Threats

Iranian Hackers Use Fake Dubai Airports Coding Test to Target Iraqi Critical Infrastructure

Iranian state-aligned hackers have used a fake Dubai Airports recruitment process to target Iraqi critical infrastructure with a booby-trapped coding…

1 hour ago

Ransomware Hacker Uses AI Coding Assistant as Attack Channel Against Enterprise Networks

A ransomware affiliate has turned an AI coding assistant into a channel for running attacks inside enterprise networks. The operator,…

2 hours ago

Hackers Exploit Exposed Industrial Controllers to Disrupt US Water and Critical Infrastructure

Hackers are exploiting internet-connected industrial controllers to disrupt US water utilities and other essential services. Recent incidents show that poorly…

2 hours ago

Midnight Blizzard Abuses Hotel Wi-Fi Captive Portals to Deliver Malware and Steal Credentials

Travelers connecting to hotel Wi-Fi may now face more than an unreliable internet signal. A campaign linked to Midnight Blizzard…

5 hours ago

ClingSTUN Backdoor Exploits Multiple IoT Vulnerabilities to Gain Persistent Remote Access

ClingSTUN is a Linux backdoor that exploits vulnerable internet-connected devices to give attackers lasting remote access. Rather than simply infecting…

7 hours ago

Google Adds 6 Advanced Protection Features to Android 17 Against Sophisticated Attacks

Google has detailed six Advanced Protection enhancements for Android 17, targeting sophisticated attacks, scams and unauthorized access. Announced on October…

7 hours ago

Malicious HEIC Images Can Trigger Remote Code Execution on WordPress Servers

A malicious HEIC image can become a route to remote code execution on a WordPress server. Researchers have demonstrated an…

1 day ago

16 Suspects Detained in Timor-Leste for Japanese Police Impersonation Scam

Investigators in Timor-Leste have detained 16 people after raiding a building in Dili allegedly used to run telephone scams against…

1 day ago

Zammad Zero-Day Chain Lets AI Agent Hijack Sessions, Execute Code and Escalate to Root

An AI agent breached the Dutch Institute for Vulnerability Disclosure by chaining two previously unknown flaws in Zammad, an open…

1 day ago

ClickFix Fake CAPTCHA Attack Executes Malware Hidden Inside Browser Cache

A new ClickFix campaign is turning a web safety check into a route for malware. Visitors to compromised websites see…

1 day ago