RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service

A sophisticated Android malware campaign has been uncovered, with attackers using a clever disguise to evade detection and pilfer sensitive financial information from unsuspecting users. The RedWing malware-as-a-service (MaaS) packages have been found to masquerade as a legitimate Telegram rental service, making it incredibly difficult for victims to discern the malicious intent behind the app. … Read more

The GitHub Actions Attack Pattern Your CI Security Scanners Miss

The Hidden Dangers Lurking in Your GitHub CI Pipelines A recent revelation has exposed a worrying trend in software development: even when your Continuous Integration (CI) security scanners give you a clean bill of health, your pipeline might still be vulnerable to attack. Researchers at Novee Security have identified a class of weaknesses they call … Read more

Hidden backdoor in Tenda router firmware grants admin access

Hidden Backdoor in Tenda Router Firmware Grants Admin Access to Attackers A disturbing security vulnerability has been discovered in multiple versions of Tenda router firmware, potentially allowing malicious actors to gain full administrative access to affected devices. The issue, tracked as CVE-2026-11405, is caused by an undocumented authentication mechanism that can be exploited using a … Read more

Chinese hackers develop LONGLEASH malware to expand ORB network

Chinese Hackers Expand Sophisticated ORB Network Using New Malware A highly advanced and evolving threat actor group tracked as “UAT-7810” has been busy expanding their Operational Relay Box (ORB) network by compromising internet-facing networking devices, primarily unpatched Ruckus routers. This malicious infrastructure allows China-aligned advanced persistent threats (APTs), including UAT-5918, to proxy their network traffic … Read more

Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots

A Critical Flaw in Google Dialogflow CX Chatbots Exposes Sensitive Data Google’s Dialogflow CX, a popular platform for building conversational interfaces, has been hit with a critical vulnerability that could have allowed attackers to hijack chatbots and access sensitive user data. The flaw, discovered by security researchers at Google Cloud, is particularly alarming due to … Read more

RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service

A sophisticated Android malware campaign, dubbed RedWing MaaS, has been discovered masquerading as a Telegram rental service, targeting unsuspecting users and facilitating bank fraud on a massive scale. The malicious packages, sold through online forums, have been spreading rapidly across the globe, compromising mobile devices and enabling cybercriminals to drain bank accounts. RedWing MaaS is … Read more

The GitHub Actions Attack Pattern Your CI Security Scanners Miss

A Critical Vulnerability in GitHub Actions Exposes Thousands of Repositories to Attack A recent discovery by researchers at Novee Security has shed light on a critical vulnerability in GitHub Actions that can leave thousands of repositories exposed to attack. Dubbed “Cordyceps,” this weakness allows an attacker with a free GitHub account to induce both trusted … Read more

Spain arrests suspected member of pro-Russian hacktivist groups

Spanish authorities have made a significant arrest in their efforts to disrupt pro-Russian hacktivist groups. A man suspected of being an active member of CyberArmy of Russia Reborn (CARR) and Z-Pentest has been taken into custody by Spain’s National Police. These groups, while often referred to as “hacktivists,” have been linked to a series of … Read more

Hidden backdoor in Tenda router firmware grants admin access

A hidden authentication backdoor has been discovered in multiple versions of Tenda router firmware, potentially allowing attackers to gain administrator access to the device’s web management panel. The issue remains unfixed due to an inability to contact the Chinese manufacturer. The vulnerability, tracked as CVE-2026-11405 by the CERT Coordination Center (CERT/CC), lies within the ‘login()’ … Read more

Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data

GitHub users, take heed: a publicly disclosed issue could be putting private repository data at risk. A flaw in GitHub’s Agentic Workflows feature – designed to automate tasks and simplify development workflows – has been identified as vulnerable to exploitation by malicious actors. The bug, discovered through responsible disclosure, can trick the system into leaking … Read more