Cyclops Blink has returned in a form that gives attackers a deeper view inside corporate networks. The malware was found on compromised Cisco Firewall Management Center devices, where it can …
New ZcopyReaper Linux Kernel Vulnerability Enables Privilege Escalation Attacks
A new Linux kernel vulnerability dubbed ZcopyReaper allows an unprivileged local attacker to escalate privileges and potentially gain root-level control. Tracked as CVE-2026-43502, the flaw was demonstrated through an exploit called ZcopyReaper …
One Click on a Malicious Link Lets Hackers Backdoor Sogou Input Method Users
A single click on a malicious link could have given attackers a direct path into Windows systems running Sogou Input Method. The flaw turned a commonly installed Chinese-language typing tool …
Hackers Leverage Claude to Exfiltrate Secrets from 1.8M Android apps
Cybercriminals linked to the ShinyHunters ecosystem used Claude to support a large-scale credential theft operation that downloaded, decompiled, and scanned 1.8 million Android applications for hardcoded secrets. The campaign shows …
Microsoft Confirms Remote Desktop Services Might Stop Working Following Sept. 2026 Security Update
Microsoft has confirmed that its September 2026 Windows security updates can destabilize Remote Desktop Services (RDS), potentially disrupting remote administration across a broad range of enterprise endpoints and servers. Last …
GitHub Pays $100,000 Bounty for Critical RCE Flaw in Git Push Pipeline
GitHub has awarded security researcher Saif Ghani a $100,000 bug bounty after the disclosure of CVE-2026-3854, a critical remote code execution vulnerability affecting GitHub’s Git push processing pipeline. The reward …
Hackers Deploy Casbaneiro Banking Trojan That Activates When Victims Open Bank Websites
Casbaneiro is targeting online banking users in Latin America through phishing messages that look like urgent invoices or legal notices. The campaign uses personalised PDF lures to push recipients toward …
Hackers Abuse YouTube Gaming Channels and SEO Poisoning to Deploy RATs and Chrome Hijacker
Hackers are turning ordinary searches and gaming videos into malware traps. A long-running campaign used YouTube channels and search-engine manipulation to steer victims toward installers that looked like useful software, …
Hackers Abuse AutoIt to Inject AsyncRAT Into Microsoft-Signed Windows Process
Hackers are using a familiar Windows automation tool to hide AsyncRAT, a remote-access trojan, inside a trusted system process. The campaign starts with a deceptive batch file named “Right-click to …
NCSC Warns of Critical Check Point VPN Flaws as Large-Scale Exploitation Is Expected
The Dutch National Cyber Security Center (NCSC) has issued an urgent warning over two critical vulnerabilities in Check Point VPN products, saying it expects large-scale exploitation attempts in the near …
