Browsing Tag
Cyber Attack
2199 posts
New GhostCode Phishing Kit Hijacks Microsoft Accounts Despite MFA
eSentire uncovers the GhostCode phishing kit abusing Microsoft OAuth to steal tokens, register attacker devices and access Microsoft 365 accounts.
September 17, 2026
FBI Seizes NightmareStresser DDoS-for-Hire Domains in Operation PowerOFF
FBI and RCMP seize NightmareStresser domains after the DDoS-for-hire service was linked to hundreds of thousands of attacks and attempted attacks worldwide.
September 16, 2026
2 Critical Calendar WordPress Plugin Flaws Put 600K Sites at Risk of Takeover
Two critical RCE flaws in The Events Calendar expose 600,000+ WordPress installations to unauthenticated attacks, with CVSS scores of 9.8.
September 16, 2026
CrowdStrike Links AI-Generated PhantomRaven Malware to Bug Bounty Hunter
CrowdStrike links PhantomRaven malware to a bug bounty hunter, finding LLM-generated code, malicious npm packages and attempts to compromise company IT systems.
September 16, 2026
Ukrainian Conti Ransomware Member Gets Four Years in US Prison
Ukrainian national Oleksii Lytvynenko gets four years in US prison for his role in the Conti ransomware operation, which targeted over 1,000 victims.
September 15, 2026
Hackers Pose as IT Support, Use Fake Passkey Lures to Steal Microsoft 365 Access
Microsoft warns of fake passkey and IT support attacks targeting Microsoft 365 accounts to steal authentication tokens and access corporate cloud data.
September 15, 2026
StyleSmuggler 0-Day Exploited to Hack Adobe Commerce and Magento Stores
A critical Adobe Commerce and Magento zero-day dubbed StyleSmuggler is under active attack, allowing hackers to execute PHP code without authentication.
September 15, 2026
Florida Confirms DMV Breach as ShinyHunters Leak Exposes SSN Cards and Licenses
Florida DMV confirms breach after ShinyHunters claimed access, while leaked files contain SSN cards, licenses, immigration records and government documents.
September 14, 2026
Trellix Details DarkSword, JSCeal, Axios npm Attack and APT28 Campaigns
DarkSword, JSCeal, Axios, Bitter APT, and APT28 campaigns reveal evolving tactics targeting iPhones, Southeast Asia, software supply chains, diplomatic organizations, and European governments.
September 14, 2026
Revolut Gave Customer Data to Scammers After Fake Government Requests
Revolut handed over highly personal and sensitive customer data, including passports, verification selfies, IBANs, and Bitcoin transaction records, to scammers after they sent requests through a government agency email domain.
September 12, 2026