
PoeLLM Malware Hides C2 Addresses in GitHub Poems, Infects 3,000+
Lumen’s Black Lotus Labs says PoeLLM malware infected over 3,000 servers, hiding C2 addresses in poems on GitHub to mine

Lumen’s Black Lotus Labs says PoeLLM malware infected over 3,000 servers, hiding C2 addresses in poems on GitHub to mine

Dell fixed a critical path traversal, CVE-2026-86360, in its System Update CLI that lets unauthenticated remote attackers run code as

Google’s Android security bulletin for patch level 2026-10-01 fixes 25 vulnerabilities, seven of them critical, with no in-the-wild exploitation reported.

Microsoft Threat Intelligence says a new ClickFix variant hides a script in the browser cache as a PNG, sidestepping the

FortiGuard and Nozomi detail Cling, a Linux botnet that hides command traffic in STUN requests and exploits about two dozen

Microsoft says Russian state-backed group Star Blizzard used fake event invitations to install a Windows backdoor at more than 100

Academics disclosed a Spectre-v2 variant called BTR that bypasses existing mitigations and recovers Linux root password hashes on Intel systems

Threat actors use sponsored Google search ads for fake ChatGPT tools to run ClickFix attacks that trick victims into installing

Kiteworks discovered and patched a previously unknown critical flaw during a precautionary shutdown ordered after a federal warning of an

Apple patched CVE-2026-86950, an out-of-bounds write vulnerability in CoreGraphics exploited in extremely sophisticated targeted attacks reported by Meta.
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.