New BTMOB Android Malware Enables Full Device Takeover
BTMOB is a $5,000 Android RAT sold as a service, enabling device compromise. Distributed via phishing with a customizable APK builder, it lets non-technical operators launch attacks globally.
ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks • How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts • The US military just turned off ad tracking on its phones. Maybe you should too • Hackers exploit Tencent app flaw to deploy GrayRabbit malware • CRPx0 ransomware: what you need to know ACTIVE THREATS: CISA: Hackers now exploit max severity GitLab flaw in attacks • How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts • The US military just turned off ad tracking on its phones. Maybe you should too • Hackers exploit Tencent app flaw to deploy GrayRabbit malware • CRPx0 ransomware: what you need to know
The full HackWire archive — 3,892 stories, newest first.
BTMOB is a $5,000 Android RAT sold as a service, enabling device compromise. Distributed via phishing with a customizable APK builder, it lets non-technical operators launch attacks globally.
Social engineering attack exposes 6M Carnival customers' data in the fourth breach since 2019. ShinyHunters stole names, addresses, DOBs, and IDs; Carnival offers 24 months of credit monitoring. (195 characters)
BTMOB, a $5,000 Android RAT with a no-code builder, lets non-technical criminals compromise devices via malware-as-a-service. It offers full control and SMS interception, surging across Latin America.
Critical Gogs zero-day allows RCE on 2,400+ servers through malicious branch names in pull requests. Unpatched in versions 0.14.2 and 0.15.0; default configurations make most instances vulnerable.
Cyber insurers now demand quantified risk assessments, forcing organizations to measure security maturity. This links insurance rates to security practices, driving executive investment in defenses.
Three critical flaws emerged this week: Claude plugin API interception, Azure RBAC privilege escalation, and Kali365 MFA bypass—exposing systemic weaknesses in cloud security most organizations depend on.
Researcher publicly disclosed unpatched Microsoft zero-days. Microsoft criticized the action, sparking debate over coordinated vs public disclosure practices amid the researcher's account suspension.
Despite rapid threat detection, incident response stays slow due to manual investigation and coordination delays across departments. AI-assisted automation could streamline the investigation phase to reduce overall dwell time and breach impact.
MSPs struggle with alert fatigue, missing real threats buried in millions of daily log events. SIEM platforms help filter noise and prioritize genuine security risks, enabling faster threat response and better client protection.
Autonomous AI attacks now move faster than human defenders can respond, adapting and scaling exponentially across multiple vectors. This speed asymmetry has rendered traditional cybersecurity defenses obsolete, forcing CISOs to fundamentally rethink organizational security strategies.
A critical container registry flaw in Gitea (CVE-2026-27771) allowed unauthenticated attackers to download private container images from ~31,750 self-hosted instances for nearly four years, exposing source code, credentials, and infrastructure secrets to widespread compromise across organizations wo
Edamame detects when AI agents drift from intended behavior and leak secrets—a blind spot in current security. The startup fills this gap as developers deploy AI agents with deep system access.
Nearly half of enterprise employees use AI, but power users drive most sensitive data exposure—often through ungoverned shadow tools. This concentration creates a visibility gap that leaves organizations blind to data exfiltration, IP theft, and compliance violations.
Carnival Corporation confirmed a data breach affecting nearly 6 million customers following a social engineering attack in April 2026, with notifications sent May 28—the latest in a series of major security incidents for the cruise industry.
Threat actor JINX-0164 targets cryptocurrency firms using LinkedIn recruitment lures and counterfeit video conferencing platforms to distribute custom malware (AUDIOFIX, MiniRAT), stealing digital assets and compromising development environments and code repositories.
Ramanan Pathmanathan received a 33-year federal sentence for sextorting 145 minors via fake social media accounts from 2014–2021. The Canadian predator posed as a teenage boy to coerce victims into producing sexual content, representing one of North America's largest documented child exploitation op
Nordic CISOs report stable cyberattack severity, contradicting AI-surge predictions. Either AI attacks haven't materialized as feared or organizations have successfully adapted defenses.
A CISA contractor leaked plain-text credentials on GitHub, exposing critical infrastructure access. Consumer devices simultaneously leak unencrypted health data while manufacturers conceal law enforcement data-sharing practices.
Hackers use SEO poisoning and AI chatbot manipulation to spread GPU mining malware targeting high-performance computers. The malware masquerades as legitimate utilities and mines cryptocurrency remotely.
The Silent Ransom Group targets law firms using social engineering, phishing, and physical office infiltration to steal confidential client data, then extorts victims by threatening to release sensitive materials. The FBI warned of this escalating hybrid attack strategy on May 27, 2026.
CISA flagged three actively exploited vulnerabilities in its KEV Catalog, including embedded malicious code in widely-used tools like Daemon Tools Lite and Nx Console. The additions underscore an escalating supply chain threat, with adversaries targeting popular software to compromise downstream use
Britain's top intelligence chief warns that Russia is escalating hybrid cyberattacks—including AI, critical infrastructure strikes, and election interference—in a "gray zone" below traditional warfare. Western nations risk losing the cyberspace battle unless governments and companies dramatically st
AI has collapsed exploit development from 125 days to 0.5 days, allowing attackers to weaponize vulnerabilities immediately upon patch release and drastically outpacing security teams. LLMs can now generate working proof-of-concept exploits from patch diffs, fundamentally shifting the threat landsca
Latin American cybercriminals are targeting government agencies, shifting from ransomware to data extortion at unprecedented scale. A breach exposed 5.8 million Uruguayan citizen records, reflecting a maturing regional threat ecosystem with deep knowledge of local governance vulnerabilities.