Ghost-Sender Spoofing
Ghost-Sender shows how Exchange Online tenants with external MX gateways can receive spoofed internal-looking mail. Check the risk and safe mitigations.
News desk
Security incidents, exploited vulnerabilities, breach reports, malware campaigns, and urgent patch notes arranged for fast daily scanning.
August 4, 2026
Ghost-Sender shows how Exchange Online tenants with external MX gateways can receive spoofed internal-looking mail. Check the risk and safe mitigations.
Nimbus RAT now rides a Teams vishing and Quick Assist chain. See the email-flood warning signs, Windows artifacts, and response steps to check first.
CISA added Mirasvit Cache Warmer CVE-2026-45247 to KEV. Check affected Magento stores, update to 1.11.12, and review logs for CacheWarmer cookie exploitation.
DesckVB RAT malspam abuses DoubleClick redirects before dropping a ZIP, script loader, and .NET RAT. Check what to do if you opened the attachment.
Kirki 6.0.0 through 6.0.6 can let unauthenticated attackers route password reset links to their own inbox. Update to 6.0.7 or later and audit administrator…
WeedHack spreads through fake Minecraft mods and clients, stealing session tokens, passwords, wallets, and adding remote-access risk.
CVE-2025-48595 has limited targeted exploitation signals. Check NVD details, PoC/exploit status, June 2026 Android patch level, and APK risk.
GoDaddy says WordPress malware hides C2 data in Steam profile comments. Check for hello-mywordl.info, injected scripts, and PHP backdoors.
Notepad++ 8.9.6.1 fixes config.xml and shortcuts.xml code execution flaws. Learn who is affected, how to update, and what to inspect after suspicious shortcuts or…