en
Feedback
Latest Cyber-Attack News

Latest Cyber-Attack News

Open in Telegram

Latest cybersecurity incidents and malware threats.

Show more
2 912
Subscribers
+124 hours
+127 days
+1530 days
Attracting Subscribers
September '26
September '26
+4
in 0 channels
August '26
+60
in 0 channels
Get PRO
July '26
+81
in 0 channels
Get PRO
June '26
+92
in 0 channels
Get PRO
May '26
+36
in 0 channels
Get PRO
April '26
+24
in 0 channels
Get PRO
March '26
+34
in 0 channels
Get PRO
February '26
+35
in 0 channels
Get PRO
January '26
+42
in 0 channels
Get PRO
December '25
+91
in 0 channels
Get PRO
November '25
+90
in 0 channels
Get PRO
October '25
+131
in 0 channels
Get PRO
September '25
+149
in 0 channels
Get PRO
August '25
+175
in 0 channels
Get PRO
July '25
+154
in 0 channels
Get PRO
June '25
+126
in 0 channels
Get PRO
May '25
+74
in 0 channels
Get PRO
April '25
+162
in 0 channels
Get PRO
March '25
+103
in 0 channels
Get PRO
February '25
+100
in 0 channels
Get PRO
January '25
+96
in 0 channels
Get PRO
December '24
+83
in 0 channels
Get PRO
November '24
+72
in 0 channels
Get PRO
October '24
+80
in 0 channels
Get PRO
September '24
+73
in 0 channels
Get PRO
August '24
+90
in 0 channels
Get PRO
July '24
+89
in 0 channels
Get PRO
June '24
+64
in 0 channels
Get PRO
May '24
+71
in 0 channels
Get PRO
April '24
+72
in 0 channels
Get PRO
March '24
+83
in 0 channels
Get PRO
February '24
+73
in 0 channels
Get PRO
January '24
+70
in 0 channels
Get PRO
December '23
+1 478
in 0 channels
Date
Subscriber Growth
Mentions
Channels
03 September0
02 September+2
01 September+2
Channel Posts
Fake Netflix APK Delivers PanDa RAT Through Meta Ads Chinese-speaking threat actors are using Meta ads for free Netflix and o
Fake Netflix APK Delivers PanDa RAT Through Meta Ads Chinese-speaking threat actors are using Meta ads for free Netflix and other streaming services to push Android malware at Spanish-speaking users in Mexico. The downloaded APK is not a streaming app: it installs a loader called ShellA and then the PanDa remote access trojan (RAT), according to Intel 471 [1]. This is not a… https://blog.gridinsoft.com/fake-netflix-apk-panda-rat/

2
Fake Exodus Installer Hides a RAT Behind a Wallet That Never Opens A Windows installer can look like Exodus, contain a workin
Fake Exodus Installer Hides a RAT Behind a Wallet That Never Opens A Windows installer can look like Exodus, contain a working copy of the wallet, and still be a remote access trojan. Huntress found this setup at four unrelated organizations between July 24 and August 18. The malicious package launched a mostly genuine Exodus 24.33.4 build without showing its window, then activated a modular RAT… https://blog.gridinsoft.com/fake-exodus-installer-rat/
61
3
iAuthFlow v2 Adds a Rogue Google Passkey That Survives Reset iAuthFlow v2 can turn one successful Google phishing login into
iAuthFlow v2 Adds a Rogue Google Passkey That Survives Reset iAuthFlow v2 can turn one successful Google phishing login into access that survives a password reset. In a seller-controlled demonstration analyzed by Abnormal AI, the toolkit relayed the victim’s Google sign-in through an attacker-controlled browser, then used that authenticated session to enroll a new passkey. Resetting the password and revoking the captured session did… https://blog.gridinsoft.com/iauthflow-v2-rogue-google-passkey/
90
4
Agent Tesla Malware Hides in Emoji-Obfuscated JScript Agent Tesla emoji malware is arriving in fake bank-payment email. A cam
Agent Tesla Malware Hides in Emoji-Obfuscated JScript Agent Tesla emoji malware is arriving in fake bank-payment email. A campaign analyzed by KnowBe4 on August 20 uses an unusually large JScript attachment filled with Unicode emoji to conceal the code that ultimately launches Agent Tesla v4 in memory. Ordinary emoji in an email are harmless; the danger begins when the recipient runs… https://blog.gridinsoft.com/agent-tesla-emoji-jscript-malware/
104
5
Superior: 19 Browser Extensions Steal Wallets and Passwords Nineteen Chrome and Edge extensions in the Superior campaign coul
Superior: 19 Browser Extensions Steal Wallets and Passwords Nineteen Chrome and Edge extensions in the Superior campaign could steal crypto, passwords, browser sessions, and form data. Socket says the operator built 14 extensions and took over five established ones, then delivered up to 16 malicious modules through updates. One acquired Chrome extension had about 70,000 users when it received the malicious update;… https://blog.gridinsoft.com/superior-malicious-browser-extensions/
110
6
SynkLoader Malware Uses a Fake Windows Lock Screen to Steal Passwords SynkLoader malware turns a Microsoft Teams help-desk me
SynkLoader Malware Uses a Fake Windows Lock Screen to Steal Passwords SynkLoader malware turns a Microsoft Teams help-desk message into a multi-stage Windows compromise. Expel says the attacker posed as “IT Service Desk,” convinced a user to install a fake PowerShell Cleaner MSI, and then deployed credential theft, network tunneling, a remote shell, and VNC access. The most visible trick is PhishLocker: a full-screen imitation… https://blog.gridinsoft.com/synkloader-malware-fake-lock-screen/
112
7
Claude Sessions Stolen by Infostealers Drain Usage Anthropic is warning some Claude users that infostealer malware copied the
Claude Sessions Stolen by Infostealers Drain Usage Anthropic is warning some Claude users that infostealer malware copied their active login sessions and let an attacker consume account usage without signing in again. A telltale pattern is a usage limit that refills and then drains while the owner is not using Claude. This is an endpoint-malware incident, not evidence that Anthropic’s infrastructure… https://blog.gridinsoft.com/claude-session-stolen-infostealer/
162
8
McKesson Data Breach: What Is Confirmed So Far McKesson has confirmed a data breach involving unauthorized access to certain
McKesson Data Breach: What Is Confirmed So Far McKesson has confirmed a data breach involving unauthorized access to certain third-party applications and the exfiltration of data associated with a subset of customers. Its August 29 update narrows the affected business areas to Oncology & Multispecialty and Medical-Surgical, but the company has not yet disclosed the number of people involved or the specific… https://blog.gridinsoft.com/mckesson-data-breach-2026/
219
9
.vu Phishing Surge Uses 1,660 Domains to Steal Accounts A phishing operation used 1,660 short-lived domains in the .vu countr
.vu Phishing Surge Uses 1,660 Domains to Steal Accounts A phishing operation used 1,660 short-lived domains in the .vu country-code zone to deliver 28,167 emails observed between April and July 2026, according to KnowBe4 Threat Lab. Nearly every observed message placed the malicious link in the email body, while the domains were typically less than 20 days old. The country… https://blog.gridinsoft.com/vu-phishing-domains-mfa-bypass/
194
10
Carhartt Data Breach Exposes 12.9 Million Accounts A published dataset attributed to Carhartt contains 12,933,413 validated a
Carhartt Data Breach Exposes 12.9 Million Accounts A published dataset attributed to Carhartt contains 12,933,413 validated account email addresses together with names, phone numbers, and physical addresses. Have I Been Pwned added the breach on August 25 after Troy Hunt removed millions of synthetic benchmark records, test accounts, deactivated aliases, and duplicate corporate addresses from an initial count of almost… https://blog.gridinsoft.com/carhartt-data-breach-12-9-million/
194
11
TerminalFix Turns Fake CAPTCHA Into a Network Tunnel Microsoft has documented an active TerminalFix campaign that turns a fak
TerminalFix Turns Fake CAPTCHA Into a Network Tunnel Microsoft has documented an active TerminalFix campaign that turns a fake CAPTCHA into a route through a victim’s internal network. Compromised websites display a counterfeit Cloudflare-style check, copy a PowerShell command to the clipboard, and tell the visitor to open Windows Terminal or PowerShell and paste it. If the command runs, the chain can… https://blog.gridinsoft.com/terminalfix-fake-captcha-reverse-tunnel/
184
12
FBI Disrupts QTFY Router Botnet Behind China-Linked Attacks The FBI and Justice Department have disabled two platforms used b
FBI Disrupts QTFY Router Botnet Behind China-Linked Attacks The FBI and Justice Department have disabled two platforms used by the China-linked QTFY hacking group: the QScan botnet and the QTRouter proxy network. Court-authorized domain seizures broke hard-coded connections that the platforms relied on, making both systems inoperable, according to the Justice Department.[1] The operation matters beyond the government agencies and critical-infrastructure organizations… https://blog.gridinsoft.com/qtfy-qscan-qtrouter-router-botnet/
199
13
Klever Fixes 2 Critical KLV Minting Flaws The Klever-Go project has published two critical advisories for flaws that could cr
Klever Fixes 2 Critical KLV Minting Flaws The Klever-Go project has published two critical advisories for flaws that could create unbacked KLV tokens. CVE-2026-54754 was used against the Klever mainnet in June, while CVE-2026-54755 describes a separate split-royalty overflow with no confirmed exploitation. Both issues are fixed in Klever-Go 1.7.19, so node operators should verify their version and… https://blog.gridinsoft.com/klever-klv-minting-cve-2026-54754-54755/
207
14
WatchGuard Fixes 4 Critical Firebox RCE Flaws WatchGuard released three Fireware OS branches on August 27, 2026 to fix 11 sec
WatchGuard Fixes 4 Critical Firebox RCE Flaws WatchGuard released three Fireware OS branches on August 27, 2026 to fix 11 security flaws, including four critical vulnerabilities rated 9.3. The company is telling customers and service providers to update every owned, managed, and client-operated Firebox immediately. The fixed versions are Fireware 2026.2.2, 12.12.2, and 12.5.20 for the… https://blog.gridinsoft.com/watchguard-firebox-critical-rce-fireware-update/
207
15
CVE-2026-53362 Exploited for Linux Container Escape CISA added CVE-2026-53362 to its Known Exploited Vulnerabilities catalog
CVE-2026-53362 Exploited for Linux Container Escape CISA added CVE-2026-53362 to its Known Exploited Vulnerabilities catalog on August 27, 2026, after finding evidence of active exploitation. The Linux kernel flaw can turn code execution inside a container into root access on the underlying host. U.S. federal agencies have until August 30 to apply vendor guidance and perform a forensic review,… https://blog.gridinsoft.com/cve-2026-53362-linux-container-escape/
202
16
OpenAI Exposes Russian Influence Campaign Behind Fake Think Tank OpenAI has banned a cluster of ChatGPT accounts that it asse
OpenAI Exposes Russian Influence Campaign Behind Fake Think Tank OpenAI has banned a cluster of ChatGPT accounts that it assesses were very likely operated from Russia and used to promote a covert influence campaign built around the International Burke Institute (IBI). The supposed Israel-based expert community displayed copied research, questionable author attributions, and a proprietary “sovereignty” index that consistently favored Russia. ChatGPT was… https://blog.gridinsoft.com/openai-russian-influence-campaign-fake-think-tank/
203
17
CVE-2026-8452 Exploited Against Citrix NetScaler CISA has added CVE-2026-8452 to its Known Exploited Vulnerabilities catalog
CVE-2026-8452 Exploited Against Citrix NetScaler CISA has added CVE-2026-8452 to its Known Exploited Vulnerabilities catalog after confirming that attackers are using the Citrix NetScaler flaw. Organizations running customer-managed NetScaler ADC or NetScaler Gateway should upgrade every affected appliance and virtual server now. CISA set August 29, 2026 as the remediation deadline for covered federal systems and lists ransomware use… https://blog.gridinsoft.com/cve-2026-8452-citrix-netscaler-exploited/
221
18
Fake Indeed Interview Apps Install Android Spyware Fake Android interview apps are being offered to job seekers through conve
Fake Indeed Interview Apps Install Android Spyware Fake Android interview apps are being offered to job seekers through conversations that begin on Indeed. Malwarebytes analyzed apps presented as an “Interview App” or “MyInterview” and found Android droppers that imitate Indeed, create a VPN connection after an email address is entered, and can install an additional spyware payload [1]. Indeed says its… https://blog.gridinsoft.com/fake-indeed-interview-app-android-spyware/
235
19
CVE-2026-60004 Exploited Against Gitea Servers CISA has added CVE-2026-60004 to its Known Exploited Vulnerabilities catalog a
CVE-2026-60004 Exploited Against Gitea Servers CISA has added CVE-2026-60004 to its Known Exploited Vulnerabilities catalog after confirming exploitation of the critical Gitea code-injection flaw. Administrators running Gitea 1.17 through 1.27.0 should upgrade to 1.27.1 or later immediately, preserve relevant logs, and review accounts and repositories created while the server was exposed. The vulnerability can turn ordinary repository write access… https://blog.gridinsoft.com/cve-2026-60004-gitea-rce/
266
20
CVE-2026-55553: urllib Redirects Can Leak Credentials A high-severity flaw in the Node.js urllib package can forward authenti
CVE-2026-55553: urllib Redirects Can Leak Credentials A high-severity flaw in the Node.js urllib package can forward authentication headers to a different origin when an application automatically follows an HTTP redirect. CVE-2026-55553 affects urllib through 4.9.0 and the legacy 2.x line through 2.44.0. Maintainers fixed it in 4.9.1 and 2.44.1. The vulnerable package is the npm client named… https://blog.gridinsoft.com/cve-2026-55553-urllib-credential-leak/
269