Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages

A Chinese-speaking cybercrime cluster known as Gambling Goblin has been observed installing malicious Apache modules on compromised web servers run by Brazilian government and educational institutions, and using them to divert visitors to attacker-cont… Continue reading Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages

Posted in Uncategorized

BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access

Virtualizor said hackers used a Border Gateway Protocol (BGP) hijack to divert Softaculous traffic. The hackers then used the diverted update traffic to deliver a malicious Virtualizor package to some installations. A hosting-provider account separatel… Continue reading BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access

Posted in Uncategorized

Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control

Cybersecurity researchers have disclosed details of a new Android banking trojan called StreamRat that was promoted to Spanish-speaking users through a fake television-streaming campaign on Meta and can give operators near-complete control of infected … Continue reading Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control

Posted in Uncategorized

Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain

SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day attacks.

The vulnerabilities, discovered internally by SonicWall’s William P… Continue reading Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain

Posted in Uncategorized

GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends

Two vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog, which sits behind many government and agency geoportals.

The project shipped fixes in versions 4.4…. Continue reading GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends

Posted in Uncategorized

Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands

The U.S. Department of Justice (DoJ) has charged a Russian national, extradited from Cyprus on August 28, with using roughly 255 fake accounts on a freelance platform to send malware-laced Excel attachments to about 80,000 of its users in 2016 and 2017… Continue reading Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands

Posted in Uncategorized

Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another

Forescout Research – Vedere Labs said it used Anthropic’s Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another, executing attacker-supplied ARM shellcode on live ha… Continue reading Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another

Posted in Uncategorized

Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials

Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution.

The vulnerability in question is CVE-2026-9586 (CVSS score: 9.3), a critical unauth… Continue reading Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials

Posted in Uncategorized

Authorities Turn Sality’s P2P Network Against Itself, Cutting Off New Malware Payloads

The U.S. Department of Justice (DoJ) on Tuesday announced the takedown of a long-standing peer-to-peer (P2P) botnet known as Sality as part of a coordinated law enforcement operation.

The effort was undertaken on August 31, 2026, by authorities from t… Continue reading Authorities Turn Sality’s P2P Network Against Itself, Cutting Off New Malware Payloads

Posted in Uncategorized