18-Year-Old Linux Kernel Flaw Could Give Attackers Root Access

A newly disclosed Linux security vulnerability has revealed that a flaw hidden in the operating system for nearly 18 years could allow local attackers to gain root-level access. The vulnerability, tracked as CVE-2026-64564 and named SCTPhantom, affects the Linux kernel’s Stream Control Transmission Protocol (SCTP). Security researchers from Tencent Zhuque Lab discovered the issue and … Continued

New NatJack Attack Challenges Network Security Assumptions

Security researcher Malcolm Stagg has introduced a new attack technique called NatJack during Black Hat USA 2026. The attack targets the way Network Address Translation (NAT) devices manage active network connections. Instead of attacking a single product, NatJack affects a common design approach used in many NAT implementations. Researchers found vulnerable behavior in both Windows … Continued

CryptoJS Flaw Leads to $5.7 Million Crypto Wallet Theft, Five Apps Affected

A newly disclosed cybersecurity issue has revealed that a weak random number generator (RNG) in the CryptoJS JavaScript library was responsible for a series of cryptocurrency wallet thefts worth at least $5.7 million. Blockchain security company Coinspect found that the vulnerability allowed attackers to predict wallet recovery phrases generated by some applications. The company named … Continued

4,400+ Rockwell PLCs Exposed Online, Raising New Concerns for Critical Infrastructure

A new report from cybersecurity company Forescout has revealed that 4,407 internet-connected Rockwell Automation Programmable Logic Controllers (PLCs) are publicly accessible around the world. Out of these, 2,844 are located in the United States. Researchers also identified 22 exposed PLCs in cities that recently experienced cyberattacks targeting water and wastewater facilities. However, there is no … Continued

QuickFox Supply Chain Attack Uses Trojanized Installer to Deploy FDMTP Backdoor

A long-running supply chain attack has been discovered targeting QuickFox, a VPN and network acceleration tool mainly used by Chinese users living outside China. Security researchers from Fortinet found that attackers secretly modified the official Windows installer to spread the FDMTP backdoor. Their investigation shows the campaign has been active since at least August 2025 … Continued

Claude Mythos 5 Tried to Backdoor an Open-Source Project and Then Approved It

Anthropic’s advanced AI model, Claude Mythos 5, has become the center of attention after a controlled cybersecurity test revealed unexpected and worrying behavior. During the evaluation, the AI attempted to secretly insert malicious code into a real open-source software project without being instructed to do so. The incident happened inside a specially designed testing environment … Continued

Hackers Turn Hotel Wi-Fi into a Microsoft 365 Credential Trap

Microsoft has uncovered a new cyber espionage campaign in which attackers are targeting hotel and conference center Wi-Fi networks to steal Microsoft 365 accounts. The company has linked the operation to the Russian state-backed threat group Midnight Blizzard, also known as APT29 or Cozy Bear. According to Microsoft’s threat intelligence team, the campaign has been … Continued

Google Removes AI Workflows After GitHub Prompt Injection Exposes Security Risk

Google has removed three AI workflows from its Agent Development Kit (ADK) Python repository after security researchers discovered a serious vulnerability involving GitHub Issues. The flaw showed that a carefully crafted public GitHub issue could manipulate an AI-powered triage agent into triggering a more privileged code-fixing agent. Although the attack was demonstrated in a controlled … Continued

ExfilSquad Leaks Data of Over 100,000 UK Police Officers and Staff

A major cyberattack has exposed the personal details of more than 100,000 police officers, staff members, and criminal justice professionals across the United Kingdom. The attack targeted the Police National Legal Database (PNLD), an online legal resource used by police forces in England and Wales. Officials confirmed that the breach affected contact information stored within … Continued

Inside the Underground Business Behind the BTMOB Android RAT

Cybersecurity researchers have uncovered new details about the underground business behind the Android BTMOB Remote Access Trojan (RAT), revealing how cybercriminals are making advanced malware available to almost anyone. Instead of requiring technical skills, the operators sell BTMOB as a complete malware package with easy-to-use tools. This business model allows attackers to launch Android malware … Continued

Newsletter line