Overview of the First VPN Service π The Federal Bureau of Investigation (FBI) has released a FLASH report to share indicators of compromise (IOCs) and tactics related to the First VPN Service. Thi...
π¨ Important Security Alert! An attachment in an email impersonating DHL about a shipment contains a link to a preconfigured SimpleHelp remote access toolβan ideal starting point for attackers to e...
Sparkplug B Protocol Fuzzing with AI Assistance
Sparkplug B Protocol Fuzzing with AI Assistance π Source: Bishopfox Date Published: May 26, 2026 Sparkplug B is the dominant MQTT-based protocol in industrial control and SCADA environments, but ...
Silent Ransom Group Impersonating IT Personnel through Social Engineering
Silent Ransom Group Targeting Law Firms π¨ The Silent Ransom Group (SRG), also known as Luna Moth, Chatty Spider, and UNC3753, is actively targeting law firms through sophisticated social engineeri...
ABB LVS MConfig Vulnerability Advisory
ABB LVS MConfig Vulnerability Advisory ABB has identified an internally discovered vulnerability in the MConfig product. This vulnerability affects the following versions: LVS <= 1.4.9.21. An a...
The AI Era Is Creating a Bug Hunting Arms Race
The AI Era Is Creating a Bug Hunting Arms Race π Vulnerability disclosure and bug bounty programs have represented a paradigm shift years in the making. When Apple finally announced a bug bounty i...
Smart Contracts for C&C How ClearFake Hid in Plain Sight on BSC Testnet
Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet TrendAIβ’ Research has conducted an in-depth analysis of a sophisticated intrusion where threat actors utilized the Ethe...
Eppendorf BioFlo 320 Vulnerability Alert
Eppendorf BioFlo 320 Vulnerability Alert π¨ Source: CISA Date Published: May 26, 2026 A critical vulnerability has been identified in the Eppendorf BioFlo 320 bioreactor. Successful exploitation o...
Cloud Atlas APT Group Modifies termsrv.dll to Enable Multiple RDP Sessions
Cloud Atlas APT Group Modifies termsrv.dll to Enable Multiple RDP Sessions A well-known advanced persistent threat group called Cloud Atlas has been caught using a dangerous technique to hijack Wi...
Zero-Click WhatsApp Account Takeover Hits iPhone Users Running iOS 16
π¨ Zero-Click WhatsApp Account Takeover π¨ A zero-click attack targeting iPhones on iOS 16 has been reported, hijacking WhatsApp accounts without any linked devices, warnings, or user interaction. T...
The Alert Firehose Finally Meets Its Match
The Alert Firehose Finally Meets Its Match π Ask a cybersecurity pro about Network Detection and Response (NDR) and you might still hear terms like βNoisyβ or βToo much data.β However, teams utili...
Hacker Selling 340 Million OnlyFans User Records Built From Old Breaches
π¨ Major Data Breach Alert! π¨ A threat actor is advertising a massive database containing information linked to hundreds of millions of OnlyFans users, including both creators and subscribers. The ...
Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability
Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability In late 2025, Mandiant responded to a security incident involving a compromised web server running KnowledgeDeliver. Kn...
British Drivers Exposed After Mercedes Data Surfaces on Hacker Market
π¨ British Drivers Exposed After Mercedes Data Surfaces on Hacker Market Mercedes-Benz, the globally renowned German luxury automotive brand, may be the latest victim in a string of attacks against...
PyrsistenceSniper Advanced Tool for Detecting Malware Techniques
PyrsistenceSniper: Advanced Tool for Detecting Malware Techniques π PyrsistenceSniper is an advanced tool designed to detect offline persistence, enabling cybersecurity analysts to identify 117 se...
2026-05-24 Daily Vulns
npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks
npm Enhances Security with 2FA-Gated Publishing π GitHub has rolled out new controls for npm to improve the security of the software supply chain, giving maintainers the ability to explicitly appr...
Italy Disrupts CINEMAGOAL Piracy App That Stole Streaming Auth Codes
Italy Disrupts CINEMAGOAL Piracy App π¨ Italian authorities have dismantled a piracy ecosystem centered around the CINEMAGOAL app that provided access to various streaming platforms, including Netf...
An Example of Stack String in High Level Language
An Example of Stack String in High Level Language This week, Iβm attending the SEC670 training (Red Teaming Tools - Developing Windows Implants, Shellcode, Command and Control). From my perspectiv...
Megalodon Chums the Waters in 5.5K+ GitHub Repo Poisonings
Megalodon Chums the Waters in 5.5K+ GitHub Repo Poisonings π¨ A malware-spreading scumbag swimming through GitHub pushed malicious commits to more than 5,500 repositories on Monday as part of an au...