July 2, 2026 A stealthy campaign is turning trusted remote access software into a weapon against everyday users and businesses. Attackers have hidden the AsyncRAT trojan inside fake software installers, …
Microsoft 365 Phishing Panel Uses OAuth Device Code Flow to Capture Tokens and Persist Access
July 2, 2026 A newly uncovered phishing panel called ARToken is giving cybercriminals an easy way to steal Microsoft 365 login sessions without ever touching a password. The tool works …
AsyncRAT Campaign Abuses TryCloudflare Tunnels and Python Scripts for Malware Delivery
July 2, 2026 AsyncRAT is back in the headlines, and the attackers behind it have found a clever way to hide in plain sight. Instead of relying on suspicious servers, …
Ousaban Malware Uses Phishing PDFs and VBS Downloader to Target Iberian Banking Users
July 2, 2026 A newly documented campaign is quietly hijacking online banking sessions across Spain and Portugal, and it starts with something as ordinary as a broken PDF file. The …
Claude Cowork’s Sandbox Vulnerability Allows Attackers to Run Arbitrary Commands as Root
July 2, 2026 A vulnerability chain in Anthropic’s Claude Cowork allows an attacker with local code execution to escalate privileges and run arbitrary commands as root inside the product’s isolated …
CitrixBleed Vulnerability Exploited by Hackers Within 24 Hours of Public Disclosure
July 2, 2026 A newly disclosed CitrixBleed-class vulnerability in Citrix NetScaler appliances came under active exploitation less than a day after public disclosure, with decoy infrastructure operator Lupovis confirming a …
DHS Confirms Breach of Information-Sharing Network Platform HSIN
July 2, 2026 The Department of Homeland Security has confirmed that hackers breached the Homeland Security Information Network (HSIN), a sensitive but unclassified platform relied upon by federal, state, local, …
ChatGPT File Download Flow Vulnerability Could Be Abused to Access System Files
July 2, 2026 A proof-of-concept vulnerability chain in ChatGPT that combined a guardrail bypass with a path traversal flaw, potentially allowing attackers to access restricted system files such as /etc/passwd …
900+ Oracle E-Business instances Exposed Online Amid Active Vulnerability Exploitation
July 2, 2026 More than 900 Oracle E‑Business Suite instances have been found exposed on the public internet. At the same time, attackers actively exploit a critical vulnerability in the …
Hackers Use Legitimate VLC Executable and Malicious libvlc.dll to Deploy ValleyRAT
July 2, 2026 Cybercriminals have found a clever way to slip past security defenses by hiding malware inside a program most people trust without a second thought. Researchers have uncovered …
