News

Application Security
Thousands of Scam Apps Exploit Google Play Early Access Program
Malicious developers abuse Google Play's Early Access program to push thousands of deceptive Android apps promising money, rewards, and premium content that do not deliver.
Cybersecurity
Four Nation-State Groups Deploy BlueMoon Kit Within 12 Days
APT31 and three additional nation-state actors deployed the BlueMoon exploit kit chaining Chrome and Windows zero-days within a two-week window, with researchers suspecting AI assistance.
Cybersecurity
NSA, CISA, FBI Accuse Six Chinese AI Firms of Model Distillation
US intelligence agencies accuse DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI of extracting billions of tokens from OpenAI, Anthropic, Google, and SpaceX at industrial ...
Application Security
UNC3569 Exploits Sogou Input Method to Deploy GRAYRABBIT Backdoor
China-linked UNC3569 exploited a vulnerability in Tencent's Sogou Input Method, one of the most widely used Chinese typing tools for Windows, to install GRAYRABBIT backdoor ...
Application Security
Attackers Use BYOD Weaknesses to Access M365 via Graph API
Threat actors exploit BYOD gaps through vishing to gain M365 access, then use Microsoft Graph API to enumerate corporate structure and identify targets for extortion ...
Cybersecurity
Surfshark VPN Breach Exposes Internal Testing and Proxy Servers
Surfshark disclosed that hackers accessed internal test servers and proxy infrastructure after a configuration error exposed testing systems to the public internet on September 10.
Application Security
Citrix NetScaler CVE-2026-19490 Exploited Since September 3
Critical authentication bypass vulnerability CVE-2026-19490 in Citrix NetScaler has been actively exploited since September 3, enabling unauthenticated attackers to bypass authentication controls.
CVE Vulnerability Alerts
CISA Sets September 12 Deadline for Cisco, Citrix, Fortinet Flaws
CISA added three actively exploited vulnerabilities in Cisco, Citrix, and Fortinet products to its KEV catalog on September 10, requiring federal agencies to patch by ...
Application Security
Infostealer Logs Expose Replayable AI Tokens That Bypass MFA
Cybercriminals harvest AI session tokens from infostealer malware logs to hijack Google, Anthropic, and OpenAI accounts, bypassing MFA through token replay attacks published September 9.
Application Security
Google Patches Seventh Chrome Zero-Day of 2026, CVE-2026-87491
Google released Chrome security update on September 9 patching CVE-2026-87491, an out-of-bounds write in V8 engine — the seventh actively exploited Chrome zero-day of 2026.