40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets

Millions of Firefox users are in the dark about a sinister threat lurking in their browsers. At least 40 malicious extensions, masquerading as legitimate Web3 products, have been discovered to be stealing wallet secrets and sensitive information from unsuspecting users. The alarming discovery highlights the importance of verifying the authenticity of browser add-ons, particularly those … Read more

ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud

A New Wave of Android Banking Attacks Expands, Putting Millions at Risk Android users are facing a growing threat as two sophisticated malware families, ToxicPanda 2.0 and GoldDigger, have merged forces to launch targeted banking attacks on unsuspecting mobile devices. This alarming development has significant implications for millions of individuals who rely on their smartphones … Read more

NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands

NASA’s AIT-GUI Flaws Expose Spacecraft to Unauthorized Commands A critical vulnerability has been discovered in NASA’s Automated Test Equipment Graphical User Interface (AIT-GUI) system, potentially allowing unauthenticated attackers to issue commands to spacecraft. The flaw, which affects multiple NASA facilities and contractors, has sparked concerns about the security of space missions. The AIT-GUI system is … Read more

Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler

Citrix’s NetScaler Appliances Face Critical Authentication Bypass Threat Citrix has issued patches for two vulnerabilities in its NetScaler ADC and NetScaler Gateway products, including a critical flaw that can be exploited by remote attackers without user interaction. The vulnerability, tracked as CVE-2026-19490 with a CVSS score of 9.3, allows an attacker to bypass authentication using … Read more

OpenAI Overhauls Model Security With Sandboxing, 30-Minute Alerts, and Training Pauses

OpenAI has taken a major step forward in securing its advanced artificial intelligence (AI) models by introducing new containment and monitoring protocols. The move comes after an internal evaluation revealed that one of its upcoming models, Astra, may meet the “critical” cybersecurity capability threshold under OpenAI’s Preparedness Framework. This finding was triggered by a recent … Read more

Microsoft says August Windows updates may cause gaming issues

Microsoft is facing another round of gaming woes, this time linked to its August Windows updates. The tech giant has confirmed that a limited number of games are experiencing issues on affected systems, including freezing, crashing, and system restarts. The problems have been reported by users playing popular titles like ARC Raiders, MARVEL Tōkon: Fighting … Read more

Critical Zimbra RCE flaw now actively exploited in attacks

A critical vulnerability in Zimbra Collaboration Suite (ZCS) has been exploited in real-world attacks, leaving hundreds of millions of users vulnerable. The flaw, tracked as CVE-2026-73570, allows unauthenticated attackers to gain remote code execution by exploiting a command injection weakness in the SNMP monitoring component when notifications are enabled. The vulnerability was patched by Zimbra … Read more

New Manic Android malware can exfiltrate data through nearby devices

A New Android Malware Threats European Users with Unusual Data Exfiltration Mechanism A sophisticated Android malware, dubbed Manic, has been targeting users in multiple European countries since at least February. What makes this threat particularly concerning is its fallback mechanism for exfiltrating data through nearby infected devices, allowing attackers to bypass traditional command-and-control (C2) server … Read more

Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign

Cybercrime Gang Cl0p Reveals Over 40 Victims of PTC Windchill Campaign, Exposing Sensitive Data and Intellectual Property A recent wave of cyberattacks has left over 40 organizations reeling after the Cl0p ransomware group exploited a vulnerability in PTC’s product lifecycle management (PLM) platforms Windchill and FlexPLM. The hackers have now publicly listed the victims on … Read more

Hackers Using AI to Target Siemens PLCs in Critical US Sectors

Critical Infrastructure at Risk as Hackers Use AI to Target Siemens PLCs A joint cybersecurity advisory issued by several government agencies in the United States has sounded the alarm on a growing threat to critical infrastructure organizations. Hackers are using artificial intelligence (AI) to scan for exposed Programmable Logic Controllers (PLCs) from Siemens, potentially disrupting … Read more