News desk

Security News

Security incidents, exploited vulnerabilities, breach reports, malware campaigns, and urgent patch notes arranged for fast daily scanning.

August 4, 2026
Ghost-Sender spoofed email passing a mail gateway despite SPF DKIM and DMARC failures.

Lead story · Jun 13, 2026

Ghost-Sender Spoofing

Ghost-Sender shows how Exchange Online tenants with external MX gateways can receive spoofed internal-looking mail. Check the risk and safe mitigations.

Latest reports

Report · Jun 5, 2026

Nimbus RAT Teams Vishing

Nimbus RAT now rides a Teams vishing and Quick Assist chain. See the email-flood warning signs, Windows artifacts, and response steps to check first.

Report · Jun 4, 2026

Mirasvit Cache Warmer RCE

CISA added Mirasvit Cache Warmer CVE-2026-45247 to KEV. Check affected Magento stores, update to 1.11.12, and review logs for CacheWarmer cookie exploitation.

Report · Jun 13, 2026

DesckVB RAT Malspam

DesckVB RAT malspam abuses DoubleClick redirects before dropping a ZIP, script loader, and .NET RAT. Check what to do if you opened the attachment.

Report · Jun 3, 2026

Kirki CVE-2026-8206

Kirki 6.0.0 through 6.0.6 can let unauthenticated attackers route password reset links to their own inbox. Update to 6.0.7 or later and audit administrator…

Report · Jun 3, 2026

WeedHack Minecraft Malware

WeedHack spreads through fake Minecraft mods and clients, stealing session tokens, passwords, wallets, and adding remote-access risk.

Report · Jun 2, 2026

Steam C2 Backdoor

GoDaddy says WordPress malware hides C2 data in Steam profile comments. Check for hello-mywordl.info, injected scripts, and PHP backdoors.

Report · Jul 23, 2026

Notepad++ XML File Risk

Notepad++ 8.9.6.1 fixes config.xml and shortcuts.xml code execution flaws. Learn who is affected, how to update, and what to inspect after suspicious shortcuts or…

AI Assistant

Hello! 👋 How can I help you today?