Saltar al contenido
Mar. Sep 22nd, 2026
Trending News: New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based SetupsAI Agents Are Rewriting the Rules of Lateral MovementCan Your SOC Actually See the Attack?Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before RemovalSideCopy Broadens India Targeting to Academia With ReverseRAT Spear-PhishingZyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM AccessWordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin SessionOne Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a BackdoorGoogle Fined €403 Million Over GDPR Violations Tied to Location DataLos conflictos internacionales impulsan nuevas campañas de ciberataques en 2025Moltbook, la nueva red social de agentes de IA, expone toda su base de datosEl 90% de las compañías dispone de un plan director de ciberseguridad validado por la alta direcciónUn ex ingeniero de Google, condenado por espionaje económico y robo de secretos de IA para ChinaCuenta atrás para la XVIII edición del Foro de la Privacidad del Data Privacy InstituteContagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in CryptoFake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDRTASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard DataCisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser HijacksClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 InfrastructureJade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK BackdoorsThe Foundation of Identity SecuritySolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCEClaude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained FlawsGoogle Gemini Broke Into Real Company Systems After Security Test Domain Mix-UpCritical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the WildCrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub RepositoriesCISA Flags Three Linux Kernel Vulnerabilities Exploited in the WildPublic Exploits Released for Four Linux Kernel Flaws That Enable Local RootUn hombre conecta su aspiradora robot con un mando de PS5 y obtiene el control de miles de dispositivosLa web para adultos Frivol.com filtra una base de datos, exponiendo casi medio millón de cuentas de emailLa brecha entre inversión en ciberresiliencia y preparación adecuada aumenta la vulnerabilidad de las empresas españolasUn hacker ucraniano se declara culpable de operar OnlyFake, un portal de venta de pasaportes generados con IAEl software para psicólogos Eholo sufre una grave filtración de datosNew WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code ExecutionPlugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding AgentsTransparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It.Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege EscalationWeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension StorageClaimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm StealerIran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal PasswordsCritical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host FilesRatHat Android Malware Abuses ADB to Retain Shell Access After UninstallSelf-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New StoriesCritical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as RootU.S. Seizes NightmareStresser Domains Linked to Hundreds of Thousands of DDoS AttacksCisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active AttacksGyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata RecordsUn ciberataque contra Inditex afecta a sus bases de datos internasHackean a una empresa de ciberseguridad y exponen datos y cámaras de clientesLos datos de los funcionarios del Palacio Real de Marruecos, en manos de un hacker75.000 sospechosos identificados y decenas de infraestructuras DDoS desmanteladas tras un macrooperativo internacionalEl organismo oficial de EE.UU. que clasifica las vulnerabilidades de ciberseguridad no da a bastoBIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPSOpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized UploadsChina-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin AmericaCISO’s Expert Guide to Agentic Pentesting for WebsitesCan You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This WebinarCritical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS ZoneAcronis cPanel Backup Plugin Vulnerability Exploited in Targeted AttacksC1b3rwall se arma contra la crisis de ciberseguridad que amenaza la supervivencia de las empresas españolasCarnival promete relax y lujo en sus cruceros; los hackers encontraron además millones de perfiles personalesUn hacker canadiense de 23 años, detenido por operar la botnet KimwolfUn gigante de la logística sufre una brecha de datos de 840 millones de registrosLos ciberdelincuentes ya no respetan ni los carros de la compraThreat Intelligence Alone Won’t Close the Exploitation GapOne Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and ClaudeThree Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and WipersAttackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command ExecutionParallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can’t Install FixAttacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 RepositoriesA New Challenge for Identity SecurityGoogle Patches Pixel Modem Flaw Amid Signs of Limited Targeted ExploitationActive Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin TokensAttackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web ShellsSi pierdes el móvil este verano, haz esto en los primeros cinco minutos para que no vacíen tus cuentasHalluSquatting, el nuevo truco para engañar a los asistentes de IA y colar malware en tu ordenadorUn hacker adolescente piratea el servicio de streaming de Bandai usando ChatGPTUna agencia de EE.UU. pagó un millón de dólares tras casi un mes de negociación con un grupo de ransomwareUn ciberataque deja sin suministro a KFC y obliga a cerrar temporalmente algunos restaurantesKREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session TokensIranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and JournalistsBambooToken Malware Uses MQTT to Control Windows and Linux SystemsMass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev ServersWhy Testing Individual Techniques Misses the PointHuman Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight SecondsLiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared ServerChina-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGECisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command ExecutionWordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before DistributionTelegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML ExportsPaperCut alerta de ataques activos contra sus programas de gestión de impresorasLas Fuerzas Armadas y la Guardia Civil aceleran su transformación digital ante un ciberespacio cada vez más complejoCuidado con estos anuncios de Facebook: parecen de Google Play, pero conducen a casinos sin licenciaUna filtración revela cómo Rusia ha creado una cantera universitaria para sus ciberoperaciones militaresUn fallo en Lenovo ID permite el acceso sin autorización a unas 5.000 cuentas de Dropbox3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber CredentialsRed Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six CountriesNew DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential ComputingRogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits
Chicago 12, Melborne City, USA
The Digital Fortress
  • Home
  • Blog
  • Sample Page
  • Get Started
Mar. Sep 22nd, 2026
Trending News: New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based SetupsAI Agents Are Rewriting the Rules of Lateral MovementCan Your SOC Actually See the Attack?Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before RemovalSideCopy Broadens India Targeting to Academia With ReverseRAT Spear-PhishingZyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM AccessWordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin SessionOne Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a BackdoorGoogle Fined €403 Million Over GDPR Violations Tied to Location DataLos conflictos internacionales impulsan nuevas campañas de ciberataques en 2025Moltbook, la nueva red social de agentes de IA, expone toda su base de datosEl 90% de las compañías dispone de un plan director de ciberseguridad validado por la alta direcciónUn ex ingeniero de Google, condenado por espionaje económico y robo de secretos de IA para ChinaCuenta atrás para la XVIII edición del Foro de la Privacidad del Data Privacy InstituteContagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in CryptoFake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDRTASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard DataCisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser HijacksClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 InfrastructureJade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK BackdoorsThe Foundation of Identity SecuritySolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCEClaude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained FlawsGoogle Gemini Broke Into Real Company Systems After Security Test Domain Mix-UpCritical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the WildCrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub RepositoriesCISA Flags Three Linux Kernel Vulnerabilities Exploited in the WildPublic Exploits Released for Four Linux Kernel Flaws That Enable Local RootUn hombre conecta su aspiradora robot con un mando de PS5 y obtiene el control de miles de dispositivosLa web para adultos Frivol.com filtra una base de datos, exponiendo casi medio millón de cuentas de emailLa brecha entre inversión en ciberresiliencia y preparación adecuada aumenta la vulnerabilidad de las empresas españolasUn hacker ucraniano se declara culpable de operar OnlyFake, un portal de venta de pasaportes generados con IAEl software para psicólogos Eholo sufre una grave filtración de datosNew WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code ExecutionPlugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding AgentsTransparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It.Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege EscalationWeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension StorageClaimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm StealerIran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal PasswordsCritical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host FilesRatHat Android Malware Abuses ADB to Retain Shell Access After UninstallSelf-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New StoriesCritical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as RootU.S. Seizes NightmareStresser Domains Linked to Hundreds of Thousands of DDoS AttacksCisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active AttacksGyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata RecordsUn ciberataque contra Inditex afecta a sus bases de datos internasHackean a una empresa de ciberseguridad y exponen datos y cámaras de clientesLos datos de los funcionarios del Palacio Real de Marruecos, en manos de un hacker75.000 sospechosos identificados y decenas de infraestructuras DDoS desmanteladas tras un macrooperativo internacionalEl organismo oficial de EE.UU. que clasifica las vulnerabilidades de ciberseguridad no da a bastoBIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPSOpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized UploadsChina-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin AmericaCISO’s Expert Guide to Agentic Pentesting for WebsitesCan You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This WebinarCritical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS ZoneAcronis cPanel Backup Plugin Vulnerability Exploited in Targeted AttacksC1b3rwall se arma contra la crisis de ciberseguridad que amenaza la supervivencia de las empresas españolasCarnival promete relax y lujo en sus cruceros; los hackers encontraron además millones de perfiles personalesUn hacker canadiense de 23 años, detenido por operar la botnet KimwolfUn gigante de la logística sufre una brecha de datos de 840 millones de registrosLos ciberdelincuentes ya no respetan ni los carros de la compraThreat Intelligence Alone Won’t Close the Exploitation GapOne Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and ClaudeThree Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and WipersAttackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command ExecutionParallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can’t Install FixAttacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 RepositoriesA New Challenge for Identity SecurityGoogle Patches Pixel Modem Flaw Amid Signs of Limited Targeted ExploitationActive Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin TokensAttackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web ShellsSi pierdes el móvil este verano, haz esto en los primeros cinco minutos para que no vacíen tus cuentasHalluSquatting, el nuevo truco para engañar a los asistentes de IA y colar malware en tu ordenadorUn hacker adolescente piratea el servicio de streaming de Bandai usando ChatGPTUna agencia de EE.UU. pagó un millón de dólares tras casi un mes de negociación con un grupo de ransomwareUn ciberataque deja sin suministro a KFC y obliga a cerrar temporalmente algunos restaurantesKREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session TokensIranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and JournalistsBambooToken Malware Uses MQTT to Control Windows and Linux SystemsMass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev ServersWhy Testing Individual Techniques Misses the PointHuman Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight SecondsLiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared ServerChina-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGECisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command ExecutionWordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before DistributionTelegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML ExportsPaperCut alerta de ataques activos contra sus programas de gestión de impresorasLas Fuerzas Armadas y la Guardia Civil aceleran su transformación digital ante un ciberespacio cada vez más complejoCuidado con estos anuncios de Facebook: parecen de Google Play, pero conducen a casinos sin licenciaUna filtración revela cómo Rusia ha creado una cantera universitaria para sus ciberoperaciones militaresUn fallo en Lenovo ID permite el acceso sin autorización a unas 5.000 cuentas de Dropbox3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber CredentialsRed Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six CountriesNew DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential ComputingRogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits
Chicago 12, Melborne City, USA
  • Home
  • Blog
  • Sample Page
The Digital Fortress
  • Get Started
Top Tags
  • Flaw
  • Malware
  • Flaws
  • Exploited
  • Code
  • Attacks
  • Microsoft
  • RCE
Uncategorized
New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups
  • admin
  • septiembre 22, 2026
Uncategorized
AI Agents Are Rewriting the Rules of Lateral Movement
  • admin
  • septiembre 22, 2026
Uncategorized

New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups

  • Por admin
  • septiembre 22, 2026
  • 0 Comentarios
  • 0 views
Uncategorized

AI Agents Are Rewriting the Rules of Lateral Movement

  • Por admin
  • septiembre 22, 2026
  • 0 Comentarios
  • 1 views
Uncategorized

Can Your SOC Actually See the Attack?

  • Por admin
  • septiembre 22, 2026
  • 0 Comentarios
  • 2 views
Uncategorized

Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal

  • Por admin
  • septiembre 22, 2026
  • 0 Comentarios
  • 3 views
Uncategorized

SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing

  • Por admin
  • septiembre 22, 2026
  • 0 Comentarios
  • 4 views
Uncategorized

Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access

  • Por admin
  • septiembre 22, 2026
  • 0 Comentarios
  • 6 views
Uncategorized
New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups
  • admin
  • septiembre 22, 2026
Uncategorized
AI Agents Are Rewriting the Rules of Lateral Movement
  • admin
  • septiembre 22, 2026

Uncategorized

1478  

GlassWorm Campaign Uses Zig Dropper to Infect Multiple Developer IDEs
  • adminadmin
  • Campaign
  • Developer
  • abril 10, 2026
  • 0 Comentarios
GlassWorm Campaign Uses Zig Dropper to Infect Multiple Developer IDEs

Ravie LakshmananApr 10, 2026Malware / Blockchain Cybersecurity researchers have flagged yet another evolution of the ongoing GlassWorm campaign, which employs a new Zig dropper that’s designed to stealthily infect all integrated…

Continue reading
Marimo RCE Flaw CVE-2026-39987 Exploited Within 10 Hours of Disclosure
  • adminadmin
  • CVE202639987
  • Disclosure
  • abril 10, 2026
  • 0 Comentarios
Marimo RCE Flaw CVE-2026-39987 Exploited Within 10 Hours of Disclosure

Ravie LakshmananApr 10, 2026Vulnerability / Threat Intelligence A critical security vulnerability in Marimo, an open-source Python notebook for data science and analysis, has been exploited within 10 hours of public disclosure,…

Continue reading
Browser Extensions Are the New AI Consumption Channel That No One Is Talking About
  • adminadmin
  • Browser
  • Channel
  • abril 10, 2026
  • 0 Comentarios
Browser Extensions Are the New AI Consumption Channel That No One Is Talking About

While much of the discussion on AI security centers around protecting ‘shadow’ AI and GenAI consumption, there’s a wide-open window nobody’s guarding: AI browser extensions.  A new report from LayerX exposes just how deep this…

Continue reading
Google Rolls Out DBSC in Chrome 146 to Block Session Theft on Windows
  • adminadmin
  • Block
  • Chrome
  • abril 10, 2026
  • 0 Comentarios
Google Rolls Out DBSC in Chrome 146 to Block Session Theft on Windows

Ravie LakshmananApr 10, 2026Malware / Browser Security Google has made Device Bound Session Credentials (DBSC) generally available to all Windows users of its Chrome web browser, months after it began testing the security feature…

Continue reading
Backdoored Smart Slider 3 Pro Update Distributed via Compromised Nextend Servers
  • adminadmin
  • Backdoored
  • Compromised
  • abril 10, 2026
  • 0 Comentarios
Backdoored Smart Slider 3 Pro Update Distributed via Compromised Nextend Servers

Ravie LakshmananApr 10, 2026Malware / Website Security Unknown threat actors have hijacked the update system for the Smart Slider 3 Pro plugin for WordPress and Joomla to push a poisoned…

Continue reading
EngageLab SDK Flaw Exposed 50M Android Users, Including 30M Crypto Wallets
  • adminadmin
  • 30M
  • 50M
  • abril 9, 2026
  • 0 Comentarios
EngageLab SDK Flaw Exposed 50M Android Users, Including 30M Crypto Wallets

Ravie LakshmananApr 09, 2026Vulnerability / Mobile Security Details have emerged about a now-patched security vulnerability in a widely used third-party Android software development kit (SDK) called EngageLab SDK that could have put millions…

Continue reading
UAT-10362 Targets Taiwanese NGOs with LucidRook Malware in Spear-Phishing Campaigns
  • adminadmin
  • Campaigns
  • LucidRook
  • abril 9, 2026
  • 0 Comentarios
UAT-10362 Targets Taiwanese NGOs with LucidRook Malware in Spear-Phishing Campaigns

Ravie LakshmananApr 09, 2026Malware / Windows Security A previously undocumented threat cluster dubbed UAT-10362 has been attributed to spear-phishing campaigns targeting Taiwanese non-governmental organizations (NGOs) and suspected universities to deploy a…

Continue reading
Bitter-Linked Hack-for-Hire Campaign Targets Journalists Across MENA Region
  • adminadmin
  • BitterLinked
  • Campaign
  • abril 9, 2026
  • 0 Comentarios
Bitter-Linked Hack-for-Hire Campaign Targets Journalists Across MENA Region

An apparent hack-for-hire campaign likely orchestrated by a threat actor with suspected ties to the Indian government targeted journalists, activists, and government officials across the Middle East and North Africa (MENA),…

Continue reading
Hybrid P2P Botnet, 13-Year-Old Apache RCE and 18 More Stories
  • adminadmin
  • 13YearOld
  • Apache
  • abril 9, 2026
  • 0 Comentarios
Hybrid P2P Botnet, 13-Year-Old Apache RCE and 18 More Stories

Ravie LakshmananApr 09, 2026Hacking News / Cybersecurity News Thursday. Another week, another batch of things that probably should’ve been caught sooner but weren’t. This one’s got some range — old vulnerabilities getting…

Continue reading
Adobe Reader Zero-Day Exploited via Malicious PDFs Since December 2025
  • adminadmin
  • Adobe
  • December
  • abril 9, 2026
  • 0 Comentarios
Adobe Reader Zero-Day Exploited via Malicious PDFs Since December 2025

Ravie LakshmananApr 09, 2026Vulnerability / Threat Intelligence Threat actors have been exploiting a previously unknown zero-day vulnerability in Adobe Reader using maliciously crafted PDF documents since at least December 2025. The…

Continue reading

Paginación de entradas

1 … 120 121 122 … 148

Recent Posts

  • New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups
  • AI Agents Are Rewriting the Rules of Lateral Movement
  • Can Your SOC Actually See the Attack?
  • Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal
  • SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing

Recent Comments

No hay comentarios que mostrar.

Archives

  • septiembre 2026
  • agosto 2026
  • julio 2026
  • junio 2026
  • mayo 2026
  • abril 2026
  • marzo 2026
  • febrero 2026
  • agosto 2024

Categories

  • Uncategorized

Other Story

Uncategorized

New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups

  • admin
  • septiembre 22, 2026
New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups
Uncategorized

AI Agents Are Rewriting the Rules of Lateral Movement

  • admin
  • septiembre 22, 2026
AI Agents Are Rewriting the Rules of Lateral Movement
Uncategorized

Can Your SOC Actually See the Attack?

  • admin
  • septiembre 22, 2026
Can Your SOC Actually See the Attack?
Uncategorized

Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal

  • admin
  • septiembre 22, 2026
Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal
Uncategorized

SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing

  • admin
  • septiembre 22, 2026
SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing
Uncategorized

Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access

  • admin
  • septiembre 22, 2026
Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access
Copyright © 2026 The Digital Fortress | Powered by Desert Themes
Back to Top