sw_KDzUzsagwP0If3VswmYHsnuYwVseU2lapxQiPpItTdAiv-CCdTFR87ZVOu65buyvmvzmdWuJPKHuPA4DSo58HQIMAV__2ymsmRe2g3UVe/s1600/windows-ai.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/05/microsofts-mdash-ai-system-finds-16.html&#34;&gt;https://thehackernews.com/2026/05/microsofts-mdash-ai-system-finds-16.html&lt;/a&gt;
    </content>
    <updated>2026-05-13T13:46:02Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqs22zktvkwr2xfu2pssqy4gc9muv8dkx8p0pas3nwhw3g3l62kqweqzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wm8wkrp</id>
    
      <title type="html">Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqs22zktvkwr2xfu2pssqy4gc9muv8dkx8p0pas3nwhw3g3l62kqweqzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wm8wkrp" />
    <content type="html">
      Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI &amp;amp; More Packages&lt;br/&gt;&lt;br/&gt;TeamPCP, the threat actor behind the recent supply chain attack spree, has been linked to the compromise of the npm and PyPI packages from TanStack, UiPath, Mistral AI, OpenSearch, and Guardrails AI as part of a fresh Mini Shai-Hulud campaign.&lt;br/&gt;The affected npm packages have been modified to include an obfuscated JavaScript file (&amp;#34;router_init.js&amp;#34;) that&amp;#39;s designed to profile the execution&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhXIhs2kZt0YGdDcd-Io67mq1GIN_iI_71LYhuin4qqmlgUgCuZ3fGUvglg_5nh5DK8kfPP8RHki86yMyqh4rTE27PGgPBh4RQjkh91-QGoB8cav5NUsYAwcV3ZJ7aEf-uEoH3pLGQ2eWuCh8lZSWAlTIa2U5I6eeB3HZmYMn4q-YoV7Ytmkpr1tN0lC2rG/s1600/mistral.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/05/mini-shai-hulud-worm-compromises.html&#34;&gt;https://thehackernews.com/2026/05/mini-shai-hulud-worm-compromises.html&lt;/a&gt;
    </content>
    <updated>2026-05-12T08:50:00Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqszkh0fjwrcppz946dfjfadpzcjwzn5gzl4urc4zpe04mqr5y507ngzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wvhav2k</id>
    
      <title type="html">Ollama Out-of-Bounds Read Vulnerability Allows Remote Process ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqszkh0fjwrcppz946dfjfadpzcjwzn5gzl4urc4zpe04mqr5y507ngzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wvhav2k" />
    <content type="html">
      Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak&lt;br/&gt;&lt;br/&gt;Cybersecurity researchers have disclosed a critical security vulnerability in Ollama that, if successfully exploited, could allow a remote, unauthenticated attacker to leak its entire process memory.&lt;br/&gt;The out-of-bounds read flaw, which likely impacts over 300,000 servers globally, is tracked as CVE-2026-7482 (CVSS score: 9.1). It has been codenamed Bleeding Llama by Cyera.&lt;br/&gt;Ollama is a&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj92eUjjTTMJPizvUJGwq7Ych7nrXHwGRNt3hS9yjNGRJk5d3pdIKjeZhQDVuFp0DnKjP4qoieGWFjswm7nHDLBaxWC3DxFIfLfRjMSEXd0Ta04vcTrbCpS9PEXebUUbMBxBt0VOb-PKVk-7Cq0FjuMXl4VtKneb5a3ujCo872goPN22GBFFhReJtWsQJLK/s1600/oll.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/05/ollama-out-of-bounds-read-vulnerability.html&#34;&gt;https://thehackernews.com/2026/05/ollama-out-of-bounds-read-vulnerability.html&lt;/a&gt;
    </content>
    <updated>2026-05-10T12:41:00Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqsdf4kn32w8dwk0dwfz4a40a64gfg0q8anktp750rfruzjq5s3wpvczypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w00c8qa</id>
    
      <title type="html">One Missed Threat Per Week: What 25M Alerts Reveal About ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqsdf4kn32w8dwk0dwfz4a40a64gfg0q8anktp750rfruzjq5s3wpvczypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w00c8qa" />
    <content type="html">
      One Missed Threat Per Week: What 25M Alerts Reveal About Low-Severity Risk&lt;br/&gt;&lt;br/&gt;The dark secret of enterprise security operations is that defenders have quietly institutionalized the practice of not looking. This is not just anecdotal, but rather backed by a recent report investigating more than 25 million security alerts, including informational and low-severity, across live enterprise environments. &lt;br/&gt;The dataset behind these findings includes 10 million monitored&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjUaPw5V89Ez9z5x8eFLFOhwPphGqXDQVGfd2sI-pX9Q1XTcpYlWEhFiZ6o12fzAyvtCFDQ0zs4AFlHl4HJNnjWH8hUXM9r_-oBl7YMEnU1F41Ho7DL23NJbgG4M3eoqF6CTZWqFtFcw0gOB8QfkCPW1_xQ-HwmvWr3GMzEeRFbC8SLgG5LsdnopTAHDOs/s1600/ai-soc.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/05/one-missed-threat-per-week-what-25m.html&#34;&gt;https://thehackernews.com/2026/05/one-missed-threat-per-week-what-25m.html&lt;/a&gt;
    </content>
    <updated>2026-05-08T10:30:00Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqsw0epmzr2fr493u6vmspz5qxrnut0p957spur8t9pphe3jre9upqgzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w7xefzr</id>
    
      <title type="html">PAN-OS RCE Exploit Under Active Use Enabling Root Access and ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqsw0epmzr2fr493u6vmspz5qxrnut0p957spur8t9pphe3jre9upqgzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w7xefzr" />
    <content type="html">
      PAN-OS RCE Exploit Under Active Use Enabling Root Access and Espionage&lt;br/&gt;&lt;br/&gt;Palo Alto Networks has disclosed that threat actors may have attempted to unsuccessfully exploit a recently disclosed critical security flaw as early as April 9, 2026.&lt;br/&gt;The vulnerability in question is CVE-2026-0300 (CVSS score: 9.3/8.7), a buffer overflow vulnerability in the User-ID Authentication Portal service of Palo Alto Networks PAN-OS software that could allow an unauthenticated attacker&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhA-FbTXMB7fJu_4ZxIlvKU2wHShSiMZaCQBah-p33256FjWEUsO0kd4s-LXOT_YQoS39Mj5f7nhj-ERtNF2EPNU9WG91ZWJXpl4cwYFoWz8npaMpVWzAhYjVVB-JnPyoycvPmik7Y5IsihIDXp7_mHvh4DYUz9vqkkVRYgylDqKeezcDEwqRJNs4F_2scA/s1600/paloalto-rce.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/05/pan-os-rce-exploit-under-active-use.html&#34;&gt;https://thehackernews.com/2026/05/pan-os-rce-exploit-under-active-use.html&lt;/a&gt;
    </content>
    <updated>2026-05-07T13:34:00Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqsqfhcjxhju6r2af9s4tj6fy52059hg9fa36arx94fz7gwmwcgcewczypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w9udtru</id>
    
      <title type="html">2026: The Year of AI-Assisted Attacks On December 4, 2025, a ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqsqfhcjxhju6r2af9s4tj6fy52059hg9fa36arx94fz7gwmwcgcewczypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w9udtru" />
    <content type="html">
      2026: The Year of AI-Assisted Attacks&lt;br/&gt;&lt;br/&gt;On December 4, 2025, a 17-year-old was arrested in Osaka under Japan’s Unauthorized Access Prohibition Act. The young man had run malicious code to extract the personal data of over 7 million users of Kaikatsu Club, Japan&amp;#39;s largest internet cafe chain. When asked, the young man shared his motivation for the hack: he wanted to buy Pokémon cards.&lt;br/&gt;In a sense, this is a fairly conventional story.&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEji6GV4hhCDB_wJkm6REZZfugW5H5hF8g8X27oGcUHnOSxYst1aJJspKKl6joygytGLwgKYvfDU_DD8DFHQ-vPt-_Tc1yzG8fJl_0tHuyOLgJC3eHKGFM_YZA_OIYoL7wI8lUWZrpGO_E2Sjunen7Y9g2fY7sRTi6cvk4DgBW5plToR5U-Je5GQeJsKuqY/s1600/ai-cyberattacks.png&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/05/2026-year-of-ai-assisted-attacks.html&#34;&gt;https://thehackernews.com/2026/05/2026-year-of-ai-assisted-attacks.html&lt;/a&gt;
    </content>
    <updated>2026-05-04T11:58:00Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqsrar2dclgzz875mkkjetnlrz4ff2qu7wuxumwq48y086l4k8vqktczypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wuytarf</id>
    
      <title type="html">Silver Fox Deploys ABCDoor Malware via Tax-Themed Phishing in ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqsrar2dclgzz875mkkjetnlrz4ff2qu7wuxumwq48y086l4k8vqktczypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wuytarf" />
    <content type="html">
      Silver Fox Deploys ABCDoor Malware via Tax-Themed Phishing in India and Russia&lt;br/&gt;&lt;br/&gt;The China-based cybercrime group known as Silver Fox has been linked to a new campaign targeting organizations in Russia and India with a new malware called ABCDoor.&lt;br/&gt;The activity involved using phishing emails that mimic correspondence from the Income Tax Department of India in December 2025, followed by a similar campaign aimed at Russian entities.&lt;br/&gt;&amp;#34;Both waves followed a nearly identical&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgjfw7HlDQIzbgA8xy1bk-sUkn-TVS85DGaL4vQkuTNYu3SGabQGuPKBD7C1qkCcpxwEFfdW6I9DJoSnmMmbkAu24SN1R_B2HNYwi-niSiST1LJqwMQ7tspMjxMyHXJtZUxGZbb2Hb1k-_2ywcG5hWFhOKQubJsYXiq8hyphenhyphenFfLyVewIet_ZcdTmNZEc9-Fum/s1600/godd.png&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/05/silver-fox-deploys-abcdoor-malware-via.html&#34;&gt;https://thehackernews.com/2026/05/silver-fox-deploys-abcdoor-malware-via.html&lt;/a&gt;
    </content>
    <updated>2026-05-04T11:57:00Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqsxr387l8yfeevn4pcwezjjr3ptyfzt37dt54glu0cv0yppxgzqeaszypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w77wgap</id>
    
      <title type="html">Trellix Confirms Source Code Breach With Unauthorized Repository ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqsxr387l8yfeevn4pcwezjjr3ptyfzt37dt54glu0cv0yppxgzqeaszypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w77wgap" />
    <content type="html">
      Trellix Confirms Source Code Breach With Unauthorized Repository Access&lt;br/&gt;&lt;br/&gt;Cybersecurity company Trellix has announced that it suffered a breach that enabled unauthorized access to a &amp;#34;portion&amp;#34; of its source code.&lt;br/&gt;It said it &amp;#34;recently identified&amp;#34; the compromise of its source code repository and that it began working with &amp;#34;leading forensic experts&amp;#34; to resolve the matter immediately. It also said it has notified law enforcement of the matter.&lt;br/&gt;Trellix did not disclose the&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgJ47NY9D4DSEZHqBNSGTjpmSJqwYVOzlIKGoG-0LTxSdIIDrMtyV2tOqRYcc-4kpxkE1UZ6nJhK4eXCGEsEmG6UcQeHn_YjAhRWXIAxo5yC75eUmLv3w5rur6SN6Qoee65gve-LgM0_3YGnAzQwTrQMTeTShRe_leh8_ImIlzU-Sgfy2kRqTcx5V-yG-3M/s1600/breach.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/05/trellix-confirms-source-code-breach.html&#34;&gt;https://thehackernews.com/2026/05/trellix-confirms-source-code-breach.html&lt;/a&gt;
    </content>
    <updated>2026-05-02T06:41:00Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqs8sggkfslh9w2nufcxzvl66vvyufxte77w9dtwjlp3zvvszerfwzczypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wr5evfh</id>
    
      <title type="html">Poisoned Ruby Gems and Go Modules Exploit CI Pipelines for ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqs8sggkfslh9w2nufcxzvl66vvyufxte77w9dtwjlp3zvvszerfwzczypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wr5evfh" />
    <content type="html">
      Poisoned Ruby Gems and Go Modules Exploit CI Pipelines for Credential Theft&lt;br/&gt;&lt;br/&gt;A new software supply chain attack campaign has been observed using sleeper packages as a conduit to subsequently push malicious payloads that enabled credential theft, GitHub Actions tampering, and SSH persistence.&lt;br/&gt;The activity has been attributed to the GitHub account &amp;#34;BufferZoneCorp,&amp;#34; which has published a set of repositories that are associated with malicious Ruby gems and Go modules. As of&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhNz4euGufhcyWdY8TkRfdXBUj2XXZlzQWEb1QyI7otpos158ctsC236sEm2NAZ20sUZv4AOqrGCSTbjGsOOkMwhQv53ZjyrVXf9SVUsMfhvhQ4LzGL87j44f0kMkXRzBAoWeHDz8hywx4gbW_trN1mFk-xCCZatTf0zNsude7k-3WE9kIY_pPgza53qsdc/s1600/buffer.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/05/poisoned-ruby-gems-and-go-modules.html&#34;&gt;https://thehackernews.com/2026/05/poisoned-ruby-gems-and-go-modules.html&lt;/a&gt;
    </content>
    <updated>2026-05-01T09:43:00Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqsx5ukmrzv8dkfrdfnd6tsd7vdpwnhr58rk28g5a4ql2f9c06jly8szypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wygg383</id>
    
      <title type="html">ThreatsDay Bulletin: SMS Blaster Busts, OpenEMR Flaws, 600K ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqsx5ukmrzv8dkfrdfnd6tsd7vdpwnhr58rk28g5a4ql2f9c06jly8szypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wygg383" />
    <content type="html">
      ThreatsDay Bulletin: SMS Blaster Busts, OpenEMR Flaws, 600K Roblox Hacks and 25 More Stories&lt;br/&gt;&lt;br/&gt;The internet is noisy this week. We are seeing some wild new tactics, like people using fake cell towers to send scam texts, while some developers are accidentally downloading tools that peek into their private files during a simple install. It is definitely a busy time to be online.&lt;br/&gt;Security is always a moving target. Millions of servers are currently sitting online without any passwords, and&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgwfqxUhPz38fAoq0CZr2tW8KqGW-Cr0zJloN9kS_80QO2e7yyah4N-nMKNxoSllB2tpyjKO25s2f8eFJNd2bBo50XRAVatMKnnk8ZAbRbz6kfQUhVUoD5vutOmFpYzojybY8aJZhA6KGL3sawNEyaqjlW63hAeEwrTsj8lnpou-4mThnzwCzO442aue-R0/s1600/threats.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/04/threatsday-bulletin-sms-blaster-busts.html&#34;&gt;https://thehackernews.com/2026/04/threatsday-bulletin-sms-blaster-busts.html&lt;/a&gt;
    </content>
    <updated>2026-04-30T13:55:00Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqszg5nrdhrqhavmz2fnwmsj67j6ql8eurnsh8ncc9lp5pt6jdtj0sczypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w6m66u9</id>
    
      <title type="html">New Python Backdoor Uses Tunneling Service to Steal Browser and ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqszg5nrdhrqhavmz2fnwmsj67j6ql8eurnsh8ncc9lp5pt6jdtj0sczypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w6m66u9" />
    <content type="html">
      New Python Backdoor Uses Tunneling Service to Steal Browser and Cloud Credentials&lt;br/&gt;&lt;br/&gt;Cybersecurity researchers have disclosed details of a stealthy Python-based backdoor framework called DEEP#DOOR that comes with capabilities to establish persistent access and harvest a wide range of sensitive information from compromised hosts.&lt;br/&gt;&amp;#34;The intrusion chain begins with execution of a batch script (&amp;#39;install_obf.bat&amp;#39;) that disables Windows security controls, dynamically extracts an&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgnv1KtLLlZSnm9a16bN-o_szrBiAIN_QljTfe09K4RzFxSqhFADtuXmRzOPZ_Poazif-VadFAnRnboCWX5yZtc5JntGopn5Fy6T1X2BexXelFOxYtEA7qULoTCkAMwEybLf42JJ_yGjSPf_T-tjYvbqxscVgZ6OyL65yKcTjC0KQL48pgYLZUmLjxfBBhd/s1600/malware-data.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/04/new-python-backdoor-uses-tunneling.html&#34;&gt;https://thehackernews.com/2026/04/new-python-backdoor-uses-tunneling.html&lt;/a&gt;
    </content>
    <updated>2026-04-30T12:36:00Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqs245s2ht60e6p8w5h0rftkuyxs0cvqfdsptta4hshmaqr3gkc3c6gzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w5twy9c</id>
    
      <title type="html">Google Fixes CVSS 10 Gemini CLI CI RCE and Cursor Flaws Enable ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqs245s2ht60e6p8w5h0rftkuyxs0cvqfdsptta4hshmaqr3gkc3c6gzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w5twy9c" />
    <content type="html">
      Google Fixes CVSS 10 Gemini CLI CI RCE and Cursor Flaws Enable Code Execution&lt;br/&gt;&lt;br/&gt;Google has addressed a maximum severity security flaw in Gemini CLI -- the &amp;#34;@google/gemini-cli&amp;#34; npm package and the &amp;#34;google-github-actions/run-gemini-cli&amp;#34; GitHub Actions workflow -- that could have allowed attackers to execute arbitrary commands on host systems.&lt;br/&gt;&amp;#34;The vulnerability allowed an unprivileged external attacker to force their own malicious content to load as Gemini configuration,&amp;#34;&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhoqSVEXaseT8C79cbC1Wjec2TiF4nMK72XiCPL3WBxqwNy9iUk5CSEqSXgwJFRug0zXq5foMAXzMYCSIP0nEnr-CxCeYFgjmVcOfPtK4nocQaGDzIFecL9SScOScUhVAgGkff6wO5ks-sqWA_KCEZnfrQhfViSGai-g0MOd2IHOYX_N03JvwIipkQ1gso7/s1600/gemini-cursor.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/04/google-fixes-cvss-10-gemini-cli-ci-rce.html&#34;&gt;https://thehackernews.com/2026/04/google-fixes-cvss-10-gemini-cli-ci-rce.html&lt;/a&gt;
    </content>
    <updated>2026-04-30T07:07:00Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqsvsle00gx9uksf0wvkya4esnz4ywru9jggus54zxckrxengcuswjszypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wr0gdz0</id>
    
      <title type="html">SAP npm Packages Compromised by “Mini Shai-Hulud” ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqsvsle00gx9uksf0wvkya4esnz4ywru9jggus54zxckrxengcuswjszypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wr0gdz0" />
    <content type="html">
      SAP npm Packages Compromised by “Mini Shai-Hulud” Credential-Stealing Malware&lt;br/&gt;&lt;br/&gt;Cybersecurity researchers are sounding the alarm about a new supply chain attack campaign targeting SAP-related npm Packages with credential-stealing malware.&lt;br/&gt;According to reports from Aikido Security, SafeDep, Socket, StepSecurity, and Google-owned Wiz, the campaign – calling itself the mini Shai-Hulud – has affected the following packages associated with SAP&amp;#39;s JavaScript and cloud application&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhoviEyxWTNHg8ARy1a-r9k4-LpHIhfCKGFL71YHc6H2v8XiyHbkvdsU26IC8jHa304gwz8zE9dXXWcL8NaA5X5KRLIWFDpxB1hjQU1af_B6uGEEr3i_RNOub2DSShyphenhyphenBXp0C3p6343TffijodxMsHVFQ-Dc9jPPApgk1uluKVP8NzUHtx1yd50YLkSw6z6G/s1600/saps.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/04/sap-npm-packages-compromised-by-mini.html&#34;&gt;https://thehackernews.com/2026/04/sap-npm-packages-compromised-by-mini.html&lt;/a&gt;
    </content>
    <updated>2026-04-29T16:26:00Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqs87tljgd0xul6s3lfzpmjh88pfwveyvzwdnlt4ahar65jvhx5d98szypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wrwh72k</id>
    
      <title type="html">Brazilian LofyGang Resurfaces After Three Years With Minecraft ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqs87tljgd0xul6s3lfzpmjh88pfwveyvzwdnlt4ahar65jvhx5d98szypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wrwh72k" />
    <content type="html">
      Brazilian LofyGang Resurfaces After Three Years With Minecraft LofyStealer Campaign&lt;br/&gt;&lt;br/&gt;A cybercrime group of Brazilian origin has resurfaced after more than three years to orchestrate a campaign that targets Minecraft players with a new stealer called LofyStealer (aka GrabBot).&lt;br/&gt;&amp;#34;The malware disguises itself as a Minecraft hack called &amp;#39;Slinky,&amp;#39;&amp;#34; Brazil-based cybersecurity company ZenoX said in a technical report. &amp;#34;It uses the official game icon to induce voluntary execution,&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgQf8Wzg1Ms0KVsO546uQuwlR3w_8qW1MQZExs5TgKCGHSNNS1UEnOITq-_y8HIrA_3n_gfq7Hm0IMb-XSRJSsGL1ncRPlPoyDX7cf_wFbEGAJCPkv6ZDBzjN1Nswe9-CMR3Tmn1F5KuVyWGdOkGEIbeI9R7zGKplJPofRFBx-Ru20JOGfAFEpiZOAlDBXh/s1600/hackers.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/04/brazilian-lofygang-resurfaces-after.html&#34;&gt;https://thehackernews.com/2026/04/brazilian-lofygang-resurfaces-after.html&lt;/a&gt;
    </content>
    <updated>2026-04-28T17:39:00Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqsrxwhha9j5snh8zqws5glazml34f8xz78t6egflm277s02ef7en9szypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wh8qa8g</id>
    
      <title type="html">Mythos Changed the Math on Vulnerability Discovery. Most Teams ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqsrxwhha9j5snh8zqws5glazml34f8xz78t6egflm277s02ef7en9szypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wh8qa8g" />
    <content type="html">
      Mythos Changed the Math on Vulnerability Discovery. Most Teams Aren&amp;#39;t Ready for the Remediation Side&lt;br/&gt;&lt;br/&gt;Anthropic’s Claude Mythos Preview has dominated security discussions since its April 7 announcement. Early reporting describes a powerful cybersecurity-focused AI system capable of identifying vulnerabilities at scale and raising serious questions about how quickly organizations can validate, prioritize, and remediate what it finds.&lt;br/&gt;The debate that followed has mostly focused on the right&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiR-gtpmKWvXoC5M5eOQM8k01yoiVjMDTYwRePtuLtpEPMevNdUs3BrVGykkop3OgF-DGCjpXB5T_AS84khCvVv7J-4W-7aE2ND0VuYbnyD8B6l1DUk_TVi96ab977o9i81hIIubY3l5F2A7_Qe4P4-qMTMzwnrvoXYC3cRhBU0X1VpG4F_MwstEGUQYHg/s1600/unnamed.png&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/04/mythos-changed-math-on-vulnerability.html&#34;&gt;https://thehackernews.com/2026/04/mythos-changed-math-on-vulnerability.html&lt;/a&gt;
    </content>
    <updated>2026-04-27T11:58:00Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqs2mvdh9wg4dutr8xpm99akg2697xpenl2s3rmvjygdkagtk09a65szypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0weznhdc</id>
    
      <title type="html">PhantomCore Exploits TrueConf Vulnerabilities to Breach Russian ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqs2mvdh9wg4dutr8xpm99akg2697xpenl2s3rmvjygdkagtk09a65szypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0weznhdc" />
    <content type="html">
      PhantomCore Exploits TrueConf Vulnerabilities to Breach Russian Networks&lt;br/&gt;&lt;br/&gt;A pro-Ukrainian hacktivist group called PhantomCore has been attributed to attacks actively targeting servers running TrueConf video conferencing software in Russia since September 2025.&lt;br/&gt;That&amp;#39;s according to a report published by Positive Technologies, which found the threat actors to be leveraging an exploit chain comprising three vulnerabilities to execute commands remotely on susceptible&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi02vvwkoYlj343usA-GYXcQHZKIceJufKYFzZNyHlsGQ6lCPD8H8bHEWtzBnJsWmnlQsGq0fBLgyKTdnOoEi83L3kQ8V3EOou_vlAmMhnMDFU5P5LxA-Sz1agVhDmFrd2qKHGnYZituJuoAEsHp0ExFR4pw6VCf9VNESl7C4q5Wkefh6_8rN2MDK96yh_a/s1600/russian-cyberattack.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/04/phantomcore-exploits-trueconf.html&#34;&gt;https://thehackernews.com/2026/04/phantomcore-exploits-trueconf.html&lt;/a&gt;
    </content>
    <updated>2026-04-27T11:54:00Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqsglmvl3jt0xj0hd83ne6r2ffjr07nrcscraexrtchkw45t4s29kfczypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wf03k0r</id>
    
      <title type="html">Researchers Uncover Pre-Stuxnet ‘fast16’ Malware Targeting ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqsglmvl3jt0xj0hd83ne6r2ffjr07nrcscraexrtchkw45t4s29kfczypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wf03k0r" />
    <content type="html">
      Researchers Uncover Pre-Stuxnet ‘fast16’ Malware Targeting Engineering Software&lt;br/&gt;&lt;br/&gt;Cybersecurity researchers have discovered a new Lua-based malware created years before the notorious Stuxnet worm that aimed to sabotage Iran&amp;#39;s nuclear program by destroying uranium enrichment centrifuges.&lt;br/&gt;According to a new report published by SentinelOne, the previously undocumented cyber sabotage framework dates back to 2005, primarily targeting high-precision calculation software to tamper&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiZkfsrDz8tSCNCt3TCff2Uhdw1B_qIeXGY5d1Hvp85TUkZlBQ85cPUd-im3PPmoW8WyfRf6QzPbly8aUVvhgTr86IUVl3XoV2xHuKhVN36WT-hM9vHmbQ9LJ0xmiYG8ha73yyNsYoKiy_e-lrAksEuQVk9iaFJPYOWu5lZlwSIqgoN4wqHUBoHZqMHwlyI/s1600/cyberattack.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/04/researchers-uncover-pre-stuxnet-fast16.html&#34;&gt;https://thehackernews.com/2026/04/researchers-uncover-pre-stuxnet-fast16.html&lt;/a&gt;
    </content>
    <updated>2026-04-25T09:26:00Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqs26tmfp7ed6rp4gsfxypvwr9ez7x65f6z4uwu4j656rprym4ze38szypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w7ug9am</id>
    
      <title type="html">UNC6692 Impersonates IT Helpdesk via Microsoft Teams to Deploy ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqs26tmfp7ed6rp4gsfxypvwr9ez7x65f6z4uwu4j656rprym4ze38szypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w7ug9am" />
    <content type="html">
      UNC6692 Impersonates IT Helpdesk via Microsoft Teams to Deploy SNOW Malware&lt;br/&gt;&lt;br/&gt;A previously undocumented threat activity cluster known as UNC6692 has been observed leveraging social engineering tactics via Microsoft Teams to deploy a custom malware suite on compromised hosts.&lt;br/&gt;&amp;#34;As with many other intrusions in recent years, UNC6692 relied heavily on impersonating IT helpdesk employees, convincing their victim to accept a Microsoft Teams chat invitation from an account&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiHoBLtF5qmS63UuZJdrs4DtwoJRc6V3OK_4vUjCp-mHUs99AlJkzxcQgZH-tD0dFneYJHfBEumdGw42jcqcYHYiqmNHBtHZVB7m83pxPakcbupcdcRmDzg2fedK4doHPUwOfGoqY2a44VUwgK1g8cyZSgpMmpzcbWuBrzxvdalA9bkt8_26WkdIfZy6qqa/s1600/helpdesk.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/04/unc6692-impersonates-it-helpdesk-via.html&#34;&gt;https://thehackernews.com/2026/04/unc6692-impersonates-it-helpdesk-via.html&lt;/a&gt;
    </content>
    <updated>2026-04-23T18:16:00Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqsqpanzdmfr0p2hlqmj7pnze4j3ps2vjprqhc5lvt63stwlq38gtvczypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w6429ea</id>
    
      <title type="html">No Exploit Needed: How Attackers Walk Through the Front Door via ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqsqpanzdmfr0p2hlqmj7pnze4j3ps2vjprqhc5lvt63stwlq38gtvczypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w6429ea" />
    <content type="html">
      No Exploit Needed: How Attackers Walk Through the Front Door via Identity-Based Attacks&lt;br/&gt;&lt;br/&gt;The cybersecurity industry has spent the last several years chasing sophisticated threats like zero-days, supply chain compromises, and AI-generated exploits. However, the most reliable entry point for attackers still hasn&amp;#39;t changed: stolen credentials.&lt;br/&gt;Identity-based attacks remain a dominant initial access vector in breaches today. Attackers obtain valid credentials through credential stuffing&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEin_RithPNlLYdgxg906-M63Q0-Kv83Kl-WNjK8x5OjKiSgcDMaljvqb7XkLPoEeUDEMRdi4Cqh9DH-pv9QP1ViNjUi3q3qn5r_Lig04a3zO9TgkgiQqSLC50mE6q-6hr94bo4UnXnP5QksLGeAgSOemxUOZaXIw9Z2UHpZuinm7pqF9N0xtJNVovfojx0/s1600/door.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/04/no-exploit-needed-how-attackers-walk.html&#34;&gt;https://thehackernews.com/2026/04/no-exploit-needed-how-attackers-walk.html&lt;/a&gt;
    </content>
    <updated>2026-04-21T11:30:00Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqs8q5tusx2haqe6zwn8ngamuh3tntcfs6dyv9lzh9mufsudgx5amwszypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0ww27gcq</id>
    
      <title type="html">Analysis of 216M Security Findings Shows a 4x Increase In ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqs8q5tusx2haqe6zwn8ngamuh3tntcfs6dyv9lzh9mufsudgx5amwszypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0ww27gcq" />
    <content type="html">
      Analysis of 216M Security Findings Shows a 4x Increase In Critical Risk (2026 Report)&lt;br/&gt;&lt;br/&gt;OX Security recently analyzed 216 million security findings across 250 organizations over a 90-day period. The primary takeaway: while raw alert volume grew by 52% year-over-year, prioritized critical risk grew by nearly 400%.&lt;br/&gt;The surge in AI-assisted development is creating a &amp;#34;velocity gap&amp;#34; where the density of high-impact vulnerabilities is scaling faster than&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh4H3KkiSOm6TbNn7e0Ceu3-etqqeLci47PtX9T-0WGgdGScHfd2tfFamA6oyOi62wWwKF7KwF_wcqNACSvRVJvH__1YKoP_fP7T5LFdDqX8jxFph0NSaVJjFEVhb0bjNvn5IWayqMwKyRNbp9mmW7f2JLs7I3pTF8yLuhCOHsbnpNVLrEVq6Uq63j8508/s1600/derailed.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/04/analysis-of-216m-security-findings.html&#34;&gt;https://thehackernews.com/2026/04/analysis-of-216m-security-findings.html&lt;/a&gt;
    </content>
    <updated>2026-04-14T10:00:00Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqspmqdp9tvachee9g5mvumgpmq9jukn669zsaary8mslscg9vryxkqzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w3n2y8c</id>
    
      <title type="html">CPUID Breach Distributes STX RAT via Trojanized CPU-Z and ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqspmqdp9tvachee9g5mvumgpmq9jukn669zsaary8mslscg9vryxkqzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0w3n2y8c" />
    <content type="html">
      CPUID Breach Distributes STX RAT via Trojanized CPU-Z and HWMonitor Downloads&lt;br/&gt;&lt;br/&gt;Unknown threat actors compromised CPUID (&amp;#34;cpuid[.]com&amp;#34;), a website that hosts popular hardware monitoring tools like CPU-Z, HWMonitor, HWMonitor Pro, and PerfMonitor, for less than 24 hours to serve malicious executables for the software and deploy a remote access trojan called STX RAT.&lt;br/&gt;The incident lasted from approximately April 9, 15:00 UTC, to about April 10, 10:00 UTC, with&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhCPq2en6ihCNpYdSr5mWkN43O4Rl3tXYz77I2achAfYSy7Emoaj8fNqmFHLOydg6Ai6DwDKBEKD91ywcO9eT2t-rrFxEiThe79Rsa4dap_UcNZSEdWl9NRGeaMqP_vsbWnKf2mMNHQ86cabK4wlspLPWRHMJ7Gj5guX6ynx57RhsDLbJeSDAdPR_BjGFNU/s1600/downloads.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/04/cpuid-breach-distributes-stx-rat-via.html&#34;&gt;https://thehackernews.com/2026/04/cpuid-breach-distributes-stx-rat-via.html&lt;/a&gt;
    </content>
    <updated>2026-04-12T05:54:00Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqsz2v67qwtflymn0dtvlv857y5j20xf7azalmmex7ek0uw7y8xvg6qzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wu5ww6q</id>
    
      <title type="html">Flowise AI Agent Builder Under Active CVSS 10.0 RCE Exploitation; ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqsz2v67qwtflymn0dtvlv857y5j20xf7azalmmex7ek0uw7y8xvg6qzypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wu5ww6q" />
    <content type="html">
      Flowise AI Agent Builder Under Active CVSS 10.0 RCE Exploitation; 12,000&#43; Instances Exposed&lt;br/&gt;&lt;br/&gt;Threat actors are exploiting a maximum-severity security flaw in Flowise, an open-source artificial intelligence (AI) platform, according to new findings from VulnCheck.&lt;br/&gt;The vulnerability in question is CVE-2025-59528 (CVSS score: 10.0), a code injection vulnerability that could result in remote code execution.&lt;br/&gt;&amp;#34;The CustomMCP node allows users to input configuration settings for connecting&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjCGR6ZfT0_UppVPQsgk7lwTbzfybdDFY-HeJi9F6VE6HuN7-Ja-lpveDnPA-kcS7x8l1oZ0lUqPoEFdRTOMt0Z8H6EeT_NadV_P7bjlh8Je6Q-T5KAlOCzOWt-LyY3jY8RsTlRTUzuXsVwf_gs-_KyXw8G_LcFz2dY-2P9XozQWy2p9PneNGUMctvpIZYM/s1600/flowise.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/04/flowise-ai-agent-builder-under-active.html&#34;&gt;https://thehackernews.com/2026/04/flowise-ai-agent-builder-under-active.html&lt;/a&gt;
    </content>
    <updated>2026-04-07T05:56:00Z</updated>
  </entry>

  <entry>
    <id>https://njump.me/nevent1qqsvquc5tcam3mf379qwn27uenp84grhq5lqwfttwrthr8d3dur7w6czypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wncy9dk</id>
    
      <title type="html">Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable ...</title>
    
    <link rel="alternate" href="https://njump.me/nevent1qqsvquc5tcam3mf379qwn27uenp84grhq5lqwfttwrthr8d3dur7w6czypyc5hjrkw268m44j7vs89sxph0qg96229njv2e6ymr6ccnvkds0wncy9dk" />
    <content type="html">
      Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300&#43; EDR Tools&lt;br/&gt;&lt;br/&gt;Threat actors associated with Qilin and Warlock ransomware operations have been observed using the bring your own vulnerable driver (BYOVD) technique to silence security tools running on compromised hosts, according to findings from Cisco Talos and Trend Micro.&lt;br/&gt;Qilin attacks analyzed by Talos have been found to deploy a malicious DLL named &amp;#34;msimg32.dll,&amp;#34;&lt;br/&gt;&lt;br/&gt; &lt;img src=&#34;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgtrUKOrJ2Y_pSYHNcKDjbrBsZa2igYlNorTwmH31JNSjdA7VP84kXj23nmkk7DTqlrCUsfCjNo6xt-niyZeKeCR7VtBzMWW9eNUKzU0WGnpmw2yYjHBdboP2uF2UA8CCsdclyeDlRJcU7DEOD8OrFthlhQX-OkgePmyT__ZDQA4IXgRYbnNtp21MoleCTU/s1600/lock-ransomware.jpg&#34;&gt; &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://thehackernews.com/2026/04/qilin-and-warlock-ransomware-use.html&#34;&gt;https://thehackernews.com/2026/04/qilin-and-warlock-ransomware-use.html&lt;/a&gt;
    </content>
    <updated>2026-04-06T10:07:00Z</updated>
  </entry>

</feed>