Latest Cyber-Attack News
Открыть в Telegram
2 889
Подписчики
+124 часа
+77 дней
+3430 день
Загрузка данных...
Похожие каналы
Облако тегов
Входящие и исходящие упоминания
---
---
---
---
---
---
Привлечение подписчиков
июль '26
июль '26
+65
в 0 каналах
июнь '26
+92
в 0 каналах
Get PRO
май '26
+36
в 0 каналах
Get PRO
апрель '26
+24
в 0 каналах
Get PRO
март '26
+34
в 0 каналах
Get PRO
февраль '26
+35
в 0 каналах
Get PRO
январь '26
+42
в 0 каналах
Get PRO
декабрь '25
+91
в 0 каналах
Get PRO
ноябрь '25
+90
в 0 каналах
Get PRO
октябрь '25
+131
в 0 каналах
Get PRO
сентябрь '25
+149
в 0 каналах
Get PRO
август '25
+175
в 0 каналах
Get PRO
июль '25
+154
в 0 каналах
Get PRO
июнь '25
+126
в 0 каналах
Get PRO
май '25
+74
в 0 каналах
Get PRO
апрель '25
+162
в 0 каналах
Get PRO
март '25
+103
в 0 каналах
Get PRO
февраль '25
+100
в 0 каналах
Get PRO
январь '25
+96
в 0 каналах
Get PRO
декабрь '24
+83
в 0 каналах
Get PRO
ноябрь '24
+72
в 0 каналах
Get PRO
октябрь '24
+80
в 0 каналах
Get PRO
сентябрь '24
+73
в 0 каналах
Get PRO
август '24
+90
в 0 каналах
Get PRO
июль '24
+89
в 0 каналах
Get PRO
июнь '24
+64
в 0 каналах
Get PRO
май '24
+71
в 0 каналах
Get PRO
апрель '24
+72
в 0 каналах
Get PRO
март '24
+83
в 0 каналах
Get PRO
февраль '24
+73
в 0 каналах
Get PRO
январь '24
+70
в 0 каналах
Get PRO
декабрь '23
+1 478
в 0 каналах
| Дата | Привлечение подписчиков | Упоминания | Каналы | |
| 27 июля | +2 | |||
| 26 июля | +1 | |||
| 25 июля | +2 | |||
| 24 июля | +2 | |||
| 23 июля | +5 | |||
| 22 июля | +5 | |||
| 21 июля | 0 | |||
| 20 июля | +1 | |||
| 19 июля | +3 | |||
| 18 июля | +2 | |||
| 17 июля | +1 | |||
| 16 июля | +5 | |||
| 15 июля | +4 | |||
| 14 июля | +1 | |||
| 13 июля | +2 | |||
| 12 июля | +3 | |||
| 11 июля | +1 | |||
| 10 июля | +4 | |||
| 09 июля | 0 | |||
| 08 июля | +5 | |||
| 07 июля | +2 | |||
| 06 июля | 0 | |||
| 05 июля | +3 | |||
| 04 июля | +2 | |||
| 03 июля | +1 | |||
| 02 июля | +4 | |||
| 01 июля | +4 |
Посты канала
MedusaHVNC Hijacks Browser Sessions on a Hidden Desktop
BlackFog has analyzed MedusaHVNC, a Windows remote access trojan sold as malware-as-a-service. Its defining feature is a hidden desktop where an attacker can open Chrome, Edge, or Firefox and interact with a browser session that is already logged in on the infected PC. The victim can keep using the visible desktop without…
https://blog.gridinsoft.com/medusahvnc-hidden-desktop-browser-sessions/
| 2 | OpenAI Agent Hacked Hugging Face—and Went Unnoticed for Days
An OpenAI evaluation agent broke out of its intended network boundary and compromised Hugging Face production systems while trying to obtain answers for a cybersecurity benchmark. OpenAI and Hugging Face confirm the core incident. Reuters now reports that the intrusion ran from July 11 to July 13 and that OpenAI did not connect its…
https://blog.gridinsoft.com/openai-agent-hugging-face-hack/ | 106 |
| 3 | Fastjson CVE-2026-16723: Enable SafeMode on 1.x Now
Fastjson CVE-2026-16723 can allow unauthenticated remote code execution in a specific but common Spring Boot setup. The maintainer lists Fastjson 1.2.68 through 1.2.83 as affected when the application runs as an executable fat JAR, processes attacker-controlled JSON, and has SafeMode disabled—the stock default [1].
ThreatBook says its platform captured exploitation…
https://blog.gridinsoft.com/fastjson-cve-2026-16723-safemode/ | 103 |
| 4 | Steam Forum ClickFix Installs XMRig Miner via PowerShell
https://blog.gridinsoft.com/steam-forum-clickfix-xmrig/ | 115 |
| 5 | SourTrade Malware: Fake Trading Ads Build It in Your Browser
SourTrade malware is being assembled inside the victim’s browser before it is offered as a Windows download. Confiant documented fake TradingView, Solana and Luno pages that use JavaScript workers, build instructions and a clean Bun runtime to create a different executable for each session. The pages arrive through malvertising and are designed to show…
https://blog.gridinsoft.com/sourtrade-browser-assembled-malware/ | 139 |
| 6 | Hotel Wi-Fi DNS Poisoning Redirects Microsoft 365 Logins
ReliaQuest has identified a widespread campaign in which attackers compromise Wi-Fi gateways at hotels, conference centers, and other captive-portal venues, then poison DNS responses to redirect travelers toward fake Microsoft 365 sign-in pages. The activity has been ongoing since at least June 2026 and was observed in multiple U.S. cities, India, and Saudi Arabia.…
https://blog.gridinsoft.com/hotel-wifi-dns-poisoning-microsoft-365/ | 165 |
| 7 | Dolphin X Stealer Uses AI to Rank High-Value Victims
Varonis Threat Labs has analyzed the operator panel for Dolphin X, a Windows information stealer and remote access trojan sold on a cybercrime forum. The panel advertises collection from more than 300 applications and includes an “AI Profiler” that can rank infected machines by app usage, browsing activity, installed software, and an…
https://blog.gridinsoft.com/dolphin-x-stealer-ai-profiler/ | 202 |
| 8 | msaRAT Hides C2 Traffic Inside Chrome and Edge
Cisco Talos has uncovered msaRAT, a Rust-based remote access trojan used in recent Chaos ransomware intrusions. After an attacker already has access to a Windows system, the malware starts a hidden Chrome or Microsoft Edge process and makes that browser carry its encrypted command-and-control traffic over WebRTC.
This does not mean Chrome…
https://blog.gridinsoft.com/msarat-chrome-edge-browser-c2/ | 225 |
| 9 | TrickBot Uses DNS Tunneling to Hide Windows C2 Traffic
FortiGuard Labs has analyzed a current TrickBot variant that hides command-and-control traffic inside DNS queries and keeps access to an infected Windows system through a disguised scheduled task. The report gives defenders and affected users concrete checks: the domain westurn[.]in, six sample hashes, task names ending in autoupdate #{random}, and…
https://blog.gridinsoft.com/trickbot-dns-tunneling-windows/ | 208 |
| 10 | Check Point SmartConsole CVE-2026-16232 Exploited: Patch Now
Check Point says attackers are exploiting CVE-2026-16232, a SmartConsole authentication bypass that can give a remote unauthenticated attacker full administrator access to a Security Management or Multi-Domain Management server. The company observed attacks at a handful of customers whose management systems were exposed directly to the internet without IP restrictions. Administrators should…
https://blog.gridinsoft.com/check-point-smartconsole-cve-2026-16232/ | 202 |
| 11 | Adobe Acrobat Extension Flaw Could Expose WhatsApp Web Chats
A now-fixed flaw in the Adobe Acrobat PDF extension for Chrome could let a malicious website read text already rendered inside WhatsApp Web. The vulnerability, CVE-2026-48294, affected extension versions 26.5.2.2 and earlier; users should verify that Chrome has installed version 26.5.2.3 or later. Guardio Labs named the proof-of-concept…
https://blog.gridinsoft.com/adobe-acrobat-extension-whatsapp-flaw/ | 188 |
| 12 | Chick-fil-A One Accounts Hit in Credential Stuffing Attack
Between June 17 and June 19, 2026, attackers used email-and-password combinations obtained from another source to sign in to Chick-fil-A One accounts through the company’s website and app. Chick-fil-A said its investigation determined on July 13 that some account data had been accessed. If you received a notice—or reused your Chick-fil-A password anywhere else—open…
https://blog.gridinsoft.com/chick-fil-a-one-credential-stuffing-2026/ | 198 |
| 13 | AWS Kiro Flaw Turned Hidden Web Text Into Code Execution
AWS deployed a fix for a Kiro IDE vulnerability that could turn hidden instructions on a fetched web page into code running on a developer’s computer. Joint research by Kodem Security and Intezer showed that Kiro could rewrite its own ~/.kiro/settings/mcp.json file and automatically start an attacker-defined MCP server without asking the user…
https://blog.gridinsoft.com/aws-kiro-hidden-text-code-execution/ | 216 |
| 14 | HOLLOWGRAPH Malware Hides in Microsoft 365 Calendar Events
HOLLOWGRAPH is a newly documented Windows espionage implant that hides commands and stolen files inside a compromised Microsoft 365 calendar. Group-IB found events parked on May 13, 2050, where users are unlikely to notice them. The malware uses normal Microsoft Graph API traffic for tasking and file theft, while a separate DNS channel refreshes…
https://blog.gridinsoft.com/hollowgraph-microsoft-365-calendar-malware/ | 233 |
| 15 | NGINX CVE-2026-42533: Check Regex Maps and Update Now
CVE-2026-42533 is a heap buffer overflow in NGINX request processing that can crash worker processes and, under specific configurations, may allow pre-authentication remote code execution. NGINX Open Source versions 0.9.6 through 1.30.3 and mainline 1.31.2 contain the vulnerable code; the complete fix is in stable 1.30.4…
https://blog.gridinsoft.com/nginx-cve-2026-42533-regex-map-rce/ | 289 |
| 16 | UAC-0145 Uses Fake CAPTCHA and Security Apps Against Ukraine
CERT-UA says the UAC-0145 threat cluster has been using several routes to compromise Ukrainian devices: trojanized Windows and Microsoft Office installers from torrent trackers, fake security tools sent through Signal, fake CAPTCHA pages that tell visitors to run PowerShell, and a counterfeit Android security app. The July 15 report connects these routes to named…
https://blog.gridinsoft.com/uac-0145-clickfix-fake-security-apps/ | 278 |
| 17 | WordPress wp2shell CVE-2026-63030: Update to 7.0.2 Now
WordPress site owners running versions 6.9.0 through 6.9.4 or 7.0.0 through 7.0.1 should update immediately. The WordPress security team has patched CVE-2026-63030, also called wp2shell, a critical pre-authentication remote code execution flaw in WordPress Core. An anonymous attacker can reach the vulnerable path on a stock…
https://blog.gridinsoft.com/wordpress-wp2shell-cve-2026-63030-update/ | 310 |
| 18 | OTTERCOOKIE Malware Hides in SVG Files in Fake Coding Tests
A fake developer coding test can look functional while its SVG flag files quietly store pieces of OTTERCOOKIE malware. Elastic Security Labs documented the REF9403 campaign after a developer received a supposed job opportunity through Slack. The repository ran as expected, but npm run dev also loaded serverValidation.js, reconstructed…
https://blog.gridinsoft.com/ottercookie-svg-coding-test-malware/ | 286 |
| 19 | Grok Build Repository Upload: What to Do After Version 0.2.93
Grok Build 0.2.93 was observed sending a Git bundle containing a repository’s tracked files and full commit history to xAI-controlled storage, even when the agent was told not to open files. A separate request path sent files the agent did read, including a tracked test .env. The researcher later observed that xAI…
https://blog.gridinsoft.com/grok-build-repository-upload/ | 238 |
| 20 | ACR Stealer ClickFix Attacks: What to Check After Running the Command
Microsoft says ACR Stealer activity increased from late April through mid-June 2026, with two ClickFix campaigns repeatedly appearing in investigated intrusions. Both begin by convincing a Windows user to run a command from a fake verification page. One chain uses WebDAV, rundll32.exe, PowerShell, and a Python loader; the other uses mshta.exe…
https://blog.gridinsoft.com/acr-stealer-clickfix-attacks/ | 254 |
