ThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors & 20+ New Stories

04/06/2026 0 Comments 0 tags

It got stupid again. The internet still feels held together with tape. Bad plugins, old bugs, fake tools, trusted apps doing shady things. Same mess, new wrapper. And now the

Claude Code GitHub Action Flaw Let One Malicious Issue Hijack Repositories

04/06/2026 0 Comments 0 tags

A security researcher found a flaw in Anthropic’s Claude Code GitHub Action that let an attacker take over vulnerable public repositories running it, with nothing more than a single opened

FlutterShell Backdoor Spreads to macOS via Malicious Google and YouTube Ads

04/06/2026 0 Comments 0 tags

Cybersecurity researchers have shed light on a macOS malvertising campaign codenamed Operation FlutterBridge that spreads a new backdoor called FlutterShell. According to Palo Alto Networks Unit 42, the campaign is

China-Linked TA4922 Expands Phishing Attacks to UK, Germany, Italy, and South Africa

04/06/2026 0 Comments 0 tags

A new China-linked cybercrime group known as TA4922 has expanded its targeting focus to target European organizations in the U.K., Germany, Italy, and South Africa. These efforts have been complemented

Hackers Spied on a Stock Exchange Executive’s Outlook Mailbox for Five Months

04/06/2026 0 Comments 0 tags

Unknown attackers spent at least five months inside the Outlook mailbox of a senior executive at a major global stock exchange, copying the inbox out in small, repeated batches and

Fake Sites Mimicking Open-Source Tools Rank High on Google to Deliver Malware via TDS

04/06/2026 0 Comments 0 tags

Cybersecurity researchers have flagged a large-scale operation that impersonates open-source and freeware projects to funnel unsuspecting users through a Traffic Distribution System (TDS) and deliver malware families like Remus Stealer,

CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog

04/06/2026 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical flaw impacting Mirasvit Cache Warmer, a popular Magento full-page cache extension, to its Known Exploited Vulnerabilities (KEV)

DoJ Disrupts Southeast Asia Crypto Fraud Networks, Freezes $3.8 Million in Assets

04/06/2026 0 Comments 0 tags

The U.S. Department of Justice (DoJ) on Wednesday announced the results of a sweeping action undertaken by government authorities and private sector companies to combat cyber-enabled and cryptocurrency fraud targeting

Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479)

03/06/2026 0 Comments 0 tags

Redis has patched a use-after-free in its blocking-client code that lets an authenticated user run arbitrary OS commands on the machine hosting the database. The flaw was found by an

Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug Flag

03/06/2026 0 Comments 0 tags

A development flag left switched on in production builds of several Microsoft 365 Android apps disabled the check that limits account-token sharing to trusted Microsoft apps. Any other app on