The Invisible Passenger in Your Car
The Invisible Passenger in Your Car đźš— While monitoring Android threats in June 2026, we discovered a new piece of Android malware. What struck us as unusual was that it installed like an ordinary ...
The Invisible Passenger in Your Car đźš— While monitoring Android threats in June 2026, we discovered a new piece of Android malware. What struck us as unusual was that it installed like an ordinary ...
SickKids Children’s Hospital Bandages Up Careers Website After Intruder Breaks In 🚨 Toronto’s Hospital for Sick Children, commonly referred to as SickKids, has reported that the data of current an...
New Agent Tesla Malware Variant Boosts Evasion Capabilities 🚀 A new version of the notorious Agent Tesla malware contains features designed to evade detection and steal credentials, as identified ...
Even MOAR Powershell: Analyzing Entra Logins One thing that folks never seem to do after “going to the CLOOOOUUUUD” is to look at their logs, logs that they would have checked daily when things we...
A Low-Tech Solution from the Past May Be Your Best Defense Against AI Deepfakes In January 2024, an employee at professional services firm Arup joined a video call with someone they believed inclu...
Trapping a Mustang Panda Source: IBM X-Force Date Published: August 20, 2026 As of mid-2026, IBM X-Force continues to monitor cyber campaigns conducted by ITG27, a China-aligned state-sponsored e...
Rust Supply Chain Attack on arrayref 🚨 On August 20, 2026, malicious versions of the arrayref Rust crate and others executed a backdoor at compile time. This campaign’s infrastructure overlaps wit...
Researcher Tricks Apple’s Find My into Sharing Location Data with Linux 🚀 A young security researcher, known as Zerotistic, has ingeniously figured out how to enroll a Linux device into Apple’s Fi...
Manic: The Android Malware That Exfiltrates Data Even When the Phone Is Offline Source: Securityaffairs Published on: August 20, 2026 🚨 Overview: Manic Android malware combines banking fraud and ...
Using Microsoft Graph and Powershell to Mine for Information - Stale Accounts and Licenses Microsoft Graph is a newer API that is meant to replace several others. It allows you to Get and Set info...
Distinct Clusters Target Individuals of Interest to Russia The Google Threat Intelligence Group (GTIG) is tracking three distinct suspected Russian cyber espionage threat clusters that are abusing...
BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive What if a signed Microsoft remediation driver could be instructed to execute arbitrary file and registry ope...
9 Million Images Exposed! 🚨 Researcher Jeremiah Fowler discovered a cloud database containing over 9 million image files accessible without authentication, as reported by WIRED. This leaky bucket,...
Benchmaxxing: When the Benchmark Becomes the Target Source: Crowdstrike Date Published: August 19, 2026 But the more attention a benchmark receives, the stronger the incentive to optimize for it....
Simple Scans for Cloud Metadata Service Cloud providers typically expose a REST API at 169.254.169.254 that allows code running on virtual machines to retrieve machine-specific data. Some of the d...
Australian Hotel Chain Leaks Guests’ PII After Breach 🚨 Important Security Update Regarding Your Quest Data 🚨 Australian aparthotel chain Quest has revealed it leaked customer data. A Reg reader ...
A New Era of Bulletproof Hosting Providers Emerge The demise of an old guard of dominant bulletproof hosting providers has given rise to a new era of upstarts – and a more fragmented competitive l...
What You Say During a Cyber Breach Can – and Will – Be Used Against You Cyber breach communications can become costly evidence 💰, making disciplined documentation and privilege practices essential...
Operation CameraSwarm: Over 14,000 Dahua Cameras Compromised Across Ukraine and Russia 🚨 Between 17 June and 22 July 2026, a single operator compromised over 14,000 Dahua IP cameras. The scanning ...
🚨 Critical Vulnerability in NASA’s Ground Control Software A significant vulnerability has been discovered in NASA’s open-source AMMOS Instrument Toolkit (AIT)-GUI ground software. This flaw could...