Saltar al contenido
Lun. Sep 14th, 2026
Trending News: Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate DataCISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEVWhat It Does to Your SOCOpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc ServersAnthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation AttacksGitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After DisclosureRussian State-Sponsored Hackers Use Claude to Rebuild Malware After DetectionClaude Used to Automate Exploitation and Data Theft Across Multiple VictimsYour Critical Vulnerabilities Might Not Be Your Biggest RiskCisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin RansomwarePaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited FlawsChina-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT BackdoorAttackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More StoriesGigabud Creates Android Work Profiles to Hide From Banking App Malware ChecksGoogle Play Early Access Abused to Push Thousands of Deceptive Android AppsPaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ InstancesCheck Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCECISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch DeadlineAnthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example «sk-1234» Admin KeyFour Spy Groups Used the Same Chrome and Windows Exploit Kit Within a WeekU.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in CryptoSAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code ExecutionResearcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be BypassedF5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk ScansU.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and GrokInfostealer Logs Expose Replayable AI Tokens That Can Bypass MFALearn How to Answer “Are We Exposed?” Faster After a New CVEAlby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin WalletsDeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without ApprovalNew cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as RootChrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside SandboxMicrosoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-DaysN-able N-central Pre-Auth RCE Flaw Exploited in the WildAutonomous AI Agents Compromise Thousands of Credentials in Under Six HoursChatGPT Flaw Let a Planted Prompt Send a Victim’s Gmail Data to Another AccountSlim Spider Steals Crypto Custody Secrets From Brazilian Financial InstitutionLiquid Hackers Return 3,400 Bitcoin Taken via Elements Bug, Still Holding $47M in BTCWhat It Took to Reach 1 Billion Build ManifestsWeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming CallsBengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support ScamsFreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator CredentialsAdobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web ShellGrindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data SharingPEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command ExecutionChrome 0-Day, Router Hijacks, Coder Supply Chain Attack and MoreFake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion AttacksTelerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit ReleasedRogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected HostsYour Cloud Security Checklist Doesn’t Work the Way You Think It DoesN-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE FlawJSCeal Malware Can Bypass Google Authentication Using Stolen Session CookiesFour REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto MinerAttackers Hijack MikroTik Routers Through Internet-Exposed SSH Without AuthenticationUnpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online StoresCritical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host CodeAttackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS CredentialsTrezor Says ShipMonk Breach Exposed 67,000 U.S. Customers’ Data It Said Was DeletedThousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination ChannelAttackers Exploit PaperCut Flaws to Steal Credentials From Schools and UniversitiesPostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code ExecutionPhishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade FiltersNew Ted Backdoor Hides Inside Victims’ Own HAProxy Builds to Intercept Web TrafficGPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit RequestsGoogle Releases Chrome Update to Patch Actively Exploited V8 Zero-DayOver 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE FlawsPlex Urges Immediate Updates After Patching Multiple Undisclosed Security FlawsThomson Reuters Court Software Breach May Have Exposed SSNs and Sealed DataCEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More StoriesBraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace InventoryCritical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as RootShai-Hulud’s Reach Just Grew to 469 Credential Locations. Here’s What That MeansUS Becomes Top Target in RMM Phishing Campaign Spanning 46 CountriesAttackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted AttacksPegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member’s iPhoneCISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto MinersResearcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike FalconAuthorities Turn Sality’s P2P Network Against Itself, Cutting Off New Malware PayloadsGoogle, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access ProgramsAttackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without CredentialsFake Software Installers Disable Windows Update and Weaken Microsoft DefenderMeta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device ControlMalicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting PagesMalicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker CodeBGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root AccessFrom Adoption to Incident ReadinessAttackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack ChainExtradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected ThousandsGeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal BackendsResearchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to AnotherBreeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment SystemsAttackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet SeedsIranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding TestsThreat Actors Don’t Want Better Attacks. They Want Repeatable OnesAttackers Steal METR API Key and Consume AI Credits Worth About $600,000Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI AnalysisAttackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 ActivityNorth Korean Job Fraud Expands Beyond IT Into Healthcare and Sales
Chicago 12, Melborne City, USA
The Digital Fortress
  • Home
  • Blog
  • Sample Page
  • Get Started
Lun. Sep 14th, 2026
Trending News: Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate DataCISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEVWhat It Does to Your SOCOpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc ServersAnthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation AttacksGitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After DisclosureRussian State-Sponsored Hackers Use Claude to Rebuild Malware After DetectionClaude Used to Automate Exploitation and Data Theft Across Multiple VictimsYour Critical Vulnerabilities Might Not Be Your Biggest RiskCisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin RansomwarePaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited FlawsChina-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT BackdoorAttackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More StoriesGigabud Creates Android Work Profiles to Hide From Banking App Malware ChecksGoogle Play Early Access Abused to Push Thousands of Deceptive Android AppsPaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ InstancesCheck Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCECISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch DeadlineAnthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example «sk-1234» Admin KeyFour Spy Groups Used the Same Chrome and Windows Exploit Kit Within a WeekU.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in CryptoSAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code ExecutionResearcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be BypassedF5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk ScansU.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and GrokInfostealer Logs Expose Replayable AI Tokens That Can Bypass MFALearn How to Answer “Are We Exposed?” Faster After a New CVEAlby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin WalletsDeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without ApprovalNew cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as RootChrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside SandboxMicrosoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-DaysN-able N-central Pre-Auth RCE Flaw Exploited in the WildAutonomous AI Agents Compromise Thousands of Credentials in Under Six HoursChatGPT Flaw Let a Planted Prompt Send a Victim’s Gmail Data to Another AccountSlim Spider Steals Crypto Custody Secrets From Brazilian Financial InstitutionLiquid Hackers Return 3,400 Bitcoin Taken via Elements Bug, Still Holding $47M in BTCWhat It Took to Reach 1 Billion Build ManifestsWeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming CallsBengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support ScamsFreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator CredentialsAdobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web ShellGrindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data SharingPEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command ExecutionChrome 0-Day, Router Hijacks, Coder Supply Chain Attack and MoreFake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion AttacksTelerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit ReleasedRogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected HostsYour Cloud Security Checklist Doesn’t Work the Way You Think It DoesN-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE FlawJSCeal Malware Can Bypass Google Authentication Using Stolen Session CookiesFour REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto MinerAttackers Hijack MikroTik Routers Through Internet-Exposed SSH Without AuthenticationUnpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online StoresCritical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host CodeAttackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS CredentialsTrezor Says ShipMonk Breach Exposed 67,000 U.S. Customers’ Data It Said Was DeletedThousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination ChannelAttackers Exploit PaperCut Flaws to Steal Credentials From Schools and UniversitiesPostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code ExecutionPhishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade FiltersNew Ted Backdoor Hides Inside Victims’ Own HAProxy Builds to Intercept Web TrafficGPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit RequestsGoogle Releases Chrome Update to Patch Actively Exploited V8 Zero-DayOver 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE FlawsPlex Urges Immediate Updates After Patching Multiple Undisclosed Security FlawsThomson Reuters Court Software Breach May Have Exposed SSNs and Sealed DataCEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More StoriesBraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace InventoryCritical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as RootShai-Hulud’s Reach Just Grew to 469 Credential Locations. Here’s What That MeansUS Becomes Top Target in RMM Phishing Campaign Spanning 46 CountriesAttackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted AttacksPegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member’s iPhoneCISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto MinersResearcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike FalconAuthorities Turn Sality’s P2P Network Against Itself, Cutting Off New Malware PayloadsGoogle, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access ProgramsAttackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without CredentialsFake Software Installers Disable Windows Update and Weaken Microsoft DefenderMeta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device ControlMalicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting PagesMalicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker CodeBGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root AccessFrom Adoption to Incident ReadinessAttackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack ChainExtradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected ThousandsGeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal BackendsResearchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to AnotherBreeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment SystemsAttackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet SeedsIranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding TestsThreat Actors Don’t Want Better Attacks. They Want Repeatable OnesAttackers Steal METR API Key and Consume AI Credits Worth About $600,000Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI AnalysisAttackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 ActivityNorth Korean Job Fraud Expands Beyond IT Into Healthcare and Sales
Chicago 12, Melborne City, USA
  • Home
  • Blog
  • Sample Page
The Digital Fortress
  • Get Started

Etiqueta Groups

  1. Inicio
  2. Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week
Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week
  • adminadmin
  • Chrome
  • Exploit
  • septiembre 9, 2026
  • 0 Comentarios
Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week

Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome. The first in-the-wild…

Continue reading
Trump Memo Paves Way for U.S. Firms to Hack and Disrupt Foreign Crime Groups
  • adminadmin
  • Crime
  • Disrupt
  • agosto 18, 2026
  • 0 Comentarios
Trump Memo Paves Way for U.S. Firms to Hack and Disrupt Foreign Crime Groups

Ravie LakshmananAug 14, 2026Cybercrime / Offensive Operation A new White House memo signed by U.S. President Donald Trump has instructed the National Coordination Center (NCC) to establish a program that…

Continue reading
Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials
  • adminadmin
  • Bleed
  • BYOVD
  • julio 2, 2026
  • 0 Comentarios
Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials

Threat actors associated with the Anubis ransomware operation have been observed exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to obtain initial access. «Although tactics differ between affiliates, common patterns emerged…

Continue reading
WinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in Ukraine
  • adminadmin
  • Deploy
  • Exploited
  • junio 9, 2026
  • 0 Comentarios
WinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in Ukraine

Ravie LakshmananJun 09, 2026Vulnerability / Cyber Espionage Two Russia-aligned cyber attack campaigns have continued to exploit a security flaw in WinRAR to target Ukrainian organisations, almost a year after patches…

Continue reading
Meta Blocks NSO Group’s New WhatsApp Phishing Attack, Files Contempt Order
  • adminadmin
  • Attack
  • Blocks
  • junio 8, 2026
  • 0 Comentarios
Meta Blocks NSO Group’s New WhatsApp Phishing Attack, Files Contempt Order

Ravie LakshmananJun 08, 2026Spyware / Mobile Security Meta on Monday said it detected and blocked spear-phishing attempts linked to Israeli spyware vendor NSO Group. In addition, the tech giant said…

Continue reading
First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups
  • adminadmin
  • Dismantled
  • Global
  • mayo 22, 2026
  • 0 Comentarios
First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups

Authorities in Europe and North America have announced the dismantling of a criminal virtual private network (VPN) service used by criminal actors to obscure the origins of ransomware attacks, data…

Continue reading
Cybercrime Groups Using Vishing and SSO Abuse in Rapid SaaS Extortion Attacks
  • adminadmin
  • Abuse
  • Attacks
  • mayo 1, 2026
  • 0 Comentarios
Cybercrime Groups Using Vishing and SSO Abuse in Rapid SaaS Extortion Attacks

Ravie LakshmananMay 01, 2026 Cybersecurity researchers are warning of two cybercrime groups that are carrying out «rapid, high-impact attacks» operating almost within the confines of SaaS environments, while leaving minimal…

Continue reading

Recent Posts

  • Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
  • CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV
  • What It Does to Your SOC
  • OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers
  • Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks

Recent Comments

No hay comentarios que mostrar.

Archives

  • septiembre 2026
  • agosto 2026
  • julio 2026
  • junio 2026
  • mayo 2026
  • abril 2026
  • marzo 2026
  • febrero 2026
  • agosto 2024

Categories

  • Uncategorized

Other Story

Uncategorized

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

  • admin
  • septiembre 13, 2026
Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
Uncategorized

CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

  • admin
  • septiembre 12, 2026
CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV
Uncategorized

What It Does to Your SOC

  • admin
  • septiembre 12, 2026
What It Does to Your SOC
Uncategorized

OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers

  • admin
  • septiembre 12, 2026
OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers
Uncategorized

Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks

  • admin
  • septiembre 11, 2026
Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks
Uncategorized

GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure

  • admin
  • septiembre 11, 2026
GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
Copyright © 2026 The Digital Fortress | Powered by Desert Themes
Back to Top