An RMM phishing campaign first tied to Canada spans 46 countries.
ANYRUN linked 601 cases to the operation, with 45% of observed activity associated with the U.S. Fake tax, shipping, and invoice lures trick targets into installing legitimate RMM software.
ANYRUN linked 601 cases to the operation, with 45% of observed activity associated with the U.S. Fake tax, shipping, and invoice lures trick targets into installing legitimate RMM software.
Thomson Reuters C-Track court software breach may have exposed SSNs and sealed court data.
Attackers are exploiting LiteLLM, Artifactory, and Switchvox flaws.
The attacks deploy crypto miners and reverse shells, mint admin tokens, and harvest API keys. CISA added seven exploited vulnerabilities to its KEV catalog.
The attacks deploy crypto miners and reverse shells, mint admin tokens, and harvest API keys. CISA added seven exploited vulnerabilities to its KEV catalog.
A major breach at Nordic/Benelux IT supplier Dustin has led it to take systems offline. Webshops are down, and orders and deliveries have stopped.
Attackers are exploiting a Chrome V8 zero-day.
CVE-2026-85046 allows arbitrary code execution inside the browser sandbox via a crafted HTML page. Google fixed it in Chrome 152.0.7977.82/.83.
CVE-2026-85046 allows arbitrary code execution inside the browser sandbox via a crafted HTML page. Google fixed it in Chrome 152.0.7977.82/.83.
Tails 7.12 is out as the first release under the project’s new two-week cadence, bringing Tor Browser 15.0.21, Electrum 4.8.1, and updated firmware.
US military disables ad trackers on devices amid location-data targeting concerns
US military officials have said they disabled advertising trackers on a range of phones and computers, according to letters released on Friday by US Senator Ron Wyden and statements provided to Reuters. The move follows reports that commercially available location data had been used to target US forces in West Asia.
US military officials have said they disabled advertising trackers on a range of phones and computers, according to letters released on Friday by US Senator Ron Wyden and statements provided to Reuters. The move follows reports that commercially available location data had been used to target US forces in West Asia.
U.S. CISA adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog.
Cyber Dispatch™️
U.S. CISA adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Google Chromium V8 flaw, tracked as CVE-2026-85046 (CVSS score of 8,8), to its Known Exploited Vulnerabilities (KEV) catalog.
Singapore police outfit Digital Disruption Centre blocks VestoFX Trader Investment App.
PostgreSQL releases since 2014 contain a severe vulnerability that allows attacker with low privileges to take over databases and servers, cybersecurity firm Cyera reports.
Tracked as CVE-2026-6471 (CVSS score of 7.2) and referred to as PostGREShell, the recently identified security defect can be exploited for remote code execution and privilege escalation.
Tracked as CVE-2026-6471 (CVSS score of 7.2) and referred to as PostGREShell, the recently identified security defect can be exploited for remote code execution and privilege escalation.
Palo Alto Networks CEO: ~$1 Trillion in Cybersecurity Infrastructure May Need to Be Modernized for the AI Era.