Popular workflow automation platform n8n disclosed a critical flaw that lets authenticated users with workflow edit rights execute OS commands on the host.
Tracked as CVE-2025-68668, the issue carries a CVSS score of 9.9.
Tracked as CVE-2025-68668, the issue carries a CVSS score of 9.9.
More than 2 million Android devices were quietly absorbed into the Kimwolf botnet.
It spreads mainly through exposed ADB, turning phones, smart TVs, and boxes into proxy relays and DDoS infrastructure.
Activity links to large-scale attacks and active resale of residential bandwidth.
It spreads mainly through exposed ADB, turning phones, smart TVs, and boxes into proxy relays and DDoS infrastructure.
Activity links to large-scale attacks and active resale of residential bandwidth.
A Russia-linked hacking group is using Viber to target Ukrainian military and government entities.
Instead of email, victims receive ZIP files containing fake Office-themed shortcuts that quietly launch malware.
The attack chain ends with Remcos RAT, giving attackers full remote control.
Instead of email, victims receive ZIP files containing fake Office-themed shortcuts that quietly launch malware.
The attack chain ends with Remcos RAT, giving attackers full remote control.
Researchers disclosed VVS Stealer, a Python-based infostealer built to drain Discord tokens and browser data.
alerts to stay active. Obfuscated with PyArmor, it’s designed to slip past signature-based defenses.
alerts to stay active. Obfuscated with PyArmor, it’s designed to slip past signature-based defenses.
Anonymous for Justice hacked Israeli databases, laboratories, and weapons schematics, stating it is “exposing technology used in the killing of children and women.”
The group also published large files containing documents and photos belong to Israeli officers and scientists.
The group also published large files containing documents and photos belong to Israeli officers and scientists.
Chinese hackers linked to Salt Typhoon group infiltrate US congressional staff emails.
A Chinese hacker group known as Salt Typhoon has reportedly breached email systems used by staffers for several powerful US House of Representatives committees.
A Chinese hacker group known as Salt Typhoon has reportedly breached email systems used by staffers for several powerful US House of Representatives committees.
Hacker group Handala claims Mossad will soon 'encounter a shock they never saw coming':
"Tonight at 6:30 PM (Occupied Territories time), Mossad will encounter a shock they never saw coming."
"Tonight at 6:30 PM (Occupied Territories time), Mossad will encounter a shock they never saw coming."
Cyber Dispatch™️
Hacker group Handala claims Mossad will soon 'encounter a shock they never saw coming': "Tonight at 6:30 PM (Occupied Territories time), Mossad will encounter a shock they never saw coming."
"While their officers were busy orchestrating unrest in other countries, they failed to notice that they were being watched right in their own backyard. Sometimes, when you’re so focused on destabilizing others, you become blind to the shadows following you at home.
The tables are turning, let’s see who is really in control."
The tables are turning, let’s see who is really in control."
Microsoft says attackers are abusing misconfigured MX routing and weak spoof protections to send phishing emails that appear internal.
Some emails use the same address in both “From” and “To,” enabling credential theft and BEC.
Some emails use the same address in both “From” and “To,” enabling credential theft and BEC.
Cisco released patches for CVE-2026-20029 in Identity Services Engine and ISE-PIC.
The XML parsing flaw allows an authenticated admin to upload a malicious file and read restricted OS files.
A public PoC exists. Patch Now.
The XML parsing flaw allows an authenticated admin to upload a malicious file and read restricted OS files.
A public PoC exists. Patch Now.
Active exploitation is hitting old D-Link DSL router.
CVE-2026-0625 (CVSS 9.3) allows unauthenticated remote code execution via the dnscfg.cgi endpoint.
The same DNSChanger-style abuse seen in past hijacking campaigns is resurfacing, and many affected models are end of life and no longer maintained.
CVE-2026-0625 (CVSS 9.3) allows unauthenticated remote code execution via the dnscfg.cgi endpoint.
The same DNSChanger-style abuse seen in past hijacking campaigns is resurfacing, and many affected models are end of life and no longer maintained.
Three npm pkgs posing as bitcoinjs tools found spreading NodeCordRAT.
Postinstall scripts chained a 2nd pkg to drop the payload, steal Chrome creds, API tokens, and crypto wallet seed phrases, and run commands via Discord C2 on Win/Linux/macOS.
Postinstall scripts chained a 2nd pkg to drop the payload, steal Chrome creds, API tokens, and crypto wallet seed phrases, and run commands via Discord C2 on Win/Linux/macOS.
European hotels are facing a phishing campaign abusing Booking-com cancellation emails.
Victims hit a fake site, see a fake blue screen, and are told to run a PowerShell “fix.” That installs DCRat via MSBuild.exe, sets Defender exclusions, and persists on the system.
Victims hit a fake site, see a fake blue screen, and are told to run a PowerShell “fix.” That installs DCRat via MSBuild.exe, sets Defender exclusions, and persists on the system.
Warning: Two Chrome extensions with 900,000+ installs were found stealing ChatGPT and DeepSeek conversations, plus all open tab URLs.
Researchers call this prompt poaching.
Researchers call this prompt poaching.
Another CVSS 10.0 n8n vulnerability disclosed.
Researchers found another critical flaw (CVE-2026-21858) in n8n that lets remote attackers take full control with no authentication required.
The bug abuses Content-Type handling in form webhooks to read local files, steal secrets, forge admin sessions, and achieve RCE.
Researchers found another critical flaw (CVE-2026-21858) in n8n that lets remote attackers take full control with no authentication required.
The bug abuses Content-Type handling in form webhooks to read local files, steal secrets, forge admin sessions, and achieve RCE.
Israel Warns Palestinians: Stop Posting Zionist War Crimes Footage
"We are monitoring your online activity. Publishing inciting content online is considered a terrorist crime in every sense and may lead to arrest or imprisonment. Consider this your warning."
"We are monitoring your online activity. Publishing inciting content online is considered a terrorist crime in every sense and may lead to arrest or imprisonment. Consider this your warning."
An investigation by Channel 12 found that about half of politically active Israeli social media accounts are bots, with many amplifying posts by PM Benjamin Netanyahu and other members of his coalition.
These bot networks rapidly like and repost pro-Israel content moments after posting to hijack platform algorithms and give the impression of a bigger reach.
These bot networks rapidly like and repost pro-Israel content moments after posting to hijack platform algorithms and give the impression of a bigger reach.
Black Cat is running an SEO poisoning campaign that ranks fake software sites in search results.
The group impersonates tools like Notepad++, tricking users into installing trojanized installers that drop a backdoor stealing browser data, keystrokes, clipboard contents, and enabling remote access.
The group impersonates tools like Notepad++, tricking users into installing trojanized installers that drop a backdoor stealing browser data, keystrokes, clipboard contents, and enabling remote access.