Hackers Use Fake Resumes to Steal Enterprise Credentials and Deploy Crypto Miner

An ongoing phishing campaign is targeting French-speaking corporate environments with fake resumes that lead to the deployment of cryptocurrency miners and information stealers.
“The campaign uses highly obfuscated VBScript files disguised as resume/CV… Continue reading Hackers Use Fake Resumes to Steal Enterprise Credentials and Deploy Crypto Miner

Posted in Uncategorized

U.S. Sentences Russian Hacker to 6.75 Years for Role in $9M Ransomware Damage

A 26-year-old Russian citizen has been sentenced in the U.S. to 6.75 years (81 months) in prison for his role in assisting major cybercrime groups, including the Yanluowang ransomware crew, in conducting numerous attacks against U.S. companies and othe… Continue reading U.S. Sentences Russian Hacker to 6.75 Years for Role in $9M Ransomware Damage

Posted in Uncategorized

Citrix Urges Patching Critical NetScaler Flaw Allowing Unauthenticated Data Leaks

Citrix has released security updates to address two vulnerabilities in NetScaler ADC and NetScaler Gateway, including a critical flaw that could be exploited to leak sensitive data from the application.
The vulnerabilities are listed below –

CVE-2026-… Continue reading Citrix Urges Patching Critical NetScaler Flaw Allowing Unauthenticated Data Leaks

Posted in Uncategorized

North Korean Hackers Abuse VS Code Auto-Run Tasks to Deploy StoatWaffle Malware

The North Korean threat actors behind the Contagious Interview campaign, also tracked as WaterPlum, have been attributed to a malware family tracked as StoatWaffle that’s distributed via malicious Microsoft Visual Studio Code (VS Code) projects.
The us… Continue reading North Korean Hackers Abuse VS Code Auto-Run Tasks to Deploy StoatWaffle Malware

Posted in Uncategorized

⚡ Weekly Recap: CI/CD Backdoor, FBI Buys Location Data, WhatsApp Ditches Numbers & More

Another week, another reminder that the internet is still a mess. Systems people thought were secure are being broken in simple ways, showing many still ignore basic advisories.
This edition covers a mix of issues: supply chain attacks hitting CI/CD se… Continue reading ⚡ Weekly Recap: CI/CD Backdoor, FBI Buys Location Data, WhatsApp Ditches Numbers & More

Posted in Uncategorized

We Found Eight Attack Vectors Inside AWS Bedrock. Here’s What Attackers Can Do with Them

AWS Bedrock is Amazon’s platform for building AI-powered applications. It gives developers access to foundation models and the tools to connect those models directly to enterprise data and systems. That connectivity is what makes it powerful – but it’s… Continue reading We Found Eight Attack Vectors Inside AWS Bedrock. Here’s What Attackers Can Do with Them

Posted in Uncategorized