Nearly 300 GitHub repos pose as legit software to push malware
The campaign using nearly 300 fake GitHub repositories shows how attackers are abusing trust in open-source platforms to distribute malware at scale.The repositories impersonated legitimate software and security project…
Jul 15, 2026
SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now
SonicWall’s warning about SMA1000 vulnerabilities being exploited as zero-days shows once again why remote-access appliances must be treated as high-priority security assets.The flaws, tracked as CVE-2026-15409 and CVE-…
Jul 15, 2026
Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths
Microsoft’s mapping of year-long ShinyHunters-linked Salesforce attacks shows how SaaS compromise is increasingly about abusing trusted access rather than breaking the platform itself.The campaigns used three main paths…
Jul 14, 2026
New CrashStealer malware poses as Apple crash reporting tool
The CrashStealer macOS malware shows how attackers are abusing trusted-looking system prompts to steal sensitive data from Mac users.CrashStealer pretends to be Apple’s crash-reporting tool and uses fake password prompt…
Jul 14, 2026
Hackers backdoor Jscrambler npm package with infostealer malware
The Jscrambler npm package compromise highlights how dangerous a single malicious software release can be in the development supply chain.Attackers backdoored version 8.14.0 of the jscrambler npm package with infosteale…
Jul 14, 2026
Japan's largest taxi operator shuts systems after cyberattack
The cyberattack on Japan’s largest taxi operator highlights how digital disruption can quickly affect real-world transport operations.Nihon Kotsu disclosed that unauthorized access led to a malware infection, forcing th…
Jul 14, 2026
Lidl discloses online shop breach after service provider hack
The Lidl online shop breach highlights how third-party service providers can become the weak link in customer-data protection.Lidl disclosed that attackers accessed customer data through an external IT service provider …
Jul 13, 2026
iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days
The actively exploited iCagenda and Balbooa Forms vulnerabilities show how dangerous CMS extension flaws can become when they allow unauthenticated file uploads.Both vulnerabilities affect Joomla extensions and have bee…
Jul 13, 2026
Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365
The exposed phishing infrastructure shows how even attackers make basic security mistakes, and how much those mistakes can reveal about active campaigns.Researchers found that a misconfigured Python HTTP server left run…
Jul 13, 2026
RedHook Android malware now uses Wireless ADB for shell access
The latest RedHook Android malware variant shows how attackers are abusing legitimate developer features to gain deeper control over mobile devices.RedHook now uses Android Wireless Debugging, also known as wireless ADB…
Jul 13, 2026
Australia warns of global campaign targeting vulnerable CMS platforms
Australia’s warning about a global campaign targeting vulnerable CMS platforms highlights how attackers continue to exploit neglected websites at scale.The campaign is targeting known vulnerabilities in content manageme…
Jul 12, 2026
Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install
The compromised Jscrambler npm release shows how quickly a trusted software package can become a malware delivery channel.The affected jscrambler 8.14.0 release included a malicious preinstall hook that executed during …
Jul 12, 2026