Category: Uncategorized
-

LeakBase Admin Arrested in Russia Over Massive Stolen Credential Marketplace [email protected] (The Hacker News)
The alleged administrator of the LeakBase cybercrime forum has been arrested by Russian law enforcement authorities, state media reported Thursday. According to TASS and MVD Media, a news website linked to the Russian Interior Ministry, the suspect is a resident of the city of Taganrog. The suspect is said to have been detained for creating…
-

GlassWorm Malware Uses Solana Dead Drops to Deliver RAT and Steal Browser, Crypto Data [email protected] (The Hacker News)
Cybersecurity researchers have flagged a new evolution of the GlassWorm campaign that delivers a multi-stage framework capable of comprehensive data theft and installing a remote access trojan (RAT), which deploys an information-stealing Google Chrome extension masquerading as an offline version of Google Docs. “It logs keystrokes, dumps cookies and session tokens, captures screenshots, andRead More
-

The Kill Chain Is Obsolete When Your AI Agent Is the Threat [email protected] (The Hacker News)
In September 2025, Anthropic disclosed that a state-sponsored threat actor used an AI coding agent to execute an autonomous cyber espionage campaign against 30 global targets. The AI handled 80-90% of tactical operations on its own, performing reconnaissance, writing exploit code, and attempting lateral movement at machine speed. This incident is worrying, but there’s a…
-

Russian Hacker Sentenced to 2 Years for TA551 Botnet-Driven Ransomware Attacks [email protected] (The Hacker News)
The U.S. Department of Justice (DoJ) said a Russian national has been sentenced to two years in prison for managing a botnet that was used to launch ransomware attacks against U.S. companies. Ilya Angelov, 40, of Tolyatti, Russia, was also fined $100,000. Angelov, who went by the online aliases “milan” and “okart,” is said to…
-

Device Code Phishing Hits 340+ Microsoft 365 Orgs Across Five Countries via OAuth Abuse [email protected] (The Hacker News)
Cybersecurity researchers are calling attention to an active device code phishing campaign that’s targeting Microsoft 365 identities across more than 340 organizations in the U.S., Canada, Australia, New Zealand, and Germany. The activity, per Huntress, was first spotted on February 19, 2026, with subsequent cases appearing at an accelerated pace since then. Notably, the campaign…
-

FCC Bans New Foreign-Made Routers Over Supply Chain and Cyber Risk Concerns [email protected] (The Hacker News)
The U.S. Federal Communications Commission (FCC) said on Monday that it was banning the import of new, foreign-made consumer routers, citing “unacceptable” risks to cyber and national security. The action was designed to safeguard Americans and the underlying communications networks the country relies on, FCC Chairman Brendan Carr said in a post on X. The…
-

TeamPCP Backdoors LiteLLM Versions 1.82.7–1.82.8 Likely via Trivy CI/CD Compromise [email protected] (The Hacker News)
TeamPCP, the threat actor behind the recent compromises of Trivy and KICS, has now compromised a popular Python package named litellm, pushing two malicious versions containing a credential harvester, a Kubernetes lateral movement toolkit, and a persistent backdoor. Multiple security vendors, including Endor Labs and JFrog, revealed that litellm versions 1.82.7 and 1.82.8 were published…
-

Tax Search Ads Deliver ScreenConnect Malware Using Huawei Driver to Disable EDR [email protected] (The Hacker News)
A large-scale malvertising campaign active since January 2026 has been observed targeting U.S.-based individuals searching for tax-related documents to serve rogue installers for ConnectWise ScreenConnect that drop a tool named HwAudKiller to blind security programs using the bring your own vulnerable driver (BYOVD) technique. “The campaign abuses Google Ads to serve rogue ScreenConnect (Read More
-

Hackers Use Fake Resumes to Steal Enterprise Credentials and Deploy Crypto Miner [email protected] (The Hacker News)
An ongoing phishing campaign is targeting French-speaking corporate environments with fake resumes that lead to the deployment of cryptocurrency miners and information stealers. “The campaign uses highly obfuscated VBScript files disguised as resume/CV documents, delivered through phishing emails,” Securonix researchers Shikha Sangwan, Akshay Gaikwad, and Aaron Beardslee said in a report sharedRead More
-
10 enterprise secure remote access best practices
Remote access is a critical necessity in today’s work-from-anywhere environment. It’s also incredibly risky. But there are ways to protect assets and combat potential attacks.Read More
