Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell

Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild.

The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has… Continue reading Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell→

Posted in Uncategorized

BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams

Cybersecurity researchers have disclosed details of a sprawling search engine optimization (SEO) poisoning campaign that paves the way for malware deployment and tech support scams.

The campaign, discovered by the DFIR Report in March 2026, has been c… Continue reading BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams→

Posted in Uncategorized

Grindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data Sharing

Online dating app Grindr has opted to pay £26 million ($35.1 million) to settle a lawsuit in the U.K. over allegations that it shared users’ personal information, including their HIV status, with third-parties.

Grindr, which is the largest LGBTQ+ dati… Continue reading Grindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data Sharing→

Posted in Uncategorized

PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution

Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser.

“Requiring prior administrative or code execution access, its installer i… Continue reading PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution→

Posted in Uncategorized

Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks

Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that’s targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-in-the-middle… Continue reading Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks→

Posted in Uncategorized

⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More

Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were … Continue reading ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More→

Posted in Uncategorized

Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts

Cybersecurity researchers have disclosed details of worm-like activity that abuses ConnectWise ScreenConnect to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems.

According to Huntress, three unrelated incidents … Continue reading Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts→

Posted in Uncategorized

Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

A TantoSec proof-of-concept turns an AES-CBC “padding oracle” in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against applications in a specific non-default configuration, and Progress patched the chain in July. The… Continue reading Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released→

Posted in Uncategorized

N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

Every on-premises N-central build below 2026.3.1.14 — including servers updated to Hotfix 3 a day earlier — needs Hotfix 4. N-able’s incident notice says the flaw has been exploited in the wild; its release notes say that is unconfirmed.

N-able has re… Continue reading N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw→

Posted in Uncategorized