Press "Enter" to skip to content

OSINT / CyberSec report 15.04.2026 00:08

1. A cluster of 108 malicious Google Chrome extensions was identified stealing user data and Telegram information from approximately 20000 users (thehackernews.com).

2. The critical ShowDoc remote code execution vulnerability CVE-2025-0520 is currently being actively exploited in the wild (thehackernews.com).

3. CISA added six vulnerabilities to its Known Exploited Vulnerabilities catalog including a critical SQL injection flaw in Fortinet FortiClient EMS tracked as CVE-2026-21643 (thehackernews.com).

4. Basic-Fit disclosed a significant data breach affecting the personal information of approximately 1 million members across several European countries (reddit.com/r/cybersecurity/comments/1skfevh).

5. Rockstar Games confirmed a data breach involving the developers of the upcoming GTA VI title (reddit.com/r/cybersecurity/comments/1skdx12).

6. A threat actor claimed to have stolen 10 petabytes of data from a Chinese supercomputing hub (reddit.com/r/cybersecurity/comments/1skiq7b).

7. The Los Angeles Police Department reported a data breach involving a digital storage system that exposed 7.7 terabytes of files (research.checkpoint.com/2026/13th-april-threat-intelligence-report).

8. A malicious website impersonating the official Claude domain was discovered distributing a remote access trojan to unsuspecting visitors (reddit.com/r/cybersecurity/comments/1skcruq).

9. JanelaRAT continues to target financial institutions in Latin America by stealing cryptocurrency data and logging keystrokes (thehackernews.com).

10. A vulnerability in the WordPress Google Authenticator plugin allows attackers to perform cross-site request forgery to overwrite 2FA secrets (reddit.com/r/cybersecurity/comments/1skw31d).

11. Anthropic restricted public access to its Claude Mythos Preview model due to concerns regarding its potential for facilitating cyberattacks (schneier.com/blog/archives/2026/04/on-anthropics-mythos-preview-and-project-glasswing.html).

12. Security researchers noted that a private company has acquired powerful zero-day exploits for a wide range of common software projects (reddit.com/r/Malware/comments/1sl442h).

Be First to Comment

Leave a Reply

Your email address will not be published. Required fields are marked *