Latest Cyber-Attack News
الذهاب إلى القناة على Telegram
Latest cybersecurity incidents and malware threats.
إظهار المزيد2 908
المشتركون
+324 ساعات
+167 أيام
+830 أيام
أرشيف المشاركات
McKesson Data Breach: What Is Confirmed So Far
McKesson has confirmed a data breach involving unauthorized access to certain third-party applications and the exfiltration of data associated with a subset of customers. Its August 29 update narrows the affected business areas to Oncology & Multispecialty and Medical-Surgical, but the company has not yet disclosed the number of people involved or the specific…
https://blog.gridinsoft.com/mckesson-data-breach-2026/
.vu Phishing Surge Uses 1,660 Domains to Steal Accounts
A phishing operation used 1,660 short-lived domains in the
.vu country-code zone to deliver 28,167 emails observed between April and July 2026, according to KnowBe4 Threat Lab. Nearly every observed message placed the malicious link in the email body, while the domains were typically less than 20 days old.
The country…
https://blog.gridinsoft.com/vu-phishing-domains-mfa-bypass/Carhartt Data Breach Exposes 12.9 Million Accounts
A published dataset attributed to Carhartt contains 12,933,413 validated account email addresses together with names, phone numbers, and physical addresses. Have I Been Pwned added the breach on August 25 after Troy Hunt removed millions of synthetic benchmark records, test accounts, deactivated aliases, and duplicate corporate addresses from an initial count of almost…
https://blog.gridinsoft.com/carhartt-data-breach-12-9-million/
TerminalFix Turns Fake CAPTCHA Into a Network Tunnel
Microsoft has documented an active TerminalFix campaign that turns a fake CAPTCHA into a route through a victim’s internal network. Compromised websites display a counterfeit Cloudflare-style check, copy a PowerShell command to the clipboard, and tell the visitor to open Windows Terminal or PowerShell and paste it. If the command runs, the chain can…
https://blog.gridinsoft.com/terminalfix-fake-captcha-reverse-tunnel/
FBI Disrupts QTFY Router Botnet Behind China-Linked Attacks
The FBI and Justice Department have disabled two platforms used by the China-linked QTFY hacking group: the QScan botnet and the QTRouter proxy network. Court-authorized domain seizures broke hard-coded connections that the platforms relied on, making both systems inoperable, according to the Justice Department.[1]
The operation matters beyond the government agencies and critical-infrastructure organizations…
https://blog.gridinsoft.com/qtfy-qscan-qtrouter-router-botnet/
Klever Fixes 2 Critical KLV Minting Flaws
The Klever-Go project has published two critical advisories for flaws that could create unbacked KLV tokens. CVE-2026-54754 was used against the Klever mainnet in June, while CVE-2026-54755 describes a separate split-royalty overflow with no confirmed exploitation. Both issues are fixed in Klever-Go 1.7.19, so node operators should verify their version and…
https://blog.gridinsoft.com/klever-klv-minting-cve-2026-54754-54755/
WatchGuard Fixes 4 Critical Firebox RCE Flaws
WatchGuard released three Fireware OS branches on August 27, 2026 to fix 11 security flaws, including four critical vulnerabilities rated 9.3. The company is telling customers and service providers to update every owned, managed, and client-operated Firebox immediately. The fixed versions are Fireware 2026.2.2, 12.12.2, and 12.5.20 for the…
https://blog.gridinsoft.com/watchguard-firebox-critical-rce-fireware-update/
CVE-2026-53362 Exploited for Linux Container Escape
CISA added CVE-2026-53362 to its Known Exploited Vulnerabilities catalog on August 27, 2026, after finding evidence of active exploitation. The Linux kernel flaw can turn code execution inside a container into root access on the underlying host. U.S. federal agencies have until August 30 to apply vendor guidance and perform a forensic review,…
https://blog.gridinsoft.com/cve-2026-53362-linux-container-escape/
OpenAI Exposes Russian Influence Campaign Behind Fake Think Tank
OpenAI has banned a cluster of ChatGPT accounts that it assesses were very likely operated from Russia and used to promote a covert influence campaign built around the International Burke Institute (IBI). The supposed Israel-based expert community displayed copied research, questionable author attributions, and a proprietary “sovereignty” index that consistently favored Russia. ChatGPT was…
https://blog.gridinsoft.com/openai-russian-influence-campaign-fake-think-tank/
CVE-2026-8452 Exploited Against Citrix NetScaler
CISA has added CVE-2026-8452 to its Known Exploited Vulnerabilities catalog after confirming that attackers are using the Citrix NetScaler flaw. Organizations running customer-managed NetScaler ADC or NetScaler Gateway should upgrade every affected appliance and virtual server now. CISA set August 29, 2026 as the remediation deadline for covered federal systems and lists ransomware use…
https://blog.gridinsoft.com/cve-2026-8452-citrix-netscaler-exploited/
Fake Indeed Interview Apps Install Android Spyware
Fake Android interview apps are being offered to job seekers through conversations that begin on Indeed. Malwarebytes analyzed apps presented as an “Interview App” or “MyInterview” and found Android droppers that imitate Indeed, create a VPN connection after an email address is entered, and can install an additional spyware payload [1]. Indeed says its…
https://blog.gridinsoft.com/fake-indeed-interview-app-android-spyware/
CVE-2026-60004 Exploited Against Gitea Servers
CISA has added CVE-2026-60004 to its Known Exploited Vulnerabilities catalog after confirming exploitation of the critical Gitea code-injection flaw. Administrators running Gitea 1.17 through 1.27.0 should upgrade to 1.27.1 or later immediately, preserve relevant logs, and review accounts and repositories created while the server was exposed. The vulnerability can turn ordinary repository write access…
https://blog.gridinsoft.com/cve-2026-60004-gitea-rce/
CVE-2026-55553: urllib Redirects Can Leak Credentials
A high-severity flaw in the Node.js
urllib package can forward authentication headers to a different origin when an application automatically follows an HTTP redirect. CVE-2026-55553 affects urllib through 4.9.0 and the legacy 2.x line through 2.44.0. Maintainers fixed it in 4.9.1 and 2.44.1.
The vulnerable package is the npm client named…
https://blog.gridinsoft.com/cve-2026-55553-urllib-credential-leak/CVE-2026-21962 Exploited in Oracle HTTP Server Proxy
CISA added CVE-2026-21962 to its Known Exploited Vulnerabilities catalog on August 24, confirming that attackers are using the maximum-severity flaw against Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in. Administrators running an affected proxy component should apply Oracle’s January 2026 Critical Patch Update now and preserve relevant HTTP and application logs before…
https://blog.gridinsoft.com/cve-2026-21962-oracle-http-weblogic-proxy/
PavinLoader Spreads Through ClickFix and Fake Downloads
Malwarebytes researchers have identified PavinLoader in several Windows infection campaigns that begin with different lures: fake CAPTCHA instructions, counterfeit software downloads, and malicious Ren’Py game installers. Seeing one of those pages is not itself an infection. The serious exposure starts when a user runs the copied command, installer, or game package, allowing a multi-stage…
https://blog.gridinsoft.com/pavinloader-clickfix-fake-downloads/
Grok Cryptographic Context Injection Could Leak Chat History
Security researchers at Adversa AI demonstrated that a prepared webpage could make Grok expose data from the current conversation after the user asked the agent to summarize the page. The page carried encrypted instructions that Grok decrypted inside its Python runtime. The agent then treated the plaintext as trusted output and opened an external…
https://blog.gridinsoft.com/grok-cryptographic-context-injection-chat-leak/
E4del and PINHOLE RATs Hide Commands in FTP Banners
Two newly documented Windows remote access trojans, E4del and PINHOLE, are using an unusual delivery trick: commands hidden inside the greeting banner returned by an FTP server. The observed chains start with a ZIP archive containing a disguised Windows shortcut. Receiving the archive is not infection, but running the shortcut can launch PowerShell, fetch…
https://blog.gridinsoft.com/e4del-pinhole-ftp-banner-malware/
CVE-2026-73570 Exploited Against Zimbra Servers
CISA added CVE-2026-73570 to its Known Exploited Vulnerabilities catalog on August 21, confirming that attackers are using the Zimbra Collaboration flaw in the wild. The command-injection path affects ZCS versions before 10.1.20 when the optional
zimbra-snmp package is installed and SNMP notifications are enabled. An unauthenticated attacker can send…
https://blog.gridinsoft.com/cve-2026-73570-zimbra-rce/CareCloud Data Breach Affects 3.75 Million Patients
The U.S. Department of Health and Human Services now lists 3,756,469 people as affected by the CareCloud data breach. CareCloud says an unauthorized third party accessed one of its Amazon Web Services environments between March 10 and March 16, 2026, and claimed to have taken data from databases there. The practical response depends…
https://blog.gridinsoft.com/carecloud-data-breach-3-75-million/
arrayref 0.3.10 Malware: Check Rust Builds and CI
The Rust Security Response Team removed malicious releases of arrayref 0.3.10, internment 0.8.7, and append-only-vec 0.1.9 from crates.io on August 20. Each poisoned release pulled in a malicious dependency named proc-macro1, whose build script downloaded and launched a payload while Cargo compiled a project. Developers should…
https://blog.gridinsoft.com/arrayref-0-3-10-malware/
