News

Cybersecurity
Gamaredon Hides USB Worm in NTFS Alternate Data Streams
Sekoia documents an active Gamaredon campaign using NTFS Alternate Data Streams to conceal USB worm modules targeting Ukrainian government networks.
Cybersecurity
PureLogs Infostealer Uses MSBuild.exe for Fileless Deployment
FortiGuard Labs documents PureLogs infostealer delivered via fake purchase order emails, using MSBuild.exe process hollowing to execute entirely in memory.
Cybersecurity
PSNI Phone Number Spoofed in Gift Card Vishing Campaign
Scammers have spoofed the PSNI's official switchboard number to impersonate officers and pressure victims into buying gift cards in a vishing campaign.
Cybersecurity
GTA Cheat Service Atlas Menu Hacked; 64,000 Records Exposed
Atlas Menu, a paid GTA Online cheat service, was breached and 64,000 user records published on GitHub, with the attacker alleging spyware behavior.
Cybersecurity
5,000 Election Phishing Domains Pre-Stage US Midterm Attacks
Over 5,000 election-themed domains registered between April and May 2026 form phishing infrastructure targeting voters, campaign staff, and election workers.
Cybersecurity
UPDATE: Dashlane Confirms Encrypted Vaults Downloaded in Attack
Dashlane now confirms attackers downloaded encrypted password vaults from fewer than 20 accounts by brute-forcing 2FA codes to register unauthorized devices.
Cybersecurity
ShadowByt3$ Ransomware Hits Syngenta’s Cropwise Platform
ShadowByt3$ ransomware claims unauthorized access to Cropwise, Syngenta's precision agriculture platform, stealing GIS data, yield models, and API keys.
Cybersecurity
TheGentlemen Ransomware Lists US Water Utility Suburban Water
TheGentlemen ransomware posted Suburban Water, a US critical infrastructure water utility, among 14 victims across five sectors in a 46-minute window.
CVE Vulnerability Alerts
NIST Inspector General: NVD Backlog Hits 27,000 CVEs
A NIST Inspector General report finds the NVD backlog has grown to over 27,000 unprocessed CVEs, degrading enterprise vulnerability management programs.
Application Security
IBM WebSphere CVE-2026-8633: CVSS 9.8 No-Auth RCE Flaw Patched
CVE-2026-8633 is a CVSS 9.8 unauthenticated RCE in IBM WebSphere's Web Server Plug-ins. Patches are available for WebSphere 8.5 and 9.0 and Liberty builds.