LummaStealer Resurfaces with CastleLoader, Marking a Dangerous Evolution in Infostealer Campaigns
In early 2026, researchers published a comprehensive analysis revealing that LummaStealer, once significantly disrupted by international law…
continue reading..
Police Dismantle JokerOTP Network, Arrest Key Seller in MFA Bypass Operation
In a significant breakthrough in the fight against online fraud, Dutch law enforcement authorities have arrested a…
continue reading..
Researchers Uncovers Ransomware Campaign Abusing Employee Monitoring and SimpleHelp RMM Tools for Stealthy Network Takeovers
Recent incident response engagements by Huntress Tactical Response have identified multiple sophisticated intrusions in which legitimate remote…
continue reading..
First-Ever Malicious Outlook Add-In “AgreeToSteal” Exposed, 4,000 Microsoft Credentials Compromised in Supply-Chain Breach
In February 2026, cybersecurity researchers publicly disclosed one of the most concerning supply-chain attacks to date affecting…
continue reading..
Microsoft Patches High-Severity Notepad Flaw (CVE-2026-20841) That Could Allow Remote Code Execution via Malicious Markdown Files
In February 2026, Microsoft addressed a serious security flaw in its Windows Notepad application — now tracked…
continue reading..
Apple Rushes Emergency Updates to Patch Zero-Day Exploited in ‘Extremely Sophisticated’ Targeted Attacks
Apple has released a series of critical security updates across its operating system ecosystem to address a…
continue reading..
Google Warns Hackers Are Exploiting Gemini AI Across Every Stage of Cyberattacks
In a recent analysis of malicious cyber activity, Google’s Threat Intelligence Group (GTIG) has observed that advanced…
continue reading..
CVE-2026-1774: Critical CASL Prototype Pollution Flaw Enables Remote Privilege Escalation in Node.js Applications
Overview CVE ID: CVE-2026-1774Component: @casl/ability (CASL Authorization Library)Vulnerability Type: Prototype Pollution (CWE-1321)CVSS v3.1 Score: 9.8 (Critical)Attack Vector:…
continue reading..
CVE-2026-25728: Critical ClipBucket v5 Flaw Allows Unauthenticated Remote Code Execution via Upload Race Condition
ClipBucket v5 – TOCTOU Race Condition → Remote Code Execution (RCE) CVE ID: CVE-2026-25728Affected Product: ClipBucket v5…
continue reading..
