Miasma Malware Abuses npm Packages and GitHub Actions in Stealthy Supply Chain Attack

Security researchers have uncovered a new supply chain attack involving malware called Miasma, which targets developers by abusing npm packages and GitHub Actions workflows. Instead of attacking users directly, the campaign focuses on software development environments where malicious code can spread through trusted projects. Researchers say this approach allows attackers to compromise systems before applications … Continued

Russian Authorities Used Cellebrite to Unlock Activist’s iPhone After Sales Ban, Investigation Finds

A new investigation has revealed that Russian authorities used digital forensic tools made by Cellebrite to unlock the iPhone of jailed Russian activist Andrei Pivovarov. The finding is significant because Cellebrite had already announced in March 2021 that it was ending all business with Russia and Belarus. Researchers say the case raises important questions about … Continued

Google Uncovers Turla’s New STOCKSTAY Backdoor Used in Cyber Espionage Against Ukraine

Google’s Threat Intelligence Group (GTIG) has uncovered a new malware called STOCKSTAY, which has been linked to the Russian state-backed hacking group Turla. The backdoor has been used in cyber espionage campaigns targeting government and military organizations in Ukraine. Researchers also found that some organizations connected to Italian foreign policy were targeted during these operations. … Continued

Cisco Zero-Day Under Active Attack Gives Hackers Root Access to SD-WAN Systems

Cisco has disclosed a new zero-day vulnerability, tracked as CVE-2026-20245, that affects Cisco Catalyst SD-WAN Manager. The flaw has already been exploited in real-world attacks before a security update was available. According to Cisco, the issue allows attackers to gain root-level access, giving them complete control over the affected system once the attack succeeds. This … Continued

Europe Becomes the New Hotspot for Ransomware Attacks as Cybercriminals Shift Focus

Europe is rapidly becoming one of the most attractive targets for ransomware gangs, according to new cybersecurity research. After a relatively quieter period in 2024 and 2025, ransomware activity has surged again across the region. Experts say attackers are increasingly focusing on European organizations because of the financial opportunities available. The trend shows that cybercriminals … Continued

macOS Backdoor Uses AI Prompt Injection to Hide Malicious Activity from Security Analysis

Security researchers have uncovered a new macOS backdoor that uses prompt injection techniques to avoid detection during AI-assisted malware analysis. Instead of relying only on code obfuscation or anti-debugging tricks, the malware attempts to manipulate AI-powered triage systems that security teams increasingly use to examine suspicious files. Researchers say this approach represents a new challenge … Continued

Cordyceps CI/CD Flaws Put 300+ GitHub Repositories at Risk of Supply-Chain Attacks

Cybersecurity researchers have uncovered a new class of CI/CD security weaknesses called “Cordyceps” that could allow attackers to hijack software development workflows and launch large-scale supply-chain attacks. The flaws were discovered in GitHub Actions environments and were found to affect more than 300 public repositories, including projects linked to major technology organizations. The issue highlights … Continued

Stealthy Mistic Backdoor Tied to KongTuke Access Broker in Emerging Ransomware Threat Chain

Cybersecurity researchers have uncovered a new connection between the stealthy Mistic backdoor and KongTuke, a well-known initial access broker active in the cybercrime ecosystem. Investigators say the activity highlights how threat actors continue to work together, with one group focusing on gaining access to systems and another using that access for follow-on attacks. The discovery … Continued

Newsletter line