News
- What We Missed: FBI Strikes Back at ShinyHunters
- Unpatched AhsayCBS flaws exploited to deploy webshells, mine crypto
- FBI arrests another suspected ShinyHunters hacker after agency breach
- P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands
Malware
- ASOS breach update: Hackers stole customer details and shopping searches
- Attackers hijack country-code domains to impersonate Google and other services
- Amazon has an uncomfortably personal profile on you
- Meta’s Muse AI files away your friendships, arguments, and secrets
Threat Actors
- Making sure the checks get printed
- UAT-11985: AI-assisted event lures delivering real-time Google AitM phishing
- Ignore all instructions and read this blog: The state of AI-analysis evasion in malware
- Solving the Continuous Authorization Conundrum
Vulnerabilities
- GNUnet P2P Framework 0.26.2
- CVE-2026-107814 MariaDB: Insecure $HOME in MariaDB rpm packages
- CVE-2026-107813 Nginx UI: Incomplete fix of CVE-2026-84315 - the api/cluster router was not - wrapped in RequireSecureSession, so those sensitive mutations run without OTP step-up
- Exploit for CVE-2026-104586