LIVE · cybersecurity feed
Live wire
Acronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide ProbesCVE-2025-66516 · Metasploit Wrap Up: This One Goes to Sixteen!
phishing

In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review

Noteworthy stories that might have slipped under the radar: Invisible Unicode slips past phishing filters, US puts $10 million bounty on Iranian cyber official, military ties of Chinese hacking group QTFY. The post In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review appeared first on SecurityWeek.

zeroday.news ·

Recent reports have highlighted several significant developments in the cybersecurity landscape, including a novel phishing technique leveraging invisible Unicode characters, a substantial bounty offered for an Iranian cyber official, and new insights into the military affiliations of a Chinese hacking group. These stories, though varied in nature, underscore ongoing challenges in digital defense, state-sponsored cyber activities, and the evolving tactics employed by malicious actors.

One notable finding concerns a new phishing method dubbed "InjectEave," which reportedly utilizes invisible Unicode characters to bypass existing email security filters. This technique exploits the way some systems process or display Unicode, allowing attackers to embed malicious elements or obfuscate URLs in a manner that appears benign to automated defenses. By rendering certain characters invisible, the true nature of a phishing link or embedded script can be concealed from initial scans, increasing the likelihood of an email reaching an intended victim's inbox.

This class of attack typically targets the parsing and rendering engines of email clients and security gateways. Products designed to detect phishing often rely on pattern matching, URL reputation, and content analysis. However, the use of non-displaying or zero-width Unicode characters can disrupt these mechanisms, making it difficult for automated systems to accurately identify the malicious intent. Mitigation strategies for such attacks generally involve robust Unicode normalization in email processing, advanced behavioral analysis of email content, and user education on scrutinizing email origins and links, even if they appear superficially legitimate.

In a separate development, the United States has reportedly offered a $10 million bounty for information leading to the identification or location of an Iranian cyber official. This action signals a continued focus on deterring and disrupting state-sponsored cyber operations. Such bounties are typically issued in response to significant cyber threats or attacks attributed to specific individuals or entities operating under state direction, reflecting a strategy to leverage financial incentives to gather intelligence and hold perpetrators accountable.

The third area of focus involves new information regarding the Chinese hacking group QTFY, specifically concerning its alleged military ties. Reports suggest that this group, known for its cyber espionage activities, has direct or indirect connections to the Chinese military. Understanding the affiliations of such groups is crucial for attributing attacks and comprehending the strategic objectives behind their operations. Groups with state or military backing often possess significant resources and operate with long-term goals, such as intellectual property theft, intelligence gathering, or critical infrastructure reconnaissance.

Collectively, these reports illustrate the multifaceted nature of current cybersecurity threats. From sophisticated technical evasions like InjectEave to geopolitical responses against state-sponsored actors and the ongoing challenge of identifying and countering military-linked hacking groups, the landscape remains dynamic. Organizations and governments continue to face pressure to adapt their defenses, enhance intelligence gathering, and implement proactive measures to safeguard digital assets and national security interests against an ever-evolving array of adversaries.

phishing
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

CVE-2026-76461critical

U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Email Gateway flaw, tracked as CVE-2026-76461 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Cisco disclosed a critical zero-day CVE-2026-76

patch

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]

ai

Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?

Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers. The post Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow? appeared first on SecurityWeek.