Cybersecurity researchers have exposed a new Mirai-derived botnet that self-identifies as xlabs_v1. This operation specifically targets internet-exposed devices running the Android Debug Bridge (ADB) to enlist them in a massive network designed for high-powered distributed denial-of-service …
Month: May 2026
The North Korea-aligned state-sponsored hacking group known as ScarCruft has compromised a video game platform in a supply chain espionage attack, trojanizing its components with a backdoor called BirdCall to likely target ethnic Koreans residing in …
Joey Melo’s personal approach to hacking is less about deconstructing an original and then reconstructing it for a different purpose, and more about controlling the experience without changing the rules. He traces this to his childhood …
A newly identified supply chain attack targeting DAEMON Tools software has compromised its installers to serve a malicious payload, according to findings from Kaspersky. The installers are distributed from the legitimate DAEMON Tools website and are …
The Apache Software Foundation (ASF) has released security updates to address several security vulnerabilities in the HTTP Server, including a severe vulnerability that could potentially lead to remote code execution (RCE). The vulnerability, tracked as CVE-2026-23918, …
Palo Alto Networks has released an advisory warning that a critical buffer overflow vulnerability in its PAN-OS software has been exploited in the wild. The vulnerability, tracked as CVE-2026-0300, has been described as a case of …
The China-based cybercrime group known as Silver Fox has been linked to a new campaign targeting organizations in Russia and India with a new malware called ABCDoor. The activity involved using phishing emails that mimic correspondence …
A newly discovered Vietnamese-linked operation has been observed using Google AppSheet as a “phishing relay” to distribute phishing emails with the aim of compromising Facebook accounts. The activity, codenamed AccountDumpling by Guardio, has resulted in approximately …
Instructure, the company behind the widely used Canvas Learning Management System (LMS), has confirmed a data breach in early May 2026, with the notorious ShinyHunters extortion group claiming responsibility for the cyberattack. The Breach ShinyHunters claims …
In a stark reminder of the vulnerabilities inherent in even the most trusted corners of the digital certificate ecosystem, DigiCert—one of the world’s leading certificate authorities—disclosed a significant security breach that resulted in the fraudulent issuance …
In an unprecedented display of international law enforcement cooperation, authorities from the United States, China, and the United Arab Emirates have successfully dismantled one of the largest cryptocurrency fraud networks ever discovered. The massive operation, which …
A sophisticated phishing campaign codenamed VENOMOUS#HELPER has been observed targeting over 80 organizations since at least April 2025, weaponizing legitimate Remote Monitoring and Management (RMM) tools—SimpleHelp and ScreenConnect—to establish persistent remote access while evading traditional security …