Critical PAN-OS zero-day under active exploitation
The flaw, tracked as CVE-2026-0300, allows unauthenticated attackers to execute arbitrary code with root privileges.
The group likely exploits vulnerabilities in web-facing applications, including both zero-day and known flaws.
The flaw, tracked as CVE-2026-0300, allows unauthenticated attackers to execute arbitrary code with root privileges.
The suspect used software-defined radio (SDR) equipment and modified handheld radios to interfere with the Taiwan High Speed Rail.
The attackers used the legitimate Microsoft Phone Link app to access sensitive mobile data without infecting the victimu2019s smartphone.
The malicious code was embedded into Android game downloads hosted on the platform.
Deniss Zolotarjovs allegedly played a key role in ransomware operations carried out by a group known as Karakurt, TommyLeaks, and SchoolBoys Ransomware.
The operation, dubbed u2018VENOMOUS#HELPER,u2019 mainly targets US-based entities and appears to be financially motivated.