Checkmarx supply chain attack impacts Bitwarden npm distribution path

2 months ago

Bitwarden CLI was hit by the Checkmarx supply chain attack. Version 2026.4.0 shipped malicious code in bw1.js via a compromised…

China-linked threat actors use consumer device botnets to evade detection, warn UK and partners

2 months ago

UK National Cyber Security Centre (NCSC) warns China-linked hackers use hijacked devices as proxy networks to hide activity and evade…

Luxury cosmetics giant Rituals discloses data breach impacting member personal details

2 months ago

Rituals disclosed a breach where hackers accessed and downloaded some My Rituals members’ data, including names and addresses. Luxury cosmetics…

iOS Flaw Let Deleted Notifications Linger, Apple Issues Fix

2 months ago

Apple fixed an iOS flaw that kept deleted notifications on devices, allowing recovery of messages, including from apps like Signal.…

RAMP Uncovered: Anatomy of Russia’s Ransomware Marketplace

2 months ago

Leaked data from RAMP reveals Russia’s ransomware ecosystem, analyzing 1,732 threads, 7,707 users, and 340,000 IP records from the forum.…

U.S. CISA adds a flaw in Microsoft Defender to its Known Exploited Vulnerabilities catalog

2 months ago

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in Microsoft Defender to its Known Exploited Vulnerabilities catalog…

Microsoft Graph API misused by new GoGra Linux malware for hidden communication<gwmw style="display:none;"></gwmw>

2 months ago

A new GoGra Linux malware uses Microsoft Graph API and an Outlook inbox to deliver payloads, making it stealthy and…

DDoS wave continues as Mastodon hit after Bluesky incident

2 months ago

Mastodon suffered a major DDoS attack shortly after a similar incident hit Bluesky. The outage was significant but resolved within…

Mirai Botnet exploits CVE-2025-29635 to target legacy D-Link routers

2 months ago

Mirai botnet is targeting old D-Link routers using CVE-2025-29635, a command injection flaw exploitable via crafted POST requests after public…

Microsoft out-of-band updates fixed critical ASP.NET Core privilege escalation flaw

2 months ago

Microsoft fixed critical ASP.NET Core vulnerability, tracked as CVE-2026-40372 (CVSS score of 9.1), that lets attackers escalate privileges. Microsoft released…

This website uses cookies.