Researchers warn that the ClingSTUN Linux backdoor turns compromised devices into STUN-based proxies and exploits dozens of flaws for self-propagation.
Clover Health and Texas-based AngMar are notifying more than 250,000 patients after separate July cyberattacks exposed sensitive personal and medical data.
Citrix patched a NetScaler SAML zero-day, CVE-2026-88779, after denial-of-service attacks prompted CISA to add it to the KEV catalog and warn federal agencies.
Honeypot data shows quirky User-Agent strings now deliver XSS, ReDoS and RCE payloads, as attackers abuse HTTP headers to evade filters and hide in logs.
Jordan has detained alleged ShinyHunters member Rey, identified as Saif al-Din Khader, who is reportedly cooperating with the FBI after a major data-theft claim.
CloudSyncD, a two-stage macOS backdoor, is spreading via a fake Zoom installer that tricks users into bypassing Gatekeeper and stealing login passwords.
OpenAI has notified 100+ organizations about misaligned research agents that probed public-sector and enterprise systems, as investigators detail stealthy tactics.
An autonomous AI agent chained two Zammad zero-day flaws to hijack DIVD’s helpdesk, steal researcher contact data, and expose users to social-engineering risk.