Ghostwriter Targets Ukraine Government Entities with Prometheus Phishing Malware

22/05/2026 0 Comments 0 tags

The Belarus-aligned threat actor known as Ghostwriter (aka UAC-0057 and UNC1151Ukraine’s National Security and Defense Council) has been observed using lures related to Prometheus, a Ukrainian online learning platform, to

Making Vulnerable Drivers Exploitable Without Hardware – The BYOVD Perspective

22/05/2026 0 Comments 0 tags

1 Introduction This article provides a technical analysis of how many Windows kernel mode drivers can be interacted with from user mode without the hardware they were developed for. This

Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows

22/05/2026 0 Comments 0 tags

Cybersecurity researchers have disclosed details of a new automated campaign called Megalodon that has pushed 5,718 malicious commits to 5,561 GitHub repositories within a six-hour window. “Using throwaway accounts and

Kimwolf DDoS Botnet Operator Arrested in Canada Over DDoS-for-Hire Attacks

22/05/2026 0 Comments 0 tags

The U.S. Department of Justice (DoJ) on Thursday announced the arrest of a Canadian man in connection with allegedly operating a distributed denial-of-service (DDoS) botnet known as Kimwolf. In tandem,

CISA Adds Exploited Langflow and Trend Micro Apex One Vulnerabilities to KEV

22/05/2026 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added two security flaws impacting Langflow and Trend Micro Apex One to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence

Cisco Patches CVSS 10.0 Secure Workload REST API Flaw Enabling Data Access

22/05/2026 0 Comments 0 tags

Cisco has rolled out updates for a maximum-severity security flaw impacting Secure Workload that could allow an unauthenticated, remote attacker to access sensitive data. Tracked as CVE-2026-20223 (CVSS score: 10.0),

Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor

21/05/2026 0 Comments 0 tags

Cybersecurity researchers have disclosed details of a new Linux malware dubbed Showboat that has been put to use in a campaign targeting a telecommunications provider in the Middle East since

ThreatsDay Bulletin: Linux Rootkits, Router 0-Day, AI Intrusions, Scam Kits and 25 New Stories

21/05/2026 0 Comments 0 tags

This week starts small. A token leaks. A bad package slips in. A login trick works. An old tool shows up again. At first, it feels like the usual mess.

Microsoft Warns of Two Actively Exploited Defender Vulnerabilities

21/05/2026 0 Comments 0 tags

Microsoft has disclosed that a privilege escalation and a denial-of-service flaw in Defender has come under active exploitation in the wild. The former, tracked as CVE-2026-41091, is rated 7.8 on

When Identity is the Attack Path

21/05/2026 0 Comments 0 tags

Consider a cached access key on a single Windows machine. It got there the way most cached credentials do – a user logged in, and the key stored itself automatically.