Hackers abuse ViPNet software to target Russian govt agencies

A sophisticated threat actor has been exploiting a vulnerability in the update mechanism of ViPNet software to target government agencies and other organizations in Russia. Dubbed HelloNet, this campaign has been active since at least May and has already had a significant impact on various sectors, including government, energy, transport, education, and logistics. ViPNet is … Read more

Scans for Hikvision Intelligent Security API, (Sun, Jul 19th)

Hikvision Cameras Exposed by Recon Scans for New API Feature Hikvision cameras have long been a target for hackers due to their vulnerabilities and exposure to internet-wide scans. Now, a new threat has emerged in the form of reconnaissance scans targeting the company’s Intelligent Security API (ISAPI), which was introduced several years ago but has … Read more

Hackers abuse ViPNet software to target Russian govt agencies

A sophisticated threat actor has been exploiting the update mechanism of ViPNet software to target Russian government agencies and organizations across various sectors. The campaign, dubbed HelloNet, has been active since at least May 2026 and uses a malicious payload that acts as a proxy and loader for additional malware. ViPNet is a suite of … Read more

SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access

Cybersecurity firm SonicWall’s Secure Mobile Access (SMA) platform suffered a devastating blow this week, with hackers exploiting two previously unknown vulnerabilities before they were even publicly disclosed. The attack allowed unauthorized access to sensitive systems, highlighting the urgent need for swift patching and robust security measures. The affected vulnerability, a zero-day exploit in SMA version … Read more

UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware

Ukrainian Devices Infected with Malware via ClickFix CAPTCHAs In a disturbing example of the dark side of artificial intelligence, Ukrainian users have been targeted by a sophisticated malware campaign that exploits ClickFix CAPTCHAs. These seemingly innocuous images are actually being used to deliver malicious payloads, leaving thousands of devices compromised. The malware in question is … Read more

SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access

A pair of zero-day vulnerabilities in SonicWall’s SMA (Secure Mobile Access) platform were exploited by attackers before a patch was made available, granting them root access and compromising sensitive data. The exploitation occurred despite the company’s claims that no customers had been affected prior to disclosure. SonicWall’s SMA is a popular solution for remote access … Read more

UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware

A New Malware Threat Emerges, Targeting Ukrainian Devices with Sophisticated CAPTCHA-based Attacks Cybersecurity researchers have uncovered a sophisticated malware attack targeting devices in Ukraine, leveraging a unique approach that exploits the ClickFix CAPTCHA system. This threat highlights the evolving nature of cyberattacks and underscores the importance of vigilance in protecting against emerging vulnerabilities. The UAC-0145 … Read more

WordPress Core “wp2shell” RCE flaws get public exploits, patch now

WordPress Core “wp2shell” RCE Flaws Exposed: Patch Now to Avoid Catastrophic Consequences A devastating pair of vulnerabilities, dubbed “wp2shell,” has been discovered in WordPress Core, allowing attackers to execute malicious code on affected sites without requiring administrator credentials. The critical flaws, affecting over 500 million websites, have already spawned public proof-of-concept exploits, making it imperative … Read more

Update now: 7-Zip fixes RCE flaw exploitable with malicious archives

A critical vulnerability has been discovered in 7-Zip, one of the most widely used archive utilities on Windows, allowing attackers to execute malicious code by convincing users to open specially crafted compressed files. The vulnerability, disclosed by researcher Landon Peng, affects 7-Zip’s processing of XZ-compressed data and can be exploited through a remote code execution … Read more