SilkParasite Threatens Central Asian Orgs With Flurry of RATs
A spear-phishing campaign by a Chinese-nexus group linked to FamousSparrow provides insight into geopolitical, technical, and strategic global moves by China's APTs.
A spear-phishing campaign by a Chinese-nexus group linked to FamousSparrow provides insight into geopolitical, technical, and strategic global moves by China's APTs.
A Agência de Segurança Cibernética e Infraestrutura dos EUA (CISA) alertou que hackers estão explorando ativamente uma vulnerabilidade crítica de execução remota de código (CVE-2026-33824) no componente Windows Internet Key Exchange (IKE) Service Extensions, conforme atualização …
The U.S. has charged 17 Iranians, alleged members of a hacking-for-hire company called Mabna Institute, involved in years-long operations that stole data from American organizations. [...]
Huntress observed a 155x increase in password spraying attacks in H1 2026, including a campaign that generated more than 81 million login attempts in two weeks. The attacks exploited legacy authentication and gaps in MFA policies that left some login flows unprotected. [...]
A previously unreported cyber espionage operation dubbed SilkParasite has been observed targeting government bodies in Central Asia. The intrusion set makes use of seven remote access tool (RAT) families, five of which have never been previously documented: DriveSilkRAT, CookiET…
Cybersecurity researchers at Hunt.io have disclosed details of a campaign that they say compromised more than 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two authentication-bypass flaws, and a peer-to-peer (P2P) relay technique. The activity…
Uma vulnerabilidade crítica no plugin Forminator Forms para WordPress pode permitir que invasores sem autenticação enviem arquivos PHP maliciosos e, em determinadas configurações, executem código no servidor. A falha é identificada como CVE-2026-15748 e recebeu nota 9,8 no CVSS. …
Most email defenses still do the job they did a decade ago. Scan the message, look for something malicious, block it. That worked when the danger sat in the payload, a bad link or an attachment. It stopped working when the danger moved into the message's intent, and it is failing…
Cybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to disseminate malware, commandeer infected hosts, store stolen documents, screenshots, and activity logs created to track the status of the a…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, stating they are being exploited in the wild. The shortcomings added to the KEV catalog are listed below - CV…
O GitLab corrigiu uma vulnerabilidade crítica em sua API GraphQL que pode permitir a invasores remotos modificar ou excluir projetos públicos e dados de usuários sem precisar de autenticação. A falha foi identificada como CVE-2026-19478. O problema envolve uma injeção de código p…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity remote code execution (RCE) flaw in the Windows Internet Key Exchange (IKE) Service Extensions component. [...]
The FBI said Tuesday that the Medusa ransomware gang has breached more than 500 critical infrastructure organizations in the United States since June 2021. [...]
Microsoft Defender Experts have linked more than 30 web domains to MacSync Stealer, a macOS-focused information stealer, after correlating recurring endpoint and network behaviors across changing infrastructure, tracing the malware from payload retrieval through data collection, …
A JavaServer Pages (JSP) web shell deployed following the exploitation of a critical security flaw in PTC Windchill and FlexPLM servers is specifically designed for the enterprise Product Lifecycle Management (PLM) software, according to new findings from ReliaQuest. The cyberse…
O governo de Berlim isolou duas secretarias estaduais de sua rede corporativa desde a última sexta-feira (14 de agosto) após a descoberta de uma invasão cibernética, conforme comunicado oficial publicado na segunda-feira (17 de agosto). As pastas afetadas — uma responsável por de…
Uma credencial de autenticação encontrada no código público de uma aplicação web, combinada a permissões excessivas e falhas de segmentação, permitiu a uma equipe de teste alcançar ambientes de nuvem, infraestrutura de produção e dados pessoais e financeiros de uma grande organiz…
O grupo de ransomware Clop desenvolveu uma webshell Java personalizada, projetada especificamente para servidores PTC Windchill e FlexPLM, com funcionalidades integradas para descriptografar credenciais, enumerar repositórios de arquivos e roubar dados, conforme análise da empres…
A Agência de Segurança Cibernética e Infraestrutura dos EUA (CISA) confirmou que grupos de ransomware estão explorando uma vulnerabilidade de alta gravidade no Windows Task Host (CVE-2025-60710), que já havia sido sinalizada como ativamente explorada em abril, conforme atualizaçã…
In the first purported "near-autonomous" attack on a nation-state, a Chinese-language operator used a complex AI framework to target and compromise government agencies, likely in Taiwan.