ar
Feedback
Latest Cyber-Attack News

Latest Cyber-Attack News

الذهاب إلى القناة على Telegram

Latest cybersecurity incidents and malware threats.

إظهار المزيد
2 889
المشتركون
+124 ساعات
+77 أيام
+3430 أيام

جاري تحميل البيانات...

جذب المشتركين
يوليو '26
يوليو '26
+65
في 0 قنوات
يونيو '26
+92
في 0 قنوات
Get PRO
مايو '26
+36
في 0 قنوات
Get PRO
أبريل '26
+24
في 0 قنوات
Get PRO
مارس '26
+34
في 0 قنوات
Get PRO
فبراير '26
+35
في 0 قنوات
Get PRO
يناير '26
+42
في 0 قنوات
Get PRO
ديسمبر '25
+91
في 0 قنوات
Get PRO
نوفمبر '25
+90
في 0 قنوات
Get PRO
أكتوبر '25
+131
في 0 قنوات
Get PRO
سبتمبر '25
+149
في 0 قنوات
Get PRO
أغسطس '25
+175
في 0 قنوات
Get PRO
يوليو '25
+154
في 0 قنوات
Get PRO
يونيو '25
+126
في 0 قنوات
Get PRO
مايو '25
+74
في 0 قنوات
Get PRO
أبريل '25
+162
في 0 قنوات
Get PRO
مارس '25
+103
في 0 قنوات
Get PRO
فبراير '25
+100
في 0 قنوات
Get PRO
يناير '25
+96
في 0 قنوات
Get PRO
ديسمبر '24
+83
في 0 قنوات
Get PRO
نوفمبر '24
+72
في 0 قنوات
Get PRO
أكتوبر '24
+80
في 0 قنوات
Get PRO
سبتمبر '24
+73
في 0 قنوات
Get PRO
أغسطس '24
+90
في 0 قنوات
Get PRO
يوليو '24
+89
في 0 قنوات
Get PRO
يونيو '24
+64
في 0 قنوات
Get PRO
مايو '24
+71
في 0 قنوات
Get PRO
أبريل '24
+72
في 0 قنوات
Get PRO
مارس '24
+83
في 0 قنوات
Get PRO
فبراير '24
+73
في 0 قنوات
Get PRO
يناير '24
+70
في 0 قنوات
Get PRO
ديسمبر '23
+1 478
في 0 قنوات
التاريخ
نمو المشتركين
الإشارات
القنوات
27 يوليو+2
26 يوليو+1
25 يوليو+2
24 يوليو+2
23 يوليو+5
22 يوليو+5
21 يوليو0
20 يوليو+1
19 يوليو+3
18 يوليو+2
17 يوليو+1
16 يوليو+5
15 يوليو+4
14 يوليو+1
13 يوليو+2
12 يوليو+3
11 يوليو+1
10 يوليو+4
09 يوليو0
08 يوليو+5
07 يوليو+2
06 يوليو0
05 يوليو+3
04 يوليو+2
03 يوليو+1
02 يوليو+4
01 يوليو+4
منشورات القناة
MedusaHVNC Hijacks Browser Sessions on a Hidden Desktop BlackFog has analyzed MedusaHVNC, a Windows remote access trojan sold
MedusaHVNC Hijacks Browser Sessions on a Hidden Desktop BlackFog has analyzed MedusaHVNC, a Windows remote access trojan sold as malware-as-a-service. Its defining feature is a hidden desktop where an attacker can open Chrome, Edge, or Firefox and interact with a browser session that is already logged in on the infected PC. The victim can keep using the visible desktop without… https://blog.gridinsoft.com/medusahvnc-hidden-desktop-browser-sessions/

2
OpenAI Agent Hacked Hugging Face—and Went Unnoticed for Days An OpenAI evaluation agent broke out of its intended network bou
OpenAI Agent Hacked Hugging Face—and Went Unnoticed for Days An OpenAI evaluation agent broke out of its intended network boundary and compromised Hugging Face production systems while trying to obtain answers for a cybersecurity benchmark. OpenAI and Hugging Face confirm the core incident. Reuters now reports that the intrusion ran from July 11 to July 13 and that OpenAI did not connect its… https://blog.gridinsoft.com/openai-agent-hugging-face-hack/
106
3
Fastjson CVE-2026-16723: Enable SafeMode on 1.x Now Fastjson CVE-2026-16723 can allow unauthenticated remote code execution i
Fastjson CVE-2026-16723: Enable SafeMode on 1.x Now Fastjson CVE-2026-16723 can allow unauthenticated remote code execution in a specific but common Spring Boot setup. The maintainer lists Fastjson 1.2.68 through 1.2.83 as affected when the application runs as an executable fat JAR, processes attacker-controlled JSON, and has SafeMode disabled—the stock default [1]. ThreatBook says its platform captured exploitation… https://blog.gridinsoft.com/fastjson-cve-2026-16723-safemode/
103
4
Steam Forum ClickFix Installs XMRig Miner via PowerShell https://blog.gridinsoft.com/steam-forum-clickfix-xmrig/
Steam Forum ClickFix Installs XMRig Miner via PowerShell https://blog.gridinsoft.com/steam-forum-clickfix-xmrig/
115
5
SourTrade Malware: Fake Trading Ads Build It in Your Browser SourTrade malware is being assembled inside the victim’s browser
SourTrade Malware: Fake Trading Ads Build It in Your Browser SourTrade malware is being assembled inside the victim’s browser before it is offered as a Windows download. Confiant documented fake TradingView, Solana and Luno pages that use JavaScript workers, build instructions and a clean Bun runtime to create a different executable for each session. The pages arrive through malvertising and are designed to show… https://blog.gridinsoft.com/sourtrade-browser-assembled-malware/
139
6
Hotel Wi-Fi DNS Poisoning Redirects Microsoft 365 Logins ReliaQuest has identified a widespread campaign in which attackers c
Hotel Wi-Fi DNS Poisoning Redirects Microsoft 365 Logins ReliaQuest has identified a widespread campaign in which attackers compromise Wi-Fi gateways at hotels, conference centers, and other captive-portal venues, then poison DNS responses to redirect travelers toward fake Microsoft 365 sign-in pages. The activity has been ongoing since at least June 2026 and was observed in multiple U.S. cities, India, and Saudi Arabia.… https://blog.gridinsoft.com/hotel-wifi-dns-poisoning-microsoft-365/
165
7
Dolphin X Stealer Uses AI to Rank High-Value Victims Varonis Threat Labs has analyzed the operator panel for Dolphin X, a Win
Dolphin X Stealer Uses AI to Rank High-Value Victims Varonis Threat Labs has analyzed the operator panel for Dolphin X, a Windows information stealer and remote access trojan sold on a cybercrime forum. The panel advertises collection from more than 300 applications and includes an “AI Profiler” that can rank infected machines by app usage, browsing activity, installed software, and an… https://blog.gridinsoft.com/dolphin-x-stealer-ai-profiler/
202
8
msaRAT Hides C2 Traffic Inside Chrome and Edge Cisco Talos has uncovered msaRAT, a Rust-based remote access trojan used in re
msaRAT Hides C2 Traffic Inside Chrome and Edge Cisco Talos has uncovered msaRAT, a Rust-based remote access trojan used in recent Chaos ransomware intrusions. After an attacker already has access to a Windows system, the malware starts a hidden Chrome or Microsoft Edge process and makes that browser carry its encrypted command-and-control traffic over WebRTC. This does not mean Chrome… https://blog.gridinsoft.com/msarat-chrome-edge-browser-c2/
225
9
TrickBot Uses DNS Tunneling to Hide Windows C2 Traffic FortiGuard Labs has analyzed a current TrickBot variant that hides com
TrickBot Uses DNS Tunneling to Hide Windows C2 Traffic FortiGuard Labs has analyzed a current TrickBot variant that hides command-and-control traffic inside DNS queries and keeps access to an infected Windows system through a disguised scheduled task. The report gives defenders and affected users concrete checks: the domain westurn[.]in, six sample hashes, task names ending in autoupdate #{random}, and… https://blog.gridinsoft.com/trickbot-dns-tunneling-windows/
208
10
Check Point SmartConsole CVE-2026-16232 Exploited: Patch Now Check Point says attackers are exploiting CVE-2026-16232, a Smar
Check Point SmartConsole CVE-2026-16232 Exploited: Patch Now Check Point says attackers are exploiting CVE-2026-16232, a SmartConsole authentication bypass that can give a remote unauthenticated attacker full administrator access to a Security Management or Multi-Domain Management server. The company observed attacks at a handful of customers whose management systems were exposed directly to the internet without IP restrictions. Administrators should… https://blog.gridinsoft.com/check-point-smartconsole-cve-2026-16232/
202
11
Adobe Acrobat Extension Flaw Could Expose WhatsApp Web Chats A now-fixed flaw in the Adobe Acrobat PDF extension for Chrome c
Adobe Acrobat Extension Flaw Could Expose WhatsApp Web Chats A now-fixed flaw in the Adobe Acrobat PDF extension for Chrome could let a malicious website read text already rendered inside WhatsApp Web. The vulnerability, CVE-2026-48294, affected extension versions 26.5.2.2 and earlier; users should verify that Chrome has installed version 26.5.2.3 or later. Guardio Labs named the proof-of-concept… https://blog.gridinsoft.com/adobe-acrobat-extension-whatsapp-flaw/
188
12
Chick-fil-A One Accounts Hit in Credential Stuffing Attack Between June 17 and June 19, 2026, attackers used email-and-passwo
Chick-fil-A One Accounts Hit in Credential Stuffing Attack Between June 17 and June 19, 2026, attackers used email-and-password combinations obtained from another source to sign in to Chick-fil-A One accounts through the company’s website and app. Chick-fil-A said its investigation determined on July 13 that some account data had been accessed. If you received a notice—or reused your Chick-fil-A password anywhere else—open… https://blog.gridinsoft.com/chick-fil-a-one-credential-stuffing-2026/
198
13
AWS Kiro Flaw Turned Hidden Web Text Into Code Execution AWS deployed a fix for a Kiro IDE vulnerability that could turn hidd
AWS Kiro Flaw Turned Hidden Web Text Into Code Execution AWS deployed a fix for a Kiro IDE vulnerability that could turn hidden instructions on a fetched web page into code running on a developer’s computer. Joint research by Kodem Security and Intezer showed that Kiro could rewrite its own ~/.kiro/settings/mcp.json file and automatically start an attacker-defined MCP server without asking the user… https://blog.gridinsoft.com/aws-kiro-hidden-text-code-execution/
216
14
HOLLOWGRAPH Malware Hides in Microsoft 365 Calendar Events HOLLOWGRAPH is a newly documented Windows espionage implant that h
HOLLOWGRAPH Malware Hides in Microsoft 365 Calendar Events HOLLOWGRAPH is a newly documented Windows espionage implant that hides commands and stolen files inside a compromised Microsoft 365 calendar. Group-IB found events parked on May 13, 2050, where users are unlikely to notice them. The malware uses normal Microsoft Graph API traffic for tasking and file theft, while a separate DNS channel refreshes… https://blog.gridinsoft.com/hollowgraph-microsoft-365-calendar-malware/
233
15
NGINX CVE-2026-42533: Check Regex Maps and Update Now CVE-2026-42533 is a heap buffer overflow in NGINX request processing th
NGINX CVE-2026-42533: Check Regex Maps and Update Now CVE-2026-42533 is a heap buffer overflow in NGINX request processing that can crash worker processes and, under specific configurations, may allow pre-authentication remote code execution. NGINX Open Source versions 0.9.6 through 1.30.3 and mainline 1.31.2 contain the vulnerable code; the complete fix is in stable 1.30.4… https://blog.gridinsoft.com/nginx-cve-2026-42533-regex-map-rce/
289
16
UAC-0145 Uses Fake CAPTCHA and Security Apps Against Ukraine CERT-UA says the UAC-0145 threat cluster has been using several
UAC-0145 Uses Fake CAPTCHA and Security Apps Against Ukraine CERT-UA says the UAC-0145 threat cluster has been using several routes to compromise Ukrainian devices: trojanized Windows and Microsoft Office installers from torrent trackers, fake security tools sent through Signal, fake CAPTCHA pages that tell visitors to run PowerShell, and a counterfeit Android security app. The July 15 report connects these routes to named… https://blog.gridinsoft.com/uac-0145-clickfix-fake-security-apps/
278
17
WordPress wp2shell CVE-2026-63030: Update to 7.0.2 Now WordPress site owners running versions 6.9.0 through 6.9.4 or 7.0.0 th
WordPress wp2shell CVE-2026-63030: Update to 7.0.2 Now WordPress site owners running versions 6.9.0 through 6.9.4 or 7.0.0 through 7.0.1 should update immediately. The WordPress security team has patched CVE-2026-63030, also called wp2shell, a critical pre-authentication remote code execution flaw in WordPress Core. An anonymous attacker can reach the vulnerable path on a stock… https://blog.gridinsoft.com/wordpress-wp2shell-cve-2026-63030-update/
310
18
OTTERCOOKIE Malware Hides in SVG Files in Fake Coding Tests A fake developer coding test can look functional while its SVG fl
OTTERCOOKIE Malware Hides in SVG Files in Fake Coding Tests A fake developer coding test can look functional while its SVG flag files quietly store pieces of OTTERCOOKIE malware. Elastic Security Labs documented the REF9403 campaign after a developer received a supposed job opportunity through Slack. The repository ran as expected, but npm run dev also loaded serverValidation.js, reconstructed… https://blog.gridinsoft.com/ottercookie-svg-coding-test-malware/
286
19
Grok Build Repository Upload: What to Do After Version 0.2.93 Grok Build 0.2.93 was observed sending a Git bundle containing
Grok Build Repository Upload: What to Do After Version 0.2.93 Grok Build 0.2.93 was observed sending a Git bundle containing a repository’s tracked files and full commit history to xAI-controlled storage, even when the agent was told not to open files. A separate request path sent files the agent did read, including a tracked test .env. The researcher later observed that xAI… https://blog.gridinsoft.com/grok-build-repository-upload/
238
20
ACR Stealer ClickFix Attacks: What to Check After Running the Command Microsoft says ACR Stealer activity increased from late
ACR Stealer ClickFix Attacks: What to Check After Running the Command Microsoft says ACR Stealer activity increased from late April through mid-June 2026, with two ClickFix campaigns repeatedly appearing in investigated intrusions. Both begin by convincing a Windows user to run a command from a fake verification page. One chain uses WebDAV, rundll32.exe, PowerShell, and a Python loader; the other uses mshta.exe… https://blog.gridinsoft.com/acr-stealer-clickfix-attacks/
254