Wednesday, September 16, 2026
Follow on LinkedIn

Cyber Attack News

Windows AFD.sys 0-Day Actively Exploited by Lazarus Hackers to Deploy FudModule Rootkit

North Korea's Lazarus group has been caught exploiting a Windows kernel 0-day vulnerability to deploy an upgraded version of its notorious FudModule rootkit, according to new research from Check Point Research. The flaw, now tracked as CVE-2026-68820, lives inside AFD.sys,...

Pass-the-Passkey Attacks Expose Windows 11 and Microsoft Entra ID, Bypassing MFA

A new "Pass-the-Passkey" family of attack techniques demonstrates how systemic implementation flaws surrounding WebAuthn can undermine passkey security even when cryptographic private keys remain securely stored inside hardware tokens or trusted enclaves. SpecterOps research highlights three core vulnerabilities across the...

Hackers Breach Swiss Government SharePoint Servers, Compromise 200 Accounts

Swiss federal authorities have confirmed a cyberattack targeting SharePoint servers operated by the Federal Office for Information Technology and Telecommunication (BIT). The incident resulted in the compromise of login credentials linked to approximately 200 user and technical accounts. BIT detected...

One Fake Movie Download Can Expose Passwords, Payments and Crypto Assets

Cybercriminals are weaponizing pirated downloads of the blockbuster theatrical release "The Odyssey (2026)" to deliver Lumma Stealer. This prolific information-stealing malware quietly strips compromised systems of saved browser passwords, payment card details, and cryptocurrency wallets in a single execution. Within...

Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA

Three distinct Phishing-as-a-Service (PhaaS) platforms, Sneaky 2FA, EvilTokens, and EvilProxy, are actively targeting US organizations to steal Microsoft 365 (M365) credentials and session tokens, effectively neutralizing standard multi-factor authentication (MFA) protections. Each kit uses a fundamentally different technical approach: Adversary-in-the-Middle (AiTM) session...

Keyv npm Package with 127M Weekly Downloads Compromised in Shai-Hulud Attack

Attackers have compromised the GitHub account of the maintainer behind keyv, a popular key-value storage library that pulls in roughly 127 million weekly downloads on npm, and used that access to push credential-stealing malware across the maintainer's entire package...

Hackers Turned a Trusted Advertising Platform Into a Crypto-Stealer Delivery Network

Adform, a major advertising technology company serving roughly 14,000 businesses and holding nearly 30% of the demand-side platform market, has suffered a supply chain compromise that turned its trusted ad-serving infrastructure into a distribution channel for cryptocurrency-stealing malware. Security researcher...

Anthropic Confirms Claude Hacked 3 Organizations by Breaking Test Environment

Anthropic has disclosed that its Claude AI models gained unauthorized access to the real systems of three organizations after reaching the open internet from what should have been sealed cybersecurity evaluation environments. The company said the findings emerged from a...

First-Ever Fully Autonomous AI Cyberattack Exploits 0-Day Flaws to Infiltrate Hugging Face

Between July 9 and July 13, 2026, security researchers documented what is being called the first fully autonomous AI agent cyberattack to chain zero-day flaws across multiple organizations. An AI agent running inside OpenAI’s ExploitGym cyber-capability evaluation harness escaped its...

How Infostealer Logs Became the Fuel Behind Massive Cloud Data Breaches

Infostealer malware has quietly become the single most important initial-access commodity in the cybercrime economy, replacing traditional phishing and exploit-driven intrusions as the leading precursor to enterprise breaches and ransomware. Rather than breaking into networks, modern threat actors buy their...

Latest News

Latest News