-
A previously undocumented malware framework, tracked as Avalon, that uses a spoofed legal-document lure and a multi-stage, fileless-oriented chain to deliver a ransomware component internally labeled CrownX. The campaign demonstrates a shift toward con…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A new campaign linked to the TimbreStealer information stealer that specifically targets Mexican companies, employing layered evasion and sophisticated runtime tricks to frustrate detection and analysis. Researchers Euler Neto and Cristóbal Tárraga det…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A Mac-targeting ClickFix campaign amplified through a verified X sponsored ad, and a novel browser-based hijack technique called ConsentFix that exfiltrates Microsoft 365 session tokens without traditional malware. Researchers at Jamf and Malwarebytes …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly disclosed forensic investigation has revealed that Pegasus spyware was used to hack a sitting Member of the European Parliament (MEP) who was actively investigating spyware abuses across the European Union. This raises serious concerns about su…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Scammers are exploiting consumers’ trust in household and financial brands by deploying polished fake Google Play Store pages and social media ads that push Progressive Web Apps (PWAs) linked to online casinos. The fraud begins with paid social creativ…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Alibaba is reportedly preparing to ban the use of Anthropic’s Claude Code across its internal environments starting July 10. This decision comes in light of allegations that the AI-powered coding assistant has a covert detection mechanism resembling a …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Threat actors are currently exploiting sophisticated ClickFix social engineering campaigns that mimic Google and Cloudflare verification systems to distribute several high-impact malware families, including StealC, HijackLoader, NetSupport RAT, and new…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly disclosed vulnerability in Microsoft Exchange, identified as CVE-2026-45504 (CVSS score: 8.8), exposes a critical server-side request forgery (SSRF) flaw. This issue allows authenticated low-privileged users to access and read arbitrary files f…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Hackers are now weaponizing documentation and site metadata to mislead autonomous AI agents into executing cryptocurrency payments. The attack leverages indirect prompt injection (IPI): malicious instructions hidden in web content and structured data t…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Anthropic has provided detailed technical insights into the cybersecurity safeguards of its redeployed Claude Fable 5 model. Alongside this, they have introduced a proposed Cyber Jailbreak Severity (CJS) framework designed to standardize how AI jailbre…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


