Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites | Cybersecurity
Threat actors are actively exploiting a critical security flaw in Everest Forms Pro, a WordPress plugin with about 4,000 active installations, to execute arbitrary code, leading to a complete site…
Read morePCPJack Hijacks 230 AWS, Google Cloud, and Azure Servers for Covert SMTP Relay Network | Cybersecurity
Ravie LakshmananJun 05, 2026Threat Intelligence / Cloud Security The threat actor known as PCPJack has hijacked cloud servers associated with Amazon Web Services (AWS), Google Cloud, and Microsoft Azure to…
Read moreFake Sites Mimicking Open-Source Tools Rank High on Google to Deliver Malware via TDS | Cybersecurity
Swati KhandelwalJun 04, 2026Malware / Open Source Cybersecurity researchers have flagged a large-scale operation that impersonates open-source and freeware projects to funnel unsuspecting users through a Traffic Distribution System (TDS)…
Read moreTravel scams are everywhere. Here’s how to avoid them | Malware
Planning a holiday should be exciting, fun, and not a cybersecurity risk. But booking flights, hotels, and rental properties often means sharing sensitive personal and financial information across multiple platforms….
Read moreClaude Code GitHub Action Flaw Let One Malicious Issue Hijack Repositories | Cybersecurity
Swati KhandelwalJun 04, 2026Vulnerability / AI Security A security researcher found a flaw in Anthropic’s Claude Code GitHub Action that let an attacker take over vulnerable public repositories running it,…
Read moreCisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public | Cybersecurity
Swati KhandelwalJun 04, 2026Vulnerability / Network Security Cisco has patched a bug in Unified Communications Manager that lets an unauthenticated attacker on the network write files to the box and,…
Read moreMeta’s AI support bot happily handed Instagram accounts to hackers | Malware
Customer service chatbots have one job: get the user what they’re asking for without bothering a human. Meta’s new AI support assistant took that brief a little too seriously. Over…
Read moreWe found this fake-invoice campaign while scammers were still building it | Malware
A new batch of fake payment invoices is being staged right now, and we caught the campaign while it was still being put together. The emails impersonate PayPal, Amazon, and…
Read moreWhatsApp, Slack Notifications Could Hijack Google Gemini on Android | Cybersecurity
Swati KhandelwalJun 03, 2026Vulnerability / Artificial Intelligence A single poisoned notification from WhatsApp, Slack, SMS, Signal, Instagram, or Messenger could have hijacked Google Gemini’s voice assistant on Android and made…
Read moreGoogle DoubleClick Abused in New Malspam Campaign to Deliver DesckVB RAT | Cybersecurity
Ravie LakshmananJun 03, 2026Malware / Microsoft Defender Cybersecurity researchers have flagged a new malspam campaign that makes use of Google’s DoubleClick domain as a way to evade detection and ultimately…
Read moreKeep getting calls from questionable numbers? Meet Scam Number Check | Malware
Have you ever gotten a phone call and had a gut feeling that those random digits looked extra suspicious? It happens to millions of people every day. While many people…
Read moreOne-Click GitHub Dev Attack Lets Attackers Steal Full GitHub OAuth Tokens | Cybersecurity
Ravie LakshmananJun 03, 2026Vulnerability / Software Development Cybersecurity researchers have disclosed a one-click attack via Microsoft Visual Studio Code (VS Code) that makes it possible to steal a user’s GitHub…
Read moreInfostealers are becoming the go-to phishing payload | Malware
Phishing has changed. Slowly but surely, cybercriminals are turning to infostealers instead. Traditional phishing hasn’t gone away. Far from it. But many attackers are no longer focused solely on tricking…
Read moreWeedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content | Cybersecurity
Cybersecurity researchers have flagged a new campaign targeting Minecraft players via YouTube to spread malware capable of gaining control of victims’ systems. The Minecraft-focused malware-as-a-service (MaaS) campaign has been codenamed…
Read moreFake virus alerts are invading mobile games | Malware
Sometimes it happens. You’re happily playing a game on your phone or laptop when suddenly alarms pop up out of nowhere: “Your device is infected!” “Your iCloud is full!” “Your…
Read moreThese convincing copyright notices are designed to steal Google logins | Malware
A new scam is targeting people who publish Chrome extensions. The scam arrives as an official-looking “copyright removal request” claiming your extension is about to be removed from the Chrome…
Read moreAI-Driven Exploitation is Destroying Vulnerability Management. Here’s How to Handle It. | Cybersecurity
AI-driven exploitation timelines are rapidly shrinking, and they are not going to stop shrinking. Vulnerabilities are being discovered, reproduced, and weaponized faster than ever in the history of enterprise security….
Read more23andMe exposed genetic information of millions, lawsuit says | Malware
California has sued the former shell of DNA testing company 23andMe over alleged security failures and misleading statements surrounding its 2023 data breach. On May 27, 2026, Attorney General Rob…
Read moreDashlane Discloses Brute-Force Attack, Encrypted Vaults of Fewer Than 20 Users Downloaded | Cybersecurity
Ravie LakshmananJun 02, 2026Identity Security / Data Protection Password manager Dashlane has disclosed that “fewer than” 20 users on the personal subscription plan had their encrypted vaults downloaded following a…
Read moreGoogle June 2026 Android Update Patches 124 Flaws, One Actively Exploited | Cybersecurity
Ravie LakshmananJun 02, 2026Vulnerability / Mobile Security Google on Monday released patches for 124 security vulnerabilities impacting its Android operating system for the month of June 2026, including one high-severity…
Read moreA week in security (May 25 – May 31) | Malware
Last week on Malwarebytes Labs: Payment apps are watching what you say (Lock and Code S07E11) Scammers pretending to be Microsoft had help from US executives 700+ education and tech…
Read moreMiasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm | Cybersecurity
A new Mini Shai-Hulud supply chain attack campaign, codenamed Miasma, has compromised @redhat-cloud-services packages to steal credentials and secrets from developer machines and deliver a self-propagating worm. “This is effectively…
Read more⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More | Cybersecurity
Ravie LakshmananJun 01, 2026Cybersecurity / Hacking Monday hit like a cron job with anger issues. A busted auth path here, a repo-side faceplant there, some “patched-ish” thing already getting chewed…
Read moreFake BlueWallet steals passwords, accounts, and crypto from Macs | Malware
A fake website impersonating BlueWallet (a real Bitcoin wallet) is targeting Mac users with a simple but effective attack. BlueWallet itself has not been compromised. Instead, cybercriminals have stolen the…
Read moreChina-Aligned Groups Ramp Up Attacks: Dragon Weave Hits Czech Republic & Taiwan | Cybersecurity
A new cyber espionage campaign codenamed Operation Dragon Weave has been observed targeting officials and citizens in the Czech Republic and Taiwan to deliver an AdaptixC2 agent. According to Seqrite…
Read moreYour phone called. It needs a cleanup. | Malware
Does it sometimes take your phone a few minutes to accomplish one simple task? That can be wildly frustrating. But you’re in luck, because we’ve got a free tool that…
Read morePayment apps are watching what you say (Lock and Code S07E11) | Malware
This week on the Lock and Code podcast… In the United States today, you can have your bank account closed, your credit cards cancelled, and your online payments revoked for…
Read moreDutch Authorities Dismantle Botnet Linked to 17 Million Infected Devices | Cybersecurity
Ravie LakshmananMay 31, 2026IoT Security / Network Security Dutch authorities have announced the takedown of a botnet that enslaved millions of infected devices, including computers, tablets, smartphones, and IoT devices,…
Read morePAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation | Cybersecurity
Ravie LakshmananMay 30, 2026Vulnerability / Network Security Palo Alto Networks has warned that a recently disclosed medium-severity security flaw impacting PAN-OS and Prisma Access has come under active exploitation in…
Read moreChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface | Cybersecurity
Cybersecurity researchers have disclosed details of a vulnerability in OpenAI ChatGPT that leverages the artificial intelligence (AI) assistant’s implicit trust in Markdown links and images to trigger prompt injections and…
Read more