New DOUBLECUP ClickFix service hides malware in browser cache images

A New Breed of Malware Lurks in Browser Cache Images, Threatening Windows and macOS Users A sophisticated Russian loader-as-a-service named DOUBLECUP has been quietly operating since early June 2026, using a clever technique to hide malicious code in PNG images cached by victims’ browsers. This service, which provides customers with licenses and a Go-based Windows … Read more

INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws

A devastating new ransomware variant has emerged, targeting organizations vulnerable to previously disclosed vulnerabilities in SonicWall’s Secure Mobile Access (SMA) 1000 products. The so-called “INC Ransomware” is exploiting unpatched flaws in SMA 1000 appliances, compromising sensitive data and leaving many businesses scrambling to contain the damage. The attack vector appears to be a classic case … Read more

Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts A critical vulnerability in Google’s password manager has been discovered, potentially allowing malicious software to access sensitive user accounts. The flaw, uncovered by cybersecurity researchers, affects users who have enabled passkeys – a feature designed to provide an additional layer of protection against phishing attacks. … Read more

18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users

A Critical Security Flaw in Alibaba’s Tool Chain Exposes Thousands to Cross-Platform Malware A severe security vulnerability has been discovered in a popular set of tools used by developers on the npm package manager, allowing malicious actors to deploy cross-platform Remote Access Trojans (RATs) with ease. The affected packages, which are designed to streamline development … Read more

Black Hat USA 2026 – Summary of Vendor Announcements (Part 1)

Black Hat USA 2026 Vendor Announcements Highlight Shift towards AI-Powered Security Solutions This week’s Black Hat conference in Las Vegas has brought together some of the biggest names in cybersecurity to showcase their latest products and services. Amidst the buzz, several notable vendor announcements have caught our attention, highlighting a significant shift towards leveraging Artificial … Read more

Is There Really a Fix for CISO Fatigue?

Cybersecurity leaders are facing unprecedented levels of stress and burnout, with a staggering 98% of professionals reporting some level of job-related anxiety. This is not just a matter of too much work or not enough resources – it’s a symptom of a deeper problem that affects entire organizations. According to research from Omdia and ISSA, … Read more

Inside the Underground Business of the Android BTMOB RAT malware

Android Malware Ecosystem Explodes into a Complex Business with BTMOB RAT at Its Core A notorious malware-as-a-service (MaaS) operation has given rise to an underground business, with multiple actors exploiting the Android BTMOB Remote Access Trojan (RAT). The ecosystem surrounding this malware is complex and rapidly evolving, making it increasingly difficult for its original operator … Read more

Is There Really a Fix for CISO Fatigue?

Cybersecurity leaders are burning out at an alarming rate, with nearly two-thirds reporting that their job has become measurably harder over the past two years. A staggering 68% of cybersecurity professionals say they experience stress on the job, and only 2% report feeling no stress at all. This crisis is not just a matter of … Read more

ExfilSquad hackers leak info of over 100,000 UK police officers, staff

Over 100,000 UK police officers and staff have had their personal contact information compromised in a cyberattack on the Police National Legal Database (PNLD), an online legal resource service used by law enforcement agencies across England and Wales. The breach, which was claimed by the ExfilSquad data extortion group, exposed the full names, organizations, and … Read more

Inside the Underground Business of the Android BTMOB RAT malware

A sprawling underground market has emerged around the Android BTMOB RAT malware, with a complex web of actors selling access to the malicious software, private infrastructure, and even the source code behind it. What was initially a centrally operated malware service has splintered into a broader ecosystem involving resellers, source-code vendors, and independent administrators. At … Read more