Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
24 Malware Crypter Sellers Turn EDR Evasion and In-Memory Execution Into Paid Services
7+ hour, 52+ min ago (391+ words) An analysis of 24 active crypting-service vendors shows that customers can now buy payload obfuscation, in-memory execution, anti-analysis controls, process injection, persistence, and rapid “re-crypting” as packaged services rather than develop them internally. The current market is far broader. Higher-tier vendors…...
Fortinet FortiWeb and FortiClient Flaws Let Unauthenticated Attackers Gain Access and Execute Arbitrary Code
10+ hour, 8+ min ago (352+ words) The flaws CVE-2026-26035 and CVE-2026-70465 were disclosed as part of an August 2026 patch release that addressed eight security issues across various Fortinet products. The vulnerabilities affect different attack surfaces and should not be regarded as a single exploit chain. CVE…...
Apple Warns iPhone Users in 110 Countries of Mercenary Spyware Attacks
8+ hour, 35+ min ago (472+ words) Apple has issued a new set of high-confidence Apple Threat Notification alerts, warning selected iPhone users in 110 countries that they may be targets of government-grade mercenary spyware. These notifications are not routine phishing messages or general security advisories. According to…...
Trezor Shipping Provider Data Breach Exposes Personal Data of 13,689 Customers
10+ hour, 26+ min ago (513+ words) Hardware wallet manufacturer Trezor has recently disclosed a data breach at ShipMonk, a third-party shipping provider. This breach exposed the personal information of 13,689 customers. ShipMonk notified Trezor on August 10, 2026, that an unauthorized actor had accessed its systems, which contained customer…...
New AmnesiaStealer Malware Targets macOS Users via ClickFix Attacks
10+ hour, 57+ min ago (545+ words) Researchers have observed the campaign using a counterfeit GitHub-themed page that displays a “Download for macOS” prompt along with a deceptive “Verified Publisher” badge. Rather than downloading an application directly, the site instructs victims to open Terminal, paste a command,…...
Jewelbug Uses Public Google Docs as Malware Command-and-Control Delivery Channel
1+ day, 2+ hour ago (418+ words) A China-linked threat group tracked as Jewelbug has turned public Google Docs into a resilient command-and-control delivery channel, embedding freshly obfuscated malware payloads in documents that victim implants retrieve and execute. Investigators found that both missions rely on shared infrastructure,…...
Akira Ransomware Reboots Windows Into Safe Mode to Disable EDR and Microsoft Defender
1+ day, 8+ hour ago (569+ words) An Akira ransomware affiliate has been observed rebooting a compromised Windows host into Safe Mode with Networking to disable endpoint protection an anti-EDR tactic linked to the operation. The intrusion failed to encrypt files after the stripped-down boot environment triggered…...
Critical Adobe Commerce Flaw Lets Unauthenticated Attackers Escalate Privileges
1+ day, 7+ hour ago (262+ words) Adobe has released security updates for Adobe Commerce, Adobe Commerce B2B, and Magento Open Source to address multiple critical vulnerabilities. One of the most serious issues is a high-impact privilege-escalation flaw, tracked as CVE-2026-71362, which can be exploited without authentication. This…...
Trump Administration Authorizes Cyber Operations Against Foreign Criminal Networks
1+ day, 3+ hour ago (382+ words) This initiative expands Executive Order 14390, issued on March 6, 2026, which directed federal agencies to combat cybercrime, fraud, and predatory schemes affecting Americans. The new program aims to integrate the private sector’s technical capabilities into law enforcement and intelligence-led efforts to disrupt…...
LiteLLM Hack Exposes Secrets From 2,488 Companies Across 118,829 CI Runner Dumps
1+ day, 4+ hour ago (541+ words) The LiteLLM supply-chain compromise has shifted from a short-lived malicious package incident into a sprawling enterprise exposure event. Analysis of an alleged 153GB attacker archive has linked 118,829 CI runner dumps to 2,488 corporate domains, exposing the depth of secrets accessible inside modern…...