Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

A notorious North Korean hacking group, Lazarus, has successfully exploited a previously unknown vulnerability in Windows operating systems to gain SYSTEM access and deploy a backdoor on compromised machines. This zero-day exploit marks the latest escalation in the group’s arsenal of cyber warfare capabilities. Lazarus, responsible for high-profile attacks including the 2014 Sony Pictures breach, … Read more

Hackers leverage new Microsoft SharePoint exploit in attacks

A Critical Microsoft SharePoint Vulnerability is Being Exploited in Attacks, Leaving Thousands of Servers at Risk A proof-of-concept (PoC) exploit for a critical Microsoft SharePoint vulnerability, tracked as CVE-2026-55040, has been published by cybersecurity company Rapid7. Just hours after its release, threat intelligence companies have already reported that the exploit is being used in attacks … Read more

The Threat Hiding in Your Hiring Process: How Fake Remote Workers Get In

A Sneaky Threat Lurks in Your Hiring Process: How Fake Remote Workers Gain Access In a shocking example of cyber deception, North Korean IT workers have been impersonating nationals of other countries to gain legitimate access to corporate networks. Once employed, these individuals send their salaries back to parent agencies in North Korea, highlighting the … Read more

Plug and Pwn attack uses fake USB devices for Windows SYSTEM access

Windows users are at risk of being exploited through a new class of attacks dubbed “Plug and Pwn,” where fake USB devices can be used to gain SYSTEM privileges on compromised machines. This disturbing trend highlights how even seemingly innocuous features in operating systems can be abused by malicious actors. Security researchers Alejandro Hernando and … Read more

Hundreds of fake Chrome VPN extensions route traffic through a proxy

Hackers Behind Fake VPN Extensions Exposed, Thousands of Users Affected A massive campaign to deceive users has been uncovered by researchers at Socket, with over 737 fake Chrome browser extensions impersonating well-known VPN and proxy services. These extensions were downloaded nearly 75,000 times from the Chrome Web Store, primarily by Russian users seeking tools to … Read more

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

Lazarus Group Exploits Windows Zero-Day Vulnerability, Leaves Trail of Backdoors in Its Wake A devastating cyber attack has been unleashed by the notorious Lazarus group, leveraging a previously unknown vulnerability in Microsoft’s Windows operating system to gain SYSTEM access and deploy a sophisticated backdoor. The group’s malicious activities have left a trail of compromised systems … Read more

Lazarus hackers exploited Windows zero-day to target defense firms

North Korean Hackers Exploit Windows Zero-Day Vulnerability to Target Defense Firms In a brazen attack, North Korea’s Lazarus threat group has been exploiting a previously unknown vulnerability in Microsoft Windows to infiltrate defense-sector companies across Europe and India. The hackers have been using the flaw, known as CVE-2026-68820, as part of their long-running Operation Dream … Read more

Plug and Pwn attack uses fake USB devices for Windows SYSTEM access

Windows Plug and Play Vulnerabilities Allow SYSTEM Access via Fake USB Devices A new wave of attacks has emerged, leveraging the Windows Plug and Play feature to compromise system security. Researchers Alejandro Hernando and Borja Martínez have revealed a family of “Plug and Pwn” attacks that exploit how Windows automatically identifies and installs software from … Read more

Enterprise Defenses Recovered at the Edge and Collapsed Inside

As enterprises continue to struggle with cybersecurity threats, a new trend has emerged that’s catching many off guard. It appears that defenses are being compromised from within, but not in the way you might think. Instead of traditional insider threats, we’re seeing a more insidious issue – identity exposure. This vulnerability is exposing active attack … Read more

OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models’ Reasoning

Recent research has uncovered a significant vulnerability in the way AI models interact with each other’s reasoning processes. Specifically, a flaw in the Google API used by several top AI companies, including OpenAI and Anthropic, allows weaker AI models to decode the internal workings of stronger models. The issue arises from a feature called “cross-domain … Read more