1. Threat actors are abusing Steam discussion forums with ClickFix attacks that trick users into downloading XMRig cryptominers under the guise of game fixes (bleepingcomputer.com).
2. A malvertising campaign dubbed SourTrade impersonates financial platforms to force browsers to assemble malicious Windows executables in memory using legitimate runtime environments (thehackernews.com).
3. Attackers are actively exploiting a critical remote code execution vulnerability in the Fastjson library tracked as CVE-2026-16723 (thehackernews.com).
4. Affiliates of the Cl0p ransomware group are targeting internet-exposed PTC Windchill and FlexPLM deployments to conduct data extortion (thehackernews.com).
5. The DevMan ransomware-as-a-service operation is using a centralized web portal to manage victim extortion and affiliate payouts (thehackernews.com).
6. Threat actors are leveraging data leaked by the ShinyHunters group to conduct sextortion campaigns demanding 2000 dollars in Bitcoin (bleepingcomputer.com).
7. A researcher published a proof-of-concept exploit for a remote code execution vulnerability in self-managed GitLab 18.11.3 servers (thehackernews.com).
8. The North Korean group BlueNoroff is using a sophisticated phishing kit to profile cryptocurrency wallets before delivering malware via impersonated Zoom and Microsoft Teams domains (thehackernews.com).
9. A new exploit named Certighost allows low-privileged Active Directory users to impersonate domain controllers and extract sensitive credentials (thehackernews.com).
10. A critical vulnerability in ChatGPT Workspace Agents known as AgentForger could have allowed attackers to deploy rogue autonomous AI agents within organizations (thehackernews.com).
11. Microsoft patched critical vulnerabilities in Bing Images that allowed crafted SVG files to execute commands with system privileges on production servers (thehackernews.com).
12. An attacker utilized the Hermes AI agent in an unattended mode to automate post-exploitation activities against the Thai Ministry of Finance (bleepingcomputer.com).
13. The Golden Chickens malware-as-a-service provider has launched four new malware families including modular implants and credential stealers (thehackernews.com).
14. OnTrac parcel delivery service confirmed a data breach involving unauthorized access to customer personal information (bleepingcomputer.com).
15. Attackers are hijacking hotel Wi-Fi DNS settings to redirect users to fraudulent Microsoft 365 login pages for credential theft (bleepingcomputer.com).
Be First to Comment