Xpykerz
Open in Telegram
1 042
Subscribers
No data24 hours
+27 days
-530 days
Posts Archive
1 042
Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities
#News
Posted On 📆 : Sat, 05 Sep 2026 13:01:53 +0530
Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe.
The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as
😍Share And Support😍
➖@Xpykerz➖
1 042
Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel
#News
Posted On 📆 : Sat, 05 Sep 2026 13:25:10 +0530
A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox.
The activity was concentrated on DSEwiki, a German software developer wiki that runs
😍Share And Support😍
➖@Xpykerz➖
1 042
Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted
#News
Posted On 📆 : Sat, 05 Sep 2026 19:47:02 +0530
Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk.
The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets
😍Share And Support😍
➖@Xpykerz➖
1 042
Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
#News
Posted On 📆 : Sat, 05 Sep 2026 21:35:08 +0530
Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions.
The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code.
"A
😍Share And Support😍
➖@Xpykerz➖
1 042
Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
#News
Posted On 📆 : Sat, 05 Sep 2026 22:22:33 +0530
JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment.
"Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.
😍Share And Support😍
➖@Xpykerz➖
1 042
GPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit Requests
#News
Posted On 📆 : Fri, 04 Sep 2026 12:17:52 +0530
OpenAI on Thursday officially unveiled GPT‑6 Astra, which it described as the "world's most intelligent and aligned model."
The development comes days after the artificial intelligence (AI) company said the model had reached the "Critical" cybersecurity capability threshold under its Preparedness Framework.
"Astra is state-of-the-art on computer use, browsing, software engineering,
😍Share And Support😍
➖@Xpykerz➖
1 042
Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day
#News
Posted On 📆 : Fri, 04 Sep 2026 12:48:47 +0530
Google on Thursday released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild.
The high-severity vulnerability, tracked as CVE-2026-85046 (CVSS score: 8.8), has been described as a type confusion bug in V8, Chrome's JavaScript and WebAssembly engine.
"Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote
😍Share And Support😍
➖@Xpykerz➖
1 042
Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws
#News
Posted On 📆 : Fri, 04 Sep 2026 13:05:14 +0530
Plex is urging users to update their instances to the latest version following the release of an update that patches multiple security flaws.
The fixes are available in Plex Media Server 1.43.3 and Plex Desktop 1.115.0. The streaming media service did not elaborate on what those issues are, but said CVE identifiers have been requested for them.
"We recommend all server owners and Desktop users
😍Share And Support😍
➖@Xpykerz➖
1 042
Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
#News
Posted On 📆 : Fri, 04 Sep 2026 14:18:45 +0530
Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence.
The vulnerabilities in question are -
CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms – Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type, including
😍Share And Support😍
➖@Xpykerz➖
1 042
New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic
#News
Posted On 📆 : Fri, 04 Sep 2026 20:21:13 +0530
A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors.
The attackers named the implant ted in debug strings left in the binary. It is not a HAProxy vulnerability, and installing it requires code execution on the host and
😍Share And Support😍
➖@Xpykerz➖
1 042
PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution
#News
Posted On 📆 : Fri, 04 Sep 2026 20:50:19 +0530
PostgreSQL has released updates to address a security flaw that allows an account with the REPLICATION attribute to run arbitrary code as the operating-system user running the database server.
The flaw, tracked as CVE-2026-6471 (CVSS score: 7.2), has been present since logical decoding was introduced in PostgreSQL 9.4 in 2014. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are
😍Share And Support😍
➖@Xpykerz➖
1 042
Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
#News
Posted On 📆 : Fri, 04 Sep 2026 21:27:15 +0530
Microsoft is alerting of a "high-volume phishing campaign" that's using invisible Unicode tag characters to bypass email filters.
"Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as 'funding' to prevent email filters from parsing them," the Microsoft Security Research team said.
The
😍Share And Support😍
➖@Xpykerz➖
1 042
CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
#News
Posted On 📆 : Thu, 03 Sep 2026 10:49:04 +0530
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in attackers' crosshairs.
The vulnerabilities are as follows -
CVE-2026-83548 (CVSS score: 10.0) - A server-side request forgery vulnerability in SonicWall SMA 1000 Appliances that could allow a remote unauthenticated
😍Share And Support😍
➖@Xpykerz➖
1 042
Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon
#News
Posted On 📆 : Thu, 03 Sep 2026 11:56:59 +0530
The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank, a proof-of-concept (PoC) for a privilege escalation flaw impacting Crowdstrike Falcon.
"FalconFlank is a 0-day privilege escalation that abuses the office malicious macros remediation in CrowdStrike Falcon Sensor," the researcher said in
😍Share And Support😍
➖@Xpykerz➖
1 042
Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone
#News
Posted On 📆 : Thu, 03 Sep 2026 14:13:17 +0530
The iPhone belonging to a member of Serbia's student protest movement was infected with NSO Group's Pegasus spyware, according to new findings from the Citizen Lab in collaboration with the SHARE Foundation.
"Our analysis confirmed that an iMessage zero-click exploit was used to infect the device with NSO Group's Pegasus spyware," the Citizen Lab said. "We found high-confidence indicators of
😍Share And Support😍
➖@Xpykerz➖
1 042
Shai-Hulud's Reach Just Grew to 469 Credential Locations. Here's What That Means
#News
Posted On 📆 : Thu, 03 Sep 2026 16:06:39 +0530
In early August, GitGuardian researchers found that a recent Shai-Hulud infostealer worm variant had evolved to scan for credentials across 469 locations across developer environments, Continuous Integration/Continuous Deployment (CI/CD) tooling, cloud configurations, and even AI tool configs.
Earlier variants of the infostealer worm only checked 189 paths. The jump says a lot. Attackers have
😍Share And Support😍
➖@Xpykerz➖
1 042
Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks
#News
Posted On 📆 : Thu, 03 Sep 2026 16:13:01 +0530
Threat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicious payloads.
According to a new report published by the Symantec Threat Hunter Team today, the attack method has been put to use in attacks targeting government departments, technology companies, and hotels since February 2026.
"The technique's appeal is that node.exe (the
😍Share And Support😍
➖@Xpykerz➖
1 042
US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries
#News
Posted On 📆 : Thu, 03 Sep 2026 17:28:00 +0530
An RMM phishing campaign initially associated with Canadian targeting due to its use of Canada Revenue Agency (CRA) tax forms as lures has turned out to be part of a broader campaign spanning 46 countries.
Around 45% of observed activity was associated with the United States, making it the campaign's top geographic target. ANY.RUN research connected 601 cases to the wider operation, which uses
😍Share And Support😍
➖@Xpykerz➖
1 042
Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data
#News
Posted On 📆 : Thu, 03 Sep 2026 20:09:05 +0530
Thomson Reuters disclosed on Wednesday that an unauthorized party obtained files from C-Track, the court case management platform sold by its West Publishing Corporation unit, in March 2026, affecting courts in 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada.
West Publishing said it discovered the activity on June 30, 2026. A subset of court records could contain individuals' names
😍Share And Support😍
➖@Xpykerz➖
1 042
BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory
#News
Posted On 📆 : Thu, 03 Sep 2026 20:56:47 +0530
Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts.
"Unlike the standard infostealer model, BraZetsu is a comprehensive master toolkit that empowers Initial Access Brokers (IABs) by turning compromised systems into highly valuable commercial
😍Share And Support😍
➖@Xpykerz➖
