FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware

Malicious GitHub Repositories Push SmartLoader and StealC Malware to Millions of Developers A massive operation, dubbed “FakeGit,” has been pushing malware through 7,600 malicious GitHub repositories that have accumulated over 14 million downloads. The campaign is using a technique called “agentbaiting” to lure in AI agents and developers, making it easier for the attackers to … Read more

Police dismantle Kratos phishing platform, arrest developer

A major blow has been struck against global cybercrime operations with the dismantling of Kratos, a sophisticated phishing-as-a-service (PhaaS) platform. Authorities in Germany and the United States have taken down the central infrastructure of the platform, seizing over 200 servers and rendering it inoperable. The developer behind the platform was also arrested in Indonesia. Kratos … Read more

Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs

Apple’s latest software update has patched a vulnerability that exposed users’ real email addresses when they used the company’s “Hide My Email” feature. This flaw allowed hackers to reveal sensitive information by exploiting a weakness in Apple’s email masking system, putting millions of users at risk. The issue was discovered in Apple’s Mail app, which … Read more

Critical SharePoint RCE flaw exploited to steal machine keys

A critical vulnerability in Microsoft SharePoint is being actively exploited by hackers to steal machine keys and maintain long-term access to compromised systems. This flaw, known as CVE-2026-50522, was addressed in July’s security updates from Microsoft, but it appears that attackers have already begun leveraging it against vulnerable on-premise deployments. The vulnerability itself is a … Read more

Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities

Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities Google has unveiled an updated version of its Gemini platform, a cutting-edge AI-powered tool designed to identify and remediate software vulnerabilities before they can be exploited by hackers. The latest iteration, Gemini 3.5 Flash Cyber AI, marks a significant milestone in the … Read more

AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code

A Critical Flaw in AWS Kiro Exposes Organizations to Unchecked Code Execution Amazon Web Services (AWS) has disclosed a critical flaw in its cloud-based service, Kiro, that enables malicious actors to rewrite the application’s configuration and execute arbitrary code. The vulnerability, which affects all versions of Kiro up to 2026-07-15, is particularly concerning due to … Read more

Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs

Apple’s Hide My Email feature, designed to protect users’ email addresses from spammers and unwanted solicitations, was found to have a critical vulnerability that exposed real addresses in Mail logs. This flaw allowed malicious actors to gather sensitive information about Apple users, including their true identities. The issue was identified by a security researcher who … Read more

Critical wp2shell WordPress flaws exploited to install webshells

Critical wp2shell Vulnerabilities Allow Hackers to Install Webshells and Malicious Plugins A critical vulnerability suite, known as “wp2shell,” has been exploited by hackers to deploy persistent webshells and install malicious plugins on WordPress installations. The vulnerability, which affects WordPress Core versions prior to 7.0.2, 6.9.5, and 6.8.6, allows remote attackers to execute code without authentication, … Read more

Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak

Anubis Ransomware Gang Claims Responsibility for Coca-Cola Fairlife Attack, Threatens Data Leak In a high-stakes cyberattack, the Anubis ransomware gang has claimed responsibility for breaching Coca-Cola’s Fairlife dairy subsidiary, leaving behind a trail of encrypted files and allegedly stolen corporate data. The attackers have threatened to publish this sensitive information unless the company pays a … Read more