Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch
1+ day, 8+ min ago (291+ words) The vulnerability, tracked as CVE-2026-58231, is rated 10.0 on the CVSS scoring system. It relates to an instance of insufficient authorization checks and input validation. "SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially…...
Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner
1+ day, 1+ hour ago (952+ words) A recently patched security flaw in Apple macOS has come under active exploitation in the wild to deploy a cryptocurrency miner, the Netherlands National Cyber Security Centre (NCSC) has warned. The vulnerability in question is CVE-2026-65400 (CVSS score: 9.8), a critical…...
Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware
1+ day, 13+ hour ago (991+ words) Threat actors are acquiring expired domains to inherit website traffic and reputation to redirect victims to scams and malware on a large scale. DNS threat intelligence firm Infoblox has given the name dropcatch domains to those that get a second…...
Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth
1+ day, 19+ hour ago (636+ words) The threat actor known as HoneyMyte (aka Mustang Panda) has been observed deploying an updated version of the CoolClient backdoor with a signed Windows kernel-mode rootkit that can hide and protect malicious processes, files, registry objects, and command-and-control (C2) network information....
Chrome DevTools Technique Enables Authenticated Session Hijacking in Live Windows Browsers
1+ day, 21+ hour ago (668+ words) Cybersecurity researchers have detailed a post-exploitation technique that enables the Chrome DevTools Protocol (CDP) inside a running Google Chrome or Microsoft Edge process on Windows, allowing an operator to access cookies, saved data, and authenticated browser sessions. The technique assumes…...
Apple Warns Users in 110 Countries They May Be Targets of Mercenary Spyware
1+ day, 21+ hour ago (355+ words) Apple on Thursday sent a fresh batch of notifications to customers whom it suspects may have been targeted by mercenary spyware attacks. In a statement shared with TechCrunch, the iPhone maker said it alerted an unspecified number of users targeted…...
Trump Memo Paves Way for U.S. Firms to Hack and Disrupt Foreign Crime Groups
1+ day, 23+ hour ago (380+ words) A new White House memo signed by U.S. President Donald Trump has instructed the National Coordination Center (NCC) to establish a program that would allow private sector companies to take advantage of their "innovative capabilities" to break into foreign Transnational Criminal…...
China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud
2+ day, 52+ min ago (795+ words) The China-linked threat actor known as Jewelbug has been observed carrying out cyber espionage operations targeting governments and militaries, while simultaneously engaging in cryptocurrency fraud. "Both missions are administered from a single control panel, XG-Web, a browser-centric remote-access and information-stealing…...
Unpatched GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE
2+ day, 13+ hour ago (266+ words) A newly disclosed zero-day flaw in GeoServer is seeing active exploitation efforts, per watchTowr. The vulnerability, which has yet to be assigned a CVE identifier, is an SQL injection vulnerability in the open-source platform that can lead to remote code…...
ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories
2+ day, 13+ hour ago (208+ words) Some weeks have one big security story. Others bring many smaller updates that are easy to miss but still matter. This week has plenty of them, covering cloud services, AI tools, malware, data breaches, scams, and new attack methods. The…...