May 25, 2026 A well-known Iranian threat group has found a new way to push malware onto people’s machines. Instead of sending phishing emails, the group built a fake website …
Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks
Authorities in the Netherlands have arrested the co-owners of two related Internet hosting companies for operating IT infrastructure used by Russia to carry out cyberattacks, influence operations and disinformation campaigns …
Kazuar Malware Evolves Into Modular Espionage Ecosystem for Secret Blizzard Operations
May 25, 2026 A Russian state-sponsored threat group has quietly upgraded one of its most powerful cyber weapons, and the result is a spying tool that is harder to detect, …
Hackers Actives Scanning SonicWall Firewall Interfaces – 597,000 Sessions Observed
May 25, 2026 A sharp rise in internet-wide scanning activity targeting SonicWall firewall management interfaces has been detected, raising concerns about a potential pre-disclosure reconnaissance phase tied to new vulnerabilities. …
Italian Authorities Dismantled CINEMAGOAL App that Enables Access to Various Streaming Platforms
May 25, 2026 Italian law enforcement has dismantled a large-scale audiovisual piracy network centered around a sophisticated application called CINEMAGOAL, which enabled users to access premium streaming services without authorization. The …
MiniUpdate RAT Uses Azure-Hosted C2 Domains for Targeted Espionage Campaigns
May 25, 2026 A new wave of targeted espionage attacks has put technology professionals across the United States, Israel, and the United Arab Emirates on high alert. The threat comes …
WhatsApp Chat Histories Stored Unencrypted on macOS and iOS
May 25, 2026 Security researchers have revealed that WhatsApp chat histories may be stored unencrypted on both macOS and iOS devices, raising fresh concerns about local data protection and cross-application …
CISA Warns of Drupal Core SQL Injection Vulnerability Exploited in Attacks
May 25, 2026 CISA has issued an urgent alert regarding a critical SQL injection vulnerability in Drupal Core, tracked as CVE-2026-9082, which is now being actively exploited in real-world attacks. …
GitHub Adds Staged Publishing to npm to Block Automated Supply Chain Attacks
May 25, 2026 GitHub has introduced a major security upgrade to the npm ecosystem with the general availability of staged publishing and new install-time controls, aimed at reducing automated supply …
Pentest Agent Suite – Bug Bounty Framework for Claude Code and 6 AI Coding Tools
May 25, 2026 A fully autonomous bug-bounty framework called Pentest Agent Suite has been open-sourced, delivering 50 specialized security agents, 26 slash commands, 19 CLI tools, and a cross-IDE installer …

