Real emails, hijacked payments: Two H1 2026 attack chains

Cyberattacks Get More Sophisticated as Hackers Use Legitimate Accounts to Steal Payments In a disturbing trend that highlights the evolving tactics of cyber attackers, two recent campaigns have shown how hackers are using legitimate accounts and exploiting browser settings to steal payments from unsuspecting victims. The attacks, which were identified by Gen Threat Labs, used … Read more

Levi Strauss & Co. says hackers stole corporate data in cyberattack

Levi Strauss & Co., the iconic clothing giant behind the famous 501-line jeans, has fallen victim to a sophisticated cyberattack. Hackers used social engineering tactics to trick three of the company’s employees into giving them access to corporate data stored on their machines. The attack, which was detected recently by Levi’s security team, allowed the … Read more

Real emails, hijacked payments: Two H1 2026 attack chains

Cyber Attackers Evade Detection with Sophisticated Techniques in H1 2026 Cybersecurity experts have been tracking two complex attack chains that emerged during the first half of 2026, highlighting the evolving tactics used by attackers to evade detection and steal sensitive information. These campaigns demonstrate how cybercriminals are adapting their methods to bypass traditional security measures … Read more

Levi Strauss & Co. says hackers stole corporate data in cyberattack

Levi Strauss & Co. has recently disclosed a cyberattack that compromised corporate data stored on company-issued computers. The attackers used social engineering tactics to trick three employees into revealing sensitive information, which was then used to gain unauthorized access to the systems. The incident highlights the ongoing threat posed by social engineering attacks, where hackers … Read more

Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets

A Critical GitHub Flaw Exposes Developers’ Secret CI Workflow Keys Developers working on a wide range of projects, from open-source software to proprietary applications, have been left exposed after a critical vulnerability was discovered in the way GitHub handles sensitive information in its Continuous Integration (CI) workflows. The flaw, found in the Gemini CLI and … Read more

Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access

Malware Can Abuse Windows Hello for Business Keys, Giving Hackers Persistent Access to Microsoft Entra ID A chilling security flaw has been discovered in Microsoft’s Windows Hello for Business feature, which allows hackers to gain persistent access to users’ Entra ID credentials. This vulnerability could potentially give attackers a backdoor into sensitive areas of an … Read more

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution – Patch ASAP

A newly discovered vulnerability in WordPress could allow attackers to execute malicious PHP code on a vulnerable website, highlighting the ongoing threat of pre-authentication (pre-auth) cross-site scripting (XSS) attacks. The issue, which affects all versions of WordPress prior to 6.0.3, has been patched by the platform’s developers, but users are urged to update their sites … Read more

AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day

A Novel HTTP Desync Technique Exploits Apache Zero-Day, Putting Millions of Websites at Risk A group of security researchers has uncovered a novel HTTP desync technique that can be used to exploit an unpatched vulnerability in Apache servers, potentially leaving millions of websites vulnerable to attacks. The discovery was made by the team behind AI-Assisted … Read more

Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails

Cyber attackers have discovered a new way to hijack Microsoft 365 accounts, using a sophisticated phishing tactic that exploits a weakness in the platform’s authentication mechanism. Dubbed “AitM” (Authentication into Mail), this campaign has already compromised numerous high-profile organizations and individuals, with reports suggesting that payroll and finance emails are being intercepted for malicious purposes. … Read more

18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers

A Long-Dormant Linux Vulnerability Can Grant Root Access and Escape Containers, Experts Warn A critical vulnerability in the Linux operating system has been discovered, allowing local attackers to gain root access and potentially escape from containers. The flaw, which affects the Session Traversal of UDP through IPv4 (SCTP) protocol, has been present since 2008 and … Read more