Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak

Coca-Cola’s Fairlife Dairy Subsidiary Hit by Anubis Ransomware, Threatened with Data Leak The Anubis ransomware gang has claimed responsibility for a cyberattack on Coca-Cola’s Fairlife dairy subsidiary, threatening to publish allegedly stolen corporate data unless the company pays a ransom. This brazen move highlights the growing threat of ransomware gangs using data theft as leverage … Read more

FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware

A Sophisticated Malware Campaign Exploits GitHub Repositories, Infiltrating Public AI Registries and Catalogs In a brazen and highly sophisticated operation, attackers have created over 7,600 malicious GitHub repositories to distribute SmartLoader and StealC malware. Dubbed the “FakeGit” campaign, this large-scale effort has accumulated more than 14 million downloads from public download counters on the platform. … Read more

Police dismantle Kratos phishing platform, arrest developer

Global Phishing Platform Dismantled, Developer Arrested in Multi-Agency Operation A major blow has been dealt to the world of cybercrime as authorities in Germany and the US have dismantled a vast phishing platform known as Kratos, shutting down its central infrastructure and arresting its developer. The operation, led by Frankfurt’s Prosecutor General Office (ZIT) and … Read more

Closing the Identity Gaps in Critical Infrastructure Security

Critical Infrastructure Under Siege: How State-Backed Actors Are Exploiting Identity Gaps The 2021 Colonial Pipeline ransomware attack was a stark reminder of how quickly a compromised account can turn into a national crisis. The attackers exploited an inactive VPN account without multi-factor authentication, disrupting fuel supply across the U.S. East Coast and highlighting the vulnerability … Read more

Critical SharePoint RCE flaw exploited to steal machine keys

A critical vulnerability in Microsoft SharePoint is being actively exploited by hackers to steal machine keys and maintain access even after affected servers are patched. The flaw, known as CVE-2026-50522, allows remote attackers to execute code on vulnerable systems without authentication. This can be done by delivering a malicious payload through a specially crafted security … Read more

FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware

Malicious GitHub Repositories Push SmartLoader and StealC Malware to Millions of Developers A massive operation, dubbed “FakeGit,” has been pushing malware through 7,600 malicious GitHub repositories that have accumulated over 14 million downloads. The campaign is using a technique called “agentbaiting” to lure in AI agents and developers, making it easier for the attackers to … Read more

Police dismantle Kratos phishing platform, arrest developer

A major blow has been struck against global cybercrime operations with the dismantling of Kratos, a sophisticated phishing-as-a-service (PhaaS) platform. Authorities in Germany and the United States have taken down the central infrastructure of the platform, seizing over 200 servers and rendering it inoperable. The developer behind the platform was also arrested in Indonesia. Kratos … Read more

Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs

Apple’s latest software update has patched a vulnerability that exposed users’ real email addresses when they used the company’s “Hide My Email” feature. This flaw allowed hackers to reveal sensitive information by exploiting a weakness in Apple’s email masking system, putting millions of users at risk. The issue was discovered in Apple’s Mail app, which … Read more

Critical SharePoint RCE flaw exploited to steal machine keys

A critical vulnerability in Microsoft SharePoint is being actively exploited by hackers to steal machine keys and maintain long-term access to compromised systems. This flaw, known as CVE-2026-50522, was addressed in July’s security updates from Microsoft, but it appears that attackers have already begun leveraging it against vulnerable on-premise deployments. The vulnerability itself is a … Read more