Hackers are using telecom networks and hosting providers across the Middle East as a foundation for massive command-and-control operations, turning trusted infrastructure into a launchpad for cyberattacks. A newly released …
World Cup Phishing Campaign Nearly Triples With 203 Unique IP Addresses
May 22, 2026 A large-scale phishing campaign targeting the 2026 FIFA World Cup has grown far beyond what security researchers originally thought. What began as a documented set of 79 …
Hackers Use Six-Layer Persistence to Maintain Access on Compromised FreePBX Systems
May 22, 2026 A hacker group known as INJ3CTOR3 has been running an active campaign against FreePBX systems, deploying a newly discovered PHP webshell called JOMANGY that uses six separate …
Ubiquiti Patches Critical UniFi OS Vulnerabilities Allowing Remote Privilege Escalation
May 22, 2026 Ubiquiti Networks has released urgent security updates to address a series of highly critical vulnerabilities affecting its UniFi OS platform. These severe flaws could allow unauthenticated, remote …
LiteSpeed cPanel Plugin 0-Day Exploited in the wild to Gain Server Root Access
May 22, 2026 LiteSpeed has disclosed and patched a critical 0‑day privilege escalation flaw in its user-end cPanel plugin that is already being actively exploited to gain root access on …
CISA adds Langflow Origin Validation Flaw to Known Exploited Vulnerabilities Catalog
May 22, 2026 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Langflow vulnerability, tracked as CVE-2025-34291, to its Known Exploited Vulnerabilities (KEV) Catalog, signaling active exploitation …
Lawmakers Demand Answers as CISA Tries to Contain Data Leak
Lawmakers in both houses of Congress are demanding answers from the U.S. Cybersecurity & Infrastructure Security Agency (CISA) after KrebsOnSecurity reported this week that a CISA contractor intentionally published AWS …
Android Malware Silently Subscribes Victims to Premium Services Without Consent
May 22, 2026 A newly uncovered Android malware campaign has been quietly draining money from mobile users across four countries by signing them up for paid services they never asked …
Operation Dragon Whistle Uses Malicious LNK Files to Target Changzhou University
May 22, 2026 A newly uncovered cyber operation has raised concerns among security professionals after a coordinated wave of attacks targeted government institutions in Pakistan. The campaign, now tracked as …
Canadian Man Arrested for Running KimWolf DDoS Botnet Service that Hacked 2 Million Devices
May 22, 2026 Canadian and U.S. authorities have arrested and charged a 23‑year‑old Ottawa resident for allegedly operating “KimWolf,” a massive Internet‑of‑Things (IoT) DDoS‑for‑hire botnet that weaponized more than a …

