Endpoint Security

Cybersecurity
Russia’s Star Blizzard Targets 100+ Orgs With Fake Invites
Microsoft says Russian state-backed group Star Blizzard used fake event invitations to install a Windows backdoor at more than 100 Ukraine-linked organizations.
Cybersecurity
New Spectre-v2 BTR Attack Leaks Linux Root Password Hashes
Academics disclosed a Spectre-v2 variant called BTR that bypasses existing mitigations and recovers Linux root password hashes on Intel systems in minutes.
Cybersecurity
Fake ChatGPT Custom GPTs Push ClickFix Attacks to Drop RAT
Threat actors use sponsored Google search ads for fake ChatGPT tools to run ClickFix attacks that trick victims into installing remote access trojan malware.
Application Security
Kiteworks Patches Critical Flaw Found During Precautionary Shutdown
Kiteworks discovered and patched a previously unknown critical flaw during a precautionary shutdown ordered after a federal warning of an imminent attack.
Application Security
Apple Patches CoreGraphics Zero-Day Used in Targeted Attacks
Apple patched CVE-2026-86950, an out-of-bounds write vulnerability in CoreGraphics exploited in extremely sophisticated targeted attacks reported by Meta.
Cybersecurity
Ransomware Attack Disrupts Keio Corporation Business Systems
Keio Corporation confirmed a ransomware attack disrupted business systems over the weekend. Railway operations continued but administrative functions impacted.
Cybersecurity
NeedyMantis Malware Maintains Long-Term Access in Targeted Intrusions
Microsoft disclosed NeedyMantis malware used in targeted attacks against telecommunications, universities, medical nonprofits, and government contractors.
Cybersecurity
RatHat Android Trojan Uses Gemini AI to Identify High-Value Victims
RatHat malware-as-a-service banking trojan analyzes stolen Android data with Google Gemini AI to prioritize victims with higher financial value.
Infostealer Logs Expose AI Credentials from 80,000+ Organizations
Cybersecurity
Infostealer Logs Expose AI Credentials from 80,000+ Organizations
Stolen infostealer data exposed AI service credentials from over 80,000 corporate domains, enabling account takeover and LLMjacking attacks.
Application Security
Carbonato Botnet Hijacks Docker Hosts to Deploy Telegram-Controlled AI
Carbonato malware installs Hermes Agent AI framework on exposed Docker daemons, then controls the agent via Telegram with a modified 39-line prompt.