Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts

South Korean authorities and four security firms have disclosed a state-sponsored campaign that compromised trusted domestic websites. The attackers used those sites to exploit locally installed financial-security software and infect targeted visitors … Continue reading Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts

Posted in Uncategorized

SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT

The Chinese cybercrime group known as Silver Fox has been observed using new drivers as part of bring your own vulnerable driver (BYOVD) attacks targeting a Japanese organization in the industrial manufacturing sector to ultimately deliver ValleyRAT (a… Continue reading SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT

Posted in Uncategorized

Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation

The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another vulnerability, this time in Microsoft Outlook Web Access (OWA), to target U.S. and European government entities… Continue reading Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation

Posted in Uncategorized

Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall Management Center (FMC) Software to its Known Exploited Vulnerabilities (KEV) catalog, following reports… Continue reading Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data

Posted in Uncategorized

Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads

Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads.

Tracked as CVE-2026-66066 (CVSS score: 9.5), the flaw ca… Continue reading Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads

Posted in Uncategorized

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution.

The vulnerability, tracked as C… Continue reading Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

Posted in Uncategorized

Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline

A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27, triggering a statewide cybersecurity response.

Braham, Plymouth, South St. Paul and Maple Plain have publicly described a pl… Continue reading Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline

Posted in Uncategorized