Star Blizzard’s RedFlick Phishing Chain Targets More Than 100 Organizations
A Russia-linked operation is using attachment-free opening messages before sending encrypted archives that deploy the CosmicPulse backdoor. More than 100 organizations, particularly those involved with Ukraine-related policy and...
CopyEscape Flaw Turns Docker File Copies Into a Route to Host Root
A flaw in Docker’s archive extraction path can let a hostile container write beyond the destination chosen for a file copy. On Linux systems where the command runs...
How a Single Poisoned Package Can Hand Attackers the Keys to Your Cloud
A new Qualys analysis ties together a string of 2025–2026 software supply chain campaigns — from the Shai-Hulud worm to malicious Ruby gems and Go modules — showing...
Cloudflare’s New Certificate Design Aims to Make Quantum-Safe HTTPS Actually Practical
Cloudflare is building a certificate authority around a new 'Merkle Tree Certificate' format designed to deliver post-quantum website authentication without bloating every TLS handshake. Early tests show a...
Google Patches 32 Chrome Flaws Including a Critical Memory-Corruption Bug — Update Now
Chrome's latest stable release closes 32 security holes across Windows, macOS, and Linux, including a critical ANGLE buffer overflow and several V8 engine flaws that could let a...
Citrix NetScaler Zero-Days Under Active Attack: Google Uncovers Hidden Web Shell Campaign
Google's threat intelligence team says attackers have been exploiting two critical, now-patched Citrix NetScaler zero-days since early September to plant a stealthy PHP web shell and pivot deep...
Fake Zoom and PDF Installers Deploy Dual Remote-Control Tools on Business PCs
A phishing campaign disguises legitimate MSP360 remote-management software as Zoom installers, PDF readers and business documents. Once installed, it adds ScreenConnect as a second access channel and delivers...
PaperPhone Bot Network Masks Automated Scraping Behind 75,000 IP Addresses
Researchers identified a coordinated headless-browser network using 75,000 IP addresses and fabricated mobile identities to disguise large-scale scraping. Contradictory browser fingerprints and synchronized traffic exposed the supposedly diverse...