May 21, 2026 Two former executives of a U.S.-based call routing and analytics company have pleaded guilty to federal charges for knowingly enabling India-based call centers to defraud thousands of …
New GhostTree Attack Causing EDR Products to Hang and Leave Files Unscanned
May 21, 2026 A novel evasion technique called GhostTree, which exploits NTFS junctions to create recursive directory loops. Uncovered by Varonis Threat Labs, this method traps Endpoint Detection and Response …
Claude Code’s Network Sandbox Vulnerability Exposes User Credentials and Source Code
May 21, 2026 Anthropic’s Claude Code AI coding assistant harbored a critical network sandbox bypass for over five months, allowing attackers to exfiltrate credentials, source code, and environment variables from …
Gremlin Stealer Stores C2 URLs and Exfiltration Paths in Encrypted Resource Sections
May 21, 2026 A newly analyzed variant of the Gremlin stealer malware has raised alarms by hiding its command-and-control (C2) addresses and data exfiltration paths inside encrypted resource sections of …
Hackers Use Fake Income Tax Assessment Pages to Infect Windows Systems
May 20, 2026 A new threat campaign is targeting Windows users in India by disguising malicious files as official income tax documents. Researchers have tracked the operation under the name …
Void Botnet Uses Ethereum Smart Contracts for Seizure-Resistant C2 Infrastructure
May 20, 2026 A new botnet called Void has emerged on the cybercrime underground, bringing a troubling twist to how attackers manage their operations remotely. Instead of relying on traditional …
Trapdoor Android Ad Fraud Operation Uses 455 Malicious Apps to Generate Fake Clicks
May 20, 2026 A large-scale ad fraud operation called Trapdoor has been discovered targeting Android users through 455 malicious apps, quietly generating fake ad clicks and draining real advertising budgets …
DevilNFC Android Malware Uses Kiosk Mode to Trap Victims During NFC Relay Attacks
A dangerous new Android malware called DevilNFC has emerged, combining NFC relay attacks with a Kiosk Mode trap that locks victims inside a fake banking screen until their card data …
PinTheft Linux Vulnerability Let Attackers Gain Root Access – PoC Released
May 20, 2026 A proof-of-concept (PoC) exploit was published for a new Linux Local Privilege Escalation (LPE) vulnerability dubbed “PinTheft.” Discovered by Aaron Esau of the V12 security team, the …
How to Close the Most Expensive Gap in Your SOC
May 20, 2026 Close Your SOC’s Most Expensive Gap There is a quiet gap inside many SOCs. It sits between the moment Tier 1 says “this should be escalated” and …
