New Manic Android malware can exfiltrate data through nearby devices

New Android Malware Exfiltrates Data Through Nearby Devices, Targeting European Users A sophisticated Android malware named Manic has been discovered by researchers at ThreatFabric, targeting users in multiple European countries with a novel data exfiltration mechanism that allows it to siphon sensitive information from compromised devices even when they are offline. The malware combines spyware, … Read more

CISA warns of hackers exploiting critical MLflow vulnerability

Cybersecurity experts are sounding the alarm as hackers begin exploiting a critical vulnerability in MLflow, an open-source platform used by thousands of organizations to build and manage artificial intelligence (AI) applications. The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning that unpatched instances of MLflow are vulnerable to attacks that can allow threat … Read more

40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets

Millions of Firefox users are in the dark about a sinister threat lurking in their browsers. At least 40 malicious extensions, masquerading as legitimate Web3 products, have been discovered to be stealing wallet secrets and sensitive information from unsuspecting users. The alarming discovery highlights the importance of verifying the authenticity of browser add-ons, particularly those … Read more

ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud

A New Wave of Android Banking Attacks Expands, Putting Millions at Risk Android users are facing a growing threat as two sophisticated malware families, ToxicPanda 2.0 and GoldDigger, have merged forces to launch targeted banking attacks on unsuspecting mobile devices. This alarming development has significant implications for millions of individuals who rely on their smartphones … Read more

NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands

NASA’s AIT-GUI Flaws Expose Spacecraft to Unauthorized Commands A critical vulnerability has been discovered in NASA’s Automated Test Equipment Graphical User Interface (AIT-GUI) system, potentially allowing unauthenticated attackers to issue commands to spacecraft. The flaw, which affects multiple NASA facilities and contractors, has sparked concerns about the security of space missions. The AIT-GUI system is … Read more

Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler

Citrix’s NetScaler Appliances Face Critical Authentication Bypass Threat Citrix has issued patches for two vulnerabilities in its NetScaler ADC and NetScaler Gateway products, including a critical flaw that can be exploited by remote attackers without user interaction. The vulnerability, tracked as CVE-2026-19490 with a CVSS score of 9.3, allows an attacker to bypass authentication using … Read more

OpenAI Overhauls Model Security With Sandboxing, 30-Minute Alerts, and Training Pauses

OpenAI has taken a major step forward in securing its advanced artificial intelligence (AI) models by introducing new containment and monitoring protocols. The move comes after an internal evaluation revealed that one of its upcoming models, Astra, may meet the “critical” cybersecurity capability threshold under OpenAI’s Preparedness Framework. This finding was triggered by a recent … Read more

Microsoft says August Windows updates may cause gaming issues

Microsoft is facing another round of gaming woes, this time linked to its August Windows updates. The tech giant has confirmed that a limited number of games are experiencing issues on affected systems, including freezing, crashing, and system restarts. The problems have been reported by users playing popular titles like ARC Raiders, MARVEL Tōkon: Fighting … Read more

Critical Zimbra RCE flaw now actively exploited in attacks

A critical vulnerability in Zimbra Collaboration Suite (ZCS) has been exploited in real-world attacks, leaving hundreds of millions of users vulnerable. The flaw, tracked as CVE-2026-73570, allows unauthenticated attackers to gain remote code execution by exploiting a command injection weakness in the SNMP monitoring component when notifications are enabled. The vulnerability was patched by Zimbra … Read more

New Manic Android malware can exfiltrate data through nearby devices

A New Android Malware Threats European Users with Unusual Data Exfiltration Mechanism A sophisticated Android malware, dubbed Manic, has been targeting users in multiple European countries since at least February. What makes this threat particularly concerning is its fallback mechanism for exfiltrating data through nearby infected devices, allowing attackers to bypass traditional command-and-control (C2) server … Read more