Endpoint Security

Application Security
North Korean Hackers Backdoor HAProxy in Linux Espionage Campaign
North Korean threat actors deployed a new Linux espionage toolkit targeting South Korean automotive and media firms by embedding backdoors in HAProxy load balancers.
Application Security
Backdoored ScreenConnect Servers Deliver Worm-Like Payloads
Attackers compromised ConnectWise ScreenConnect servers to automatically deliver malicious payloads to newly connected clients in a self-propagating campaign.
Application Security
BigBear Phishing Service Bypassed MFA at 258 Organizations
BigBear 2.0 phishing-as-a-service framework stole over 5,000 Microsoft 365 credentials from 258 organizations using adversary-in-the-middle attacks.
Application Security
ConnectWise Discloses Unpatched ScreenConnect Flaw
ConnectWise disclosed a new ScreenConnect vulnerability with no patch available. The vendor shared temporary mitigations and plans a fix this week.
Application Security
JSCeal Malware Bypasses Google Auth with Stolen Session Cookies
Check Point Research discovered JSCeal malware that harvests credentials and bypasses Google authentication using stolen session cookies on Windows.
Application Security
REVSTEALER Modules Disable Windows Defender to Deploy Miner
Elastic Security Labs found four REVSTEALER persistence modules that remain after the stealer deletes itself, disabling Defender to run a crypto miner.
Application Security
Anthropic Warns Infostealer Malware Hijacking Claude Sessions
Anthropic warns Vidar, Lumma, StealC, RedLine, and AMOS malware are stealing Claude session tokens, enabling attackers to drain user credits fraudulently.
Application Security
AI Research Org METR Loses $600K in Credits to Dual Breach Attacks
METR disclosed two incidents where attackers stole API keys and consumed $600,000 in AI credits through fail-open authentication and targeted probing.
CVE Vulnerability Alerts
Russia-Aligned UAC-0099 Embeds Nuclear Weapon Text to Evade AI Tools
Russian threat actor UAC-0099 deployed GuardBreaker technique, inserting safety-sensitive phrases into malware to trip AI security analysis mechanisms.
Cybersecurity
Five Venezuelan Nationals Plead Guilty to Kansas ATM Jackpotting
Five Venezuelan nationals pleaded guilty to ATM jackpotting conspiracy following December 2025 arrests for Tren de Aragua malware operations in Kansas.