ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories

03/09/2026 0 Comments 0 tags

The worst part is how normal these attacks look. A call from IT. A shared file. A trusted app. A simple request to click “Allow.” Why break in when someone

Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data

03/09/2026 0 Comments 0 tags

Thomson Reuters disclosed on Wednesday that an unauthorized party obtained files from C-Track, the court case management platform sold by its West Publishing Corporation unit, in March 2026, affecting courts

BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory

03/09/2026 0 Comments 0 tags

Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts. “Unlike the standard infostealer model, BraZetsu

Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

03/09/2026 0 Comments 0 tags

Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside

US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries

03/09/2026 0 Comments 0 tags

An RMM phishing campaign initially associated with Canadian targeting due to its use of Canada Revenue Agency (CRA) tax forms as lures has turned out to be part of a

Shai-Hulud’s Reach Just Grew to 469 Credential Locations. Here’s What That Means

03/09/2026 0 Comments 0 tags

In early August, GitGuardian researchers found that a recent Shai-Hulud infostealer worm variant had evolved to scan for credentials across 469 locations across developer environments, Continuous Integration/Continuous Deployment (CI/CD) tooling,

Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks

03/09/2026 0 Comments 0 tags

Threat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicious payloads. According to a new report published by the Symantec Threat

Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member’s iPhone

03/09/2026 0 Comments 0 tags

The iPhone belonging to a member of Serbia’s student protest movement was infected with NSO Group’s Pegasus spyware, according to new findings from the Citizen Lab in collaboration with the

CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners

03/09/2026 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in attackers’ crosshairs. The vulnerabilities are

Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon

03/09/2026 0 Comments 0 tags

The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank, a privilege escalation flaw impacting Crowdstrike Falcon. “FalconFlank is a