Risk & Resilience

Research Reveals SLEEPWALKER Windows Backdoor With Custom Bytecode Command System

Security researcher uncovers the SLEEPWALKER Windows backdoor featuring a custom bytecode language, passive network activation, DLL side loading, and stealth capabilities.

CISA Warns Of Active Exploitation Of Critical Gitea Remote Code Execution Flaw

CISA adds the critical Gitea remote code execution vulnerability CVE 2026 60004 to its Known Exploited Vulnerabilities catalog following reports of active exploitation.

OpenAI ChatGPT Messages Plugin Raises Privacy Questions On macOS

OpenAI has introduced a ChatGPT Messages plugin for macOS that requires Full Disk Access and can read, search and send messages with user permission.

OX Security Uncovers npm Campaign Using unpkg Mirrors For Fake CAPTCHA Attacks

OX Security has uncovered a campaign abusing 24 npm packages and unpkg mirrors to host fake Cloudflare CAPTCHA pages that can redirect users to phishing infrastructure.

FTP Banner Malware Campaign Uses E4del And PINHOLE RATs For Remote Access Attacks

Researchers have uncovered a malware campaign using FTP banners as dead drop resolvers to deliver E4del and PINHOLE RATs, introducing a new technique for command and control operations.

GitLab Vulnerability CVE-2026-19478 Exploited Soon After Disclosure

GitLab CVE-2026-19478 is being actively exploited after disclosure, allowing unauthenticated attackers to modify or delete public projects under certain conditions.

Cisco Releases Security Updates For Critical Crosswork And Secure Workload Vulnerabilities

Cisco has released security updates addressing nine vulnerabilities in Crosswork platforms and Secure Workload Software, including five critical flaws with CVSS 10.0 ratings.

Check Point Research Reveals Microsoft Defender Boot Driver Security Technique

Check Point Research has disclosed a technique that uses Microsoft Defender BTR.sys driver to perform kernel level operations without exploiting a software vulnerability.

Critical NASA Ground Software Flaws Allow Unauthenticated Spacecraft Control

Security researchers at Cycode have identified critical flaws in NASA AIT-GUI software that allow attackers to issue unauthenticated spacecraft commands.

StopAndProtect Campaign Abuses WordPress Sites To Deliver Malware And Steal Data

Check Point Research uncovers StopAndProtect operation using nearly 2,000 hacked WordPress websites for malware distribution, surveillance, and data theft.

CISA Flags Apple Microsoft And VMware Vulnerabilities Exploited In Active Attacks

CISA adds four critical vulnerabilities affecting macOS, SharePoint, VMware vCenter, and Microsoft IKE Service Extensions to its KEV catalog.

CISA Warns Of Active Exploitation In Critical Ray Remote Code Execution Vulnerability

CISA has added a critical Ray vulnerability to its KEV catalog after active exploitation reports. The flaw could allow remote code execution through browser based DNS rebinding attacks.

Recent articles

spot_img