“Eye” Spy: Cyclops Blink Returns with Extended Capabilities 🚀 In August 2026, Counter Threat Unit™ (CTU) researchers analyzed a malicious 64-bit Linux executable named timezone_check that was disc...
Overview Earlier this month, security sleuth and researcher “Chaotic Eclipse” (also known as Nightmare-Eclipse) published a zero-day exploit known as YellowKey, which allowed them to access BitLoc...
Overview of the First VPN Service 🚀 The Federal Bureau of Investigation (FBI) has released a FLASH report to share indicators of compromise (IOCs) and tactics related to the First VPN Service. Thi...
🚨 Important Security Alert! An attachment in an email impersonating DHL about a shipment contains a link to a preconfigured SimpleHelp remote access tool—an ideal starting point for attackers to e...
Star Blizzard Refines Phishing And Malware Delivery With The Redflick Technique
Star Blizzard Refines Phishing And Malware Delivery With The Redflick Technique 🚀 Source: Microsoft Date Published: September 29, 2026 STAR BLIZZARD (also known as APT29 or Nobelium) has signific...
Multiple Vulnerabilities in Pgpool-II
Multiple Vulnerabilities in Pgpool-II 🚨 Pgpool-II, provided by the Pgpool Global Development Group, has been found to contain multiple vulnerabilities, as reported under JVN#22475874 and published...
Multiple Vulnerabilities in Image Scanner Driver for Linux
Multiple Vulnerabilities in Image Scanner Driver for Linux 🚨 The Image Scanner Driver for Linux, provided by PFU Limited, contains multiple vulnerabilities that could affect your system. These vul...
Fake iPhone Duo Preorder Scam Triggers DarkSword Attack
Fake iPhone Duo Preorder Scam Triggers DarkSword Attack 🚨 A new scam has emerged that mimics a preorder page for the iPhone Duo, designed to exploit vulnerabilities in iPhones using the leaked Dar...
Cloudflare Announces Public Certificate Authority for the Post-Quantum Web
Cloudflare Announces Public Certificate Authority for the Post-Quantum Web 🚀 Cloudflare, Inc. (NYSE: NET) today announced its intent to become a public Certificate Authority (CA), an open service ...
CVE-2026-94204 - Incorrect Permission Assignment for Critical Resource in Viidure Dashcam Android Application
CVE-2026-94204 - Incorrect Permission Assignment for Critical Resource in Viidure Dashcam Android Application CVE-2026-94204 highlights a critical vulnerability in the Viidure Dashcam Android Appl...
CVE-2026-93853 - Barman Snapshot Backup Deletion Vulnerability
CVE-2026-93853 - Barman Snapshot Backup Deletion Vulnerability Date Published: September 29, 2026 A critical vulnerability has been identified in Barman snapshot backup deletion that allows unver...
Baicells Nova 430H Vulnerability Advisory
Baicells Nova 430H Vulnerability Advisory Date Published: September 29, 2026 Source: CISA A critical vulnerability has been identified in the Baicells Nova 430H eNodeB (model pBS3101SH) that coul...
2026-09-29 Daily Vulns
NEW: CVE vendor-product description metric Referenceurl title GithubURL CVE-2026-52744 gocd - gocd GoCD...
NeedyMantis Unpacking a Post-Compromise Malware Family
NeedyMantis: Unpacking a Post-Compromise Malware Family Microsoft Threat Intelligence has identified NeedyMantis, a modular post-compromise malware family observed in a limited number of targeted ...
Why I Find Linux Keyrings Actually Very Useful 5 Reasons
Why I Find Linux Keyrings Actually Very Useful: 5 Reasons If you’ve used Linux, your desktop may have reminded you to set up your keyring. Keyring apps, such as KDE Wallet or Seahorse (GNOME), aut...
Times Car Confirms Data Breach Affecting 6.6 Million User Accounts
Times Car Confirms Data Breach Affecting 6.6 Million User Accounts 🚨 Japanese car-sharing service Times Car has confirmed that approximately 6.6 million user accounts were compromised in a cyberat...
Over 16,000 Supabase Databases Expose PII, Passwords, Auth Tokens
Over 16,000 Supabase Databases Expose PII, Passwords, Auth Tokens 🚨 Researchers have discovered that over 16,000 misconfigured Supabase databases are exposing readable tables containing personally...
Former US Soldier Sentenced for Hacking and Extortion Scheme
Former US Soldier Sentenced for Hacking and Extortion Scheme Cameron John Wagenius, 22, a former Army soldier, was sentenced today to 70 months in prison and ordered to pay $294,978 in restitution...
Russian Tech Surveillance Company Infiltrated Europe's Law Enforcement Agencies
Russian Tech Surveillance Company Infiltrated Europe’s Law Enforcement Agencies A U.S.-based data-extraction firm accused of being secretly run from Russia has worked on EU-backed projects and sol...
Kothamine Malware Uses Tailscale's Tailcat to Evade Network Detection
Kothamine Malware Uses Tailscale’s Tailcat to Evade Network Detection 🚨 We discovered an undocumented remote-access Trojan (RAT) called Kothamine Agent. It supports more than 30 commands and gives...