Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks

29/06/2026 0 Comments 0 tags

The China-aligned espionage group Mustang Panda is running two campaigns against the Indian government and hydropower targets, deploying new malware and turning a legitimate cloud service into its command channel. Acronis Threat

WhatsApp is Finally Getting Usernames to Help Keep Phone Numbers Private

29/06/2026 0 Comments 0 tags

WhatsApp on Monday officially announced the start of global reservations of usernames with an aim to protect the privacy of more than three billion users on the messaging platform. The

⚡ Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and More

29/06/2026 0 Comments 0 tags

This week was a reminder that attackers do not always need big tricks. One small mistake, one old access path, one missed patch, and suddenly the door is open. The

236,000 DCloud Uni-App Sites Used in Crypto Scams, Phishing, and Wallet Drainers

29/06/2026 0 Comments 0 tags

New findings unearthed by Infoblox show that more than 236,000 websites are using investment scam templates built using a legitimate Chinese open-source, cross-platform application development framework called DCloud Uni-App. The

Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse

29/06/2026 0 Comments 0 tags

A Russian advanced persistent threat (APT) group has continued to evolve and expand its malware arsenal as part of its ongoing cyber onslaught against Ukraine throughout 2025. Slovakian cybersecurity company

Why Post-Quantum Cryptography Starts With Credentials

29/06/2026 0 Comments 0 tags

Today’s encrypted data, such as credentials, may no longer remain confidential in the future because the public-key cryptography protecting it will soon be broken by quantum computers. Although no machine

Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts

29/06/2026 0 Comments 0 tags

Microsoft has shut down a long-running malicious extension operation on the Edge Add-ons store that hid its payloads inside ordinary image and font files, then woke up days after install

Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw

29/06/2026 0 Comments 0 tags

A public proof-of-concept is now out for CVE-2026-55200, a critical flaw in libssh2 that lets a malicious or compromised SSH server trigger memory corruption on a connecting client, with possible

Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer

29/06/2026 0 Comments 0 tags

Cybersecurity researchers have uncovered two hijacked npm packages and a cluster of Go packages that are designed to deploy a Python-based information stealer on compromised Windows, Linux, and macOS hosts.

Ukraine Says Russian Intelligence Used Fake Support Texts to Steal Messaging Credentials

27/06/2026 0 Comments 0 tags

The Security Service of Ukraine (SSU) said it, together with the U.S. Federal Bureau of Investigation (FBI), uncovered a long-running campaign orchestrated by Russian intelligence services to break into the