• ⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More

    ⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More

    Monday hit like a cron job with anger issues. A busted auth path here, a repo-side faceplant there, some “patched-ish” thing already getting chewed on in the wild, and then the usual bonus round: poisoned dev tools, sketchy forum chatter, phishing kits pretending to be productivity, and AI lowering the bar for people who already…

    Read More

  • The Security Growth Platform: Why MSPs Are Moving Beyond vCISO Tools

    The Security Growth Platform: Why MSPs Are Moving Beyond vCISO Tools

    Three years ago, the practical question for an MSP building a cybersecurity practice was which “vCISO platform” to buy. The term was good shorthand for the work at the time: assessments, advisory, reporting, maybe a compliance module bolted on the side. The work has since outgrown the descriptor. A Security Growth Platform is the more…

    Read More

  • Critical WP Maps Pro Flaw Actively Exploited to Create Admin Accounts

    Critical WP Maps Pro Flaw Actively Exploited to Create Admin Accounts

    Threat actors are attempting to actively exploit a critical security flaw impacting WP Maps Pro, a WordPress plugin that has had over 15,000 sales on the Envato Market, to create malicious administrator accounts on susceptible sites. WP Maps Pro allows site owners to embed customizable Google Maps and OpenStreetMap with markers, listings, and advanced location…

    Read More

  • Dutch Authorities Dismantle Botnet Linked to 17 Million Infected Devices

    Dutch Authorities Dismantle Botnet Linked to 17 Million Infected Devices

    Dutch authorities have announced the takedown of a botnet that enslaved millions of infected devices, including computers, tablets, smartphones, and IoT devices, to carry out malicious attacks. The bot network, per the Dutch Politie and the National Cyber Security Center (NCSC), consisted of at least 17 million infected devices. More than 200 servers located in…

    Read More

  • PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation

    PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation

    Palo Alto Networks has warned that a recently disclosed medium-severity security flaw impacting PAN-OS and Prisma Access has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-0257 (CVSS score: 7.8), refers to a case of authentication bypass that could be exploited by bad actors to set up VPN connections. “Authentication bypass vulnerabilities…

    Read More

  • ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface

    ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface

    Cybersecurity researchers have disclosed details of a vulnerability in OpenAI ChatGPT that leverages the artificial intelligence (AI) assistant’s implicit trust in Markdown links and images to trigger prompt injections and open the door to phishing attacks. The technique has been codenamed ChatGPhish by Permiso Security. “The chatgpt.com response renderer trusts Markdown links and Markdown

    Read More

  • Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit

    Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit

    An unknown threat actor has been observed using a large language model (LLM) agent to conduct post-compromise actions after obtaining initial access following the exploitation of a publicly-accessible Marimo network using a recently disclosed vulnerability. “The attacker compromised an internet-reachable Marimo notebook via CVE-2026-39987, extracted two cloud credentials from the compromised

    Read More

  • New Russian-Linked GREYVIBE Targets Ukraine with AI-Powered Cyberattacks

    New Russian-Linked GREYVIBE Targets Ukraine with AI-Powered Cyberattacks

    A previously undocumented threat actor dubbed GREYVIBE has been attributed to ongoing and persistent attacks targeting Ukraine and Ukraine-related entities since at least August 2025. GREYVIBE, per WithSecure, is assessed to be a Russian-speaking group operating broadly in the Russian time zone, with the activities aligning with Kremlin state interests, specifically when it comes to

    Read More

  • Malicious Sicoob NuGet Steals Banking Credentials as npm Packages Target Cloud Secrets

    Cybersecurity researchers have discovered a malicious NuGet package that masquerades as a C# software development kit for Sicoob, one of Brazil’s largest cooperative financial systems, to siphon client IDs and PFX certificates. According to Socket, versions 2.0.0 through 2.0.4 of “Sicoob.Sdk” contain functionality to exfiltrate sensitive information, including PFX certificates that are used to

    Read More

  • Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels

    Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels

    The North Korean state-sponsored threat actor known as Kimsuky (aka Velvet Chollima) has been attributed to a fresh set of cyber attacks targeting South Korean military and corporate entities through March and April 2026. “Kimsuky employed a range of tailored social engineering tactics, such as spoofing security software installation pages and crafting a fake Webex…

    Read More