Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption

27/07/2026 0 Comments 0 tags

Dysphoria, an Internet of Things (IoT) botnet line tracked by CNCERT and XLab, has adopted blockchain-based name services and infected-device relays after a March law-enforcement operation against JackSkid infrastructure. The

Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw

27/07/2026 0 Comments 0 tags

Public exploit details released on July 27 show how an unauthenticated request can reach PHP’s eval() function inside vBulletin and execute code on an unpatched forum server. The attack requires

⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More

27/07/2026 0 Comments 0 tags

Monday starts with the usual promise that everything is under control. Then the logs wake up. This week, trusted tools crossed lines, old flaws found new work, exposed systems stayed

Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update

27/07/2026 0 Comments 0 tags

Cybersecurity researchers have flagged a Microsoft Teams-themed phishing campaign that employs “secure document” lures to deliver legitimate remote monitoring and management (RMM) tools. “The victim was directed through compromised web

n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process

27/07/2026 0 Comments 0 tags

n8n has patched a high-severity expression-sandbox escape that could let an authenticated workflow editor execute operating-system commands on the server running the automation platform. Security Joes found the flaw while

Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware

27/07/2026 0 Comments 0 tags

The China-linked cybercrime group behind the use of income tax-related phishing lures targeting Indian taxpayers, tax professionals, and corporate finance teams has been observed using a sophisticated crypter service called

GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption

27/07/2026 0 Comments 0 tags

GitHub has announced a new cooldown mechanism in Dependabot, allowing the tool to wait at least three days after a release is published before opening a pull request. “The cooldown

TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments

27/07/2026 0 Comments 0 tags

Cybersecurity researchers have flagged fresh malicious cyber activity by a threat actor with ties to East Asia targeting government entities in the Middle East. The intrusions have resulted in the

Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

25/07/2026 0 Comments 0 tags

A malvertising operation dubbed SourTrade is making victims’ browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base instead of serving one complete malicious file

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

25/07/2026 0 Comments 0 tags

Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba’s JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute