home / news / cybersecurity
🛡️

Cybersecurity

CVEs, exploits, pentesting & threat intel

73 posts // cybersecurity updated daily
MuddyWater Iran espionage campaign targets 9 countries cyber threat

Iran’s MuddyWater Hackers Just Hit 9 Countries in One Quarter — Including a Major Samsung Supplier

Iran-linked MuddyWater spent Q1 2026 infiltrating electronics manufacturers, airports, and banks across 4 continents using DLL side-loading with stolen SentinelOne…

FBI warns Kali365 phishing kit bypasses Microsoft 365 MFA security

FBI Warns Kali365 Phishing Kit Is Stealing Microsoft 365 Tokens at Scale — And MFA Won’t Save You

The FBI just issued a public warning about Kali365, a $250/month phishing service that bypasses MFA by stealing OAuth tokens.…

TrapDoor supply chain attack npm PyPI Crates.io credential stealing malware 2026

TrapDoor: The Supply Chain Attack That Poisoned npm, PyPI, and Crates.io — And Tried to Hijack Your AI Assistant

A coordinated attack across 34 malicious packages targeted crypto and AI developers — and even tried to weaponize Claude and…

Škoda Auto data breach online shop hacked VW subsidiary customer data exposed 2026

Škoda Auto Data Breach 2026: VW Subsidiary Online Shop Hacked, Customer Data Exposed

Škoda Auto confirms hackers exploited a vulnerability in its German online shop, exposing customer names, addresses, emails, phone numbers, order…

Lazarus Group RemotePE fileless malware 77M crypto theft 2026

North Korea’s Lazarus Group Just Stole $577M in Crypto With Malware That Lives Only in RAM — And You’d Never Know It Was There

North Korea's Lazarus Group stole $577M in crypto using RemotePE, a fileless RAT that lives only in RAM. Now responsible…

Ghost CMS SQL injection hack 700 sites ClickFix malware 2026

Harvard and DuckDuckGo Got Hacked Through Ghost CMS — 700 Sites Now Serving Malware via Fake Cloudflare Prompts

A critical SQL injection in Ghost CMS (CVE-2026-26980) has compromised 700+ sites including Harvard and DuckDuckGo. Attackers inject ClickFix malware…

DAEMON Tools supply chain attack backdoor malware 2026

DAEMON Tools Was Silently Backdoored for 47 Days — And the Installers Were Signed With the Real Developer’s Certificate

Kaspersky discovered DAEMON Tools installers were compromised with Chinese-linked malware since April 8, 2026. Legitimate digital signatures made detection nearly…

Anthropic Project Glasswing Mythos finds 10000 critical vulnerabilities in open source software 2026

Anthropic’s Mythos Just Found 10,000 Security Flaws in the World’s Most Critical Software — And Maintainers Can’t Keep Up

Anthropic's Project Glasswing used Claude Mythos to find 10,000+ critical vulnerabilities in open-source software in just one month — but…

Laravel-Lang supply chain attack credential stealer 2026

Laravel-Lang Packages Hijacked: 700 GitHub Repos Compromised to Steal Your AWS Keys and Browser Passwords

Attackers compromised 233 versions of Laravel-Lang PHP packages via 700 hijacked GitHub repos. A 5,900-line credential stealer targets AWS, GCP,…