Cisco Patches 9.8 CVSS IMC and SSM Flaws Allowing Remote System Compromise

02/04/2026 0 Comments 0 tags

Cisco has released updates to address a critical security flaw in the Integrated Management Controller (IMC) that, if successfully exploited, could allow an unauthenticated, remote attacker to bypass authentication and gain

ThreatsDay Bulletin: Pre-Auth Chains, Android Rootkits, CloudTrail Evasion & 10 More Stories

02/04/2026 0 Comments 0 tags

The latest ThreatsDay Bulletin is basically a cheat sheet for everything breaking on the internet right now. No corporate fluff or boring lectures here, just a quick and honest look at the

The State of Trusted Open Source Report

02/04/2026 0 Comments 0 tags

In December 2025, we shared the first-ever The State of Trusted Open Source report, featuring insights from our product data and customer base on open source consumption across our catalog of container

Researchers Uncover Mining Operation Using ISO Lures to Spread RATs and Crypto Miners

02/04/2026 0 Comments 0 tags

A financially motivated operation codenamed REF1695 has been observed leveraging fake installers to deploy remote access trojans (RATs) and cryptocurrency miners since November 2023. “Beyond cryptomining, the threat actor monetizes infections through CPA (Cost Per

WhatsApp Alerts 200 Users After Fake iOS App Installed Spyware; Italian Firm Faces Action

02/04/2026 0 Comments 0 tags

Meta-owned messaging platform WhatsApp said it alerted about 200 users who were tricked into installing a bogus version of its iOS app that was infected with spyware. According to reports from

Apple Expands iOS 18.7.7 Update to More Devices to Block DarkSword Exploit

02/04/2026 0 Comments 0 tags

Apple on Wednesday expanded the availability of iOS 18.7.7 and iPadOS 18.7.7 to a broader range of devices to protect users from the risk posed by a recently disclosed exploit kit known as DarkSword. “We

CERT-UA Impersonation Campaign Spread AGEWHEEZE Malware to 1 Million Emails

01/04/2026 0 Comments 0 tags

The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of a new phishing campaign in which the cybersecurity agency itself was impersonated to distribute a remote administration tool

New Chrome Zero-Day CVE-2026-5281 Under Active Exploitation — Patch Released

01/04/2026 0 Comments 0 tags

Google on Thursday released security updates for its Chrome web browser to address 21 vulnerabilities, including a zero-day flaw that it said has been exploited in the wild. The high-severity

Microsoft Warns of WhatsApp-Delivered VBS Malware Hijacking Windows via UAC Bypass

01/04/2026 0 Comments 0 tags

Microsoft is calling attention to a new campaign that has leveraged WhatsApp messages to distribute malicious Visual Basic Script (VBS) files. The activity, beginning in late February 2026, leverages these

Casbaneiro Phishing Targets Latin America and Europe Using Dynamic PDF Lures

01/04/2026 0 Comments 0 tags

A multi-pronged phishing campaign is targeting Spanish-speaking users in organizations across Latin America and Europe to deliver Windows banking trojans like Casbaneiro (aka Metamorfo) via another malware called Horabot. The