New ChocoPoC malware targets researchers via trojanized PoC exploits

Researchers have uncovered a sophisticated malware campaign targeting cybersecurity professionals through a unique tactic of hiding malicious code within proof-of-concept (PoC) exploits on GitHub. The Python-based remote access trojan (RAT), dubbed ChocoPoC, has been embedded in at least seven PoC repositories, allowing attackers to deliver a payload that can execute commands, steal sensitive data, and … Read more

Kubota says hackers had month-long access to network systems

Kubota Exposes Employee Data in Month-Long Hackers’ Stroll Through its Network Japanese industrial manufacturer Kubota North America Corporation has just revealed that hackers had unfettered access to its network systems for over a month earlier this year. Between March 16 and April 20, the threat actor browsed through files containing sensitive personal information of employees … Read more

FortiBleed credential-theft campaign linked to Lynx ransomware

A Massive Credential-Stealing Campaign Exposed: FortiBleed Linked to Lynx Ransomware Group In a shocking revelation, researchers have uncovered a massive credential-theft campaign known as FortiBleed, which has been linked to two notorious ransomware groups: INC and Lynx. The operation, which exposed over 73,000 Fortinet devices worldwide, was not just a simple case of data breaches … Read more

2026 Cybersecurity Assessment: The Gap Between Awareness and Resilience

A growing concern for organizations worldwide is the increasing gap between awareness and resilience when it comes to software vulnerabilities discovered by advanced artificial intelligence (AI) models. These sophisticated tools are rapidly evolving, making it challenging for even experienced security professionals to keep pace with the latest threats. In 2026, a cybersecurity assessment highlighted the … Read more

VEIL#DROP Malware Chain Uses Blogger Platform to Deliver PureLogs Stealer

**Malware Chain Exploits Blogger Platform, Steals Sensitive Data** A sophisticated malware chain, dubbed Veil#DROP, has been uncovered, leveraging the blogger platform to deliver a stealthy data stealer known as PureLogs. This malicious operation affects not only individuals but also businesses, emphasizing the importance of robust security measures in today’s digital landscape. Veil#DROP is an intricate … Read more

SEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRAT

Cybercrime gangs have been exploiting a vulnerability in ScreenConnect, a widely-used remote access software, to deploy AsyncRAT malware on unsuspecting victims’ computers. This sophisticated scheme involves manipulating search engine optimization (SEO) techniques to poison software websites with malicious code, effectively turning legitimate sites into vectors for cyber attacks. The nefarious operation relies on compromised software … Read more

19-Year-Old Scattered Spider Suspect Extradited to Face U.S. Hacking Charges

A 19-year-old accused of using advanced hacking techniques to breach multiple high-profile companies has been extradited from the UK to face charges in the United States. The suspect, whose name is not being disclosed due to ongoing legal proceedings, was allegedly involved in a sophisticated cyber campaign that exploited vulnerabilities in software systems. According to … Read more

Unpatched Argo CD Repo-Server Flaw Could Let Attackers Take Over Kubernetes Clusters

A critical vulnerability discovered in Argo CD’s repository server could potentially allow attackers to gain unauthorized access to Kubernetes clusters, compromising sensitive data and disrupting business operations. Argo CD is an open-source continuous delivery tool used by many organizations to manage their cloud-native applications. A recent discovery revealed a flaw in the repository server component … Read more

2026 Cybersecurity Assessment: The Gap Between Awareness and Resilience

As AI-powered tools increasingly infiltrate the world of cybersecurity, researchers have made a groundbreaking discovery that could either bolster or undermine an organization’s defenses – depending on its approach. A recent assessment highlights a staggering gap between awareness and resilience when it comes to addressing software vulnerabilities discovered by AI models. At the heart of … Read more

VEIL#DROP Malware Chain Uses Blogger Platform to Deliver PureLogs Stealer

Malware Chain Exploits Blogger Platform, Steals Sensitive Data from Thousands of Victims A sophisticated malware chain known as VEIL#DROP has been uncovered, leveraging a popular blogging platform to spread a notorious data-stealing tool called PureLogs. The attack vector exploits vulnerabilities in the platform’s infrastructure, compromising thousands of users’ sensitive information. At its core, VEIL#DROP is … Read more