Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China.
PRC State-Sponsored Actors Use BRICKSTORM Malware Across Public Sector and Information Technology Systems.
Smartphones worldwide were silently infected with Israeli malware via malicious ads.
Simply viewing their ads was enough to get infected.
Surveillance company Intellexa gained full access to cameras, microphones, chat apps, emails, GPS locations, photos, files, and browsing activity.
Simply viewing their ads was enough to get infected.
Surveillance company Intellexa gained full access to cameras, microphones, chat apps, emails, GPS locations, photos, files, and browsing activity.
Cyber Dispatch™️
Smartphones worldwide were silently infected with Israeli malware via malicious ads. Simply viewing their ads was enough to get infected. Surveillance company Intellexa gained full access to cameras, microphones, chat apps, emails, GPS locations, photos…
A new investigation jointly published by inside story, Haaretz & WAV Research Collective with the technical assistance of Amnesty international has exposed the internal operations of Intellexa, a company notorious for selling Predator spyware.
Tails OS is a fully portable privacy driven operating system that runs entirely in memory. Nothing is stored permanently unless you choose to encrypt it.
Simulating and Detecting React2Shell: A Deep Dive into CVE-2025-55182 & CVE-2025-66478.
Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails.
React2Shell flaw exploited to breach 30 orgs, 77k IP addresses vulnerable.
The Webshell Underground: Student Hacker Selling PHP Backdoors To Asia-Based Threat Actors To Pay for School.
Researchers Uncover 30+ Flaws in AI Coding Tools Enabling Data Theft and RCE Attacks.
CISA added the new 10.0-rated React RCE flaw (CVE-2025-55182) to its exploited list.
Exploited within hours by Chinese hackers.
Affects Next.js, React Router, Vite, Waku & more.
Some attacks dropped crypto-miners & stole AWS creds.
Exploited within hours by Chinese hackers.
Affects Next.js, React Router, Vite, Waku & more.
Some attacks dropped crypto-miners & stole AWS creds.
A new attack can trick Perplexity’s Comet browser into deleting your Google Drive.
Just one normal-looking email with hidden cleanup instructions can make the AI agent erase real files — no exploit, no warning.
Just one normal-looking email with hidden cleanup instructions can make the AI agent erase real files — no exploit, no warning.
Critical Apache Tika flaw (CVE-2025-66516) just dropped — CVSS 10.0.
A single fake PDF can trigger an XXE attack, letting hackers read server files or run code.
A single fake PDF can trigger an XXE attack, letting hackers read server files or run code.