embedded
-
April 17, 2026
Critical Flaw in Anthropic’s MCP Protocol Exposes Systems to Remote Command Execution
OX Security researchers have uncovered a critical, systemic vulnerability embedded directly in the architecture of Anthropic’s Model Context Protocol (MCP),…
Read More » -
April 17, 2026
Resurgent Payouts King Ransomware Group: BlackBasta Legacy Meets Advanced Evasion Tactics
A sophisticated new ransomware operation called Payouts King is rapidly emerging, leveraging proven social-engineering tactics from the now-defunct BlackBasta collective…
Read More » -
April 16, 2026
Proton VPN Impersonation Exposes NWHStealer: A Sophisticated Malware Campaign
Multiple ongoing malware campaigns are deploying the sophisticated information-stealing trojan, designated as NWHStealer, via deceptive VPN installer packages, gaming modifications,…
Read More » -
April 16, 2026
Webhook Exploitation at Scale: n8n Infrastructure Abuse Surges 686% in Phishing Campaigns
A sophisticated threat campaign has emerged targeting agentic AI-driven workflow automation platforms, particularly n8n, to facilitate the delivery of malicious…
Read More » -
April 16, 2026
Exposed: Over 1,250 Command and Control Servers Active in Russian Hosting Providers
New research reveals a startling reality within Russian networks: over 1,250 active command-and-control (C2) servers have been operating across 165…
Read More » -
April 16, 2026
Pushpaganda: AI-Scams Hijack Google Discovery Feed to Spread Malicious Notifications
A large-scale cyber operation called Pushpaganda is exploiting Google’s Discovery feed to distribute malicious notifications and scams through AI-generated content.…
Read More » -
April 15, 2026
Agentic LLM Browsers: Productivity Gains Intensify Security Battlefield
AI-powered browsers are quietly rewriting the rules of web security — and not in our favor. By embedding large language…
Read More » -
April 15, 2026
JanaWare: The Under-the-Radar Ransomware That Has Been Quietly Targeting Turkey Since 2020
A stealthy ransomware operation known as JanaWare has been silently preying on Turkish internet users for at least five years…
Read More » -
April 14, 2026
Exposed Botnet Panel Reveals Live Twitter/X Credential-Stuffing Operation With No Authentication
A fully operational credential-stuffing botnet targeting Twitter/X accounts has been discovered running entirely without authentication, leaving its command-and-control infrastructure, worker…
Read More » -
April 14, 2026
New Malware Campaign Abuses Obsidian Vaults to Target Crypto and Finance Professionals
A sophisticated new malware campaign is exploiting the popular note-taking app Obsidian to deliver a powerful remote access trojan called…
Read More » -
April 13, 2026
MSBuild.exe: The Stealthy Weapon in Fileless Attacks
Cyber attackers are increasingly leveraging Living Off the Land Binaries (LOLBins) to bypass modern security defenses. By weaponizing legitimate system…
Read More » -
April 13, 2026
VIPERTUNNEL: Python Malware Unmasked Through Fake DLLs & Multi-Stage Obfuscation
Hackers are leveraging a sophisticated Python backdoor called VIPERTUNNEL to establish covert command-and-control channels in victim networks. The attack chain…
Read More » -
April 10, 2026
Hackers Exploit GitHub Copilot Flaw to Exfiltrate Sensitive Data
A high-severity flaw in GitHub Copilot Chat recently allowed attackers to silently steal sensitive data like API keys and private…
Read More » -
April 9, 2026
ClickFix Campaign Abuses macOS Script Editor to Deploy Atomic Stealer
A refreshed ClickFix campaign that swaps macOS Terminal for Script Editor to deliver an Atomic Stealer payload to unsuspecting Mac users quietly.…
Read More » -
April 9, 2026
STX RAT Hides Remote Desktop, Steals Data to Dodge Detection
A stealthy new remote access trojan, dubbed STX RAT, that blends hidden remote desktop control with powerful infostealer capabilities while…
Read More » -
April 9, 2026
Fake Security Tool Spreads LucidRook in Taiwan Cyberattacks
Hackers are using fake security tools and cleverly crafted phishing emails to secretly deploy a new malware family, LucidRook, against…
Read More » -
April 8, 2026
Remus Infostealer Debuts With Stealthy New Credential-Theft Tactics
Hackers are rolling out a new 64‑bit infostealer dubbed Remus. The code strongly suggests it is a direct successor to the…
Read More » -
April 8, 2026
Claude Code Leak Exploited to Spread Vidar and GhostSocks via GitHub Releases
Hackers exploited the exposed Claude Code source leak as a channel for malware distribution, using GitHub Releases to deliver the…
Read More » -
April 8, 2026
ComfyUI Servers Hijacked for Cryptomining, Proxy Botnet Ops
Hackers are aggressively hijacking Internet-exposed ComfyUI servers and converting them into high‑value cryptomining rigs and proxy botnet nodes, abusing weakly…
Read More » -
April 8, 2026
Claude Identifies Critical 13-Year-Old RCE Vulnerability in Apache ActiveMQ
An AI assistant recently uncovered a critical remote code execution (RCE) vulnerability in Apache ActiveMQ Classic that went unnoticed for…
Read More »