Cybersecurity

ToxicPanda 2.0 Android malware targets 349 banks across 16 countries

ToxicPanda 2.0 now supports 167 remote commands and targets over 140 banking and cryptocurrency apps across 16 countries.The malware abuses Android accessibility services to...

CISA Adds 4 Actively Exploited Flaws to KEV Catalog

CISA added four critical vulnerabilities to its Known Exploited Vulnerabilities catalog, including flaws in Apple macOS, Microsoft SharePoint, VMware vCenter, and Microsoft IKE.The Apple...

Critical MLflow and FUXA flaws exploited in wild

Two critical vulnerabilities in MLflow (CVE-2026-64849, CVSS 9.3) and FUXA (CVE-2026-25895, CVSS 9.5) are under active exploitation.Attackers are exploiting the MLflow flaw to reach...

City Forum campaign steals data via Salesforce, ServiceNow guest access

A single server (158.220.87.87) has been systematically extracting data from Salesforce and ServiceNow customer portals for over a year, using a purpose-built Go program.Named...

StubMaker: 16 typosquat RubyGems packages steal data

Cybersecurity researchers have discovered a new typosquatting campaign, tracked as StubMaker, targeting RubyGems users with a Windows-based information stealer.The 16 malicious gem packages were...

SharePoint CVE-2026-55040 exploited after PoC release

Threat actors are actively exploiting a critical Microsoft SharePoint vulnerability (CVE-2026-55040, CVSS 9.1) after a proof-of-concept code was released by Rapid7.The flaw allows unauthenticated...

Chrome Store Hit: 737 Fake VPN Extensions Target Russian Users

737 malicious Chrome extensions, impersonating 66 VPN brands like NordVPN and Proton VPN, routed Russian users' browser traffic through a single SOCKS5 proxy infrastructure.Over...

Cisco Firewall Flaw Actively Exploited in the Wild

Cisco has confirmed active exploitation of a high-severity vulnerability (CVE-2026-20349) in its Secure Firewall ASA and FTD Software.The flaw allows an unauthenticated, remote attacker...

Latest news

Cuba submits BRICS membership application before 2026 summit

Cuba has officially applied to join the BRICS alliance weeks before the 2026 summit in New DelhiFull-fledged membership is...

Tokenized stock transfers surge 415% to $29.5B in August

Monthly tokenized stock transfer volume surged 415% to $29.5 billion over the past 30 days.Monthly active addresses jumped 209%...

Critical WordPress plugin flaws allow site takeover, RCE

Five critical vulnerabilities in popular WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, could...