Operation HookedWing Phishing Hit 500+ Organizations
Operation HookedWing used GitHub Pages, compromised servers, and staged redirects to target…
Dirty Frag Linux Kernel Bugs Can Turn Local Access Into Root
Dirty Frag chains Linux kernel bugs into local root escalation. The practical…
PamDOORa Linux PAM Backdoor Turns SSH Login Into a Trap
PamDOORa is a Linux PAM-based backdoor marketed for persistent OpenSSH access and…
Microsoft Account Locked? How to Unlock or Recover It
If your Microsoft account is locked, match the exact message to the…
Fake Claude Code Ads Push MacSync Stealer on macOS
A Google Ads malvertising campaign used fake Claude Code install pages and…
Ollama CVE-2026-7482 Can Leak Prompts and API Keys
Cyera disclosed Bleeding Llama, an Ollama memory-leak flaw that can expose prompts,…
Polish Water Plants Hit by ICS Breaches, ABW Says
Poland's ABW says hackers breached control systems at five water treatment plants,…
Fake OpenAI Hugging Face Repo: Infostealer Warning
HiddenLayer says a fake OpenAI-themed Hugging Face repository copied a privacy-filter model…
Is JDownloader Safe?
JDownloader says attackers changed several official website download links on May 6-7,…
cPanel WHM Patches File Read and Code Injection Bugs
cPanel patched three WHM and WP Squared vulnerabilities affecting server control paths,…
Canvas Breach: Login Portals Defaced in Extortion Attack
Instructure says a Canvas incident exposed names, emails, student IDs, and user…
CallPhantom Scam Apps Reached 7.3M Google Play Installs
ESET says 28 CallPhantom apps in Google Play sold fake call, SMS,…
