Attackers Abuse LiveChat to Phish Credit Card, Personal Data
Criminals impersonate support on fake live chat to steal payment cards via social engineering and urgency tactics. They exploit user trust in official customer support interactions.
ACTIVE THREATS: Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers • AI-powered attack exploited PaperCut flaws to hack 395 organizations • Microsoft Excel KB5002914 update breaks copy and paste for some users • Surfshark VPN says hackers breached internal testing, proxy servers • PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances ACTIVE THREATS: Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers • AI-powered attack exploited PaperCut flaws to hack 395 organizations • Microsoft Excel KB5002914 update breaks copy and paste for some users • Surfshark VPN says hackers breached internal testing, proxy servers • PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances
Latest cybersecurity vulnerabilities news, analysis, and intelligence.
Criminals impersonate support on fake live chat to steal payment cards via social engineering and urgency tactics. They exploit user trust in official customer support interactions.
MacSync infostealer spreads through ClickFix campaigns disguised as AI tool installers, using social engineering and fake security alerts to trick users into running malicious commands on macOS systems.
Microsoft removed Samsung Galaxy Connect from its Store after the app blocked access to Windows C: drives on Galaxy Book 4 systems. The incident reveals gaps in vetting device management tools.
A global Microsoft Exchange Online outage disrupted email and calendar access across industries. The incident exposed organizational reliance on cloud services and highlighted critical gaps in disaster recovery planning.
DRILLAPP backdoor targets Ukrainian organizations using Microsoft Edge debugging features to evade detection. The Russian-linked malware maintains persistence via legitimate developer tools for command-and-control communications.
Twitter suspended 800M accounts for spam, yet state-backed disinformation campaigns persist openly. This reveals suspension volume alone doesn't suppress platform manipulation effectively.
Threat actors are selling unauthorized access to thousands of unpatched surveillance cameras. They exploit default credentials and brute-force attacks, then resell access on dark web marketplaces.
0ktapus phishing spoofed Okta to compromise 130+ organizations. Using fake authentication emails, attackers stole credentials for ransomware and data theft across finance, tech, and healthcare sectors.
Trane Tracer building management systems contain critical vulnerabilities (CVSS 8.1) in cryptographic and memory handling, allowing unauthorized access to building automation controlling HVAC, lighting, and security systems.
A critical Siemens S7-1500 vulnerability enables code execution through malicious trace files via social engineering. Attackers exploit legitimate diagnostic workflows to compromise industrial infrastructure globally.
CISA flagged two exploited Google flaws—CVE-2026-3909 (Skia) and CVE-2026-3910 (V8). Attackers are actively weaponizing these browser vulnerabilities across government and critical infrastructure.
HPE AOS-CX networking platform contains a critical authentication bypass allowing unauthenticated attackers to remotely reset admin credentials. The vulnerability provides immediate administrative access without requiring valid credentials or prior system compromise, exposing millions of network dev
Vulnerability exploitation now dominates Google Cloud attacks over credential theft. Attackers exploit flaws faster than organizations patch, leveraging automation and zero-day stockpiles.
AI smartphone phishing defenses fail against targeted attacks, Omdia research shows. Attackers evolve faster than detection systems, using social engineering and technical evasion techniques.
Nonprofits face rising cyberattacks despite being mission-driven. Limited security budgets and access to sensitive donor data make them attractive targets for ransomware gangs and other threat actors.
Nonprofits face frequent cyberattacks but rarely report them, creating a data gap in threat intelligence. These organizations are attractive targets due to valuable data and limited security resources.
Microsoft patched a critical RRAS remote code execution vulnerability in Windows 11 Enterprise through an emergency hotpatch, allowing attackers to execute arbitrary code with elevated privileges. The severity triggered an out-of-band release bypassing the standard patch cycle for immediate deployme
** Starkiller is a new phishing-as-a-service platform that proxies real login pages in real time, capturing credentials and session tokens to bypass MFA. Only FIDO2/passkeys resist this attack.
Attackers hijacked AppsFlyer's Web SDK, injecting malware to steal cryptocurrency from affected users and organizations. The supply chain compromise reveals the massive risk when trusted software becomes weaponized—exposing thousands of dependent systems to attack.
Kimwolf, built from a weaponized vulnerability by operator "Dort," became the largest botnet ever. Dort escalated from cyber attacks to real-world violence against researchers, forcing law enforcement intervention.
March's 77 Microsoft patches span Windows, Office, and Edge with no active zero-days. Yet the broad attack surface—from RCE to privilege escalation—requires urgent prioritization.
Microsoft is investigating a critical C: drive access issue on Samsung Windows 11 laptops following February 2026 updates. Affected systems cannot access the drive or launch applications, with the problem appearing limited to specific Samsung configurations.
Threat actor Storm-2561 distributes counterfeit VPN clients impersonating Ivanti, Cisco, and Fortinet to steal enterprise credentials. Spread via phishing emails and fraudulent download sites, the malware silently harvests logins before displaying error messages to maintain the deception.
Law enforcement sinkholed 45,000 IP addresses and seized servers in Operation Synergia III, one of the largest cybercrime infrastructure takedowns on record. The coordinated global operation redirects malicious traffic to law enforcement-controlled systems to identify victims and gather forensic evi
Microsoft is investigating widespread synchronization failures in classic Outlook affecting enterprises. Beyond productivity disruption, users may resort to unauthorized workarounds that could compromise system security. (164 characters, 2 sentences)
Law enforcement dismantled SocksEscort, a botnet controlling 369,000 residential routers across 163 countries used to anonymize criminal fraud schemes. Attackers exploited the compromised home devices as proxy exit nodes, making illicit traffic appear to originate from legitimate ISP customers.
Nine "CrackArmor" vulnerabilities in Linux AppArmor allow unprivileged users to escalate to root and escape containers by exploiting confused deputy flaws in the access control system, threatening cloud infrastructure and containerized workloads.
Google patched two actively exploited Chrome zero-days: Skia graphics flaw (CVE-2026-3909, CVSS 8.8) enabling arbitrary code execution and a V8 JavaScript sandbox escape. Both require minimal user interaction—simply visiting a malicious website can trigger the vulnerabilities.
Google released emergency patches for two Chrome zero-days already being exploited in real-world attacks. These remotely-triggerable browser vulnerabilities pose an immediate critical threat, requiring users to update immediately to avoid compromise through malicious websites.
Google paid $17.1M to 747 researchers in 2025 for vulnerability reports, showing how tech companies depend on external security expertise. Bug bounties are now essential to modern defense.