Cybersecurity

Critical Arista VeloCloud Flaw Under Active Attack, Patch Now

A maximum-severity command injection flaw (CVE-2026-16812, CVSS 10.0) in on-premises Arista VeloCloud Orchestrator (VCO) is under active exploitation.CISA has added the vulnerability to its...

Dysphoria botnet uses blockchain to evade takedown after police raid

The Dysphoria IoT botnet, tracked by CNCERT and XLab, now uses Ethereum Name Service (ENS) and Solana Name Service (SNS) for resilient command-and-control, making...

n8n patches high-severity sandbox escape allowing OS command execution

n8n fixed a high-severity sandbox escape (CVSS 8.7) in versions 2.31.5 and 2.32.1 that could allow authenticated workflow editors to execute OS commands on...

East Asia hackers target Middle East govts with new Telegram malware

A previously undocumented East Asian threat actor is targeting Middle East government agencies with three new malware families: TELESHIM, MIXEDKEY, and BINDCLOAK.The TELESHIM backdoor...

SourTrade Malware Built in Browser Using Bun Runtime

SourTrade malvertising campaign targets cryptocurrency investors by assembling malware inside the victim's browser using a legitimate Bun runtime.It operates since late 2024, impersonating TradingView,...

Critical Fastjson flaw lets attackers hijack Spring Boot apps

A critical remote code execution vulnerability (CVE-2026-16723, CVSS 9.0) affects Alibaba's Fastjson library versions 1.2.68 through 1.2.83 when used in Spring Boot applications.Security firms...

BlueNoroff uses typosquatted Zoom domains in phishing

North Korean threat actor BlueNoroff is running ClickFix-style campaigns using typosquatted Zoom and Microsoft Teams domains.The group operates an active phishing kit designed to...

Claude Cowork bug lets AI break sandbox, access Mac files

Researchers at Accomplish AI discovered a sandbox escape vulnerability in Anthropic's Claude Cowork, affecting approximately 500,000 macOS users.The flaw, named SharedRoot, allowed an agent...

Latest news

TASK#STOMP Campaign Uses PowerShell Backdoor to Steal Data

Security researchers have uncovered a new campaign dubbed TASK#STOMP that deploys a PowerShell backdoor on compromised systems.The malware...

Bitmine 98% to 5% ETH goal after $74M buy

Bitmine bought 27,562 ETH, bringing its total holdings to 5,983,940 ETH ($16.1 billion), or 4.9% of the total supply.Chairman...

Einride, Nvidia Partner for Next-Gen Autonomous Trucks

Einride will build its next-gen autonomous system on NVIDIA’s Drive Hyperion platform.The company expects 80% of its projected 1,500...