How MSPs can catch phishing attacks email filters miss

**Phishing Attacks Get a Boost with AI – How MSPs Can Stay Ahead of the Game** Phishing attacks have always been a headache for Managed Service Providers (MSPs), but the recent surge in artificial intelligence-powered campaigns has made them even more challenging to detect and prevent. With AI, attackers can create highly personalized emails that … Read more

Critical Elementor Pro bug exposes WordPress sites to RCE attacks

A Critical Vulnerability in Elementor Pro Exposes WordPress Sites to Remote Code Execution Attacks A serious security bug has been discovered in the popular Elementor Pro plugin, which could allow attackers to upload malicious files and execute arbitrary code on vulnerable websites. The flaw, identified as CVE-2026-32475, affects all versions of Elementor Pro prior to … Read more

Hackers poison arrayref Rust crate to push infostealer malware

Cybersecurity experts have uncovered a sophisticated supply-chain attack that has compromised several popular Rust crates, including arrayref, append-only-vec, and internment. The attackers injected malicious code into these libraries, which are used by thousands of developers worldwide to build software applications. The hackers took advantage of the maintainer account behind arrayref, one of the most widely … Read more

How MSPs can catch phishing attacks email filters miss

Phishing Attacks Just Got a Whole Lot Smarter – And It’s Up to MSPs to Catch Them Cybersecurity professionals have long warned about the dangers of phishing emails, but recent advancements in artificial intelligence (AI) have made these attacks more convincing and harder to detect than ever. Managed Service Providers (MSPs), who are often responsible … Read more

Critical Elementor Pro bug exposes WordPress sites to RCE attacks

A Critical Elementor Pro Bug Exposes WordPress Sites to Remote Code Execution Attacks A severe vulnerability in the popular Elementor Pro plugin for WordPress has been uncovered, putting millions of websites at risk of remote code execution attacks. The flaw, identified as CVE-2026-32475, affects all versions of Elementor Pro prior to 4.2.2 and could allow … Read more

Hackers poison arrayref Rust crate to push infostealer malware

A devastating supply-chain attack has compromised the popular Rust crate arrayref, allowing hackers to push infostealer malware onto developers’ systems during compilation. The malicious code was injected into the crate by an attacker who had access to the maintainer’s account and exploited a vulnerability in the package management system. The attack, which occurred on August … Read more

Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

A sophisticated attack campaign has been uncovered, with suspected Russian hackers exploiting a combination of Google’s OAuth authentication system and WhatsApp’s linking feature to gain unauthorized access to multiple high-profile targets. This brazen hacking operation not only highlights the vulnerabilities in our increasingly interconnected online lives but also underscores the importance of robust security measures. … Read more

Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads

A Supply Chain Hack Has Injected Malware into a Crucial Rust Package, Potentially Affecting Millions of Developers and Users A malicious actor has successfully infiltrated the supply chain of one of the most widely-used libraries in the Rust programming language, injecting malware that can compromise systems during the build process. The affected library, called “crates.io”, … Read more

40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets

Malicious Firefox Extensions Pose as Web3 Products, Steal Wallet Secrets from Thousands of Users A recent investigation has uncovered a sophisticated threat campaign targeting users of the popular web browser Mozilla Firefox. At least 40 malicious extensions, masquerading as legitimate Web3 products, have been found to be secretly stealing sensitive wallet secrets and other user … Read more

ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud

A devastating new wave of Android banking attacks is sweeping the globe, as two sophisticated malware strains – ToxicPanda 2.0 and GoldDigger – have been spotted exploiting vulnerabilities in mobile devices to facilitate on-device fraud. The malicious software has already infected thousands of users worldwide, compromising their financial data and putting them at risk of … Read more