Russian Hackers Exploit Exchange OWA Zero-Day to Deploy OWAReaper Backdoor
Laundry Bear is exploiting a zero-day XSS flaw in Exchange OWA to deploy the OWAReaper backdoor, enabling persistent mailbox access that survives credential res
ToolsLaundry Bear is exploiting a zero-day XSS flaw in Exchange OWA to deploy the OWAReaper backdoor, enabling persistent mailbox access that survives credential res
ToolsGitHub has added a 72-hour Dependabot cooldown, while PyPI now blocks new files added to releases older than 14 days.
ThreatsCTM360 research exposes a phishing kit targeting insurance portals with real-time OTP interception and live session hijacking across multiple regions.
ThreatsCheck Point has patched three vulnerabilities, including a critical actively exploited authentication bypass in SmartConsole. CISA has added the flaw to its KEV
ToolsGoogle has introduced an opt-in selfie video feature for account recovery. It uses facial comparison to verify identity when users are locked out.
ToolsA viral incident exposes how Flock's camera network wrongly tracked a writer using partial plate matching, while police use the system to surveil people, not ju
Threats
Expel attributes the April 2026 DigiCert certificate theft to CylindricalCanine, a subgroup of Chinese cybercrime group GoldenEyeDog using Golden Gh0st RAT.
ESET found 11 old UEFI shims that bypass Secure Boot on most UEFI systems. Microsoft revoked the vulnerable binaries in the June 2026 Patch Tuesday update.
Microsoft fixed 570 vulnerabilities in July's Patch Tuesday, nearly triple last month's record. AI-assisted discovery is driving the surge in patch volume.
OpenAI is temporarily lifting GPT-5.6 Sol's five-hour usage cap for Plus, Pro, and Business plans and issuing a one-time usage reset.
Attackers compromised the Injective Labs GitHub repository to publish a malicious npm package that exfiltrates private keys and mnemonic phrases.
AI is rapidly widening the gap between skill and ability in cyberattacks. The same tools that strengthen defense also enable harm.
North Korea's Contagious Interview campaign has published 108 malicious packages across npm, Packagist, Go, and Chrome in an active supply chain operation calle
Security firm runZero disclosed seven vulnerabilities in FatFs, a filesystem library embedded in cameras, drones, and industrial controllers. No upstream fix ex
CISA has added a high-severity Microsoft SharePoint RCE flaw to its KEV catalog. Federal agencies must patch by Saturday under BOD 26-04.