Microsoft’s January 2026 Patch Tuesday fixes over 100 security issues, one zero-day
ZDI said that CVE-2026-20805 was likely used in targeted attacks as part of a larger exploit chain.
ZDI said that CVE-2026-20805 was likely used in targeted attacks as part of a larger exploit chain.
CERT-UA attributed the activity to a state-backed group known as Void Blizzard.
VoidLink is a cloud-focused implant written primarily in Zig with a flexible modular architecture.
Trellix researchers report that stolen Facebook accounts are used to spread scams, harvest personal data, and commit identity fraud.
The campaign appears to be opportunistic, mainly targeting enterprise and small-to-medium business environments.
The suspected criminal activity occurred throughout 2025 and into 2026, although investigators believe the alleged spying may have begun as early as 2022.
Historically, Muddy Water has relied on PowerShell and VBS loaders for initial access and post-compromise operations.
Scammers can now buy solutions that allow them to run sophisticated fraud campaigns without advanced technical skills.
An unknown actor has leaked an archive containing a MyBB users table and BreachForums’ private PGP key used to sign administrator messages.
In brief: Google fixes a high-severity Chrome flaw, a MongoDB flaw exploited in the wild, and more.
Showing elements 311 - 320