Hackers are conducting a large-scale automated scanning campaign against internet-exposed Vite development servers, attempting to steal AWS credentials, Azure access tokens, environment variables, and Infrastructure-as-Code secrets. F5 honeypot sensors recorded …
UK Government Begins Moving 23 Million Users Away From Passwords
The UK government has begun rolling out passkeys across GOV.UK One Login, offering more than 23 million users a passwordless way to access public services. The deployment covers everything from …
Nintendo Switch Vulnerability Allows Attackers to Run Unauthorized Code on Your Console
Nintendo has patched a high-severity vulnerability in the original Nintendo Switch that could let a nearby attacker execute unauthorized code and access information stored on the console. Tracked as CVE-2026-82079, …
Microsoft Offers Up to $30,000 for Critical AI Flaws in Dynamics 365 and Power Platform
Microsoft is offering security researchers up to $30,000 for finding critical AI vulnerabilities in Dynamics 365 and Power Platform, sharpening its focus on flaws that could manipulate AI inference or …
AWS Systems Manager Agent Vulnerability Allows Attackers to Bypass Port-Forwarding Restrictions
A critical vulnerability in the AWS Systems Manager Agent could let authenticated attackers bypass remote-host port-forwarding restrictions and access sensitive link-local services, including the Amazon EC2 Instance Metadata Service. The …
Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users
A browser extension promoted as a Twitch viewing helper has been found sending live account tokens through servers controlled by its operator. The add-on, called “Twitch Enhanced Viewer | JeetBot,” …
WhatsApp’s New Restricted Chat Feature Locks Conversation on Your Primary Phone
WhatsApp is developing a new privacy control called Restricted Chat that will keep selected conversations accessible only from a user’s primary mobile phone. The feature is designed to prevent protected …
Cyclops Blink Evolves Into x86-64 Linux Implant With Packet Sniffing and Internal Network Scanning
Cyclops Blink has returned in a form that gives attackers a deeper view inside corporate networks. The malware was found on compromised Cisco Firewall Management Center devices, where it can …
New ZcopyReaper Linux Kernel Vulnerability Enables Privilege Escalation Attacks
A new Linux kernel vulnerability dubbed ZcopyReaper allows an unprivileged local attacker to escalate privileges and potentially gain root-level control. Tracked as CVE-2026-43502, the flaw was demonstrated through an exploit called ZcopyReaper …
One Click on a Malicious Link Lets Hackers Backdoor Sogou Input Method Users
A single click on a malicious link could have given attackers a direct path into Windows systems running Sogou Input Method. The flaw turned a commonly installed Chinese-language typing tool …
