Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner

Malware Takedown Exposes Lethal Combo of Exploits and Crypto Mining Malice A recent malware campaign has left a trail of compromised Windows devices in its wake, with threat actors leveraging four linked modules to disable crucial security features and secretly mine cryptocurrency. The malicious combo, attributed to the REVSTEALER gang, has been identified as a … Read more

Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication

MikroTik Router Hacking Spree Exposes Hundreds of Thousands of Users to Remote Takeover A disturbing trend has emerged in the cybersecurity landscape, as hackers have been exploiting a vulnerability in MikroTik routers to gain remote access and control over affected devices. This brazen attack vector involves utilizing internet-exposed SSH connections without authentication, leaving hundreds of … Read more

Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

Cybersecurity experts have sounded the alarm over a zero-day vulnerability affecting Magento and Adobe Commerce, two popular e-commerce platforms used by thousands of online stores worldwide. The unpatched flaw has already been exploited in the wild, allowing attackers to gain unauthorized access and plant malicious code on affected sites. The issue revolves around a privilege … Read more

Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

Cybersecurity researchers have discovered a critical zero-day vulnerability in Magento and Adobe Commerce, two popular e-commerce platforms used by thousands of online stores. This flaw allows attackers to remotely backdoor websites, giving them full control over sensitive data and operations. The vulnerability, which has been actively exploited since August 2026, affects versions 2.4.x and earlier … Read more

Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code

A Critical Flaw in VMware’s Virtualization Software Exposes VM Admins to Host Code Execution Risks VMware, a leading provider of virtualization software, has disclosed a critical vulnerability that affects its Workstation and Fusion products. The flaw, tracked as CVE-2026-1234, allows administrators with privileges within a virtual machine (VM) to execute code on the host operating … Read more

Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials

A Critical Vulnerability in JetBrains Cadence Exposed Thousands of AWS Credentials Thousands of developers and organizations using JetBrains’ project management tool, Cadence, have been left vulnerable to a critical security breach after attackers exploited an unpatched vulnerability in TeamCity, a closely related service. The attack allowed hackers to extract sensitive AWS credentials, compromising the security … Read more

Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain

Over 5,400 hacked websites are being used as unwitting accomplices in a massive cybercrime operation that’s delivering malicious payloads stored on the BNB Smart Chain (BSC) blockchain. This sprawling campaign involves thousands of compromised small-business sites, with most built on WordPress and PrestaShop platforms. Researchers at cloud security firm Netskope have uncovered the scope of … Read more

Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers’ Data It Said Was Deleted

A major security breach has rocked cryptocurrency hardware wallet provider Trezor, with a staggering 67,000 U.S. customers’ data potentially compromised in a hacking incident that’s left many wondering how such a massive vulnerability could be overlooked. The breach, which occurred at ShipMonk, a third-party logistics company used by Trezor for order fulfillment and shipping, has … Read more

Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code

Critical Flaw in VMware Workstation and Fusion Exposes Host Systems to Unauthorized Access A severe vulnerability has been discovered in VMware’s popular virtualization software, Workstation and Fusion. The flaw allows administrators of virtual machines (VMs) to execute code on the underlying host system with escalated privileges, potentially leading to unauthorized access and data breaches. The … Read more

Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials

A Critical Vulnerability in JetBrains Cadence Exposes AWS Credentials, Leaving Thousands of Developers at Risk In a disturbing revelation, cybersecurity researchers have uncovered an alarming security breach that has compromised thousands of developers worldwide. Attackers exploited an unpatched vulnerability in JetBrains TeamCity, a popular continuous integration and continuous deployment (CI/CD) tool used by numerous organizations, … Read more