Fake Software Sites Are Gaming Google Search to Deliver Malware, Researchers Warn

Cybersecurity researchers have uncovered a malware campaign that abuses Google search results to target users looking for popular open-source software. Attackers are creating fake websites that closely imitate legitimate project pages and then using SEO techniques to push those sites higher in search rankings. This increases the chances that users will visit a malicious website … Continued

CISA Warns of Critical Magento Flaw Under Active Attack: Thousands of Stores Potentially at Risk

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Magento-related vulnerability, tracked as CVE-2026-45247, to its Known Exploited Vulnerabilities (KEV) Catalog after confirming that it is being actively exploited in real-world attacks. The flaw affects Mirasvit Cache Warmer, a Magento extension used by online stores to improve website performance through full-page caching. … Continued

Researchers Uncover Unpatched Windows Vulnerability That Leaks NTLMv2 Hashes 

A new Windows security vulnerability has been discovered that could allow attackers to steal NTLMv2 authentication hashes from users. The flaw affects the Windows Search URI handler and currently remains unpatched. Security researchers found that attackers can exploit the issue using specially crafted links. These links can be delivered through emails, websites, or other online … Continued

Global Crackdown Dismantles 9 Crime Groups Behind Illegal Streaming Networks

Law enforcement agencies from several countries have successfully dismantled nine organized crime groups involved in illegal streaming activities. The operation targeted networks that were distributing copyrighted television channels, sports broadcasts, movies, and other premium content without authorization. Authorities worked together to identify the people behind these services and disrupt their operations. The action is being … Continued

Unpatched Oracle PLM Bug Under Active Attack, CISA Alerts Organizations

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added an Oracle security flaw to its Known Exploited Vulnerabilities (KEV) Catalog after confirming that it is being actively exploited in real-world attacks. The vulnerability affects Oracle Agile Product Lifecycle Management (PLM), a platform used by organizations to manage product development and supply chain operations. The … Continued

SideCopy Targets Afghanistan Finance Ministry with Stealthy XenoRAT Campaign

A Pakistan-linked cyber espionage group known as SideCopy has been linked to a targeted cyberattack against Afghanistan’s Ministry of Finance. Security researchers identified the operation and named it Operation XENOFISCAL. The campaign was specifically aimed at finance-related government offices across Afghanistan. Investigators believe the attackers were conducting a focused intelligence-gathering operation rather than a large-scale … Continued

OverlayPhantom Android Banking Trojan Abuses Accessibility Services to Hijack Devices 

A newly discovered Android banking malware called OverlayPhantom has been identified by cybersecurity researchers as a serious threat to mobile users. The malware is mainly designed to steal banking credentials and monitor activity on infected devices. Researchers say it can also give attackers remote access to smartphones. The threat was recently discovered during investigations into … Continued

Kimsuky Evolves Cyber Operations with HelloDoor, HTTPSpy, and Remote Access Tactics 

Cybersecurity researchers have revealed that the North Korean-linked hacking group Kimsuky has expanded its cyber espionage toolkit with new malware and attack methods. The group is known for targeting government agencies, defense organizations, and research institutions. According to recent findings, Kimsuky is continuing to improve its operations to make attacks more effective. Experts say the … Continued

Newsletter line