🔥⚡ Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaos
Monday recap. Same mess, new week. A sketchy dev tool got people pwned, old bugs came back from the dead, and security products somehow needed protecting from themselves. A bunch of companies spent...
🕵️Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks
Authorities in the Netherlands have arrested the co-owners of two related Internet hosting companies for operating IT infrastructure used by Russia to carry out cyberattacks, influence operations and
🔥Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks
Threat actors are exploiting a recently disclosed critical security flaw in Ghost CMS to inject malicious JavaScript code with an aim to fuel ClickFix attacks. According to QiAnXin XLab, the activity
🔥The Alert Firehose Finally Meets Its Match
Ask a cybersecurity pro about Network Detection and Response (NDR) and you might still hear "Noisy," "Too much data." But ask the teams running NDR that includes agentic AI capabilities and you'll...
🔥Lazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto Firms
Cybersecurity researchers have shed light on a cross-platform malware called RemotePE that has been put to use by the North Korea-linked Lazarus Group in attacks targeting financial and...
🖥️"Un cri pour la Tunisie: la liberté n'est pas un crime": piratée, l’application de Tunisie Telecom a diffusé un message critique du pouvoir
Samedi dernier, certains des abonnés de Tunisie Telecom, qui ont installé l'application de l'opérateur sur leur smartphone, ont eu la surprise de …
🖥️« Je pensais que les victimes se faisaient rembourser » : cette petite bande qui faisait son beurre grâce au service de spoofing téléphonique iSpoof - ZDNET
Trois ans après la chute de cette plateforme au Royaume-Uni, l’un de ses utilisateurs français vient d’être jugé. Novembre 2022 : l’agence de …
🖥️Des sons inaudibles cachés dans des podcasts peuvent aider les hackers à pirater votre téléphone, faites attention - PaperGeek
Des chercheurs ont découvert que de simples sons, inaudibles pour l’oreille humaine, peuvent interagir avec l’assistant vocal d’IA de votre …
🔥TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO
A new coordinated cross-ecosystem software supply chain attack campaign has targeted npm, PyPI, and Crates.io to distribute credential-stealing malware. The campaign, codenamed TrapDoor, spans more...
🖥️Cybersécurité : la fuite de données vise aussi les ministres, palmarès des piratages parmi les membres du gouvernement
Les attaques tous azimuts visant à démontrer la fragilité de la France en matière de cybersécurité n’épargnent pas le plus haut niveau de l’État Si …
🖥️Ce nouveau virus contourne la double authentification et vole vos données sans se faire repérer
Un nouveau logiciel malveillant suscite l’inquiétude des chercheurs en sécurité de Varonis. Cet infostealer aspire discrètement vos mots de passe, …
📰FBI warns about fast-growing phishing kit targeting Microsoft 365 users
Kali365, which was first observed in April, abuses legitimate Microsoft device authorization pages to grant persistent access to cybercriminal-controlled applications. The post FBI warns about...
🕵️Lawmakers Demand Answers as CISA Tries to Contain Data Leak
Lawmakers in both houses of Congress are demanding answers from the U.S. Cybersecurity & Infrastructure Security Agency (CISA) after KrebsOnSecurity reported this week that a CISA contractor...
📰Alleged leader of Kimwolf, a sweeping botnet for cybercriminals, arrested in Canada
Jacob Butler, a 23-year-old from Ottawa, awaits extradition to the United States and faces up to 10 years in prison. The post Alleged leader of Kimwolf, a sweeping botnet for cybercriminals, arrested
🕵️Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada
Canadian authorities on Wednesday arrested a 23-year-old Ottawa man on suspicion of building and operating Kimwolf, a fast spreading Internet-of-Things botnet that enslaved millions of devices for...
🔥⚡ Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaos
Monday recap. Same mess, new week. A sketchy dev tool got people pwned, old bugs came back from the dead, and security products somehow needed protecting from themselves. A bunch of companies spent...
🕵️Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks
Authorities in the Netherlands have arrested the co-owners of two related Internet hosting companies for operating IT infrastructure used by Russia to carry out cyberattacks, influence operations and
🔥Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks
Threat actors are exploiting a recently disclosed critical security flaw in Ghost CMS to inject malicious JavaScript code with an aim to fuel ClickFix attacks. According to QiAnXin XLab, the activity
🔥The Alert Firehose Finally Meets Its Match
Ask a cybersecurity pro about Network Detection and Response (NDR) and you might still hear "Noisy," "Too much data." But ask the teams running NDR that includes agentic AI capabilities and you'll...
🔥Lazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto Firms
Cybersecurity researchers have shed light on a cross-platform malware called RemotePE that has been put to use by the North Korea-linked Lazarus Group in attacks targeting financial and...
🖥️"Un cri pour la Tunisie: la liberté n'est pas un crime": piratée, l’application de Tunisie Telecom a diffusé un message critique du pouvoir
Samedi dernier, certains des abonnés de Tunisie Telecom, qui ont installé l'application de l'opérateur sur leur smartphone, ont eu la surprise de …
🖥️« Je pensais que les victimes se faisaient rembourser » : cette petite bande qui faisait son beurre grâce au service de spoofing téléphonique iSpoof - ZDNET
Trois ans après la chute de cette plateforme au Royaume-Uni, l’un de ses utilisateurs français vient d’être jugé. Novembre 2022 : l’agence de …
🖥️Des sons inaudibles cachés dans des podcasts peuvent aider les hackers à pirater votre téléphone, faites attention - PaperGeek
Des chercheurs ont découvert que de simples sons, inaudibles pour l’oreille humaine, peuvent interagir avec l’assistant vocal d’IA de votre …
🔥TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO
A new coordinated cross-ecosystem software supply chain attack campaign has targeted npm, PyPI, and Crates.io to distribute credential-stealing malware. The campaign, codenamed TrapDoor, spans more...
🖥️Cybersécurité : la fuite de données vise aussi les ministres, palmarès des piratages parmi les membres du gouvernement
Les attaques tous azimuts visant à démontrer la fragilité de la France en matière de cybersécurité n’épargnent pas le plus haut niveau de l’État Si …
🖥️Ce nouveau virus contourne la double authentification et vole vos données sans se faire repérer
Un nouveau logiciel malveillant suscite l’inquiétude des chercheurs en sécurité de Varonis. Cet infostealer aspire discrètement vos mots de passe, …
📰FBI warns about fast-growing phishing kit targeting Microsoft 365 users
Kali365, which was first observed in April, abuses legitimate Microsoft device authorization pages to grant persistent access to cybercriminal-controlled applications. The post FBI warns about...
🕵️Lawmakers Demand Answers as CISA Tries to Contain Data Leak
Lawmakers in both houses of Congress are demanding answers from the U.S. Cybersecurity & Infrastructure Security Agency (CISA) after KrebsOnSecurity reported this week that a CISA contractor...
📰Alleged leader of Kimwolf, a sweeping botnet for cybercriminals, arrested in Canada
Jacob Butler, a 23-year-old from Ottawa, awaits extradition to the United States and faces up to 10 years in prison. The post Alleged leader of Kimwolf, a sweeping botnet for cybercriminals, arrested
🕵️Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada
Canadian authorities on Wednesday arrested a 23-year-old Ottawa man on suspicion of building and operating Kimwolf, a fast spreading Internet-of-Things botnet that enslaved millions of devices for...