New Threat Cluster OP-512 Targets Microsoft IIS Servers with Custom Web Shell Framework

05/06/2026 0 Comments 0 tags

Cybersecurity researchers have discovered a previously unreported threat cluster dubbed OP-512 that has been observed targeting Microsoft Internet Information Services (IIS) servers to deploy a bespoke web shell framework. ReliaQuest

Only 10% of SOCs Say They’re Getting Excellent Value From AI. Here’s What the Second Wave Has to Deliver

05/06/2026 0 Comments 0 tags

Eighteen months ago, the AI SOC was a marketing line. Today it’s a budget item. The category has crossed over from interesting to inevitable, with billions of dollars now flowing

Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites

05/06/2026 0 Comments 0 tags

Threat actors are actively exploiting a critical security flaw in Everest Forms Pro, a WordPress plugin with about 4,000 active installations, to execute arbitrary code, leading to a complete site

PCPJack Hijacks 230 AWS, Google Cloud, and Azure Servers for Covert SMTP Relay Network

05/06/2026 0 Comments 0 tags

The threat actor known as PCPJack has hijacked cloud servers associated with Amazon Web Services (AWS), Google Cloud, and Microsoft Azure to create a covert SMTP email relay network. “Compromised

FIFA World Cup 2026 Scams Are Already Live: Fake Sites, Banking Malware, and Stolen Logins

05/06/2026 0 Comments 0 tags

Security researchers and the FBI are warning that a wave of FIFA-themed fraud is already hitting World Cup 2026 fans, days before the June 11 kickoff. Recent reports describe thousands

Agentic AI Is Transforming Defense, But Only Secure IT Infrastructure Will Maximize It

04/06/2026 0 Comments 0 tags

Over the past several weeks, the cybersecurity community has been reminded how quickly frontier and agentic AI in defense networks can challenge our assumptions. When Anthropic’s Claude Mythos model was

Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public

04/06/2026 0 Comments 0 tags

Cisco has patched a bug in Unified Communications Manager that lets an unauthenticated attacker on the network write files to the box and, from there, climb to root. It is

ThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors & 20+ New Stories

04/06/2026 0 Comments 0 tags

It got stupid again. The internet still feels held together with tape. Bad plugins, old bugs, fake tools, trusted apps doing shady things. Same mess, new wrapper. And now the

Claude Code GitHub Action Flaw Let One Malicious Issue Hijack Repositories

04/06/2026 0 Comments 0 tags

A security researcher found a flaw in Anthropic’s Claude Code GitHub Action that let an attacker take over vulnerable public repositories running it, with nothing more than a single opened

FlutterShell Backdoor Spreads to macOS via Malicious Google and YouTube Ads

04/06/2026 0 Comments 0 tags

Cybersecurity researchers have shed light on a macOS malvertising campaign codenamed Operation FlutterBridge that spreads a new backdoor called FlutterShell. According to Palo Alto Networks Unit 42, the campaign is