Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
2+ hour, 47+ min ago (539+ words) A fake browser update served over hijacked hotel Wi-Fi has been used to deliver CornFlake, a remote access trojan (RAT) that can capture webcam images, microphone audio, and keystrokes, Microsoft said in its latest report. Researchers track the operation as…...
Cheap Android TV Boxes Pose as Phones and Turn Owners’ Broadband Into Proxies
17+ hour, 33+ min ago (629+ words) Bitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones, then click ads on websites run by the same operators. Researchers named the operation Fuyao and…...
6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026
21+ hour, 51+ min ago (1044+ words) Device code phishing - the abuse of the OAuth 2.0 device authorization grant to steal access tokens - has evolved from a niche red-team technique to an industrial-scale threat in under six months. Designed for input-constrained devices like smart TVs, printers, and so…...
Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw
21+ hour, 12+ min ago (769+ words) An academic study has disclosed a "widespread class" of security vulnerabilities impacting 4G and 5G core networks that, if successfully exploited, could trigger denial-of-service (DoS) attacks and even session hijacking, allowing an attacker to seize control of a user's network session. The…...
Russia Charges Telegram Founder Pavel Durov With Aiding Terrorist Activity
2+ day, 22+ hour ago (500+ words) The Federal Security Service of the Russian Federation (FSB) on Wednesday said it charged Telegram founder Pavel Durov for allegedly facilitating terrorist activities and for failing to remove prohibited information in violation of Russian law. The principal security agency said…...
Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root
3+ day, 20+ hour ago (1248+ words) OpenWrt has shipped version 24.10.8 to close a critical DHCPv6 stack overflow and a wider set of remotely triggerable flaws in network services enabled by default. The critical issue, tracked as CVE-2026-53921 and rated 9.8 on CVSS 3.1 in OpenWrt's GitHub advisory, lets an…...
Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays
3+ day, 21+ hour ago (455+ words) The Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been attributed to a fresh set of attacks targeting entities across the Middle East, Africa, and South Asia. The intrusions involve…...
Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption
4+ day, 15+ hour ago (677+ words) Dysphoria, an Internet of Things (IoT) botnet line tracked by CNCERT and XLab, has adopted blockchain-based name services and infected-device relays after a March law-enforcement operation against JackSkid infrastructure. The researchers say the design makes the botnet harder to disrupt....
Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw
4+ day, 18+ hour ago (442+ words) SSD Secure Disclosure lists vBulletin 6.2.1 and earlier, and 6.1.6 and earlier, as affected, but does not give a lower version boundary. vBulletin issued security patches for 6.2.1, 6.2.0, and 6.1.6 at the end of June and released the fixed version 6.2.2 on July 1, nearly four…...
TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments
5+ day, 24+ min ago (470+ words) Cybersecurity researchers have flagged fresh malicious cyber activity by a threat actor with ties to East Asia targeting government entities in the Middle East. The intrusions have resulted in the deployment of previously unreported malware families dubbed TELESHIM, MIXEDKEY, and…...