π° Whoβs Tracking You? Use This New Service to Find Out
It can be daunting to determine who’s responsible for showing ads on the websites we visit, or who’s harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and traditionally much of it has remained walled away in the hands of large advertising platforms. Not anymore: A powerful and free new service called DecryptAds scrapes and correlates this adtech data and makes it simple to quickly learn a great deal about the entities that are tracking you.
π Source
#RSS #CyberSecurity #Security #Tool #Report
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
It can be daunting to determine who’s responsible for showing ads on the websites we visit, or who’s harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and traditionally much of it has remained walled away in the hands of large advertising platforms. Not anymore: A powerful and free new service called DecryptAds scrapes and correlates this adtech data and makes it simple to quickly learn a great deal about the entities that are tracking you.
π Source
#RSS #CyberSecurity #Security #Tool #Report
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Krebs on Security
Whoβs Tracking You? Use This New Service to Find Out β Krebs on Security
It can be daunting to determine whoβs responsible for showing ads on the websites we visit, or whoβs harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and traditionally much of it hasβ¦
π° Canadian Man Pleads Guilty in Snowflake Extortions
A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud provider Snowflake. Connor Riley Moucka, of Kitchener, Ontario, also admitted to stealing call and text history records of more than 100 million AT&T customers. A surveillance photo of Connor Riley Moucka, a.
π Source
#RSS #CyberSecurity #Security #Tool #Report
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud provider Snowflake. Connor Riley Moucka, of Kitchener, Ontario, also admitted to stealing call and text history records of more than 100 million AT&T customers. A surveillance photo of Connor Riley Moucka, a.
π Source
#RSS #CyberSecurity #Security #Tool #Report
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Krebs on Security
Canadian Man Pleads Guilty in Snowflake Extortions β Krebs on Security
A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud provider Snowflake. Connor Rileyβ¦
π° Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user’s Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of a sprawling operation that seeks to defraud online merchants and advertising networks. Pedro FalΓ© is a threat researcher with the security firm Bitsight.
π Source
#RSS #CyberSecurity #Security #Tool #Report #Tutorial
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user’s Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of a sprawling operation that seeks to defraud online merchants and advertising networks. Pedro FalΓ© is a threat researcher with the security firm Bitsight.
π Source
#RSS #CyberSecurity #Security #Tool #Report #Tutorial
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Krebs on Security
Read This Before You Buy That TV Streaming Stick β Krebs on Security
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the userβs Internet connection out to strangers. But a groundbreakingβ¦
π° FBI Seizes NetNut Proxy Platform, Popa Botnet
The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies NASDAQ: ALAR. The action comes roughly two weeks after KrebsOnSecurity published findings from multiple security firms connecting NetNut to the Popa botnet, a collection of at least two million devices that have been compromised by malicious software with little or no consent from victims. The NetNut homepage today was replaced by this seizure banner from the FBI.
π Source
#RSS #CyberSecurity #Security #Tool #Report
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies NASDAQ: ALAR. The action comes roughly two weeks after KrebsOnSecurity published findings from multiple security firms connecting NetNut to the Popa botnet, a collection of at least two million devices that have been compromised by malicious software with little or no consent from victims. The NetNut homepage today was replaced by this seizure banner from the FBI.
π Source
#RSS #CyberSecurity #Security #Tool #Report
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Krebs on Security
FBI Seizes NetNut Proxy Platform, Popa Botnet
The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR].β¦
π° Scattered Spider Hackers Plead Guilty on Day 1 of Trial
Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London, the entity responsible for the public transport network in the Greater London area. The duo were key members of a prolific cybercrime group known as Scattered Spider, and their guilty pleas came on the first day of what was expected to be a six-week trial. Owen Flowers (left) 18, and Thalha Jubair, 20.
π Source
#RSS #CyberSecurity #Security #Tool #Report
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London, the entity responsible for the public transport network in the Greater London area. The duo were key members of a prolific cybercrime group known as Scattered Spider, and their guilty pleas came on the first day of what was expected to be a six-week trial. Owen Flowers (left) 18, and Thalha Jubair, 20.
π Source
#RSS #CyberSecurity #Security #Tool #Report
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Krebs on Security
Scattered Spider Hackers Plead Guilty on Day 1 of Trial
Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London, the entity responsible for the public transport network in the Greater London area. The duo wereβ¦
π° 16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets
Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer. OpenSourceMalware, which discovered the activity on August 15, 2026, is tracking the threat under the moniker StubMaker. The complete list of packages published as part of the campaign is below - ubnuler ubnlder ri18nr reaker rakier orakw joxn.
π Source
#RSS #CyberSecurity #Security #Report
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer. OpenSourceMalware, which discovered the activity on August 15, 2026, is tracking the threat under the moniker StubMaker. The complete list of packages published as part of the campaign is below - ubnuler ubnlder ri18nr reaker rakier orakw joxn.
π Source
#RSS #CyberSecurity #Security #Report
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
π° ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories
Some weeks have one big security story. Others bring many smaller updates that are easy to miss but still matter. This week has plenty of them, covering cloud services, AI tools, malware, data breaches, scams, and new attack methods.
π Source
#RSS #CyberSecurity #Security #Tool
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Some weeks have one big security story. Others bring many smaller updates that are easy to miss but still matter. This week has plenty of them, covering cloud services, AI tools, malware, data breaches, scams, and new attack methods.
π Source
#RSS #CyberSecurity #Security #Tool
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
π° New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure
Afghan telecom providers and South Asian critical infrastructure organizations have emerged as the target of a new ongoing campaign that delivers a previously undocumented backdoor called PATCHCORD. According to Acronis Threat Research Unit (TRU), the backdoor is a compiled C/C++ implant delivered by means of sector-specific lures, including fake VPN installers impersonating Afghan Telecom (.
π Source
#RSS #CyberSecurity #Security #Report
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Afghan telecom providers and South Asian critical infrastructure organizations have emerged as the target of a new ongoing campaign that delivers a previously undocumented backdoor called PATCHCORD. According to Acronis Threat Research Unit (TRU), the backdoor is a compiled C/C++ implant delivered by means of sector-specific lures, including fake VPN installers impersonating Afghan Telecom (.
π Source
#RSS #CyberSecurity #Security #Report
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
π° Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack
Microsoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks. The bug sits in a core Windows kernel driver that handles network socket operations. An attacker with code already running on a machine can use it to escalate to SYSTEM.
π Source
#RSS #CVE #CyberSecurity #Security #Tool CVE-2026-68820
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Microsoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks. The bug sits in a core Windows kernel driver that handles network socket operations. An attacker with code already running on a machine can use it to escalate to SYSTEM.
π Source
#RSS #CVE #CyberSecurity #Security #Tool CVE-2026-68820
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
π° F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers
Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says. The flaw, CVE-2026-94127, affects only systems in which APM serves as an OAuth authorization server, issuing access tokens to applications. F5 disclosed it in an advisory on September 22 and has released engineering hotfixes.
π Source
#RSS #CVE #CyberSecurity #Security #Tool CVE-2026-94127
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says. The flaw, CVE-2026-94127, affects only systems in which APM serves as an OAuth authorization server, issuing access tokens to applications. F5 disclosed it in an advisory on September 22 and has released engineering hotfixes.
π Source
#RSS #CVE #CyberSecurity #Security #Tool CVE-2026-94127
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
π° Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites. The attacks, detected on September 3 and 4, 2026, involved the chaining of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and one impacting Windows Advanced Local Procedure Call (CVE-2026-85880) to break.
π Source
#RSS #CVE #CyberSecurity #Security CVE-2026-85880 CVE-2026-87491 CVE-2026-85046
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites. The attacks, detected on September 3 and 4, 2026, involved the chaining of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and one impacting Windows Advanced Local Procedure Call (CVE-2026-85880) to break.
π Source
#RSS #CVE #CyberSecurity #Security CVE-2026-85880 CVE-2026-87491 CVE-2026-85046
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
π° EDR Evasion Stack Helps Process Injection Slip Past Defenses
A process parameter-poisoning technique evades EDR by injecting code into process initialization structures without using the Windows APIs that EDR tools typically watch out for.
π Source
#RSS #CyberSecurity #Security #Tool
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
A process parameter-poisoning technique evades EDR by injecting code into process initialization structures without using the Windows APIs that EDR tools typically watch out for.
π Source
#RSS #CyberSecurity #Security #Tool
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Dark Reading
EDR Evasion Stack Helps Process Injection Slip Past Defenses
The process parameter poisoning EDR evasion technique bypasses security tools by hiding payloads in Windows process initialization structures.
π° Critical F5 BIG-IP Vulnerability Exploited as Zero-Day
Unauthenticated attackers could send malicious traffic to BIG-IP to achieve remote code execution. The post Critical F5 BIG-IP Vulnerability Exploited as Zero-Day appeared first on SecurityWeek.
π Source
#RSS #CVE #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Unauthenticated attackers could send malicious traffic to BIG-IP to achieve remote code execution. The post Critical F5 BIG-IP Vulnerability Exploited as Zero-Day appeared first on SecurityWeek.
π Source
#RSS #CVE #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
SecurityWeek
Critical F5 BIG-IP Vulnerability Exploited as Zero-Day
Unauthenticated attackers could send malicious traffic to BIG-IP to achieve remote code execution.
π° MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication. The chain, which CERT Polska calls MikroTrick, combines an SSH state-machine flaw (CVE-2026-67279) with an argument-injection bug in the RouterOS login process (CVE-2026-86060). Attack logs date to at.
π Source
#RSS #CVE #CyberSecurity #Security CVE-2026-67279 CVE-2026-86060
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication. The chain, which CERT Polska calls MikroTrick, combines an SSH state-machine flaw (CVE-2026-67279) with an argument-injection bug in the RouterOS login process (CVE-2026-86060). Attack logs date to at.
π Source
#RSS #CVE #CyberSecurity #Security CVE-2026-67279 CVE-2026-86060
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
π° Adobe Patches Critical Flaws in Connect, AEM Forms
The nine critical security defects could be exploited for arbitrary code execution and privilege escalation. The post Adobe Patches Critical Flaws in Connect, AEM Forms appeared first on SecurityWeek.
π Source
#RSS #CVE #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
The nine critical security defects could be exploited for arbitrary code execution and privilege escalation. The post Adobe Patches Critical Flaws in Connect, AEM Forms appeared first on SecurityWeek.
π Source
#RSS #CVE #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
SecurityWeek
Adobe Patches Critical Flaws in Connect, AEM Forms
The nine critical security defects could be exploited for arbitrary code execution and privilege escalation.
π° Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
Cybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat actors are using the centralized repository hosted by HashiCorp as a distribution vector for malicious payloads. According to Aikido, the list of Terraform providers and Go modules is below - gocommunity-io/dockerd (222 downloads) kreuzwenker/.
π Source
#RSS #CyberSecurity #Security #Report
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Cybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat actors are using the centralized repository hosted by HashiCorp as a distribution vector for malicious payloads. According to Aikido, the list of Terraform providers and Go modules is below - gocommunity-io/dockerd (222 downloads) kreuzwenker/.
π Source
#RSS #CyberSecurity #Security #Report
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
π° GitLab Email Addresses Can Be Weaponized for Supply Chain Attacks
Incoming email addresses automatically assigned to each user on the platform contain highly privileged access tokens that attackers can use.
π Source
#RSS #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Incoming email addresses automatically assigned to each user on the platform contain highly privileged access tokens that attackers can use.
π Source
#RSS #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Dark Reading
GitLab Email Addresses Can Be Weaponized for Supply Chain Attacks
Incoming email addresses automatically assigned to each user on the platform contain highly privileged access tokens that attackers can use.
π° Arista Urges Immediate Patching of Exploited VCO Zero-Day
Remote attackers could trigger the critical-severity flaw to access privileged internal functionality. The post Arista Urges Immediate Patching of Exploited VCO Zero-Day appeared first on SecurityWeek.
π Source
#RSS #CVE #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Remote attackers could trigger the critical-severity flaw to access privileged internal functionality. The post Arista Urges Immediate Patching of Exploited VCO Zero-Day appeared first on SecurityWeek.
π Source
#RSS #CVE #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
SecurityWeek
Arista Urges Immediate Patching of Exploited VCO Zero-Day
Remote attackers could trigger the critical-severity flaw to access privileged internal functionality.
π° Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input
A new security vulnerability in Next. js could allow attackers to run code on a server via ImageResponse, the feature that generates Open Graph and other social preview images, Vercel said. The risk applies when an app puts values an attacker controls, such as text read from the request URL, into the image.
π Source
#RSS #CVE #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
A new security vulnerability in Next. js could allow attackers to run code on a server via ImageResponse, the feature that generates Open Graph and other social preview images, Vercel said. The risk applies when an app puts values an attacker controls, such as text read from the request URL, into the image.
π Source
#RSS #CVE #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
π° **Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape**
A use-after-free in the Linux kernel's AF_UNIX socket subsystem can be used to escape a container and gain root on the host, security firm DepthFirst said in research published September 22. The flaw, tracked as CVE-2026-80521 (CVSS score: 7. 8), was fixed upstream on August 6, but Ubuntu has not shipped the patch for its 26.
π [Source](https://thehackernews.com/2026/09/exploit-released-for-unpatched-ubuntu.html)
#RSS #CVE #CyberSecurity #Security #Tool #Report CVE-2026-80521
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
A use-after-free in the Linux kernel's AF_UNIX socket subsystem can be used to escape a container and gain root on the host, security firm DepthFirst said in research published September 22. The flaw, tracked as CVE-2026-80521 (CVSS score: 7. 8), was fixed upstream on August 6, but Ubuntu has not shipped the patch for its 26.
π [Source](https://thehackernews.com/2026/09/exploit-released-for-unpatched-ubuntu.html)
#RSS #CVE #CyberSecurity #Security #Tool #Report CVE-2026-80521
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
π° Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials
A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request. The flaw, tracked as CVE-2026-90898 (CVSS score: 9. 8), affects all versions of the Bifrost HTTP transport before 2.
π Source
#RSS #CVE #CyberSecurity #Security CVE-2026-90898
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request. The flaw, tracked as CVE-2026-90898 (CVSS score: 9. 8), affects all versions of the Bifrost HTTP transport before 2.
π Source
#RSS #CVE #CyberSecurity #Security CVE-2026-90898
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab