Your LG smart TV may be doing far more than displaying your favorite shows while it sits “off” in the corner of your living room. A new investigation from Gamers …
New BYOTC Attack Hijacks Trusted Windows Apps to Abuse Privileged Kernel Drivers
A new Windows attack shows how a trusted program can become a path to sensitive system functions. The method, called Bring Your Own Trusted Caller, or BYOTC, turns a legitimate …
Kimsuky Hackers Use OpenCode AI Agent to Mass-Produce Phishing Decoys in LNK Attacks
Kimsuky has been observed using an AI agent to produce convincing phishing decoys at scale, then hiding malware inside Windows shortcut files. The latest activity shows how ordinary-looking documents can …
DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms
South Korean automotive and media organizations have been hit by a quiet Linux intrusion toolkit built for long-term access. The malware hides inside software that manages web traffic, allowing attackers …
Roundcube Webmail Patches 12 Security Flaws, Including Zero-Click XSS and SSRF Bypass
Roundcube Webmail has released security updates for its 1.6 LTS and 1.7 branches, fixing 12 vulnerabilities that could expose users and servers to cross-site scripting, email header injection, cross-user data …
Fake Minecraft Mod Deploys Myth Stealer RAT to Steal Browser Credentials and Cookies
A counterfeit Minecraft optimisation mod is installing Myth Stealer, malware that can steal browser passwords, cookies and data. Its malicious file looks useful because features work as advertised, giving players …
Telerik Flaw Chain Lets Unauthenticated Attackers Turn Padding Oracle Into Remote Code Execution
Security researchers have uncovered a significant vulnerability chain in Telerik UI for ASP.NET AJAX, allowing unauthenticated attackers to execute remote code in vulnerable enterprise web applications. The issue primarily affects …
OpenVPN Fixes 7 Security Flaws Affecting VPN Connections and Windows Systems
The OpenVPN project has shipped version 2.7.7, a security-focused release that patches seven distinct vulnerabilities spanning the software’s core reliability layer and its Windows-specific service components. The update, released on …
Malicious Chrome Extension Can Steal Login Sessions and Turn PCs Into Remote Backdoors
PEEP, a malicious Chrome extension posing as Smart Bookmarks, can steal active login sessions and turn an already compromised Windows computer into a remote backdoor. The finding shows how a …
N-able Released Hotfix for RCE Vulnerability Affecting Platform
N-able has released N-central 2026.3 Hotfix 4 to fix CVE-2026-86218. This critical vulnerability could allow an unauthenticated attacker to execute code remotely on an exposed N-central server. The update, identified …
