UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

07/08/2026 0 Comments 0 tags

A recent wave of cyber attacks targeting financial services, private equity, and professional services is attributed to a data extortion group known as UNC6671. “UNC6671 continues to rely on voice

ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets

07/08/2026 0 Comments 0 tags

ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials. The macOS-focused infection

Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

07/08/2026 0 Comments 0 tags

A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution – Patch ASAP

07/08/2026 0 Comments 0 tags

WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. Under additional conditions, the bug can be

18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers

07/08/2026 0 Comments 0 tags

A use-after-free bug in Linux’s SCTP networking code can be turned into full root on a host, and Tencent researchers say they used it to escape a container and reach

Growing Up The Hard Way

07/08/2026 0 Comments 0 tags

Open Source had a great childhood. For two decades it got to be a kid. It ran around barefoot, gave everything away, trusted strangers, and never once thought about who

AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day

07/08/2026 0 Comments 0 tags

PortSwigger says HTTP Terminator, an artificial intelligence (AI)-assisted research system built by James Kettle, generated and proved new HTTP desynchronization techniques after exploring 30,000 candidate attack vectors. PortSwigger said a

Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails

07/08/2026 0 Comments 0 tags

Cybersecurity researchers have called attention to an active “widespread email-driven phishing campaign” that employs adversary-in-the-middle (AitM) techniques to take control of Microsoft 365 accounts with an aim to identify key

Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets

07/08/2026 0 Comments 0 tags

A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic’s and Google’s own coding-agent repositories. On OpenAI’s, it

Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access

07/08/2026 0 Comments 0 tags

Security researcher Malcolm Stagg has disclosed a new attack class calledĀ NatJackĀ that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, disclose victim IP addresses