-
China-Linked Malware Found in Counterfeit USB Drives Used on Japan Defense Force Classified Networks

Japan’s defense infrastructure has faced scrutiny following an investigation that revealed members of the Japan Self-Defense Forces (JSDF) used counterfeit USB drives embedded with malware linked to China on systems handling classified informatio…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A critical server-side template injection (SSTI) vulnerability in FOSSBilling, tracked as CVE-2026-28496, is exposing instances to potential full database compromise and remote code execution (RCE), with early signs of active exploitation appearing sho…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Hackers have weaponized a WinRAR path-traversal flaw tracked as CVE-2025-8088 to silently plant a Startup shortcut and run a multi-stage PowerShell loader that maps a headerless, reflectively loaded PE in memory. The campaign reuses the Ukrainian recon…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Scammers are increasingly exploiting Shopify’s ecosystem and its Shop order-tracking app to deliver fraudulent invoices directly into users’ purchase histories, marking a shift from traditional email-based phishing to in-app social engineering attacks….
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Russian authorities leveraged Cellebrite’s Universal Forensic Extraction Device (UFED) to gain access to a detained human rights activist’s iPhone, according to a detailed forensic investigation that raises fresh concerns over the use of commercial dig…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A previously undocumented Rust-based infostealer they call KuinaExtractor, a family that has evolved from a capable early prototype into a hardened, stealth-focused threat now rebranded as “k0to.” Analysis of dozens of samples and function-level code c…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
WhatsApp has introduced a new proactive security feature that warns users before they start conversations with unknown phone numbers. This update, currently being rolled out to both Android and iOS users, adds a trust verification layer at the very beg…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A Chinese-speaking threat cluster tracked as CL-STA-1062 has deployed a newly discovered .NET backdoor, TinyRCT, in targeted campaigns against government and critical energy infrastructure across Southeast Asia during 2025. The recent campaign combines…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
OpenAI has reportedly delayed the full public release of its next-generation AI model, GPT-5.6, following a formal request from the Trump administration to limit early access to a select group of government-approved entities. This raises new concerns a…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Microsoft’s long-planned Secure Boot certificate rollover has reached a critical milestone, impacting more than just routine updates. The Microsoft Corporation KEK CA 2011 expired on June 24, 2026, the Microsoft UEFI CA 2011 expires on June 27, 2026, a…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶

