May 26, 2026 A new wave of phishing operations is quietly changing the way cybercriminals steal financial data from everyday people. Rather than relying on traditional SMS messages that carriers …
Payload Ransomware Uses ChaCha20 and Curve25519 ECDH to Encrypt Windows Files
May 26, 2026 A dangerous new ransomware strain called Payload has been quietly building a global victim list since it first appeared in February 2026. The group launched its leak …
PuTTY 0.84 Released With Fix for SSH KEX Crashes and Telnet Prompt Spoofing Flaw
May 26, 2026 PuTTY 0.84 has been released with fixes for multiple minor security flaws, including issues that could trigger SSH key exchange crashes and a Telnet prompt spoofing weakness. …
New 7-Zip Vulnerabilities Let Attackers Execute Arbitrary Code and Compromise Systems
A critical heap buffer overflow vulnerability has been disclosed in 7-Zip version 26.00, enabling attackers to achieve arbitrary code execution via a vtable hijack by exploiting a defect in the …
Anthropic’s Restricted Claude Mythos Moves Toward Public Release via Claude Code and Security
May 26, 2026 Anthropic appears to be loosening its grip on Claude Mythos, the company’s most powerful and previously restricted AI model, with new signals pointing to a commercially versioned …
InvisibleFerret Malware Now Ships as .pyd and .so Files to Evade Script Detection
May 25, 2026 A North Korea-linked hacker group has quietly upgraded one of its most dangerous tools, making it harder for security software to detect. InvisibleFerret, an information-stealing malware tied …
Cloud Atlas APT Group Modifies termsrv.dll to Enable Multiple RDP Sessions on Victim Hosts
May 25, 2026 A well-known advanced persistent threat group called Cloud Atlas has been caught using a dangerous technique to hijack Windows systems without alerting anyone on the network. The …
Russian Hacker Used Jailbroken Gemini to Steal Admin Credentials and Drain Crypto Wallets
May 25, 2026 A solo Russian-speaking threat actor leveraged a jailbroken instance of Google Gemini to run a five-year MAGA-themed influence operation, crack WordPress administrator credentials, and empty at least …
Hackers Abuse Shared CDN Infrastructure to Bypass Domain Reputation Security Controls
May 25, 2026 Hackers are actively abusing a flaw in shared Content Delivery Network (CDN) infrastructure to hide malicious traffic behind trusted, high-reputation domains, effectively slipping past the security tools …
KnowledgeDeliver LMS Zero-Day Exploited to Deploy BLUEBEAM Web Shell
May 25, 2026 A newly disclosed zero-day vulnerability in the KnowledgeDeliver Learning Management System (LMS) has been actively exploited in the wild to deploy the BLUEBEAM in-memory web shell, according …
