• First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups

    First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups

    Authorities in Europe and North America have announced the dismantling of a criminal virtual private network (VPN) service used by criminal actors to obscure the origins of ransomware attacks, data theft, scanning, and denial-of-service attacks. The disruption of First VPN Service was led by France and the Netherlands, with several other nations supporting the investigation…

    Read More

  • Ghostwriter Targets Ukraine Government Entities with Prometheus Phishing Malware

    The Belarus-aligned threat actor known as Ghostwriter (aka UAC-0057 and UNC1151Ukraine’s National Security and Defense Council) has been observed using lures related to Prometheus, a Ukrainian online learning platform, to target government organizations in the country. The activity, per the Computer Emergency Response Team of Ukraine (CERT-UA), involves sending phishing emails to government

    Read More

  • Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows

    Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows

    Cybersecurity researchers have disclosed details of a new automated campaign called Megalodon that has pushed 5,718 malicious commits to 5,561 GitHub repositories within a six-hour window. “Using throwaway accounts and forged author identities (build-bot, auto-ci, ci-bot, pipeline-bot), the attacker injected GitHub Actions workflows containing base64-encoded bash payloads that exfiltrate CI

    Read More

  • Kimwolf DDoS Botnet Operator Arrested in Canada Over DDoS-for-Hire Attacks

    Kimwolf DDoS Botnet Operator Arrested in Canada Over DDoS-for-Hire Attacks

    The U.S. Department of Justice (DoJ) on Thursday announced the arrest of a Canadian man in connection with allegedly operating a distributed denial-of-service (DDoS) botnet known as Kimwolf. In tandem, Jacob Butler (aka Dort), 23, Ottawa, Canada, has been charged with offenses related to the development and operation of the botnet. Kimwolf is assessed to…

    Read More

  • CISA Adds Exploited Langflow and Trend Micro Apex One Vulnerabilities to KEV

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added two security flaws impacting Langflow and Trend Micro Apex One to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities in question are listed below – CVE-2025-34291 (CVSS score: 9.4) – An origin validation error vulnerability in Langflow that could

    Read More

  • Cisco Patches CVSS 10.0 Secure Workload REST API Flaw Enabling Data Access

    Cisco Patches CVSS 10.0 Secure Workload REST API Flaw Enabling Data Access

    Cisco has rolled out updates for a maximum-severity security flaw impacting Secure Workload that could allow an unauthenticated, remote attacker to access sensitive data. Tracked as CVE-2026-20223 (CVSS score: 10.0), the vulnerability arises from insufficient validation and authentication when accessing REST API endpoints. “An attacker could exploit this vulnerability if they are able to send

    Read More

  • Following death of Commissioner Phil Brady on Election Day, runner up Mike Urness will appear on November ballot

    Following death of Commissioner Phil Brady on Election Day, runner up Mike Urness will appear on November ballot

    Brady, a first term commissioner, was running for reelection.

    Read More

  • Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor

    Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor

    Cybersecurity researchers have disclosed details of a new Linux malware dubbed Showboat that has been put to use in a campaign targeting a telecommunications provider in the Middle East since at least mid-2022. “Showboat is a modular post-exploitation framework designed for Linux systems, capable of spawning a remote shell, transferring files, and functioning as a…

    Read More

  • ThreatsDay Bulletin: Linux Rootkits, Router 0-Day, AI Intrusions, Scam Kits and 25 New Stories

    ThreatsDay Bulletin: Linux Rootkits, Router 0-Day, AI Intrusions, Scam Kits and 25 New Stories

    This week starts small. A token leaks. A bad package slips in. A login trick works. An old tool shows up again. At first, it feels like the usual mess. Then you see the pattern: attackers are not always breaking in. They are using the parts we already trust. That is what makes it worrying.…

    Read More

  • Microsoft Warns of Two Actively Exploited Defender Vulnerabilities

    Microsoft Warns of Two Actively Exploited Defender Vulnerabilities

    Microsoft has disclosed that a privilege escalation and a denial-of-service flaw in Defender has come under active exploitation in the wild. The former, tracked as CVE-2026-41091, is rated 7.8 on the CVSS scoring system. Successful exploitation of the flaw could allow an attacker to gain SYSTEM privileges. “Improper link resolution before file access (‘link following’)…

    Read More