Press "Enter" to skip to content

Posts tagged as “phishing”

OSINT / CyberSec report 31.05.2026 00:07

1. Palo Alto Networks confirmed that CVE-2026-0257, an authentication bypass vulnerability in PAN-OS and Prisma Access, is currently under active exploitation (thehackernews.com). 2. Dutch authorities successfully dismantled a massive botnet consisting of 17 million infected devices and seized over 200 associated servers (bleepingcomputer.com). 3. A Russian-linked threat actor named GREYVIBE has been identified conducting persistent AI-powered cyberattacks against Ukrainian entities since August 2025 (thehackernews.com). 4.…

OSINT / CyberSec report 29.05.2026 00:08

1. A new phishing campaign targeting Japanese online banking users is utilizing a domain and branding typo related to PayPoy (https://www.reddit.com/r/cybersecurity/comments/1tpvisr/new_phishing_campaign_targeting_japanese_online/). 2. Threat actor JINX-0164 is targeting cryptocurrency firms using fake recruiter lures and custom macOS malware to facilitate asset theft (https://thehackernews.com/2026/05/jinx-0164-targets-cryptocurrency-firms.html). 3. A malicious npm package named mouse5212-super-formatter was discovered stealing files from the local directory used by the Claude AI tool (https://thehackernews.com/2026/05/malicious-npm-package-stole-files-from.html). 4.…

OSINT / CyberSec report 27.05.2026 00:08

1. The ShinyHunters extortion group breached 7-Eleven systems and leaked a 9.4GB database containing personal information of over 183,000 individuals (BleepingComputer). 2. Threat actors are actively exploiting a critical SQL injection vulnerability in Ghost CMS, tracked as CVE-2026-26980, to compromise over 700 websites (The Hacker News). 3. CISA has issued an emergency directive for U.S. federal agencies to patch an actively exploited SQL injection vulnerability…

OSINT / CyberSec report 21.05.2026 00:07

1. GitHub is investigating a breach of approximately 3800 internal repositories after an employee installed a malicious VS Code extension (The Hacker News). 2. Microsoft released a mitigation for the YellowKey BitLocker bypass vulnerability tracked as CVE-2026-45585 (The Hacker News). 3. Grafana Labs confirmed a breach of its internal GitHub environment involving source code, though customer production systems remain unaffected (The Hacker News). 4. The…

OSINT / CyberSec report 19.05.2026 00:08

1. A critical heap buffer overflow vulnerability in NGINX tracked as CVE-2026-42945 is being actively exploited in the wild to cause worker crashes and potential remote code execution (The Hacker News). 2. Security researcher Chaotic Eclipse released a proof of concept for a Windows zero day exploit named MiniPlasma that grants attackers SYSTEM privileges on fully patched systems (Bleeping Computer). 3. The Tycoon2FA phishing kit…

OSINT / CyberSec report 17.05.2026 00:06

1. Microsoft Exchange and Windows 11 were successfully compromised by researchers using zero day vulnerabilities during the Pwn2Own Berlin 2026 event (bleepingcomputer.com). 2. The Funnel Builder WordPress plugin is being actively exploited to inject malicious JavaScript into WooCommerce checkout pages to steal credit card data (bleepingcomputer.com). 3. A critical supply chain attack targeting the TanStack library impacted two OpenAI employee devices, prompting immediate security containment…

OSINT / CyberSec report 13.05.2026 00:09

1. A mass npm supply chain attack involving the Mini Shai-Hulud worm has compromised over 170 packages including TanStack and Mistral AI. (https://thehackernews.com/2026/05/mini-shai-hulud-worm-compromises.html) 2. Instructure reached an agreement with the ShinyHunters extortion group to prevent the leak of 3.65TB of stolen data. (https://thehackernews.com/2026/05/instructure-reaches-ransom-agreement.html) 3. A rogue version of the official Checkmarx Jenkins plugin was published on the Jenkins Marketplace containing an infostealer. (https://www.bleepingcomputer.com/news/security/official-checkmarx-jenkins-package-compromised-with-infostealer/) 4. A…

OSINT / CyberSec report 05.05.2026 00:08

1. Instructure confirmed a data breach involving its Canvas platform with the ShinyHunters extortion gang claiming responsibility for the attack (bleepingcomputer.com). 2. An IBM subsidiary responsible for managing Italian public administration infrastructure suffered a breach where attackers maintained access for two weeks (reddit.com). 3. A critical cPanel vulnerability is being mass exploited in ongoing Sorry ransomware attacks (reddit.com). 4. A global law enforcement operation involving…

OSINT / CyberSec report 03.05.2026 00:06

1. Trellix confirmed a security breach involving unauthorized access to a portion of its internal source code repository (thehackernews.com). 2. A Vietnamese-linked operation named AccountDumpling compromised 30,000 Facebook accounts using Google AppSheet as a phishing relay (thehackernews.com). 3. China-linked threat group SHADOW-EARTH-053 is conducting an espionage campaign targeting government and defense sectors across Asia and a NATO member state (thehackernews.com). 4. Cybercrime groups Cordial Spider…

OSINT / CyberSec report 29.04.2026 00:08

1. Microsoft confirmed active exploitation of the Windows Shell spoofing vulnerability CVE 2026 32202 (The Hacker News). 2. A Chinese national linked to the Silk Typhoon threat group was extradited to the United States for cyberattacks against government agencies (The Hacker News). 3. French authorities arrested a 21 year old hacker known as HexDex for approximately 100 data breaches including the French Ministry of National…