IPCola A Tangled Mess
On September 4th 2023, the user “ipmakers” posted a thread on the Proxies for Sale section of BlackHatWorld. This thread promoted the launch of ipcola[.]com, a new proxy service claiming to have mi...
On September 4th 2023, the user “ipmakers” posted a thread on the Proxies for Sale section of BlackHatWorld. This thread promoted the launch of ipcola[.]com, a new proxy service claiming to have mi...
Google has released the December 2025 Android security bulletin, addressing 107 vulnerabilities, including two flaws actively exploited in targeted attacks. The two high-severity vulnerabilities a...
The Everest ransomware group has announced a claimed compromise of ASUS, a major global hardware and electronics manufacturer. According to a post on the group’s dark web leak site, they assert pos...
The personal data of more than 33 million customers was leaked in a breach believed to have started on June 24 through overseas servers, though the company did not learn of the problem until Novemb...
Law enforcement officers from Switzerland and Germany have taken down the Cryptomixer cryptocurrency-mixing service, believed to have helped cybercriminals launder over €1.3 billion in Bitcoin sinc...
Today we’re taking a look at several malware samples from the advanced persistent threat group “Primitive Bear” aka “Gamaredon”. Primitive Bear is a Russian state-sponsored Advanced Persistent Thr...
The Glassworm malware campaign, initially identified in October, has resurfaced for a third time, introducing 24 new malicious packages to the OpenVSX and Microsoft Visual Studio marketplaces. Thes...
Recent analysis has exposed two Chinese technology companies, BIETA and CIII, that allegedly provide sophisticated steganography solutions to support advanced persistent threat campaigns.\n\nAnalys...
During testing, we found that Codex CLI will automatically load and execute MCP server entries from a project-local configuration whenever codex is run inside that repository. Concretely, if a repo...
The fake sites were identified by their suspicious resource usage and recurring templates. This operation includes two main groups: one with over 750 interconnected sites, 170 of which impersonate ...
North Korea-linked threat actors added 197 new malicious npm packages to spread updated OtterCookie malware as part of the ongoing Contagious Interview campaign, cybersecurity firm Socket warns. T...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has updated its Known Exploited Vulnerabilities (KEV) catalog to include a security flaw impacting OpenPLC ScadaBR, citing evidence ...
NEW: CVE vendor-product description metric Referenceurl title GithubURL CVE-2019-25226 Dongyoung Media Tech C...
The ShadowV2 botnet, based on Mirai, has resurfaced, targeting IoT devices across industries. Fortinet assesses that a recent campaign coinciding with an AWS outage in late October 2025 was likely ...
A new campaign, dubbed Shai-hulud 2.0, has been identified targeting cloud and developer ecosystems with a sophisticated malware variant. This updated version builds upon its predecessor by stealin...
Google’s Antigravity, an AI agent development tool released on November 18th, is facing scrutiny due to newly discovered vulnerabilities. Security researchers are cautioning app developers about th...
If the domain hosting the calendar is abandoned and subsequently expires, it opens a dangerous vulnerability. Cybercriminals can re-register these expired domains, effectively hijacking the trust e...
Earlier this month, the Anthropic report assessed with high confidence that a state-sponsored cyber actor backed by the PRC executed an autonomous attack against the U.S. company using AI with mini...
GitLab’s Vulnerability Research team has uncovered a large-scale supply chain attack spreading a destructive malware variant through the npm ecosystem. Once running, the malware aggressively harve...
Bloody Wolf, an actor active since at least late 2023, is expanding its operations in Central Asia, now targeting Kyrgyzstan and Uzbekistan with the NetSupport RAT. The group has been active since ...