“Cyber warfare is as much about psychological strategy as technical prowess.”
― James Scott
-

Weekly Recap: Outlook Add-Ins Hijack, 0-Day Patches, Wormable Botnet & AI Malware [email protected] (The Hacker News)
This week’s recap shows how small gaps are turning into big entry points. Not always through new exploits, often through tools, add-ons, cloud setups, or workflows that people already trust and rarely question. Another signal: attackers are mixing old and new methods. Legacy botnet tactics, modern cloud abuse, AI assistance, and supply-chain exposure are being…
-

Safe and Inclusive E‑Society: How Lithuania Is Bracing for AI‑Driven Cyber Fraud [email protected] (The Hacker News)
Presentation of the KTU Consortium Mission ‘A Safe and Inclusive Digital Society’ at the Innovation Agency event ‘Innovation Breakfast: How Mission-Oriented Science and Innovation Programmes Will Address Societal Challenges’. Technologies are evolving fast, reshaping economies, governance, and daily life. Yet, as innovation accelerates, so do digital risks. Technological change is no longerRead More
-

New ZeroDayRAT Mobile Spyware Enables Real-Time Surveillance and Data Theft [email protected] (The Hacker News)
Cybersecurity researchers have disclosed details of a new mobile spyware platform dubbed ZeroDayRAT that’s being advertised on Telegram as a way to grab sensitive data and facilitate real-time surveillance on Android and iOS devices. “The developer runs dedicated channels for sales, customer support, and regular updates, giving buyers a single point of access to a…
-

New Chrome Zero-Day (CVE-2026-2441) Under Active Attack — Patch Released [email protected] (The Hacker News)
Google on Friday released security updates for its Chrome browser to address a security flaw that it said has been exploited in the wild. The high-severity vulnerability, tracked as CVE-2026-2441 (CVSS score: 8.8), has been described as a use-after-free bug in CSS. Security researcher Shaheen Fazim has been credited with discovering and reporting the shortcoming…
-

Microsoft Discloses DNS-Based ClickFix Attack Using Nslookup for Malware Staging [email protected] (The Hacker News)
Microsoft has disclosed details of a new version of the ClickFix social engineering tactic in which the attackers trick unsuspecting users into running commands that carry out a Domain Name System (DNS) lookup to retrieve the next-stage payload. Specifically, the attack relies on using the “nslookup” (short for nameserver lookup) command to execute a custom…
-

Google Ties Suspected Russian Actor to CANFAIL Malware Attacks on Ukrainian Orgs [email protected] (The Hacker News)
A previously undocumented threat actor has been attributed to attacks targeting Ukrainian organizations with malware known as CANFAIL. Google Threat Intelligence Group (GTIG) described the hack group as possibly affiliated with Russian intelligence services. The threat actor is assessed to have targeted defense, military, government, and energy organizations within the Ukrainian regional andRead More
-

Google Links China, Iran, Russia, North Korea to Coordinated Defense Sector Cyber Operations [email protected] (The Hacker News)
Several state-sponsored actors, hacktivist entities, and criminal groups from China, Iran, North Korea, and Russia have trained their sights on the defense industrial base (DIB) sector, according to findings from Google Threat Intelligence Group (GTIG). The tech giant’s threat intelligence division said the adversarial targeting of the sector is centered around four key themes: striking…
-

UAT-9921 Deploys VoidLink Malware to Target Technology and Financial Sectors [email protected] (The Hacker News)
A previously unknown threat actor tracked as UAT-9921 has been observed leveraging a new modular framework called VoidLink in its campaigns targeting the technology and financial services sectors, according to findings from Cisco Talos. “This threat actor seems to have been active since 2019, although they have not necessarily used VoidLink over the duration of…
-
CISO’s guide: How to prevent business email compromise
Business email compromise feeds on professional email norms — and exploits emotions such as fear or urgency. Learn what BEC is, how it works and how to prevent it.Read More
-
News brief: 6 Microsoft zero days and a warning from CISA
Check out the latest security news from the Informa TechTarget team.Read More
“Security used to be an inconvenience sometimes, but now it’s a necessity all the time.”
― Martina Navratilova
