June 25, 2026 Anthropic has formally accused Chinese tech and e-commerce giant Alibaba of orchestrating a massive, unauthorized extraction campaign targeting its Claude AI model, marking what the company describes …
Mistic Backdoor Blends With Microsoft Endpoint Security Tooling to Evade Detection
June 24, 2026 A new and stealthy backdoor named Mistic has been quietly targeting corporate networks since April 2026, disguising itself using the names and appearance of legitimate Microsoft endpoint …
Microsoft Teams Impersonation Campaign Enables Unauthorized Access Through RMM Abuse
June 24, 2026 Threat actors are once again exploiting the trust people place in everyday workplace tools. A newly discovered phishing campaign is using fake Microsoft Teams notifications to trick …
Malicious Edge Extension Uses Chrome Native Messaging to Execute Code on Victim Systems
June 24, 2026 A new and deceptive malware campaign has been uncovered, one that turns an everyday browser extension into a dangerous tool for system compromise. Security researchers have identified …
EvilTokens Hides Its Attack Flow in the Browser, Exposing Static Analysis Gaps
June 24, 2026 EvilTokens EvilTokens is drawing attention in phishing investigations for abusing Microsoft Device Code authentication and hiding key parts of its attack flow from static URL analysis. In a recent analysis, …
Hackers Exploiting Cisco Catalyst SD-WAN Manager 0-Day Flaw to Gain Root-Level Access
June 24, 2026 A sophisticated threat actor is actively targeting SD-WAN infrastructure at a major service provider. The campaign culminated in the exploitation of a zero-day privilege escalation vulnerability, now …
Authorities Disrupt Password-Stealing Malware StealC Infrastructure in Global Operation
June 24, 2026 Europol and law enforcement partners across multiple countries have dealt a significant blow to the cybercriminal ecosystems powering StealC, Amadey, and SocGholish malware, three widely deployed tools …
Fake Income Tax Assessment Notice Delivers RAT-Like Malware to Windows Users
June 24, 2026 Cybercriminals are now using fake government tax notices to push dangerous malware onto Windows computers, and the tactic is proving alarmingly effective. A newly uncovered campaign targets …
PoC Exploit Released for Microsoft Exchange Server Elevation of Privilege Vulnerability
June 24, 2026 A public proof-of-concept exploit is now available for CVE-2026-45504, a high‑severity server-side request forgery vulnerability in Microsoft Exchange Server that enables privilege escalation via arbitrary file reads. …
Laravel Livewire Applications Compromised to Steal Credentials Exploiting RCE Vulnerability
June 24, 2026 A large-scale cyber campaign targeting Laravel Livewire applications has been uncovered, with attackers exploiting a critical remote code execution (RCE) flaw to steal sensitive credentials from thousands …


