Cloudflare just stopped the largest DDoS attack ever — a 29.7 Tbps strike from the AISURU botnet that used up to 4 million hacked devices.
It hit 15,000 ports every second for 69 seconds before being blocked.
It hit 15,000 ports every second for 69 seconds before being blocked.
A major WordPress flaw is being exploited right now.
The King Addons for Elementor plugin let anyone sign up as an admin — no login needed.
Over 48,000 attack attempts have been blocked since October.
The King Addons for Elementor plugin let anyone sign up as an admin — no login needed.
Over 48,000 attack attempts have been blocked since October.
Businesses are facing a new threat!
#Salty2FA and #Tycoon2FA are now attacking together. The #phishing campaign that's just been discovered is stealing corporate logins at scale.
#Salty2FA and #Tycoon2FA are now attacking together. The #phishing campaign that's just been discovered is stealing corporate logins at scale.
Three critical flaws just found in Picklescan — the open-source tool made to detect unsafe PyTorch models.
Attackers could use them to slip in malicious code and bypass its scans.
Attackers could use them to slip in malicious code and bypass its scans.
GlassWorm is back.
24 fake VS Code and Open VSX extensions are stealing developer credentials — spreading through popular names like Flutter, React, and Tailwind.
The malware hides its control data on the Solana blockchain and runs Rust implants on both Windows and macOS.
24 fake VS Code and Open VSX extensions are stealing developer credentials — spreading through popular names like Flutter, React, and Tailwind.
The malware hides its control data on the Solana blockchain and runs Rust implants on both Windows and macOS.
Israel has signed off on a $725M propaganda budget for 2026 to polish its global reputation.
Porsche outage in Russia serves as a reminder of the risks in connected vehicle security.
Hackers are hiding malware in normal websites.
A new attack called JS#SMUGGLER plants code that quietly runs PowerShell through mshta.exe to install NetSupport RAT — giving attackers full control of your computer.
It even checks your device type to avoid being caught.
A new attack called JS#SMUGGLER plants code that quietly runs PowerShell through mshta.exe to install NetSupport RAT — giving attackers full control of your computer.
It even checks your device type to avoid being caught.
Three new Android threats just dropped:
• FvncBot – fake “mBank” app that logs keys, streams screens, and steals banking data.
• SeedSnatcher – spreads via Telegram to steal crypto seed phrases and 2FA codes.
• ClayRat – upgraded spyware faking YouTube & taxi apps for full device control.
All abuse Android’s accessibility features.
• FvncBot – fake “mBank” app that logs keys, streams screens, and steals banking data.
• SeedSnatcher – spreads via Telegram to steal crypto seed phrases and 2FA codes.
• ClayRat – upgraded spyware faking YouTube & taxi apps for full device control.
All abuse Android’s accessibility features.
Hackers are exploiting a bug in the Sneeit Framework plugin (CVE-2025-6389) to run code on servers and create admin accounts on WordPress sites.
Separately, a flaw in ICTBroadcast (CVE-2025-2611) lets attackers use the BROADCAST cookie for unauthenticated remote shell access on exposed hosts.
Separately, a flaw in ICTBroadcast (CVE-2025-2611) lets attackers use the BROADCAST cookie for unauthenticated remote shell access on exposed hosts.
MuddyWater hackers are using a new backdoor called "UDPGangster" that hides in fake “election seminar” Word files.
It only runs after checking if your computer is real — not a sandbox — then steals data over UDP to dodge detection.
It only runs after checking if your computer is real — not a sandbox — then steals data over UDP to dodge detection.
Four Threat Clusters Using CastleLoader as GrayBravo Expands Its Malware Service Infrastructure.
Storm-0249 Escalates Ransomware Attacks with ClickFix, Fileless PowerShell, and DLL Sideloading.
STAC6565 Targets Canada in 80% of Attacks as Gold Blade Deploys QWCrypt Ransomware.
North Korean hackers exploit React2Shell flaw in EtherRAT malware attacks.