Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites | Cybersecurity

Threat actors are actively exploiting a critical security flaw in Everest Forms Pro, a WordPress plugin with about 4,000 active installations, to execute arbitrary code, leading to a complete site…

Read more

PCPJack Hijacks 230 AWS, Google Cloud, and Azure Servers for Covert SMTP Relay Network | Cybersecurity

Ravie LakshmananJun 05, 2026Threat Intelligence / Cloud Security The threat actor known as PCPJack has hijacked cloud servers associated with Amazon Web Services (AWS), Google Cloud, and Microsoft Azure to…

Read more

Fake Sites Mimicking Open-Source Tools Rank High on Google to Deliver Malware via TDS | Cybersecurity

Swati KhandelwalJun 04, 2026Malware / Open Source Cybersecurity researchers have flagged a large-scale operation that impersonates open-source and freeware projects to funnel unsuspecting users through a Traffic Distribution System (TDS)…

Read more

Travel scams are everywhere. Here’s how to avoid them | Malware

Planning a holiday should be exciting, fun, and not a cybersecurity risk. But booking flights, hotels, and rental properties often means sharing sensitive personal and financial information across multiple platforms….

Read more

Claude Code GitHub Action Flaw Let One Malicious Issue Hijack Repositories | Cybersecurity

Swati KhandelwalJun 04, 2026Vulnerability / AI Security A security researcher found a flaw in Anthropic’s Claude Code GitHub Action that let an attacker take over vulnerable public repositories running it,…

Read more

Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public | Cybersecurity

Swati KhandelwalJun 04, 2026Vulnerability / Network Security Cisco has patched a bug in Unified Communications Manager that lets an unauthenticated attacker on the network write files to the box and,…

Read more

Meta’s AI support bot happily handed Instagram accounts to hackers | Malware

Customer service chatbots have one job: get the user what they’re asking for without bothering a human. Meta’s new AI support assistant took that brief a little too seriously. Over…

Read more

We found this fake-invoice campaign while scammers were still building it | Malware

A new batch of fake payment invoices is being staged right now, and we caught the campaign while it was still being put together. The emails impersonate PayPal, Amazon, and…

Read more

WhatsApp, Slack Notifications Could Hijack Google Gemini on Android | Cybersecurity

Swati KhandelwalJun 03, 2026Vulnerability / Artificial Intelligence A single poisoned notification from WhatsApp, Slack, SMS, Signal, Instagram, or Messenger could have hijacked Google Gemini’s voice assistant on Android and made…

Read more

Google DoubleClick Abused in New Malspam Campaign to Deliver DesckVB RAT | Cybersecurity

Ravie LakshmananJun 03, 2026Malware / Microsoft Defender Cybersecurity researchers have flagged a new malspam campaign that makes use of Google’s DoubleClick domain as a way to evade detection and ultimately…

Read more

Keep getting calls from questionable numbers? Meet Scam Number Check | Malware

Have you ever gotten a phone call and had a gut feeling that those random digits looked extra suspicious? It happens to millions of people every day. While many people…

Read more

One-Click GitHub Dev Attack Lets Attackers Steal Full GitHub OAuth Tokens | Cybersecurity

Ravie LakshmananJun 03, 2026Vulnerability / Software Development Cybersecurity researchers have disclosed a one-click attack via Microsoft Visual Studio Code (VS Code) that makes it possible to steal a user’s GitHub…

Read more

Infostealers are becoming the go-to phishing payload | Malware

Phishing has changed. Slowly but surely, cybercriminals are turning to infostealers instead. Traditional phishing hasn’t gone away. Far from it. But many attackers are no longer focused solely on tricking…

Read more

Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content | Cybersecurity

Cybersecurity researchers have flagged a new campaign targeting Minecraft players via YouTube to spread malware capable of gaining control of victims’ systems. The Minecraft-focused malware-as-a-service (MaaS) campaign has been codenamed…

Read more

Fake virus alerts are invading mobile games | Malware

Sometimes it happens. You’re happily playing a game on your phone or laptop when suddenly alarms pop up out of nowhere: “Your device is infected!” “Your iCloud is full!” “Your…

Read more

These convincing copyright notices are designed to steal Google logins | Malware

A new scam is targeting people who publish Chrome extensions. The scam arrives as an official-looking “copyright removal request” claiming your extension is about to be removed from the Chrome…

Read more

AI-Driven Exploitation is Destroying Vulnerability Management. Here’s How to Handle It. | Cybersecurity

AI-driven exploitation timelines are rapidly shrinking, and they are not going to stop shrinking. Vulnerabilities are being discovered, reproduced, and weaponized faster than ever in the history of enterprise security….

Read more

23andMe exposed genetic information of millions, lawsuit says | Malware

California has sued the former shell of DNA testing company 23andMe over alleged security failures and misleading statements surrounding its 2023 data breach. On May 27, 2026, Attorney General Rob…

Read more

Dashlane Discloses Brute-Force Attack, Encrypted Vaults of Fewer Than 20 Users Downloaded | Cybersecurity

Ravie LakshmananJun 02, 2026Identity Security / Data Protection Password manager Dashlane has disclosed that “fewer than” 20 users on the personal subscription plan had their encrypted vaults downloaded following a…

Read more

Google June 2026 Android Update Patches 124 Flaws, One Actively Exploited | Cybersecurity

Ravie LakshmananJun 02, 2026Vulnerability / Mobile Security Google on Monday released patches for 124 security vulnerabilities impacting its Android operating system for the month of June 2026, including one high-severity…

Read more

A week in security (May 25 – May 31) | Malware

Last week on Malwarebytes Labs: Payment apps are watching what you say (Lock and Code S07E11) Scammers pretending to be Microsoft had help from US executives 700+ education and tech…

Read more

Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm | Cybersecurity

A new Mini Shai-Hulud supply chain attack campaign, codenamed Miasma, has compromised @redhat-cloud-services packages to steal credentials and secrets from developer machines and deliver a self-propagating worm. “This is effectively…

Read more

⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More | Cybersecurity

Ravie LakshmananJun 01, 2026Cybersecurity / Hacking Monday hit like a cron job with anger issues. A busted auth path here, a repo-side faceplant there, some “patched-ish” thing already getting chewed…

Read more

Fake BlueWallet steals passwords, accounts, and crypto from Macs | Malware

A fake website impersonating BlueWallet (a real Bitcoin wallet) is targeting Mac users with a simple but effective attack. BlueWallet itself has not been compromised. Instead, cybercriminals have stolen the…

Read more

China-Aligned Groups Ramp Up Attacks: Dragon Weave Hits Czech Republic & Taiwan | Cybersecurity

A new cyber espionage campaign codenamed Operation Dragon Weave has been observed targeting officials and citizens in the Czech Republic and Taiwan to deliver an AdaptixC2 agent. According to Seqrite…

Read more

Your phone called. It needs a cleanup. | Malware

Does it sometimes take your phone a few minutes to accomplish one simple task? That can be wildly frustrating. But you’re in luck, because we’ve got a free tool that…

Read more

Payment apps are watching what you say (Lock and Code S07E11) | Malware

This week on the Lock and Code podcast… In the United States today, you can have your bank account closed, your credit cards cancelled, and your online payments revoked for…

Read more

Dutch Authorities Dismantle Botnet Linked to 17 Million Infected Devices | Cybersecurity

Ravie LakshmananMay 31, 2026IoT Security / Network Security Dutch authorities have announced the takedown of a botnet that enslaved millions of infected devices, including computers, tablets, smartphones, and IoT devices,…

Read more

PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation | Cybersecurity

Ravie LakshmananMay 30, 2026Vulnerability / Network Security Palo Alto Networks has warned that a recently disclosed medium-severity security flaw impacting PAN-OS and Prisma Access has come under active exploitation in…

Read more

ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface | Cybersecurity

Cybersecurity researchers have disclosed details of a vulnerability in OpenAI ChatGPT that leverages the artificial intelligence (AI) assistant’s implicit trust in Markdown links and images to trigger prompt injections and…

Read more
Update cookies preferences