International cybercriminal network dismantled in major European police operation
The group developed and sold phishing and smishing tools that allowed other criminals to steal banking information from victims.
The group developed and sold phishing and smishing tools that allowed other criminals to steal banking information from victims.
The flaw, tracked as CVE-2026-5426, impacts KnowledgeDeliver deployments that used default ASP.NET configuration settings before February 24, 2026.
Researchers traced the campaign to compromised versions of the open-source chatbot platform called Tiledesk.
This toolset may be reserved for high-value targets where long-term, stealthy access is the objective.
The attackers used a previously undocumented backdoor called MiniFast, replacing the group’s earlier MiniJunk malware framework.
Officials claim the pair indirectly supplied economic resources to Russian and Belarusian entities under EU sanctions.
Threat actors have been exploiting an SQL injection flaw in Ghost CMS to inject malicious JavaScript that launches ClickFix attack chains.
In brief: Microsoft fixes two zero-days in Defender, authorities dismantle the First VPN service used by cybercriminals, and more.
Criminal groups allegedly used the service to hide their identities and online infrastructure.
The company has also patched a critical remote execution flaw, which has no signs of active exploitation.
Showing elements 131 - 140