UNC3753 Used Vishing and Physical Intrusions in U.S. Data Theft Extortion Campaign | Cybersecurity
Cybersecurity researchers have disclosed details of a financially motivated data theft extortion campaign that has targeted dozens of organizations across professional, legal, and financial services in the U.S. between January…
Read moreNew ChatGPT Lockdown Mode Limits Tools That Could Enable Data Exfiltration | Cybersecurity
Ravie LakshmananJun 06, 2026Cybersecurity / Artificial Intelligence OpenAI has begun rolling out a new Lockdown Mode to ChatGPT for eligible personal accounts to reduce the risk of data exfiltration arising…
Read moreFree Apps Are Quietly Turning Smart TVs Into Web-Scraping Proxies for AI | Cybersecurity
A researcher has reverse-engineered the iOS SDK that Bright Data embeds in consumer apps and documented how it turns devices, including always-on smart TVs, into exit nodes that relay web-scraping…
Read moreCisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available | Cybersecurity
Ravie LakshmananJun 06, 2026Vulnerability / Network Security Cisco has warned that a high-severity security flaw impacting Catalyst SD-WAN Manager has come under active exploitation. The vulnerability, tracked as CVE-2026-20245, carries…
Read moreAndroid Spyware Asin Targets Arabic Users via Fake News, PDF and War Map Apps | Cybersecurity
Ravie LakshmananJun 05, 2026Spyware / Mobile Security Arabic-speaking users have emerged as the target of a new Android spyware codenamed Asin, according to findings from ESET. The Slovakian cybersecurity company…
Read moreNew Threat Cluster OP-512 Targets Microsoft IIS Servers with Custom Web Shell Framework | Cybersecurity
Ravie LakshmananJun 05, 2026Cyber Espionage / Threat Intelligence Cybersecurity researchers have discovered a previously unreported threat cluster dubbed OP-512 (where “OP” stands for “opponent”) that has been observed targeting Microsoft Internet…
Read moreAI: Threat, tool, or both? | Malware
Public attitudes toward Artificial Intelligence (AI) are changing, and we wanted to understand why. A recent Pew Research survey found that about half of adults say the increased use of…
Read moreHackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites | Cybersecurity
Threat actors are actively exploiting a critical security flaw in Everest Forms Pro, a WordPress plugin with about 4,000 active installations, to execute arbitrary code, leading to a complete site…
Read morePCPJack Hijacks 230 AWS, Google Cloud, and Azure Servers for Covert SMTP Relay Network | Cybersecurity
Ravie LakshmananJun 05, 2026Threat Intelligence / Cloud Security The threat actor known as PCPJack has hijacked cloud servers associated with Amazon Web Services (AWS), Google Cloud, and Microsoft Azure to…
Read moreFake Sites Mimicking Open-Source Tools Rank High on Google to Deliver Malware via TDS | Cybersecurity
Swati KhandelwalJun 04, 2026Malware / Open Source Cybersecurity researchers have flagged a large-scale operation that impersonates open-source and freeware projects to funnel unsuspecting users through a Traffic Distribution System (TDS)…
Read moreTravel scams are everywhere. Here’s how to avoid them | Malware
Planning a holiday should be exciting, fun, and not a cybersecurity risk. But booking flights, hotels, and rental properties often means sharing sensitive personal and financial information across multiple platforms….
Read moreClaude Code GitHub Action Flaw Let One Malicious Issue Hijack Repositories | Cybersecurity
Swati KhandelwalJun 04, 2026Vulnerability / AI Security A security researcher found a flaw in Anthropic’s Claude Code GitHub Action that let an attacker take over vulnerable public repositories running it,…
Read moreCisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public | Cybersecurity
Swati KhandelwalJun 04, 2026Vulnerability / Network Security Cisco has patched a bug in Unified Communications Manager that lets an unauthenticated attacker on the network write files to the box and,…
Read moreMeta’s AI support bot happily handed Instagram accounts to hackers | Malware
Customer service chatbots have one job: get the user what they’re asking for without bothering a human. Meta’s new AI support assistant took that brief a little too seriously. Over…
Read moreWe found this fake-invoice campaign while scammers were still building it | Malware
A new batch of fake payment invoices is being staged right now, and we caught the campaign while it was still being put together. The emails impersonate PayPal, Amazon, and…
Read moreWhatsApp, Slack Notifications Could Hijack Google Gemini on Android | Cybersecurity
Swati KhandelwalJun 03, 2026Vulnerability / Artificial Intelligence A single poisoned notification from WhatsApp, Slack, SMS, Signal, Instagram, or Messenger could have hijacked Google Gemini’s voice assistant on Android and made…
Read moreGoogle DoubleClick Abused in New Malspam Campaign to Deliver DesckVB RAT | Cybersecurity
Ravie LakshmananJun 03, 2026Malware / Microsoft Defender Cybersecurity researchers have flagged a new malspam campaign that makes use of Google’s DoubleClick domain as a way to evade detection and ultimately…
Read moreKeep getting calls from questionable numbers? Meet Scam Number Check | Malware
Have you ever gotten a phone call and had a gut feeling that those random digits looked extra suspicious? It happens to millions of people every day. While many people…
Read moreOne-Click GitHub Dev Attack Lets Attackers Steal Full GitHub OAuth Tokens | Cybersecurity
Ravie LakshmananJun 03, 2026Vulnerability / Software Development Cybersecurity researchers have disclosed a one-click attack via Microsoft Visual Studio Code (VS Code) that makes it possible to steal a user’s GitHub…
Read moreInfostealers are becoming the go-to phishing payload | Malware
Phishing has changed. Slowly but surely, cybercriminals are turning to infostealers instead. Traditional phishing hasn’t gone away. Far from it. But many attackers are no longer focused solely on tricking…
Read moreWeedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content | Cybersecurity
Cybersecurity researchers have flagged a new campaign targeting Minecraft players via YouTube to spread malware capable of gaining control of victims’ systems. The Minecraft-focused malware-as-a-service (MaaS) campaign has been codenamed…
Read moreFake virus alerts are invading mobile games | Malware
Sometimes it happens. You’re happily playing a game on your phone or laptop when suddenly alarms pop up out of nowhere: “Your device is infected!” “Your iCloud is full!” “Your…
Read moreThese convincing copyright notices are designed to steal Google logins | Malware
A new scam is targeting people who publish Chrome extensions. The scam arrives as an official-looking “copyright removal request” claiming your extension is about to be removed from the Chrome…
Read moreAI-Driven Exploitation is Destroying Vulnerability Management. Here’s How to Handle It. | Cybersecurity
AI-driven exploitation timelines are rapidly shrinking, and they are not going to stop shrinking. Vulnerabilities are being discovered, reproduced, and weaponized faster than ever in the history of enterprise security….
Read more23andMe exposed genetic information of millions, lawsuit says | Malware
California has sued the former shell of DNA testing company 23andMe over alleged security failures and misleading statements surrounding its 2023 data breach. On May 27, 2026, Attorney General Rob…
Read moreDashlane Discloses Brute-Force Attack, Encrypted Vaults of Fewer Than 20 Users Downloaded | Cybersecurity
Ravie LakshmananJun 02, 2026Identity Security / Data Protection Password manager Dashlane has disclosed that “fewer than” 20 users on the personal subscription plan had their encrypted vaults downloaded following a…
Read moreGoogle June 2026 Android Update Patches 124 Flaws, One Actively Exploited | Cybersecurity
Ravie LakshmananJun 02, 2026Vulnerability / Mobile Security Google on Monday released patches for 124 security vulnerabilities impacting its Android operating system for the month of June 2026, including one high-severity…
Read moreA week in security (May 25 – May 31) | Malware
Last week on Malwarebytes Labs: Payment apps are watching what you say (Lock and Code S07E11) Scammers pretending to be Microsoft had help from US executives 700+ education and tech…
Read moreMiasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm | Cybersecurity
A new Mini Shai-Hulud supply chain attack campaign, codenamed Miasma, has compromised @redhat-cloud-services packages to steal credentials and secrets from developer machines and deliver a self-propagating worm. “This is effectively…
Read more⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More | Cybersecurity
Ravie LakshmananJun 01, 2026Cybersecurity / Hacking Monday hit like a cron job with anger issues. A busted auth path here, a repo-side faceplant there, some “patched-ish” thing already getting chewed…
Read more