Malware Alert
Attackers Hijack MikroTik Routers Through Exposed SSH
Attackers are actively hijacking MikroTik routers around the world. They exploit the router’s Secure Shell (SSH) remote-access service when it faces the internet. Alarmingly, this…
New AI-Enhanced BraZetsu Malware is Hacking Windows PCs
Cybersecurity researchers disclosed BraZetsu, a sophisticated Python-based Windows malware framework that turns compromised systems into commercial assets. The AI-enhanced toolkit profiles infected hosts, harvests financial…
New NodeRabbit and PollCat Malware Hits Windows, Linux, and macOS
Security researchers uncovered a campaign targeting software developers with fake recruitment assessments. The coding challenges secretly hide two newly discovered cross-platform remote access trojans, NodeRabbit…
Hackers Exploit Unpatched MLflow Versions to Access Cloud Metadata and Steal Credentials
CISA added MLflow CVE-2026-64849 to Known Exploited Vulnerabilities catalog after threat actors actively exploited the critical server-side request forgery flaw. Attackers access cloud metadata endpoints…
This macOS Malware Watches You Browse in Real Time, Without A Hint It Exists
Researchers at Jamf Threat Labs have identified AmnesiaStealer, a sophisticated multi-stage infostealer targeting macOS systems. Beyond standard credential harvesting, it grants malicious actors real-time, invisible…
Seven WordPress Plugins Compromised via Poisoned JSON Feed, Affecting 100,000+ Sites
Cybersecurity researchers at Wordfence disclosed a supply chain attack on August 11 that compromised seven WordPress plugins from BdThemes by poisoning a remote JSON data…
Hackers Hid Inside This VPN App and Only Attacked You if You Weren’t Playing Video Games
FortiGuard Labs uncovered a year-long supply chain attack hiding inside QuickFox, a popular VPN app used by Chinese expats and students to access Chinese services…
A Single JSON Request Can Now Hijack Java Servers, and There Is No Fix
Attackers are actively exploiting a critical flaw in Fastjson, and Alibaba has not released a fixed 1.x version yet. The vulnerability, tracked as CVE-2026-16723, carries…
New Attack Makes Coding Assistants Run Strangers’ Commands
Ask an AI agent to summarise product reviews, and a single planted review can make it click “Buy Now” instead. That is the unsettling demonstration…
New Ghostcommit Attack Tricks AI Coding Agents Into Stealing Secrets
Security researchers have exposed a clever new way to weaponize AI coding assistants, and it hides in plain sight. The attack, named Ghostcommit, buries malicious…
Your Wi-Fi Router Could Be Hiding Chinese Spy Traffic
Chinese hackers have developed a new LONGLEASH malware to expand their covert relay network, as per Cisco Talos researchers, who exposed the campaign this week.…
New RustDuck Malware Targets Routers and Cameras to Build DDoS Botnet
A new two-stage malware family called RustDuck is hijacking devices worldwide. It targets home routers, IP cameras, Android boxes, and poorly secured servers. It then…
There’s A New Malware Hitting Governments Worldwide Now
Security researchers have uncovered a new malware family called SharkLoader. The loader deploys Cobalt Strike Beacon on compromised systems. The campaign casts a wide net…
