GootLoader now uses 500–1,000 ZIP files glued together!
The broken ZIP won’t open in WinRAR or 7-Zip, but Windows Explorer still opens it and runs the JavaScript malware. Each download is different, so file hashes don’t match.
The broken ZIP won’t open in WinRAR or 7-Zip, but Windows Explorer still opens it and runs the JavaScript malware. Each download is different, so file hashes don’t match.
Researchers uncovered 5 malicious Chrome extensions masquerading as HR/ERP tools like Workday and NetSuite.
They exfiltrate auth cookies and suppress access to security and admin pages via DOM manipulation.
They exfiltrate auth cookies and suppress access to security and admin pages via DOM manipulation.
Hacker Nicholas Moore, 24, pleaded guilty to infiltrating U.S. government systems, including the Supreme Court's filing portal. Using stolen login credentials, he accessed sensitive personal data from victims at the Supreme Court, AmeriCorps, and the Department of Veterans Affairs. Notably, Moore brazenly posted the stolen information—including names, addresses, and even prescribed medications—to his Instagram account, @ihackthegovernment. He now faces up to a year in prison and a $100,000 fine for the breaches.
Palo Alto Networks patched a high-severity DoS flaw in GlobalProtect.
CVE-2026-0227 (CVSS 7.7) lets unauthenticated attackers repeatedly crash firewalls into maintenance mode.
CVE-2026-0227 (CVSS 7.7) lets unauthenticated attackers repeatedly crash firewalls into maintenance mode.
Researchers null-routed traffic to 550+ AISURU/Kimwolf C2 nodes since early Oct 2025.
Kimwolf has compromised 2M+ Android devices—mostly unsanctioned TV boxes via exposed ADB—and resold them as residential proxies.
Kimwolf has compromised 2M+ Android devices—mostly unsanctioned TV boxes via exposed ADB—and resold them as residential proxies.
Microsoft’s first Patch Tuesday of 2026 fixes 114 Windows flaws, including one exploited in the wild.
CVE-2026-20805 is a local info-leak in Desktop Window Manager that can expose memory addresses and weaken ASLR.
CVE-2026-20805 is a local info-leak in Desktop Window Manager that can expose memory addresses and weaken ASLR.
A fake Chrome ad blocker crashes the browser on purpose, then tricks users into running attacker commands.
Huntress calls it CrashFix, an evolved ClickFix tactic linked to the KongTuke traffic distribution system for reuse in follow-on attacks.
Huntress calls it CrashFix, an evolved ClickFix tactic linked to the KongTuke traffic distribution system for reuse in follow-on attacks.
Malware Analysis: LummaC2/Vidar Infostealer Disguised as XAPK Viewer on Uptodown.
Mandiant releases rainbow table that cracks weak admin password in 12 hours.
Researchers found an indirect prompt injection flaw abusing Google Gemini via calendar invites.
A hidden prompt in an event could trigger Gemini, when asked about a schedule, to summarize private meetings into a new calendar entry—visible to attackers in some enterprise setups.
A hidden prompt in an event could trigger Gemini, when asked about a schedule, to summarize private meetings into a new calendar entry—visible to attackers in some enterprise setups.
Thousands of fake banking sites are quietly pulling users in via Google.
CTM360 tracked 11,000+ fake bank domains targeting the U.S. and UK, many ranking next to real institutions. These sites run full onboarding and fake approvals before charging “fees” via crypto or PayPal.
CTM360 tracked 11,000+ fake bank domains targeting the U.S. and UK, many ranking next to real institutions. These sites run full onboarding and fake approvals before charging “fees” via crypto or PayPal.
A major Telegram scam marketplace may be winding down.
Elliptic reports Tudou Guarantee has largely halted transactions in its public channels after processing $12B+ in illicit activity.
Elliptic reports Tudou Guarantee has largely halted transactions in its public channels after processing $12B+ in illicit activity.
New breach: Under Armour was the victim of a ransomware attack in November. Customer data was published to a hacking forum this week and includes 72M email addresses, along with other personal information.