SecurityTicks

ThreatsDay Bulletin: Hybrid P2P Botnet, 13-Year-Old Apache RCE and 18 More Stories

ThreatsDay Bulletin: Hybrid P2P Botnet, 13-Year-Old Apache RCE and 18 More Stories 2026-04-09 at 17:32 By Thursday. Another week, another batch of things that probably should’ve been caught sooner but weren’t. This one’s got some range — old vulnerabilities getting new life, a few “why was that even possible” moments, attackers leaning on platforms and tools you’d […]

ThreatsDay Bulletin: Hybrid P2P Botnet, 13-Year-Old Apache RCE and 18 More Stories Read More »

Security researchers tricked Apple Intelligence into cursing at users. It could have been a lot worse

Security researchers tricked Apple Intelligence into cursing at users. It could have been a lot worse 2026-04-09 at 16:17 By Jessica Lyons Wash your mouth out with digital soap Apple Intelligence, the personal AI system integrated into newer Macs, iPhones, and other iThings, can be hijacked using prompt injection, forcing the model into producing an

Security researchers tricked Apple Intelligence into cursing at users. It could have been a lot worse Read More »

Err-Hiding and Seek: How ErrTraffic v3 Leverages EtherHiding in ClickFix Campaign

Err-Hiding and Seek: How ErrTraffic v3 Leverages EtherHiding in ClickFix Campaign 2026-04-09 at 16:17 By King Orande and Cris Tomboc TLP: AMBER+STRICT The LevelBlue SpiderLabs team examined the latest version of ErrTraffic, which emerged in early 2026. In a recently observed campaign, the team found that ErrTraffic primarily targets WordPress websites by deploying a PHP backdoor script

Err-Hiding and Seek: How ErrTraffic v3 Leverages EtherHiding in ClickFix Campaign Read More »

Claude helps researcher dig up decade-old Apache ActiveMQ RCE vulnerability (CVE-2026-34197)

Claude helps researcher dig up decade-old Apache ActiveMQ RCE vulnerability (CVE-2026-34197) 2026-04-09 at 16:17 By Zeljka Zorz In the latest demonstration of how AI assistants can help with bug hunting, Horizon3.ai researcher Naveen Sunkavally used Claude to unearth CVE-2026-34197, a remote code execution vulnerability in Apache ActiveMQ that’s been introduced in the codebase 13 years

Claude helps researcher dig up decade-old Apache ActiveMQ RCE vulnerability (CVE-2026-34197) Read More »

Mallory brings contextual threat intelligence to security operations

Mallory brings contextual threat intelligence to security operations 2026-04-09 at 16:16 By Industry News Mallory is launching an AI-native threat intelligence platform, purpose-built to answer the questions CISOs and their teams are asking every day: What are the real threat vectors for our organization? What’s actually exploitable in our environment right now? What should we

Mallory brings contextual threat intelligence to security operations Read More »

Gold, silver and oil drive 65,000% jump in commodity perpetuals

Gold, silver and oil drive 65,000% jump in commodity perpetuals 2026-04-09 at 15:44 By Cointelegraph by Zoltan Vardai BitMEX said commodity perpetual swaps volume jumped from $38.1 million to $25 billion in Q1 as traders flocked to 24/7 gold, silver and oil exposure. This article is an excerpt from Cointelegraph.com News View Original Source

Gold, silver and oil drive 65,000% jump in commodity perpetuals Read More »

Crypto exchanges chase TradFi commodities market as pricing gaps persist

Crypto exchanges chase TradFi commodities market as pricing gaps persist 2026-04-09 at 15:44 By Cointelegraph by Zoltan Vardai Crypto exchanges are racing to capture the market share of TradFi trading venues, but tokenized commodities adoption remains limited by pricing and liquidity concerns. This article is an excerpt from Cointelegraph.com News View Original Source

Crypto exchanges chase TradFi commodities market as pricing gaps persist Read More »

Bitcoin Depot discloses $3.7M BTC theft in cybersecurity breach

Bitcoin Depot discloses $3.7M BTC theft in cybersecurity breach 2026-04-09 at 15:44 By Cointelegraph by Amin Haqshanas Bitcoin Depot said a hacker stole 50.9 BTC, worth about $3.7 million, after gaining access to internal systems linked to corporate wallets. This article is an excerpt from Cointelegraph.com News View Original Source

Bitcoin Depot discloses $3.7M BTC theft in cybersecurity breach Read More »

Microsoft developer chief Julia Liuson is logging off

Microsoft developer chief Julia Liuson is logging off 2026-04-09 at 15:44 By Tim Anderson Departure may accelerate further AI-centric moves for programming tools Julia Liuson, president of Microsoft’s developer division (DevDiv), will resign at the end of June, though she will continue in an advisory role.… This article is an excerpt from The Register View

Microsoft developer chief Julia Liuson is logging off Read More »

Zephyr Energy loses £700K in cyber hit that rerouted contractor payment

Zephyr Energy loses £700K in cyber hit that rerouted contractor payment 2026-04-09 at 15:44 By Carly Page Attackers slipped into the process and redirected funds, leaving the company scrambling to recover the cash UK-listed oil and gas outfit Zephyr Energy plc has admitted a cyber incident siphoned off roughly £700,000 after a single payment to

Zephyr Energy loses £700K in cyber hit that rerouted contractor payment Read More »

Amazon put a filesystem on S3; I showed up with a test suite and bad intentions

Amazon put a filesystem on S3; I showed up with a test suite and bad intentions 2026-04-09 at 15:44 By Corey Quinn The core product is solid and priced fairly I’ve spent over a decade telling anyone who’d listen that S3 is not a filesystem, which in retrospect was a really weird way to start

Amazon put a filesystem on S3; I showed up with a test suite and bad intentions Read More »

OPSWAT adds predictive AI engine to MetaDefender for pre-execution threat detection

OPSWAT adds predictive AI engine to MetaDefender for pre-execution threat detection 2026-04-09 at 15:44 By Industry News OPSWAT has announced OPSWAT Predictive Alin AI, its first proprietary AI-based threat detection engine for the MetaDefender Platform. This AI-based innovation introduces a new category of capability within the MetaDefender Platform, a high-confidence predictive layer that works alongside

OPSWAT adds predictive AI engine to MetaDefender for pre-execution threat detection Read More »

Acrobat Reader zero-day exploited in the wild for many months

Acrobat Reader zero-day exploited in the wild for many months 2026-04-09 at 15:44 By Zeljka Zorz Unknown attackers have exploited a zero-day Adobe Acrobat Reader vulnerability since November 2025 and possibly even earlier, security researcher Haifei Li has discovered. PDF files carry the exploit Haifei Li is one of the creators of EXPMON, a sandbox-based

Acrobat Reader zero-day exploited in the wild for many months Read More »

Palo Alto Networks, SonicWall Patch High-Severity Vulnerabilities

Palo Alto Networks, SonicWall Patch High-Severity Vulnerabilities 2026-04-09 at 15:44 By Ionut Arghire The bugs could allow attackers to modify protected resources and escalate their privileges to administrator. The post Palo Alto Networks, SonicWall Patch High-Severity Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Palo Alto Networks, SonicWall Patch High-Severity Vulnerabilities Read More »

Google API Keys in Android Apps Expose Gemini Endpoints to Unauthorized Access

Google API Keys in Android Apps Expose Gemini Endpoints to Unauthorized Access 2026-04-09 at 15:44 By Ionut Arghire Dozens of such keys can be extracted from apps’ decompiled code to gain access to all Gemini endpoints. The post Google API Keys in Android Apps Expose Gemini Endpoints to Unauthorized Access appeared first on SecurityWeek. This

Google API Keys in Android Apps Expose Gemini Endpoints to Unauthorized Access Read More »

The Hidden Security Risks of Shadow AI in Enterprises

The Hidden Security Risks of Shadow AI in Enterprises 2026-04-09 at 15:44 By As AI tools become more accessible, employees are adopting them without formal approval from IT and security teams. While these tools may boost productivity, automate tasks, or fill gaps in existing workflows, they also operate outside the visibility of security teams, bypassing controls and

The Hidden Security Risks of Shadow AI in Enterprises Read More »

Bitter-Linked Hack-for-Hire Campaign Targets Journalists Across MENA Region

Bitter-Linked Hack-for-Hire Campaign Targets Journalists Across MENA Region 2026-04-09 at 15:44 By An apparent hack-for-hire campaign likely orchestrated by a threat actor with suspected ties to the Indian government targeted journalists, activists, and government officials across the Middle East and North Africa (MENA), according to findings from Access Now, Lookout, and SMEX. Two of the targets included prominent Egyptian journalists

Bitter-Linked Hack-for-Hire Campaign Targets Journalists Across MENA Region Read More »

Adobe Reader Zero-Day Exploited via Malicious PDFs Since December 2025

Adobe Reader Zero-Day Exploited via Malicious PDFs Since December 2025 2026-04-09 at 15:44 By Threat actors have been exploiting a previously unknown zero-day vulnerability in Adobe Reader using maliciously crafted PDF documents since at least December 2025. The finding, detailed by EXPMON’s Haifei Li, has been described as a highly-sophisticated PDF exploit. The artifact (“Invoice540.pdf”) first appeared on

Adobe Reader Zero-Day Exploited via Malicious PDFs Since December 2025 Read More »

South Korea court cancels Upbit suspension, citing regulatory gaps: Report

South Korea court cancels Upbit suspension, citing regulatory gaps: Report 2026-04-09 at 14:24 By Cointelegraph by Ezra Reguerra The decision closes a legal battle spanning more than a year, after Dunamu moved to overturn the sanction and halt its enforcement. This article is an excerpt from Cointelegraph.com News View Original Source

South Korea court cancels Upbit suspension, citing regulatory gaps: Report Read More »

Morgan Stanley Bitcoin ETF trails BlackRock with $30M in first-day inflows

Morgan Stanley Bitcoin ETF trails BlackRock with $30M in first-day inflows 2026-04-09 at 14:24 By Cointelegraph by Helen Partz Morgan Stanley’s Bitcoin ETF drew $30.6 million in first-day inflows, ranking second behind BlackRock’s IBIT as US spot Bitcoin ETFs clocked net outflows on Wednesday. This article is an excerpt from Cointelegraph.com News View Original Source

Morgan Stanley Bitcoin ETF trails BlackRock with $30M in first-day inflows Read More »

Scroll to Top