“Cyber warfare is as much about psychological strategy as technical prowess.”
― James Scott
-
The breakup: Why CISOs are decoupling data from their SIEMs
Breaking up is hard to do — but some CISOs find that decoupling SIEMs from security log data feeds is worth it. Learn about the benefits and challenges.Read More
-

cPanel, WHM Release Fixes for Three New Vulnerabilities — Patch Now [email protected] (The Hacker News)
cPanel has released updates to address three vulnerabilities in cPanel and Web Host Manager (WHM) that could be exploited to achieve privilege escalation, code execution, and denial-of-service. The list of vulnerabilities is as follows – CVE-2026-29201 (CVSS score: 4.3) – An insufficient input validation of the feature file name in the “feature::LOADFEATUREFILE” adminbin call that…
-

TCLBANKER Banking Trojan Targets Financial Platforms via WhatsApp and Outlook Worms [email protected] (The Hacker News)
Threat hunters have flagged a previously undocumented Brazilian banking trojan dubbed TCLBANKER that’s capable of targeting 59 banking, fintech, and cryptocurrency platforms. The activity is being tracked by Elastic Security Labs under the moniker REF3076. The malware family is assessed to be a major update of the Maverick, which is known to leverage a worm…
-

Fake Call History Apps Stole Payments From Users After 7.3 Million Play Store Downloads [email protected] (The Hacker News)
Cybersecurity researchers have discovered fraudulent apps on the official Google Play Store for Android that falsely claimed to offer access to call histories for any phone number, only to trick users into joining a subscription that provided fake data and incurred financial loss. The 28 apps have collectively racked up more than 7.3 million downloads,…
-
News brief: Security worries and warnings as AI use expands
Check out the latest security news from TechTarget SearchSecurity’s sister sites, Cybersecurity Dive and Dark Reading.Read More
-

Quasar Linux RAT Steals Developer Credentials for Software Supply Chain Compromise [email protected] (The Hacker News)
A previously undocumented Linux implant codenamed Quasar Linux RAT (QLNX) is targeting developers’ systems to establish a silent foothold as well as facilitate a broad range of post-compromise functionality, such as credential harvesting, keylogging, file manipulation, clipboard monitoring, and network tunneling. “QLNX targets developers and DevOps credentials across the software supply chain,”Read More
-

One Missed Threat Per Week: What 25M Alerts Reveal About Low-Severity Risk [email protected] (The Hacker News)
The dark secret of enterprise security operations is that defenders have quietly institutionalized the practice of not looking. This is not just anecdotal, but rather backed by a recent report investigating more than 25 million security alerts, including informational and low-severity, across live enterprise environments. The dataset behind these findings includes 10 million monitoredRead More
-

New Linux PamDOORa Backdoor Uses PAM Modules to Steal SSH Credentials [email protected] (The Hacker News)
Cybersecurity researchers have disclosed details of a new Linux backdoor named PamDOORa that’s being advertised on the Rehub Russian cybercrime forum for $1,600 by a threat actor called “darkworm.” The backdoor is designed as a Pluggable Authentication Module (PAM)-based post-exploitation toolkit that enables persistent SSH access by means of a magic password and specific TCP…
-

Linux Kernel Dirty Frag LPE Exploit Enables Root Access Across Major Distributions [email protected] (The Hacker News)
Details have emerged about a new, unpatched local privilege escalation (LPE) vulnerability impacting the Linux kernel. Dubbed Dirty Frag, it has been described as a successor to Copy Fail (CVE-2026-31431, CVSS score: 7.8), a recently disclosed LPE flaw impacting the Linux kernel that has since come under active exploitation in the wild. The vulnerability was…
-

Ivanti EPMM CVE-2026-6973 RCE Under Active Exploitation Grants Admin-Level Access [email protected] (The Hacker News)
Ivanti is warning that a new security flaw impacting Endpoint Manager Mobile (EPMM) has been explored in limited attacks in the wild. The high-severity vulnerability, CVE-2026-6973 (CVSS score: 7.2), is a case of improper input validation affecting EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1. It allows “a remotely authenticated user with administrative access to achieve…
“Security used to be an inconvenience sometimes, but now it’s a necessity all the time.”
― Martina Navratilova
