Wednesday, September 16, 2026
Follow on LinkedIn

Cyber Attack News

Hackers Mass-Scan Exposed Vite Servers to Steal AWS and Azure Cloud Credentials

Hackers are conducting a large-scale automated scanning campaign against internet-exposed Vite development servers, attempting to steal AWS credentials, Azure access tokens, environment variables, and Infrastructure-as-Code secrets. F5 honeypot sensors recorded 807 session-grouped attacks and about 32,000 raw events in...

LLMjacking Attack Uses Leaked AWS IAM Key to Steal Paid AI Model Access

A newly documented cloud intrusion shows how quickly attackers can turn a single leaked AWS credential into a revenue stream by hijacking access to premium AI models, a technique researchers call LLMjacking. Security researchers at FortiGuard Labs traced the incident...

Popular Rust Packages With 244M Downloads Compromised to Run Malware

A major supply chain attack targeting the Rust ecosystem, in which two widely used crates, arrayref and append-only-vec, were hijacked to silently deliver malware the moment developers compiled their projects. Together, the two packages account for hundreds of millions of...

New Android Malware Steals Banking PINs and Relays Data Through Someone Else’s Infected Phones

A newly discovered Android malware family named Manic combines banking fraud with full-scale spyware, and it comes with a trick researchers rarely see in the wild: when an infected phone has no internet connection of its own, it can...

Hackers Let Microsoft 365 Users Complete MFA, Then Steal Logged-In Sessions

A sophisticated Phishing-as-a-Service (PhaaS) platform marketed as Mirage2FA is enabling threat actors to bypass multi-factor authentication (MFA) by allowing Microsoft 365 users to complete their regular login process before covertly stealing the authenticated session. Threat researchers at ANY.RUN discovered...

CISA Warns Medusa Ransomware Hackers Steal Data, Kill Security Tools, and Encrypt Entire Networks

The Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the U.S. Department of Health and Human Services (HHS) have jointly released an updated security advisory warning that Medusa ransomware threat actors are actively infiltrating...

AmnesiaStealer macOS Malware Hijacks Browser Sessions via Fake GitHub Lure

A newly identified macOS infostealer called AmnesiaStealer is spreading via a convincing fake GitHub download page, tricking Mac users into pasting a malicious Terminal command that silently installs malware and can later grant attackers live, hidden control of the...

Hackers Actively Exploiting Microsoft SharePoint Vulnerability Following PoC Release

Threat actors have wasted no time weaponizing a newly disclosed Microsoft SharePoint authentication bypass, launching real-world attacks against internet-facing servers just hours after security firm Rapid7 published a technical breakdown and proof-of-concept exploit for the flaw. The vulnerability, tracked as...

New “City-Forum” Hackers Attacking Salesforce and ServiceNow Instances Worldwide

A newly identified threat actor is running a large-scale, long-running cyber campaign targeting Salesforce Experience Cloud sites and ServiceNow Service Portals globally. Dubbed the "City-Forum Campaign" after a domain tied to the attacker's infrastructure, the operation has been quietly...

Eclipse Ransomware Launches RaaS Platform Targeting Windows, Linux, and ESXi Infrastructure

A threat actor operating under the handle EclipseSupport is actively promoting a new Ransomware-as-a-Service (RaaS) operation named Eclipse Ransomware on cybercrime forums. The group is recruiting cybercrime affiliates, claiming its platform can compromise a wide spectrum of enterprise systems, including...

Latest News

Latest News