-
Progress’s Kemp LoadMaster, a widely deployed edge load balancer and ADC, is at the center of a critical pre-authentication Remote Code Execution (RCE) vulnerability tracked as CVE-2026-8037. The flaw allows unauthenticated attackers with access to the…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
BumbleBee and AdaptixC2 are being used in a highly efficient intrusion chain that starts with Bing SEO poisoning and ends with Akira ransomware deployment, showing how trusted search traffic is now being turned into an enterprise compromise vector. The…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A new technical analysis has exposed six proximity-transfer flaws across Apple AirDrop, Samsung Quick Share on Android, and Google Quick Share for Windows, showing that device-sharing stacks still contain fragile pre-authentication attack surfaces that…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A proof-of-concept has been published that bypasses Microsoft’s mitigation for the NTLM reflection vulnerability tracked as CVE-2025-33073 and allows escalation to NT AUTHORITY\SYSTEM on Windows Server. The exploit leverages two conceptual weaknesses l…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
SystemBC (also tracked as Coroxy) remains a versatile and persistent Windows malware family that operators routinely deploy to convert compromised hosts into SOCKS5 proxy gateways and to maintain remote access for follow-on operations. First observed a…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Kali Linux 2026.2 arrives on schedule in the final week of Q2 with a pragmatic blend of desktop environment refreshes, infrastructure hardening, and practical usability refinements that will matter to both pentesters and platform maintainers. The relea…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The new “Boss Scam” is a sharp escalation in CEO fraud: attackers now combine impersonation, Windows DLL sideloading, and WhatsApp Web session theft to turn trusted executive channels into fraud infrastructure. The campaign was highlighted in advisorie…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Japan’s hotel sector is the latest target of a sophisticated phishing and remote-access trojan (RAT) campaign that leverages guest-complaint lures and an unusual resilience mechanism: a TON blockchain–based dead-drop resolver. Beginning in late May 202…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Two concurrent espionage campaigns by Mustang Panda targeting Indian government and energy-sector organisations, deploying a novel malware suite that includes SHARDLOADER, MINIRECON and ZOHOMURK. The intrusions, observed in June 2026, focused on hydrop…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A malicious Chromium extension that impersonated the Perplexity AI brand to intercept browser searches and capture keystrokes before delivering users to legitimate search results. The extension, listed as “Search for perplexity ai” (ID flkebkiofojicogd…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


