tokens
-
Carnival Corporation Data Breach: 5.99M PII Records Exposed, Attack Vector Remains Unconfirmed
Carnival Corporation has confirmed a massive data security incident that has compromised the personally identifiable information (PII) of approximately 5.99…
Read More » -
codexui-android Supply Chain Attack: Stealing AI Tokens Through npm and Android
A sophisticated supply chain attack has been identified targeting the AI development ecosystem, leveraging a deceptive developer tool named codexui-android…
Read More » -
Immutable Malice: How the ClearFake Campaign Leverages BSC Smart Contracts for Resilient C2
A recent analysis of the ClearFake campaign reveals a sophisticated evolution in command-and-control (C2) architecture: the use of BNB Smart…
Read More » -
Deep Dive: Analyzing the VIP Keylogger Infection Chain and Evasion Tactics
Threat actors are currently executing sophisticated phishing campaigns to deploy the VIP Keylogger, a highly evasive infostealer. By leveraging multi-layered…
Read More » -
Exploiting Trust: How CVE-2026-35616 Turns FortiClient EMS into a Malware Distribution Engine
Security teams are currently navigating a sophisticated new threat landscape where the very tools meant to secure an organization are…
Read More » -
Deep Dive: Analyzing Quasar Linux (QLNX), the Stealthy Supply-Chain Trojan
A sophisticated new threat actor has emerged in the Linux ecosystem: Quasar Linux (QLNX). Despite its name, this is not…
Read More » -
Analyzing CVE-2026-47783: Timing Side-Channel Vulnerabilities in Memcached SASL Authentication
Security researchers have recently identified a critical timing side-channel vulnerability within Memcached, a high-performance, distributed memory caching system. The flaw,…
Read More » -
Critical Memory Safety Vulnerabilities Discovered in 7-Zip: From Data Leaks to Remote Code Execution
A series of sophisticated memory safety vulnerabilities has been identified in 7-Zip version 26.00 and earlier, creating a significant security…
Read More » -
SEO Poisoning: Threat Actors Target AI Developers via Malicious CLI Impersonation
A sophisticated SEO poisoning campaign is currently targeting the developer community, leveraging the rapid adoption of AI-driven development tools to…
Read More » -
Analyzing “TrapDoor”: A Sophisticated Multi-Ecosystem Supply Chain Campaign
A highly coordinated software supply chain attack is currently targeting the developer ecosystem, specifically aimed at compromising high-value credentials within…
Read More » -
FBI Alert: Kali365 PhaaS Campaign Targets Microsoft 365 MFA
The Federal Bureau of Investigation (FBI) has officially released Public Service Announcement Alert I-052126-PSA, sounding the alarm on a sophisticated…
Read More » -
Evolving Initial Access Tactics: Analyzing Russian State-Sponsored Multi-Vector Campaigns
Russian state-sponsored actors and their aligned affiliates are shifting away from singular exploit methods toward a sophisticated, multi-vector approach to…
Read More » -
Critical Security Alert: CISA Adds Langflow Origin Validation Vulnerability (CVE-2025-34291) to KEV Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has officially added a critical vulnerability affecting Langflow—tracked as CVE-2025-34291—to its Known…
Read More »