Latest stories — Page 92

Threat Intelligence

TrapDoor Campaign Plants Credential Stealers Across npm, PyPI, and Crates.io

A coordinated operation seeded 34+ malicious packages across three registries since May 2026. If you ship code, this one is sitting in your dependency tree right now.

3 min read
Threat Intelligence

GRU Operators Drained Microsoft 365 Tokens by Rewriting DNS on 18,000 SOHO Routers

Forest Blizzard shifted from targeted router malware to mass DNS hijacking after a UK advisory in August, intercepting OAuth tokens on Outlook on the web.

3 min read
Vulnerabilities

Hard-coded ASP.NET machine keys in KnowledgeDeliver LMS abused to drop Godzilla, then Cobalt Strike

CVE-2026-5426 let attackers forge ViewState payloads against a Japanese LMS used across universities and corporate training portals. The bug was a zero-day before Digital Knowledge shipped a fix.

2 min read
Vulnerabilities

April Patch Tuesday Lands With 167 Microsoft Fixes, SharePoint Zero-Day Under Attack

BlueHammer Defender bug goes public, Adobe Reader flaw exploited since November, and Chrome ships its fourth zero-day of the year.

2 min read
Threat Intelligence

The Boy Who Topped the Leaderboard: How 'Tylerb' Became a Cooperating Witness

Tyler Buchanan, the Scottish core of Scattered Spider's 2022 phishing spree, pleaded guilty in U.S. federal court. His path there ran through a blowtorch, a Barcelona departure gate, and a Telegram scoreboard.

3 min read
Threat Intelligence

The Firewall Guard Was Holding a Crowbar: Brazilian DDoS-Protection Firm Caught Powering the Attacks

Exposed archive ties Huge Networks infrastructure and its CEO's SSH keys to a long-running Mirai botnet hammering Brazilian ISPs. The CEO blames a competitor.

3 min read
Breaches

The Login Page That Demanded a Ransom

ShinyHunters defaced Canvas mid-finals week, taking the learning platform offline and exposing what one researcher calls an eight-month attack arc against Instructure.

3 min read
Vulnerabilities

Microsoft Skips a Zero-Day for the First Time in Two Years. Nobody Wants to Talk About Why.

118 fixes shipped, none under active exploit, and a quiet Anthropic project keeps surfacing in vendor briefings. Microsoft, Apple and Oracle declined to discuss it on the record.

3 min read
Cloud Security

CISA Contractor Spent Six Months Treating GitHub as a Personal Dropbox

A Nightwing employee's public 'Private-CISA' repo leaked AWS GovCloud admin keys, plaintext passwords and the agency's internal build pipeline — with secret-scanning deliberately switched off.

2 min read
Threat Intelligence

Ottawa 23-Year-Old Charged as 'Dort,' Alleged Operator of the 30 Tbps Kimwolf IoT Botnet

Jacob Butler is in OPP custody on a U.S. extradition warrant. Prosecutors say his botnet pushed nearly 30 terabits per second. The questions I sent his lawyer remain unanswered.

3 min read
Policy & Regulation

Dutch Investigators Seize 800 Servers, Arrest Two Tied to Stark Industries Successor

FIOD raids in Enschede, Almere, Dronten and Schiphol-Rijk target MIRhosting and WorkTitans BV over alleged sanctions breaches linked to Russian influence operations.

3 min read
Cloud Security

CISA Contractor's Public GitHub Repo Spilled GovCloud Keys for Months; Lawmakers Want Answers

An RSA private key tied to the CISA-IT GitHub organization sat in a public 'Private-CISA' repo since November 2025. The agency is still rotating credentials.

3 min read
Policy & Regulation

npm Introduces Staged Publishing With Mandatory 2FA Gate for Maintainer Approval

GitHub's package registry now requires a human maintainer to clear a two-factor challenge before a release leaves a staging area, a control aimed at the supply chain attacks that have repeatedly compromised the JavaScript ecosystem.

2 min read
Threat Intelligence

Lazarus' RemotePE Lives Entirely in Memory, Targets Crypto Treasuries

A fresh in-memory RAT from DPRK's Lazarus Group is being chained behind two custom loaders to drain finance and crypto orgs. Here is what to check tonight.

3 min read
Policy & Regulation

Agentic AI Quietly Rewrites the NDR Pitch, But Procurement Rules Have Not Caught Up

Network detection vendors say autonomous triage is thinning the alert queue. Buyers are now asking what regulators will let those agents actually do.

3 min read
Vulnerabilities

A SQL Bug in a Blogging Tool Just Became a ClickFix Delivery Truck

Attackers turned 700+ Ghost CMS sites into watering holes by exploiting CVE-2026-26980, smuggling fake CAPTCHA prompts that trick visitors into running malware on themselves.

2 min read
Threat Intelligence

The Week the Backlog Came Due: Linux Holes, Defender Zero-Days, and a Poisoned Dev Tool

A messy seven days for defenders, where forgotten servers and trusted tooling did most of the damage.

3 min read
Threat Intelligence

Nimbus Manticore Drops MiniFast and MiniJunk V2 in Aviation Phishing Wave

Iran-linked UNC1549 is back with refreshed loaders, SEO-poisoned lures, and aviation-themed bait aimed at U.S., European, and Gulf targets.

3 min read
Policy & Regulation

Twelve Hours, or Else: India's New Patch Clock Starts Ticking

CERT-In tells operators of internet-facing systems to close critical flaws within half a day, citing AI-assisted exploit chains that compress the attacker's runway to minutes.

2 min read
Identity & Access

Prompt Bombing Turned Your Second Factor Into a Doorbell Nobody Stops Ringing

Attackers stopped trying to steal push notifications. They just wait for tired users to tap 'approve' at 2 a.m.

2 min read
AI Security

Anthropic's Mythos AI Found 23,000 Potential Vulnerabilities Across 1,000 Open-Source Projects — and Counting

The numbers are large. The confirmed critical findings are real. What Anthropic has not yet said publicly is whether any of them were exploited before disclosure.

2 min read
© 2026 Threat Vectr