top of page
ALL POSTS
Gcore and Ucom Secure Armenia's Parliamentary Election Broadcast Infrastructure
Key Findings Gcore deployed Network Layer DDoS protection for Ucom's broadcast infrastructure during Armenia's 2026 parliamentary elections Protection was activated within one day through rapid technical coordination No DDoS-related disruptions occurred during the election period Deployment leveraged Gcore's distributed scrubbing capacity and geographic infrastructure across six continents Service remained fully available throughout the protected period Background Ucom is one
Jun 192 min read
Microsoft Uncovers Windows Clipper Malware Campaign with USB Worm and Tor-Based Command & Control
Key Findings Windows-based clipper malware campaign active since February 2026 targets cryptocurrency wallets through USB-distributed LNK shortcut files Malware uses bundled Tor client with SOCKS5 proxy to communicate with hidden-service C2 servers, avoiding traditional IP-based infrastructure detection Attack chain involves worm component that replicates across USB drives by masking itself as legitimate documents like DOC, XLSX, and PDF files Clipper steals BIP39 seed phrase
Jun 183 min read
DragonForce Ransomware Exploits Microsoft Teams Relays to Conceal Malicious Command-and-Control Traffic
Key Findings DragonForce ransomware operators deployed Backdoor.Turn, a custom Go-based remote access trojan that conceals command-and-control traffic within Microsoft Teams relay infrastructure This marks the first publicly documented abuse of Microsoft's TURN relay servers by threat actors Attackers maintained network access for one to two months while evading detection by routing malicious traffic through legitimate Microsoft servers The group employed sophisticated defens
Jun 183 min read
Microsoft Confirms RoguePlanet Defender Zero-Day Vulnerability, Patch in Development
Key Findings Microsoft has formally acknowledged RoguePlanet, a privilege escalation zero-day in Microsoft Defender's Malware Protection Engine, assigned CVE-2026-50656 with a CVSS score of 7.8 The vulnerability exploits a race condition that can grant attackers SYSTEM-level privileges, and a patch is currently in development Security researcher Chaotic Eclipse released a working proof-of-concept that functions regardless of whether real-time protection is enabled or disabled
Jun 182 min read
FortiBleed: Global Credential Breach Affects 73,932 Fortinet Firewalls Across 194 Countries
Key Findings FortiBleed campaign exposed valid login credentials for 73,932 Fortinet firewall URLs across 194 countries, affecting 21,632 unique domains Attackers conducted approximately 1.16 billion credential attempts against over 320,000 FortiGate targets using a self-feeding system Compromised organizations include Samsung, Oracle, Foxconn, Comcast, Siemens, Lenovo, Spotify, Sony, and numerous government and critical infrastructure entities The operation leverages previou
Jun 184 min read
China-Linked FishMonger APT Deploys SprySOCKS Windows Backdoor With Kernel-Level Stealth and UEFI Bootkit Capabilities
Key Findings FishMonger, a China-linked APT group, has ported SprySOCKS backdoor to Windows with two new variants: WIN_DRV and WIN_PLUS WIN_DRV uses kernel drivers to hide network connections, processes, files, and registry keys from user-level detection tools WIN_PLUS exploits the Windows Print Spooler service to blend malicious activity into normal system operations Both variants were deployed against government targets in Honduras, Taiwan, Thailand, and Pakistan between 20
Jun 173 min read
Heimdal Survey: Executive Overconfidence in AI Risk Management Outpaces Technical Team Concerns
Key Findings Executive confidence vastly outpaces frontline reality. In the US, 29% of C-suite and VP respondents say AI risk is under control versus only 7% of mid-level practitioners. The UK shows a similar pattern at 18% versus 11%. AI adoption has nearly doubled security readiness. Only about 40% of teams rate their security stack as prepared for AI-related threats. ChatGPT and Microsoft Copilot are already embedded across most organizations. ChatGPT runs in 72% of UK and
Jun 173 min read
Phishing Attacks Surge Across Fortune 100: Employee Data Exposed at 86% of Companies
Key Findings 86% of Fortune 100 companies had employee data exposed through phishing attacks in the past 12 months 78% of large organizations experienced increased phishing volume over the past year 84% report AI-generated phishing attacks are becoming more prevalent or harder to defend against Phishing attacks now target enterprise users five times more frequently than malware infections Only 38% of organizations can confidently detect and respond to credential theft within
Jun 172 min read
JetBrains IDE Plugins Caught Stealing AI API Keys and Sensitive Data
Key Findings 15 malicious plugins discovered on JetBrains Marketplace posing as AI coding assistants, active since October 2025 Nearly 70,000 combined downloads with top plugins exceeding 25,000 downloads each Plugins exfiltrate OpenAI, DeepSeek, and SiliconFlow API keys to attacker-controlled server over unencrypted HTTP Seven different seller accounts used to distribute the malicious extensions Fake five-star reviews added to increase perceived legitimacy Secondary monetiza
Jun 173 min read
New Rokarolla Android Trojan Steals PINs and SMS Codes While Targeting 217 Banking and Crypto Apps
Key Findings Zimperium's zLabs identified a new Android banking trojan named Rokarolla that targets 217 cryptocurrency and banking applications The malware combines financial fraud with comprehensive device surveillance, featuring 137 remote commands for near-total phone control Attack begins through malicious websites distributing fake versions of popular apps like TikTok and Chrome Once installed, Rokarolla uses fake login overlays to steal credentials and manipulate transa
Jun 173 min read
Developer Laptops Emerge as Prime Target for Credential Theft in 2026, GitGuardian Reports
Key Findings Developer laptops have become the primary attack vector for supply-chain compromises, with attackers harvesting plaintext credentials to move laterally into production systems and cloud infrastructure GitGuardian launched Developer Endpoint Protection to address a critical gap where existing endpoint detection and identity tools miss secrets stored at rest on developer workstations Beta testing revealed an average of 150 secrets per developer laptop, with private
Jun 163 min read
AppViewX Introduces Agent Identity Security Platform for AI and Quantum Computing Governance
Key Findings AppViewX launched Agent Identity Security, a new platform capability for discovering, governing, and monitoring AI agents across enterprises The solution combines AI agent governance with native PKI infrastructure, addressing ungoverned AI agents as a major security blind spot Two converging threats are forcing enterprise rethinking: rapid AI agent proliferation with minimal oversight and quantum computing threats to current cryptography Agent Identity Security p
Jun 162 min read
Aembit Expands Identity Management Capabilities for AI Agents Across Microsoft Copilot Studio Platform
Key Findings Aembit announced integration with Microsoft Copilot Studio to extend identity and access management capabilities for AI agents Integration addresses critical security gap where agents access sensitive systems with static, broadly scoped credentials and no centralized oversight Platform issues ephemeral credentials scoped to specific tasks rather than persistent standing access Every access decision is logged for compliance review and incident investigation Integr
Jun 162 min read
Cisco SD-WAN Vulnerability Now Exploited in the Wild: Patch CVE-2026-20262 Immediately
Key Findings CVE-2026-20262 affects Cisco Catalyst SD-WAN Manager and is actively exploited in the wild The vulnerability allows authenticated attackers to write or overwrite arbitrary files on the system Planted files can be leveraged to escalate privileges to root level All deployment types are vulnerable: On-Prem, Cloud-Pro, Cisco-managed cloud, and FedRAMP installations Cisco has released patched builds across all affected versions Attackers are already deploying suspicio
Jun 162 min read
LiteSpeed and FreeBSD Privilege Escalation Flaws Under Active Exploitation (CVE-2026-54420, CVE-2026-49413)
Key Findings LiteSpeed cPanel plugin versions before 2.4.8 contain a privilege escalation flaw actively exploited in the wild Vulnerability allows low-privileged users on shared hosting to gain full root access by abusing symlink handling Flaw affects servers running CloudLinux/CageFS and scores 8.5 on CVSS scale Patch available now in cPanel plugin v2.4.8 and WHM Plugin v5.3.2.1 Attackers use distinctive pattern of certificate endpoint calls repeated 7-10 times from single I
Jun 152 min read
Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Bypass Flaw (CVE-2026-0257)
Key Findings CVE-2026-0257 is an authentication bypass vulnerability in Palo Alto Networks PAN-OS affecting GlobalProtect portals and gateways Active exploitation confirmed by Rapid7 starting May 17, 2026, with two distinct attack waves originating from different hosting providers Vulnerability allows attackers to forge authentication cookies and bypass VPN access controls without credentials CISA added the flaw to its Known Exploited Vulnerabilities catalog in early June, re
Jun 153 min read
Anthropic Claude: Export Ban Forces Refunds and Service Halt
Key Findings US government issued export control directive preventing foreign nationals in the US from accessing Claude Fable and Mythos 5 models Anthropic globally deactivated these systems in compliance, citing national security concerns Ban reportedly triggered by jailbreak vulnerabilities discovered by security researchers Anthropic established limited refund program with strict eligibility requirements and application deadline of June 20, 2026 Only subscriptions purchase
Jun 153 min read
WinRAR Vulnerability from Years Past Still Powering 2026 Attacks Against Ukraine
Key Findings CVE-2025-8088, a WinRAR path traversal flaw patched in July 2025, remains actively exploited against Ukrainian organizations as of April 2026, nearly a year after the fix was released Two Russia-aligned threat groups, SHADOW-EARTH-066 (UAC-0226) and Earth Dahu (Gamaredon), are leveraging the vulnerability in coordinated campaigns targeting Ukrainian government and military entities The exploit abuses NTFS Alternate Data Streams to silently write files to the Wind
Jun 144 min read
Argamal Malware and RAT Discovered Embedded in Trojanized Hentai Games
Key Findings Kaspersky discovered Argamal, a remote access Trojan hidden in hentai game installers, detected in April 2026 The malware is distributed through adult game sites, file-sharing platforms like PixelDrain, and torrent trackers such as AniRena Infected games function perfectly, allowing users to remain unaware their systems are compromised The malware establishes persistence through COM hijacking of Windows Color System Calibration Loader Hundreds of users infected,
Jun 142 min read
Ukrainian Extradited to US Pleads Guilty in Conti Ransomware Operation
Key Findings Ukrainian national Oleksii Lytvynenko pleaded guilty to conspiracy to commit wire fraud for his role in Conti ransomware operations Conti infected over 1,000 computers and networks across 47 U.S. states, 31 countries, and generated at least $150 million in ransom payments by January 2022 Lytvynenko joined the conspiracy in September 2021 and worked on malware development including creating a "loader" for delivering additional malicious tools He possessed stolen d
Jun 142 min read
bottom of page
