Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters

Microsoft is alerting of a “high-volume phishing campaign” that’s using invisible Unicode tag characters to bypass email filters.

“Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used t… Continue reading Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters

Posted in Uncategorized

PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution

PostgreSQL has released updates to address a security flaw that allows an account with the REPLICATION attribute to run arbitrary code as the operating-system user running the database server.

The flaw, tracked as CVE-2026-6471 (CVSS score: 7.2), has … Continue reading PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution

Posted in Uncategorized

New Ted Backdoor Hides Inside Victims’ Own HAProxy Builds to Intercept Web Traffic

A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors.

The attackers named … Continue reading New Ted Backdoor Hides Inside Victims’ Own HAProxy Builds to Intercept Web Traffic

Posted in Uncategorized

Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence.

The vulnerabilities in question are –

CVE-2026-14894 (CVSS score: 9.8) – A missing file type validat… Continue reading Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

Posted in Uncategorized

Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws

Plex is urging users to update their instances to the latest version following the release of an update that patches multiple security flaws.

The fixes are available in Plex Media Server 1.43.3 and Plex Desktop 1.115.0. The streaming media service did… Continue reading Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws

Posted in Uncategorized

GPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit Requests

OpenAI on Thursday officially unveiled GPT‑6 Astra, which it described as the “world’s most intelligent and aligned model.”

The development comes days after the artificial intelligence (AI) company said the model had reached the “Critical” cybersecuri… Continue reading GPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit Requests

Posted in Uncategorized

ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories

The worst part is how normal these attacks look. A call from IT. A shared file. A trusted app. A simple request to click “Allow.” Why break in when someone might open the door?

That idea runs through this edition. Attackers use real tools, fake login … Continue reading ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories

Posted in Uncategorized

Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7 umbrella CV… Continue reading Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

Posted in Uncategorized

BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory

Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts.

“Unlike the standard infostealer model, BraZe… Continue reading BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory

Posted in Uncategorized