embedded
-
April 7, 2026
CUPS Vulnerabilities Could Allow Remote Attackers to Achieve Root-Level Code Execution
A team of AI-driven vulnerability hunting agents directed by security researcher Asim Viladi Oglu Manizada has discovered two critical security…
Read More » -
April 7, 2026
BPFDoor Variants Hide with Stateless C2 and ICMP Relay Tactics
Seven novel BPFDoor variants enhance Linux backdoor tradecraft, embedding implants deep within kernel space to evade detection in extensive telecom…
Read More » -
April 7, 2026
Fake Gemini npm Package Steals AI Tool Tokens
Malicious actors are exploiting a counterfeit Gemini-themed npm package to pilfer tokens and secrets from developers utilizing AI coding tools…
Read More » -
April 7, 2026
Threat Actors Exploit LogMeIn Resolve, ScreenConnect in Phishing Campaigns
Cybercriminals are exploiting legitimate remote monitoring and management (RMM) tools LogMeIn Resolve and ScreenConnect in a multi-stage phishing operation that…
Read More » -
April 6, 2026
36 Malicious Strapi npm Packages Deliver Redis RCE, Persistent C2 Malware
A coordinated supply chain attack has been uncovered involving 36 malicious npm packages masquerading as Strapi CMS plugins, delivering a…
Read More » -
April 3, 2026
Axios npm compromise traced to targeted social engineering attack
The recent compromise of the widely used Axios npm package has been confirmed as the result of a targeted social…
Read More » -
April 2, 2026
NoVoice on Google Play Exploits 22 Flaws to Hit Millions of Android Users
A sophisticated Android rootkit campaign named Operation NoVoice infiltrated over 50 applications on Google Play, exploiting 22 known vulnerabilities to…
Read More » -
April 2, 2026
FBI Warns Chinese Mobile Apps Could Expose User Data to Cyberattacks
The Federal Bureau of Investigation (FBI) has issued a public warning about potential data security risks associated with foreign-developed mobile…
Read More » -
April 1, 2026
Windows 11 Update Fixes Critical Installation Loop Problem
Microsoft has rolled out an urgent, out-of-band update to fix a frustrating installation glitch plaguing Windows 11 users. On March…
Read More » -
March 31, 2026
PNG Vulnerabilities Allow Attackers to Trigger Crashes and Leak Sensitive Data
Security researchers have disclosed two high-severity vulnerabilities in libpng, the widely deployed reference library used for processing Portable Network Graphics…
Read More » -
March 31, 2026
Windows Tools Abused to Kill AV Ahead of Ransomware Attacks
Hackers are increasingly turning legitimate Windows administration tools into stealthy weapons to disable antivirus and EDR before launching ransomware, making…
Read More » -
March 30, 2026
Telnyx Python SDK Backdoored on PyPI to Steal Cloud Credentials
The popular Telnyx Python SDK on PyPI has been used in a multi-stage credential-stealing operation targeting cloud infrastructure, Kubernetes clusters,…
Read More » -
March 27, 2026
Red Hat Warns of Malware Embedded in Popular Linux Tool, Opening Doors for Unauthorized Access
Red Hat has issued an urgent security alert concerning a highly sophisticated supply chain attack that compromised recent versions of…
Read More » -
March 27, 2026
Hackers Deploy USB Malware, RATs, and Stealers in Southeast Asian Government Attacks
A multi-cluster cyberespionage operation in which attackers used USB-propagated malware, multiple RATs, loaders, and a custom stealer to target a…
Read More » -
March 27, 2026
CISA Adds Critical Aquasecurity Trivy Scanner Vulnerability to KEV Catalog
CISA has urgently added a critical flaw affecting Aquasecurity’s Trivy scanner to its Known Exploited Vulnerabilities (KEV) catalog under tracking…
Read More » -
March 26, 2026
New ClickFix Attack Exploits Windows Run Dialog and macOS Terminal to Deploy Malware
Threat actors are standardizing a powerful ClickFix-based attack that abuses the Windows Run dialog box and macOS Terminal to deliver…
Read More » -
March 25, 2026
Obfuscated VBS and PNG Loaders Power New Open Directory Malware Campaign with RAT Payloads
A sophisticated, multi-stage delivery mechanism utilizing obfuscated Visual Basic Script (VBS) files, fileless PowerShell loaders, and payloads concealed within PNG…
Read More » -
March 25, 2026
China-Backed Hackers Target Southeast Asian Military Systems in Ongoing Spy Campaign
China-linked threat actors have been identified targeting Southeast Asian military networks in a long-running cyber espionage campaign focused on intelligence…
Read More » -
March 25, 2026
Critical Magento Vulnerability Actively Exploited Across Thousands of Stores
A critical vulnerability called “PolyShell” is being actively exploited on Magento and Adobe Commerce platforms, putting thousands of online stores…
Read More » -
March 21, 2026
Trivy Vulnerability Scanner Compromised to Inject Malicious Scripts That Steal Credentials
Ahighly sophisticated supply chain attack has successfully compromised the official Trivy GitHub Actions repository, severely impacting continuous integration environments. Discovered…
Read More »