A new Microsoft Teams vishing campaign is using fake IT support calls to gain remote access to corporate systems. The attackers then deploy GoGRPC, a Go-based backdoor that can run …
PortSwigger Launches Burp AT Agentic AI for Human-Led Web Penetration Testing
July 28, 2026 PortSwigger has officially launched Burp AT in public beta, bringing agentic AI capabilities directly into Burp Suite Professional for the first time. The new feature allows penetration …
Operation STANDOFF Hides Command-and-Control Traffic Behind GitHub Redirects
July 28, 2026 Operation STANDOFF is a Russian-speaking cybercrime campaign that turns a single infection into a wider compromise. Its installer delivers information stealers, loaders, a cryptocurrency miner, and botnet …
CISA Warns of Fortinet FortiOS Vulnerability Exploited in Attacks
July 28, 2026 CISA has added the actively exploited Fortinet FortiOS vulnerability CVE-2025-68686 to its Known Exploited Vulnerabilities (KEV) catalog after confirming evidence of active attacks. The vulnerability affects Fortinet …
How DCSync Attack Helps Hackers Steal Password Hashes Silently from Active Directory
Active Directory is the beating heart of identity in most enterprises, and its single most valuable secret is the password hash of every user, service, and machine account. A DCSync …
Europol Targets the Online Network Turning Teen Hackers Into Extortionists and Violent Offenders
July 28, 2026 Europol is enhancing its response to “The Com,” a dangerous online ecosystem that allegedly recruits and manipulates minors into cyberattacks, extortion schemes, sexual exploitation, and violent offenses. …
OpenAI CEO Sam Altman Claims AI Has Reached Singularity, Where Systems Improve by Themselves
July 28, 2026 OpenAI CEO Sam Altman has declared that artificial intelligence has entered the long-theorized singularity, a pivotal stage where AI systems begin improving themselves at an accelerating pace …
Microsoft Defender for Endpoint Update Leaves Few Linux Servers Unprotected After Reboot
July 27, 2026 A recent Microsoft Defender for Endpoint update briefly disabled antivirus protection on Linux servers following an upgrade and reboot, exposing affected machines to threats before Microsoft rolled …
Critical vBulletin Flaw Lets Unauthenticated Attackers Execute PHP Code Remotely
July 27, 2026 vBulletin has patched CVE-2026-61511, a critical remote code execution flaw that could let unauthenticated attackers execute arbitrary PHP code and compromise vulnerable forum servers. This issue affects …
GitHub Adds 3-Day Dependabot Cooldown to Block Malicious Package Updates
July 27, 2026 GitHub has introduced a default three-day cooldown period for Dependabot version updates to reduce the risk of projects automatically adopting new malicious packages. This change targets a …
