U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Ray-Project Ray vulnerability to its Known Exploited Vulnerabilities catalog. The U.S.…
Tag: Security Affairs
New Mirai-Based Evooo1Bot Botnet Targets Linux Devices
Evooo1Bot is a Mirai-based Linux botnet that hijacks routers and IoT devices for DDoS attacks, credential theft and criminal proxy services. Fortinet’s…
SafePal Says 39,798 Customers Hit by Data Breach
SafePal says a breach exposed personal data of 39,798 customers, but not wallet credentials, private keys, seed phrases, or payment information. SafePal…
LiteLLM Supply-Chain Attack – Technology, Banking and Healthcare the Most Affected
The SANDCLOCK LiteLLM supply-chain attack exposed credentials across 2,038 repositories, affecting technology, finance, healthcare, retail and more.…
Invisible AI Prompts Trigger Court Sanctions
A litigant hid AI prompt injections in a court filing to influence a ruling. The judge caught it and banned him from electronic filing. A man suing the…
McDonald’s Employee Data Appears in Leak, Seller Claims 1.7M Records Stolen
A seller claims 1.7M McDonald’s employee records were stolen from Azure. An 8,000-row sample appears genuine, but its age and full size remain…
Akira Ransomware Uses Safe Mode to Bypass EDR
Akira attackers used Safe Mode to disable EDR before deploying ransomware, but memory issues caused the encryptor to fail. An Akira ransomware affiliate…
DDoS Attacks Cause Major Threema Outages
Large DDoS attacks disrupted Threema, causing severe communication outages. Threema On-Prem users were unaffected by the attacks. Threema suffered…
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 110
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter…
Mustang Panda Upgrades CoolClient With a Kernel Rootkit
Mustang Panda upgraded CoolClient with a signed kernel driver that hides processes, files and network activity, making the backdoor harder to detect.…
Security Affairs newsletter Round 590 by Pierluigi Paganini – INTERNATIONAL EDITION
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email…
Sophisticated Cyberattack Exposes Data of 678,000 French Taxpayers
France’s tax agency says hackers stole data on 678,000 taxpayers, including income and tax details, in a sophisticated cyberattack. A threat actor claimed…
APT36 Suspected in PATCHCORD Espionage Campaign Using Google Sheets C2
Acronis uncovered PATCHCORD, a stealthy backdoor targeting Afghan telecom and South Asian infrastructure via fake VPN tools and Google Sheets C2.…
Crooks Are Buying Your Expired Domains and Using Them to Deliver Malware
Attackers are buying expired domains to exploit their reputation, traffic and DNS history, using them for malware delivery, scams and C2 infrastructure.…
SAP Commerce Cloud CVE-2026-58231 Exploited in the Wild
Attackers are actively exploiting a maximum severity SAP Commerce Cloud vulnerability, tracked as CVE-2026-58231, just days after SAP released a patch. A…
Storm-1175 Replaces Medusa With New StormEncryptor Ransomware
Microsoft says China-linked Storm-1175 is using a new ransomware called StormEncryptor, replacing Medusa in its latest attacks. Microsoft says…
macOS Screen Sharing Flaw Exploited to Deploy Monero Miners
Hackers are exploiting a macOS Screen Sharing flaw to gain root access and install Monero miners on Macs with port 5900 exposed online. The Dutch National…
GeoServer Zero-Day Is Already Being Probed. That’s the Problem
GeoServer faces an unpatched zero-day enabling SQL injection and potentially RCE, with attackers already probing exposed systems. A newly disclosed…
CEVA Logistics Cyberattack Disrupts European Warehouses and Shipments
CEVA Logistics suffered a cyberattack disrupting European operations, with eight warehouses affected and shipments halted at impacted sites. CEVA…
Apple warned hundreds of users of mercenary spyware attacks
Apple warns users of credible, targeted attacks and urges immediate verification, stronger protections, and expert assistance. Apple has sent a new round…