GTA 6 early access is nothing but a scam | Malware

A new wave of scam websites is offering something millions of people want: a way to play Grand Theft Auto VI before it comes out. “Get GTA 6 before everyone…

Read more

New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks | Cybersecurity

A newly discovered cyber attack campaign has been observed delivering a previously undocumented malware family called SharkLoader that acts as a loader for deploying Cobalt Strike Beacon on compromised hosts….

Read more

Malware steals Chrome session cookies to take over your accounts | Malware

An email attachment leads to the installation of a malicious Chrome extension. Researchers say it is part of a Windows backdoor delivered via a phishing email. The malware abuses Chrome…

Read more

New Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries | Cybersecurity

Swati KhandelwalJun 26, 2026Linux / Vulnerability A flaw in the Linux kernel’s traffic-control subsystem can let a local unprivileged user gain root on affected systems. CVE-2026-46331, nicknamed “pedit COW,” is…

Read more

Russia Used Cellebrite on Jailed Activist’s iPhone Months After Sales Cutoff | Cybersecurity

Russian authorities used Cellebrite’s UFED forensic tools to break into the iPhone of detained opposition activist Andrey Pivovarov in June 2021, three months after Cellebrite said it would stop selling…

Read more

Fake domain renewal emails trick website owners into paying scammers | Malware

You receive an email warning that your website’s domain name is about to expire. Renew now, it says, or your website and email could stop working. The link opens a…

Read more

Beware of “Parcel Expert” job offers: They’re parcel mule scams | Malware

A parcel mule scam, also called a reshipping scam, is a fake job offer designed to recruit people into handling stolen goods. It usually starts with a fake remote job…

Read more

Chrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection Capability | Cybersecurity

An analysis of a popular Google Chrome ad block extension for YouTube has uncovered the ability to execute arbitrary JavaScript code. According to Island, the extension, named Adblock for YouTube…

Read more

Update Chrome to patch critical browser security flaws | Malware

Google released a security update for Chrome that fixes 18 vulnerabilities, including four rated Critical. There is no indication that any of these newly patched bugs are being actively exploited…

Read more

ThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More Stories | Cybersecurity

Ravie LakshmananJun 25, 2026Hacking News / Cybersecurity News It’s dumb out there again. This week has the usual smell of prod on fire and nobody wanting to admit who left…

Read more

Elite network says it was hacked after members’ personal data was left exposed | Malware

Some organizations exist to be exclusive. They’re invite-only, and discreet, the kind of place where the membership directory is the product. Dialog, the exclusive network founded by billionaire investor and…

Read more

Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root Access | Cybersecurity

Ravie LakshmananJun 25, 2026Vulnerability / Threat Intelligence An unknown threat actor exploited a recently disclosed high-severity security flaw impacting Cisco Catalyst SD-WAN as a zero-day at least two months before…

Read more

Watch out for renewal scams pretending to be Malwarebytes | Malware

Fake subscription renewal notices are doing the rounds again. Some of these scams impersonate Malwarebytes, and we’ve also seen them reach our customers. You’re more likely to trust the message…

Read more

CISA Warns Critical Lantronix EDS5000 Flaw Is Being Actively Exploited | Cybersecurity

Ravie LakshmananJun 24, 2026Vulnerability / Network Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation of a critical security flaw impacting Lantronix EDS5000 Series…

Read more

PixelSmash flaw turns video files into attack tools | Malware

A newly discovered vulnerability in FFmpeg’s MagicYUV decoder can turn a tiny, malformed video into a foothold for attackers. Researchers have disclosed PixelSmash, a critical vulnerability tracked as CVE-2026-8461, in…

Read more

Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered | Cybersecurity

A coordinated law enforcement operation, in partnership with private sector companies, including Bitdefender, Bitsight, ESET, and Microsoft, has resulted in the takedown of criminal infrastructure powering Amadey and StealC. “The…

Read more

“Total access to all your devices.” Sextortion scammers strike again | Malware

At the moment, we’re seeing all kinds of sextortion emails. The scam is cheap to run, easy to automate, and apparently profitable enough that cybercriminals keep using it. Some criminals…

Read more

DoJ Seizes Huione Cloud Account Tied to Cyber Scam Money Laundering | Cybersecurity

Ravie LakshmananJun 24, 2026Money Laundering / Cybercrime The U.S. Department of Justice (DoJ) on Tuesday announced the seizure of a cloud computing account put to use by subsidiaries of Cambodia-based…

Read more

Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root | Cybersecurity

Ravie LakshmananJun 24, 2026Vulnerability / Network Security Threat actors have begun to exploit a recently disclosed critical security flaw impacting Cisco Unified Communications Manager (Unified CM) and Unified Communications Manager…

Read more

Hackers steal passport and driver’s license data of 3 million Texans | Malware

You can change a password and cancel a card. But replacing a passport or driver’s license number every time someone leaves yours unsecured in a vendor database isn’t so easy….

Read more

Inside the dark web: Stolen identities for 95¢, malware, and scams-for-hire | Malware

Most people have heard of the dark web, but few understand what it actually looks like or what goes on there. To separate fact from fiction, our research team spent…

Read more

FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation | Cybersecurity

Ravie LakshmananJun 23, 2026Initial Access Broker / Firewall Security A Russian-speaking initial access broker (IAB) driven by financial gain is assessed to be behind a large-scale credential-harvesting operation known as…

Read more

Meta pauses controversial employee-tracking program after security review | Malware

Meta has paused a controversial employee‑tracking program after an internal security review found that highly granular keystroke and screen‑capture data from staff laptops was far more widely accessible inside the…

Read more

Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents | Cybersecurity

Security firm AIR built a fake AI agent skill, pushed it through a popular skill marketplace and an Instagram ad, and says it reached roughly 26,000 agents, including some on corporate accounts….

Read more

Malicious npm Packages Pose as PostCSS Tools to Deliver Windows RAT | Cybersecurity

Ravie LakshmananJun 23, 2026Supply Chain Attack / Developer Security Cybersecurity researchers have discovered a set of malicious npm packages that are designed to deliver a Windows-based remote access trojan (RAT)….

Read more

WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool | Cybersecurity

Ravie LakshmananJun 23, 2026Malware / Social Engineering Direct messages sent via WhatsApp are being used to distribute malicious Visual Basic Script (VBScript) files that lead to the installation of legitimate…

Read more

Document delivery scams: What are they and what’s their goal? | Malware

One of Malwarebytes’ managers recently received a call from scammers pretending to be a document delivery service. The voicemail sounded official: “I am calling on behalf of document delivery services….

Read more

ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack | Cybersecurity

Ravie LakshmananJun 22, 2026Supply Chain Attack / Malware Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack after unknown threat actors managed to tamper with the official…

Read more

Thousands of D-Link routers under control of AryStinger botnet | Malware

Researchers have found that the recently discovered AryStinger botnet has quietly hijacked thousands of end‑of‑life D‑Link routers and some network-attached storage (NAS) devices, turning them into a distributed scanning and…

Read more

29-Year-Old Squid Proxy Bug ‘Squidbleed’ Can Leak Cleartext HTTP Requests | Cybersecurity

Swati KhandelwalJun 22, 2026Vulnerability / Server Security A heap over-read in the Squid web proxy can leak another user’s cleartext HTTP request, including any credentials or session tokens it carries,…

Read more
Update cookies preferences