LIVE · cybersecurity feed
Live wire
Malware Hijacks Android Car Head UnitsCritical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command ExecutionCVE-2026-73570 · U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalogCVE-2024-3094 · Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2Hundreds of leaked AWS keys give full control over corporate accountsAndroid Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy BotnetMalware injected into popular Rust packages to steal developer credentialsSix Maximum-Severity Flaws Found in Cisco ProductsCritical Isolated-vm Vulnerability Leads to RCE on Host

data theft

malwarehigh

ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit, and More

This week's cybersecurity landscape features several significant threats, including the abuse of legitimate signed drivers for kernel operations, a large-scale cyber espionage campaign by an Iran-based group targeting universities, and malware utilizing DLL sideloading. Additionally, advancements in AI safety are being explored by OpenAI and Google, while a new service, Kriminal AI, offers unfiltered AI responses, raising concerns about misuse. Apple is also modifying its App Tracking Transparency feature in Germany following regulatory scrutiny.

ransomwarehigh

Rogue ransomware affiliate poses as recovery firm to steal payments

A threat actor, operating under the guise of a ransomware recovery service named 'Ransom Busters,' is contacting victims before attacks are publicly disclosed. This entity claims to offer decryption keys and data deletion services for a fee, but evidence suggests it is actually the ransomware affiliate responsible for the attacks. The group is suspected of exploiting vulnerabilities to gain access to encryption keys and victim data, then attempting to extort victims directly, potentially defrauding both the victims and the ransomware gangs they work with.

helixhigh

New Helix Group Targets SharePoint Data via Vishing and MFA Abuse

A newly identified cybercriminal group, known as Helix, is employing sophisticated identity-based attacks to exfiltrate data from SharePoint environments. Their methods include voice phishing, device code phishing, and the abuse of multi-factor authentication systems.

googlehigh

Dialogflow CX 'Rogue Agent' Flaw Enabled AI Chatbot Data Theft

Varonis identified a vulnerability in Google Dialogflow CX, dubbed the Rogue Agent flaw, which allowed for the theft of AI chatbot data. Google has since implemented a fix for this issue.

phishinghigh

Phishing Campaign Deploys JavaScript-Driven PureLogs Variant to Steal Sensitive Data

A recent phishing campaign has been identified that utilizes sophisticated techniques including obfuscated JavaScript and PowerShell. The attackers employ process hollowing and a variant of the PureLogs malware to exfiltrate sensitive user data.