Aggregator
'Hades' Campaign Against PyPI Puts New Spin on Shai-Hulud
BRPDV Data Breach: 542K Brazilian Invoices and Customer Records Leaked
Malspam Attack Uses Google DoubleClick Redirects to Deliver Fileless .NET Loader
Cybercriminals have found a new way to sneak malware past email security tools, and this time they are hiding behind a name that most systems trust without question. A recent malspam campaign has been caught using Google’s own DoubleClick ad-tracking infrastructure to route victims toward a fileless .NET loader, a type of malware that runs […]
The post Malspam Attack Uses Google DoubleClick Redirects to Deliver Fileless .NET Loader appeared first on Cyber Security News.
从 EDR 到 ADR:Agent 安全正在进入检测响应时代
AI brands as bait: How threat actors are using the AI hype in social engineering
As threat actors operationalize AI to accelerate attacks, they are also leveraging the wider global interest around AI itself as a social engineering lure.
The post AI brands as bait: How threat actors are using the AI hype in social engineering appeared first on Microsoft Security Blog.
潘汉年的三本传记
AI brands as bait: How threat actors are using the AI hype in social engineering
As threat actors operationalize AI to accelerate attacks, they are also leveraging the wider global interest around AI itself as a social engineering lure.
The post AI brands as bait: How threat actors are using the AI hype in social engineering appeared first on Microsoft Security Blog.
SecWiki News 2026-06-08 Review
更多最新文章,请访问SecWiki
9.8 из 10. Хакеры массово ломают сайты на WordPress через брешь в форме обратной связи
Critical UniFi OS bug lets hackers gain root without authentication
CVE-2026-11459 | SecureAge CatchPulse up to 10.9.3 IOCTL saappctl.sys information disclosure (EUVD-2026-34989)
Investigating suspicious AI workflows in Microsoft Entra Agent ID: Assistive agents
Phish Feed
CVE-2026-11511 | Bolt CMS up to 3.7.5 HTML Attribute TextType.php style HTML injection (EUVD-2026-35059)
CVE-2026-3011 | wpzoom Recipe Card Blocks Lite Plugin up to 3.4.13 on WordPress deserialize_block_attributes summary/notes cross site scripting (EUVD-2026-35049)
CVE-2026-11577 | Keycloak on Red Hat partialImport authorization (EUVD-2026-35058)
UNC3753 Attacking US Law Firms Using Vishing and RMM Tools to Exfiltrate Data
A sophisticated cybercriminal group known as UNC3753 has been running an aggressive campaign against US law firms since early 2026, using phone calls, screen-sharing tricks, and remote monitoring software to break into corporate systems and steal sensitive files. The group is also tracked as Luna Moth, Chatty Spider, and Silent Ransom Group, and has been […]
The post UNC3753 Attacking US Law Firms Using Vishing and RMM Tools to Exfiltrate Data appeared first on Cyber Security News.