Brazilian Banking Trojan Actively Spreading in Portugal

Brazilian Banking Trojan Still Wreaking Havoc in Portugal A long-forgotten banking malware has resurfaced to wreak havoc on Portuguese organizations, with researchers at Acronis discovering that it’s still being used in attacks today. The “Lampion” Trojan, named after Japanese-style paper lanterns, originated in Brazil and first emerged around the 2019 holiday season. The attackers have … Read more

Check Point warns of SmartConsole zero-day exploited in attacks

A Critical Vulnerability in Check Point’s SmartConsole Exposes Organizations to Unprecedented Risk Check Point Software, a leading Israeli cybersecurity firm, has issued an urgent advisory warning of an actively exploited zero-day flaw in its SmartConsole graphical user interface (GUI) admin panel. The vulnerability, tracked as CVE-2026-16232, allows unauthenticated attackers to obtain an application login token … Read more

Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access

A critical vulnerability in Check Point’s SmartConsole management console has been patched, but not before attackers exploited it to gain full administrative access to affected systems. The flaw, discovered by researchers at Check Point itself, allowed unauthorized users to execute arbitrary code on vulnerable machines, potentially leading to devastating consequences. The vulnerability, identified as CVE-2023-3664, … Read more

Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks

A fourth SharePoint vulnerability has been exploited in a wave of attacks that have shaken organizations worldwide. The flaw, tracked as CVE-2026-50522, was patched by Microsoft on July 14 with its latest Patch Tuesday updates, but threat actors were quick to capitalize on it. Microsoft describes CVE-2026-50522 as a critical remote code execution vulnerability stemming … Read more

Vibe-Coded Apps Riddled With Exploitable Security Flaws

A Worrying Trend Emerges in the World of Vibe-Coded Apps: Security Flaws Galore The use of artificial intelligence (AI) to assist or perform code generation, known as vibe coding, is on the rise. According to a report from Hostinger, 90% of developers now regularly use at least one AI tool at work. While this trend … Read more

StrongestLayer Raises $4.1 Million in Seed Funding Extension

A cybersecurity startup has just landed a major funding boost, securing $4.1 million in seed investment to bring its total seed funding to $9.3 million. This significant injection of capital will fuel StrongestLayer’s go-to-market strategy and platform expansion efforts, allowing it to tackle the growing threat of sophisticated email attacks. StrongestLayer, which emerged from stealth … Read more

US Warns of Iranian Hackers Targeting Siemens, Schneider, and Rockwell ICS Devices

The US government has issued a stern warning about Iranian hackers targeting critical infrastructure organizations, including those that rely on industrial control systems (ICS) from leading vendors such as Siemens, Schneider Electric, and Rockwell Automation. The attackers have been using sophisticated tactics to gain access to operational technology (OT) devices, putting the safety of people … Read more

Brazilian Banking Trojan Actively Spreading in Portugal

Brazilian Banking Trojan Continues to Spread in Portugal, Exploiting Language Barrier A notorious banking Trojan, Lampion, has been causing trouble for Portuguese organizations since its discovery around 2019. Despite being nearly a decade old, this malware remains a threat, with researchers at Acronis observing ongoing attacks against businesses in Portugal. The fact that the attackers … Read more

When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover

A recent attack on my own wireless services account exposed significant weaknesses in how organizations treat identity as a one-time event rather than something that must be continuously evaluated throughout the customer journey. The incident involved a coordinated assault that combined social engineering, identity impersonation, stolen personal information, SIM swapping, session hijacking, and unauthorized account … Read more

Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft

A recent discovery by web and browser security firm Guardio has shed light on a serious vulnerability in Adobe’s popular Chrome extension, Acrobat. The exploit, dubbed HermeticReader, allowed attackers to silently steal users’ WhatsApp chats and contacts without their knowledge or consent. The vulnerable extension, installed on approximately 329 million browsers, was found to have … Read more