Uncategorized

Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT

Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT 2026-07-06 at 15:38 By A suspected China-nexus threat activity cluster has been observed targeting Indian taxpayers, tax professionals, and corporate finance teams to deliver a remote access trojan designed to steal sensitive data from compromised hosts. The multi-stage campaign, codenamed Operation DragonReturn by […]

Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT Read More »

New TrojPix Attack Leaks Data From Air-Gapped Systems via Video Cable Emissions

New TrojPix Attack Leaks Data From Air-Gapped Systems via Video Cable Emissions 2026-07-06 at 11:50 By Researchers at Shandong University have shown a fast new way to pull data off computers that are cut off from every network. The technique, called TrojPix, tweaks on-screen pixels in ways the eye cannot see, so that the video cable carrying them

New TrojPix Attack Leaks Data From Air-Gapped Systems via Video Cable Emissions Read More »

New Java-Based QuimaRAT MaaS Built to Run on Windows, Linux, and macOS

New Java-Based QuimaRAT MaaS Built to Run on Windows, Linux, and macOS 2026-07-06 at 11:13 By Cybersecurity researchers have flagged a novel Java-based remote access trojan (RAT) called QuimaRAT that’s capable of targeting Windows, Linux, and macOS environments. According to LevelBlue, the cross-platform malware is advertised under a malware-as-a-service (MaaS) model, costing anywhere between $150

New Java-Based QuimaRAT MaaS Built to Run on Windows, Linux, and macOS Read More »

Opera GX Flaw Let Malicious Sites Auto-Install Mods to Steal Data From Visited Pages

Opera GX Flaw Let Malicious Sites Auto-Install Mods to Steal Data From Visited Pages 2026-07-06 at 10:27 By Researchers found a flaw in Opera GX, the gaming-focused version of the Opera browser, that let a malicious website silently install a browser add-on and use it to lift specific data from the pages a victim visits. In

Opera GX Flaw Let Malicious Sites Auto-Install Mods to Steal Data From Visited Pages Read More »

SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing

SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing 2026-07-06 at 09:33 By Scanners meant to catch malicious add-on “skills” for AI coding agents can be fooled by a few simple changes that leave the malware working, according to a new study from researchers at the Hong Kong University of Science and Technology. Their

SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing Read More »

U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case

U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case 2026-07-04 at 17:57 By A U.S. government entity paid about $1 million to keep stolen files from being leaked, according to a new case study by Rakesh Krishnan for Ransom-ISAC, built on a leaked negotiation chat and the blockchain trail the payment left. The odd

U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case Read More »

North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign

North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign 2026-07-04 at 16:12 By The North Korean threat actors linked to the Contagious Interview campaign have been observed publishing 108 unique packages and web browser extensions spanning npm, Packagist, Go, and Google Chrome as part of an ongoing activity referred to as PolinRider.

North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign Read More »

Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices

Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices 2026-07-04 at 00:33 By Security firm runZero has disclosed seven vulnerabilities in FatFs, a small filesystem library that lets a device read and write the FAT and exFAT formats used on USB drives and SD cards. The flaws matter because FatFs is nearly everywhere. It ships inside

Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices Read More »

New “Bad Epoll” Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android

New “Bad Epoll” Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android 2026-07-03 at 23:37 By A newly disclosed Linux kernel flaw called Bad Epoll (CVE-2026-46242) lets an ordinary user with no special access take full control of a machine as root. It affects Linux desktops, servers, and Android, and a fix is out.

New “Bad Epoll” Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android Read More »

New Avalon Malware Framework Packs CrownX Ransomware Capabilities

New Avalon Malware Framework Packs CrownX Ransomware Capabilities 2026-07-03 at 21:55 By Cybersecurity researchers have discovered a previously undocumented modular malware framework codenamed Avalon that’s distributed by means of a multi-stage phishing chain capable of bypassing traditional security controls. Avalon combines credential collection, lateral movement, remote access, recovery disruption, and ransomware execution, bringing together diverse

New Avalon Malware Framework Packs CrownX Ransomware Capabilities Read More »

Woman loses savings to AI-powered romance scam featuring intimate video calls with deepfake ‘Dubai prince’

Woman loses savings to AI-powered romance scam featuring intimate video calls with deepfake ‘Dubai prince’ 2026-07-03 at 19:19 By Ariel Zilber The woman said she met the scammer posing as the prince on a dating site before their conversations shifted to WhatsApp. This article is an excerpt from Latest Technology News | New York Post

Woman loses savings to AI-powered romance scam featuring intimate video calls with deepfake ‘Dubai prince’ Read More »

North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets

North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets 2026-07-03 at 19:07 By Threat actors with ties to North Korea have been linked to a fresh set of malicious npm packages that masquerade as Rollup polyfill tooling to facilitate remote access and data theft. According to JFrog, the packages “rollup-packages-polyfill-core” and “rollup-runtime-polyfill-core” mimic

North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets Read More »

Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer

Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer 2026-07-03 at 16:36 By A previously undocumented threat actor known as Armored Likho has been attributed to cyber attacks targeting government agencies and the electric power sector across Russia, Brazil, and Kazakhstan. “Armored Likho blends financially motivated campaigns targeting private individuals with targeted cyber espionage

Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer Read More »

PamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login Passwords

PamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login Passwords 2026-07-03 at 16:32 By Cybersecurity researchers have flagged a new macOS information stealer called PamStealer that employs a series of clever tricks to infect systems and siphon sensitive data. The stealer, discovered by Jamf Threat Labs, is distributed as a compiled AppleScript

PamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login Passwords Read More »

DEI finally getting ditched by corporate charities: Here’s what they’re pivoting towards instead

DEI finally getting ditched by corporate charities: Here’s what they’re pivoting towards instead 2026-07-03 at 16:07 By Charles Gasparino It’s nice to see big corporations backing something that’s concrete and hard to argue with. This article is an excerpt from Latest Technology News | New York Post View Original Source

DEI finally getting ditched by corporate charities: Here’s what they’re pivoting towards instead Read More »

I have no AC in the NYC heatwave — 3 tools that are keeping me cool while I sleep

I have no AC in the NYC heatwave — 3 tools that are keeping me cool while I sleep 2026-07-03 at 15:59 By McKenzie Beard The Post’s wellness reporter McKenzie Beard is among the 850,000 New Yorkers without AC. But she’s found a few solutions — besides fans — to keep her cool at night.

I have no AC in the NYC heatwave — 3 tools that are keeping me cool while I sleep Read More »

European Parliament Member Investigating Spyware Was Hacked With Pegasus

European Parliament Member Investigating Spyware Was Hacked With Pegasus 2026-07-03 at 14:05 By A new report from the Citizen Lab has revealed that former Member of the European Parliament Stelios Kouloglou had his mobile device repeatedly hacked with the notorious Pegasus spyware while serving on a committee that was tasked with investigating the abuse of

European Parliament Member Investigating Spyware Was Hacked With Pegasus Read More »

Scroll to Top