Risk & Resilience

New TrickMo Android Malware Variant Uses TON And SOCKS5 To Expand Banking Attacks

Cybersecurity researchers have identified a new TrickMo Android banking trojan variant that uses TON based command and control infrastructure, SOCKS5 proxying, and SSH tunnelling to target banking and cryptocurrency users in Europe.

CVE-2026-41940 cPanel Vulnerability Actively Exploited To Deploy Filemanager Backdoor In Global Attacks

A critical cPanel vulnerability CVE-2026-41940 is being actively exploited by threat actor Mr_Rot13 to deploy Filemanager backdoor, enabling credential theft, ransomware, botnet activity, and persistent system compromise across global infrastructure.

Instructure Reaches Ransom Agreement With ShinyHunters After 3.65TB Canvas Data Breach

Instructure confirms an agreement with ShinyHunters following a Canvas breach involving 3.65TB of stolen data impacting nearly 9000 institutions, with threat actors leveraging a vulnerability to exfiltrate sensitive education records.

Mini Shai Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI And Multiple Open Source Packages In Supply Chain Attack

A Mini Shai Hulud worm linked to TeamPCP has compromised npm and PyPI packages across TanStack, Mistral AI, Guardrails AI and others, deploying credential stealers, CI/CD exploits, and cross ecosystem propagation techniques.

TCLBANKER Banking Trojan Expands Reach Through WhatsApp And Outlook Propagation

Newly identified TCLBANKER banking trojan targets 59 financial platforms using WhatsApp and Outlook worms, highlighting evolving cybercrime tactics.

PAN OS CVE-2026-0300 Exploited In Active Attacks Enables Root Level Remote Code Execution

Palo Alto Networks reports active exploitation of PAN OS CVE-2026-0300 allowing root level RCE, with espionage activity linked to suspected state sponsored threat cluster CL STA 1132.

Ivanti EPMM CVE-2026-6973 Exploited In Limited Attacks Enables Admin Level Remote Code Execution

Ivanti warns of CVE-2026-6973 in EPMM being actively exploited in limited attacks, enabling admin authenticated remote code execution, alongside multiple patched vulnerabilities.

Linux Kernel Dirty Frag Vulnerability Enables Root Access Across Major Linux Distributions

Dirty Frag Linux kernel vulnerability enables local privilege escalation to root across major distributions including Ubuntu, RHEL, Fedora, and CentOS, with active exploitation risk.

Silver Fox Targets India And Russia With Phishing Campaign Delivering ABCDoor And ValleyRAT Malware

China linked group Silver Fox targets organizations in India and Russia using phishing emails with tax themed lures to distribute ValleyRAT and newly identified ABCDoor malware, according to Kaspersky analysis.

Critical cPanel Vulnerability Exploited To Target Government And MSP Networks Across Multiple Regions

A critical cPanel vulnerability CVE 2026 41940 is being actively exploited to target government, military, and MSP networks globally, enabling authentication bypass and remote control, with thousands of systems impacted.

Weaver E-cology Critical RCE Vulnerability CVE 2026 22679 Actively Exploited Via Debug API Endpoint

A critical Weaver E-cology vulnerability CVE 2026 22679 is being actively exploited, enabling unauthenticated remote code execution through debug API endpoints affecting enterprise systems globally.

AI Assisted Cyber Attacks Surge In 2026 As Threat Landscape Rapidly Evolves

AI assisted cyber attacks are rising sharply in 2026, lowering barriers for attackers, accelerating exploit timelines, and increasing phishing, malware, and supply chain threats globally.

Recent articles

spot_img