Chinese Framework Powers 200,000 Scam Sites

Over 200,000 websites have been found to be using a Chinese open-source framework called Uni-App, which is being exploited by threat actors to power massive investment scam operations. According to cybersecurity firm Infoblox, these scams are linked to the same cluster of activity and share patterns in growth and domain registration, suggesting a centralized owner … Read more

Third-Party Breaches Teach Education Sector a Costly Lesson in Vendor Risk

The education sector is learning a costly lesson about vendor risk, with rising threats from third-party actors forcing institutions to play defense against ransomware and other attacks. Cybercriminals have long viewed education as an enticing target, given its mix of legacy technology and new applications, uneven IT resources, and large amounts of sensitive data. According … Read more

Cybersecurity firms targeted by fraudulent OpenAI organization invites

Cybersecurity firms targeted by sophisticated phishing campaign using OpenAI organization invites Threat actors have launched a cunning phishing campaign targeting cybersecurity companies, leveraging legitimate-looking invitations from OpenAI to trick employees into submitting sensitive company information. The “Poisoned Tenant” campaign, discovered by Push Security, involves creating fake ChatGPT organizations that impersonate the target company and inviting … Read more

Polymarket customers lose $3 million in supply-chain attack

A massive cryptocurrency heist has shaken Polymarket, one of the world’s largest prediction markets, with hackers making off with an estimated $3 million in a sophisticated supply-chain attack. The incident highlights the increasing threat posed by these types of attacks, where malicious actors inject malware into trusted third-party software or services to gain access to … Read more

CISA sets urgent deadline to fix Cisco flaw exploited in attacks

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent directive to federal agencies, requiring them to patch two critical vulnerabilities by Sunday. These flaws, identified as CVE-2026-20230 and CVE-2026-12569, have already been exploited in attacks, making immediate action necessary to prevent further damage. CVE-2026-20230 is a server-side request forgery (SSRF) vulnerability affecting … Read more

FBI: Russian hackers now target Signal backup recovery keys

Russian Hackers Target Signal Users with Sophisticated Phishing Campaign A sophisticated phishing campaign tied to Russian intelligence services has evolved to target Signal users, potentially giving attackers access to their historical messages. The Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA) have issued a public service announcement warning about the threat, … Read more

Clean GitHub repo tricks AI coding agents into running malware

A sophisticated new attack method has been uncovered by researchers at Mozilla’s Zero Day Investigative Network (0DIN) AI security platform, which allows an attacker to trick a developer’s AI coding agent into running malware on their device. This insidious tactic exploits the trust placed in seemingly benign GitHub repositories and AI-powered tools like Claude Code. … Read more

Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign

A sophisticated Chinese-speaking Advanced Persistent Threat (APT) group has been linked to a new backdoor malware campaign targeting organizations in Southeast Asia, sparking concerns about the region’s cybersecurity landscape. The malicious activity, which began earlier this year, involves the deployment of a novel backdoor tool known as TinyRCT. The attackers are believed to have compromised … Read more

New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks

Cyberattacks have just escalated with the emergence of SharkLoader, a new malware strain that combines the potency of Cobalt Strike with sophisticated AI-driven reconnaissance capabilities. This menacing fusion has left security experts scrambling to contain its spread and protect vulnerable organizations worldwide. SharkLoader’s malicious activity was first detected in April 2023 by cybersecurity firms monitoring … Read more

FBI Warns Russian Intelligence Hackers Target Signal Backup Recovery Keys

A devastating new threat has emerged, with Russian intelligence hackers using sophisticated tactics to compromise encrypted messaging service Signal’s backup recovery keys. The warning comes from the FBI, which has issued an alert to its partners and affiliates detailing the highly targeted attacks. If successful, these attacks could potentially allow hackers to access users’ sensitive … Read more