Fake Indian Tax Notice Drops XWorm RAT via Multi-Stage .NET Loader
A financially motivated campaign targeting Indian Windows users delivers a RAT — likely XWorm — through fake Income Tax Department assessment notices and a multi-stage .NET loader.
Stories cluster related articles into a single narrative, linked to the underlying CVEs and affected products. 3,753 stories synthesized.
A financially motivated campaign targeting Indian Windows users delivers a RAT — likely XWorm — through fake Income Tax Department assessment notices and a multi-stage .NET loader.
Key findings • Seven XSS vulnerabilities disclosed together in Frappe Framework 17.0.0-dev on June 24, 2026. • Vulnerabilities affect multiple UI components including Tree View, Number Cards,…
A public proof-of-concept exploit is now available for CVE-2026-45504, an SSRF flaw in Exchange Server 2016 and 2019 that lets authenticated attackers read arbitrary files.
Attackers are exploiting CVE-2025-54068, a critical RCE vulnerability in Laravel Livewire, to steal credentials from thousands of applications worldwide.
Multiple critical vulnerabilities in Webmin before version 2.641 allow attackers to impersonate users, bypass 2FA, and gain root access.
The White House issued an executive order directing U.S. federal civilian agencies to migrate high-value systems to NIST-approved post-quantum cryptography by 2030 for key establishment and 2031 for digital signatures.
Palo Alto Networks Unit 42 discovered a BitB campaign that fakes software error pop-ups inside realistic browser windows to trick users into downloading malware installers.
A new malware cluster named GhostShell is targeting Ukrainian drone operators and defense supply chains with a multi-stage attack using mTLS implants and Telegram-based C2.
Security researchers at Cracken have identified critical architectural vulnerabilities in 12 open-source agentic red-team tools that allow attackers to steal LLM API keys, escape sandboxes, and fully compromise operators' systems.
SentinelLabs has discovered Gaslight, a Rust-based macOS backdoor tied to North Korea that uses 38 fabricated system messages to manipulate AI-powered analysis tools into misclassifying it as benign.
Key findings • 25 Jenkins plugins were affected by vulnerabilities disclosed on June 24, 2026. • Common themes include missing permission checks and cross-site request forgery (CSRF) across m…
Microsoft's Digital Crimes Unit, in coordination with Europol and industry partners, has disrupted the infrastructure behind the StealC infostealer and Amadey loader, taking down over 200 command-and-control domains and IPs.
Jenkins released a security advisory on June 24, 2026, patching 18 plugins for vulnerabilities ranging from sandbox bypass and arbitrary code execution to CSRF and information disclosure.
XM Cyber discovered a privilege-escalation technique abusing macOS CDHash caching that allows standard users to silently disable CrowdStrike Falcon and Kandji MDM, with Apple reportedly declining to fix the underlying OS issue.
NCC Group reports that Iran-linked MuddyWater is masquerading as the Chaos ransomware gang to conceal cyber espionage operations, blurring the line between criminal and state-backed activity.
Key findings • 25 CVEs disclosed together, all fixed in Capgo 12.128.2 (two in 12.128.12) • Multiple authentication and authorization bypasses, including 2FA bypass at the API level • Sub…
Key findings • Five vulnerabilities disclosed in Unclecode's Crawl4AI between June 21-24, 2026. • Multiple authentication bypass flaws including hardcoded JWT keys and unauthenticated monitor…
Initial access broker Woodgnat is deploying a new remote access trojan called Mistic to gain persistent footholds and resell access to ransomware groups including Qilin, Akira, and Black Basta.
Microsoft DART reveals that threat actor Storm-2603 is exploiting unpatched on-premises SharePoint servers to deploy ransomware and custom backdoors, with a second unknown actor simultaneously exfiltrating Active Directory credentials.
A new stealthy backdoor named Mistic has been tied to the initial access broker KongTuke, deployed against insurance, education, IT, and professional services organizations to enable ransomware attacks.
Kaspersky uncovered StrikeShark, a campaign deploying the new SharkLoader malware to deliver Cobalt Strike Beacon via exploits targeting Exchange, Openfire, GeoServer, and other internet-facing applications.
ReliaQuest's new report details six practical ways attackers are using AI to lower costs, speed up operations, and evade detection, from industrial-scale phishing to deepfake identity fabrication.
Anthropic's Claude Fable 5 autonomously produced a bootable NT-compatible Windows kernel in Rust, raising security implications for AI-authored critical infrastructure.
Google will now notify all administrators when any admin password is reset, expanding the Alert Center rule beyond super admins to improve privileged account oversight.