Hackers are making some phishing pages harder to track by changing the code delivered to every visitor. An examined operation served a credential-stealing form whose appearance stayed familiar while its …
Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days
A cyber incident reportedly forced a British power plant to halt operations for about four days in July, drawing attention to the security of less-visible energy sites. The shutdown did …
Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies, and diplomatic organizations in Romania, Spain, and Türkiye. The campaign relied on Word documents designed …
Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort through 700GB of stolen corporate data every hour. The group says the system helps it …
Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix
A fake student resume is being used to place a remote-access tool on researchers’ Windows computers. The campaign hides a Windows executable inside an archive that appears to contain a …
Hackers Use Fake Student Resume to Secretly Install Malware on Researchers’ Computers
A fake student resume is being used to place a remote-access tool on researchers’ Windows computers. The campaign hides a Windows executable inside an archive that appears to contain a …
Russian University Leak Exposes GRU Cyber Training Pipeline Behind APT28 and Sandworm
Leaked university records have opened an unusual window into Russia’s military cyber ecosystem. The documents point to a structured training program, not a newly discovered piece of malware, that appears …
Dark Caracal Hackers Use Ethereum Blockchain to Keep New Malware Connected After C2 Disruption
Dark Caracal has returned with a new tool that helps attackers stay connected when defenders shut down their control servers. The cyberespionage group is linked by researchers to a Venezuelan …
Claude Code Opus 5 Auto Mode Hijacked via Prompt Injection to Execute Malicious Code
Claude Code Opus 5 in Auto Mode can be tricked into running malicious code via a simple website summary request. In a limited lab test, the attack reportedly succeeded in …
CISA Warns of Linux Kernel Privilege Escalation Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency has added a Linux kernel vulnerability, tracked as CVE-2026-53362, to its Known Exploited Vulnerabilities catalog after confirming that attackers are exploiting the flaw …
