-
Security researcher Christopher Domas has released a proof-of-concept project called “skitter-creek-bath-salts,” which demonstrates a vulnerability in AMD’s DRAM-controller configuration that could compromise hardware-enforced memory isolation. T…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Apple has issued a new set of high-confidence Apple Threat Notification alerts, warning selected iPhone users in 110 countries that they may be targets of government-grade mercenary spyware. These notifications are not routine phishing messages or gene…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly uncovered espionage operation targeting Afghan telecom providers and South Asian critical infrastructure has exposed a layered attacker ecosystem built around custom implants, spoofed delivery portals, cloud-backed command-and-control channels….
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A rapidly expanding financial cybercrime model called AI token jacking, where threat actors steal developer API keys for popular AI platforms, consume the victim’s allocated model capacity, and resell that compute through gray-market proxy services. Th…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Fortinet has released security updates to address high-severity vulnerabilities in FortiWeb and FortiClient for Windows. These vulnerabilities could allow unauthenticated attackers to access appliance administration interfaces or execute arbitrary code…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly analyzed malware operation called Aeternum is turning the public Polygon blockchain into a command-and-control (C2) channel, allowing attackers to distribute botnet instructions without relying on a conventional server or domain. The design shi…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Hardware wallet manufacturer Trezor has recently disclosed a data breach at ShipMonk, a third-party shipping provider. This breach exposed the personal information of 13,689 customers. Importantly, Trezor’s internal systems, hardware wallets, pri…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Beacon CRM has confirmed that a threat actor likely downloaded a complete copy of its customer database after gaining access to its Amazon Web Services (AWS) environment using a compromised AWS access key. In an incident update published on August 12, …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly identified macOS infostealer, named AmnesiaStealer, targets users via ClickFix social-engineering campaigns that impersonate GitHub download pages. This malware combines various malicious features, including password theft, browser data collect…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A China-linked threat group tracked as Jewelbug has turned public Google Docs into a resilient command-and-control delivery channel, embedding freshly obfuscated malware payloads in documents that victim implants retrieve and execute. The technique all…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


