Cybersecurity researchers have disclosed a new adversary-in-the-middle (AitM) phishing toolkit called NovaCookies, which is used as a proxy to redirect Microsoft 365…
Cybersecurity researchers at OX Security have uncovered a campaign that abuses 24 npm packages as free phishing infrastructure. The packages host HTML…
Cybersecurity researchers have uncovered a cyber espionage campaign targeting Myanmar government and IT sectors, dubbed Operation QUICSILVER. The campaign, first observed in…
Cybersecurity researchers have disclosed two denial-of-service (DoS) attack techniques, collectively named "CDN Tsunami," that exploit how major content delivery networks (CDNs) convert…
Cybersecurity researchers have disclosed a remote Spectre attack against Cloudflare Workers that leaked a JSON Web Token (JWT) from a co-located Worker…
Cybersecurity researchers at CTM360 have exposed a large-scale, global recruitment-themed phishing campaign that leverages Browser-in-the-Browser (BitB) windows to steal Google and Facebook…
account takeoverAmazon Web ServicesAWS EC2Browser-in-the-Browser
A massive operation involving 737 free VPN and proxy extensions on the Chrome Web Store has been uncovered, primarily targeting Russian-speaking users…
1.1.1.1AdGuard VPNadversary-in-the-middleAI Sidebar with Deepseek, ChatGPT, Claude, and more
OpenAI has launched GPT-5.6-Cyber, a specialized cybersecurity model designed for vulnerability research, penetration testing, and incident response. Built on the GPT-5.6 Sol…
N-able has issued Hotfix 2 for its N-central Remote Monitoring and Management (RMM) product, responding to ongoing exploitation of a recently disclosed…