#News


Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails

Aug 8, 2026 // 01:07

Cybersecurity researchers have called attention to an active “widespread email-driven phishing campaign” that employs adversary-in-the-middle (AitM) techniques to take control of Microsoft 365 accounts with […]

New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables

Aug 8, 2026 // 01:07

Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, […]

18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers

Aug 8, 2026 // 01:07

A use-after-free bug in Linux’s SCTP networking code can be turned into full root on a host, and Tencent researchers say they used it to […]

Growing Up The Hard Way

Aug 8, 2026 // 01:07

Open Source had a great childhood. For two decades it got to be a kid. It ran around barefoot, gave everything away, trusted strangers, and […]

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution – Patch ASAP

Aug 8, 2026 // 01:06

WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. pwn.ai demonstrated […]

UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

Aug 8, 2026 // 01:05

A recent wave of cyber attacks targeting financial services, private equity, and professional services is attributed to a data extortion group known as UNC6671. “UNC6671 […]

ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets

Aug 8, 2026 // 01:05

ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and […]

Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

Aug 8, 2026 // 01:05

A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware […]

North Carolina Ports confirms cyberattack disrupting operations

Aug 8, 2026 // 01:05

The North Carolina Ports Authority has confirmed that a cyberattack disrupted IT systems and slowed operations at the Port of Wilmington, Port of Morehead City, […]

Real emails, hijacked payments: Two H1 2026 attack chains

Aug 8, 2026 // 01:05

Gen Threat Labs followed two H1 2026 campaigns where attackers used legitimate accounts, browser settings and blockchain data as part of the attack path. The […]

Previous 1 53 54 55 56 57 353 Next