China-Linked GopherWhisper Infects 12 Mongolian Government Systems with Go Backdoors

Mongolian governmental institutions have emerged as the target of a previously undocumented China-aligned advanced persistent threat (APT) group tracked as GopherWhisper.
“The group wields a wide array of tools mostly written in Go, using injectors and… Continue reading China-Linked GopherWhisper Infects 12 Mongolian Government Systems with Go Backdoors

Posted in Uncategorized

Apple Patches iOS Flaw That Stored Deleted Signal Notifications in FBI Forensic Case

Apple has rolled out a software fix for iOS and iPadOS to address a Notification Services flaw that stored notifications marked for deletion on the device.
The vulnerability, tracked as CVE-2026-28950 (CVSS score: N/A), has been described as a logging … Continue reading Apple Patches iOS Flaw That Stored Deleted Signal Notifications in FBI Forensic Case

Posted in Uncategorized

Malicious KICS Docker Images and VS Code Extensions Hit Checkmarx Supply Chain

Cybersecurity researchers have warned of malicious images pushed to the official “checkmarx/kics” Docker Hub repository.
In an alert published today, software supply chain security company Socket revealed that unknown threat actors managed to have over… Continue reading Malicious KICS Docker Images and VS Code Extensions Hit Checkmarx Supply Chain

Posted in Uncategorized

Self-Propagating Supply Chain Worm Hijacks npm Packages to Steal Developer Tokens

Cybersecurity researchers have flagged a fresh set of packages that have been compromised by bad actors to deliver a self-propagating worm that spreads through stolen developer npm tokens.
The supply chain worm has been detected by both Socket and Step… Continue reading Self-Propagating Supply Chain Worm Hijacks npm Packages to Steal Developer Tokens

Posted in Uncategorized

Harvester Deploys Linux GoGra Backdoor in South Asia Using Microsoft Graph API

The threat actor known as Harvester has been attributed to a new Linux version of its GoGra backdoor deployed as part of attacks likely targeting entities in South Asia.
“The malware uses the legitimate Microsoft Graph API and Outlook mailboxes as a co… Continue reading Harvester Deploys Linux GoGra Backdoor in South Asia Using Microsoft Graph API

Posted in Uncategorized

Microsoft Patches Critical ASP.NET Core CVE-2026-40372 Privilege Escalation Bug

Microsoft has released out-of-band updates to address a security vulnerability in ASP.NET Core that could allow an attacker to escalate privileges.
The vulnerability, tracked as CVE-2026-40372, carries a CVSS score of 9.1 out of 10.0. It’s rated Import… Continue reading Microsoft Patches Critical ASP.NET Core CVE-2026-40372 Privilege Escalation Bug

Posted in Uncategorized

Mustang Panda’s New LOTUSLITE Variant Targets India Banks, South Korea Policy Circles

Cybersecurity researchers have discovered a new variant of a known malware called LOTUSLITE that’s distributed via a theme related to India’s banking sector.
“The backdoor communicates with a dynamic DNS-based command-and-control server over HTTPS and … Continue reading Mustang Panda’s New LOTUSLITE Variant Targets India Banks, South Korea Policy Circles

Posted in Uncategorized