Microsoft 365 Session Hijacking Campaigns Hide Behind Trusted Remote-Support Tools
Campaigns spanning the United States and Europe are combining adversary-in-the-middle phishing with legitimate remote-management software. Stolen session cookies can outlive password resets, forcing defenders to revoke tokens and...
Lenovo ID Trust Flaw Opened About 5,000 Dropbox Accounts to Takeover
Dropbox says attackers compromised roughly 5,000 accounts by creating Lenovo IDs with victims’ email addresses and abusing a federated-login integration. The incident demonstrates why matching email claims cannot...
TukTuk Malware Gives Ransomware Crews Cross-Platform Control and EDR-Killing Tools
Researchers recovered a previously undocumented command-and-control framework linked to the Gentlemen ransomware ecosystem. TukTuk supports Windows and Linux agents, credential prompts, screen capture, remote commands, and preparation for...
New WhatsApp Video Call Trick Bypasses Android Lock Screens to Expose Your Photos
A newly disclosed WhatsApp flaw lets anyone answer a video call on a locked Android phone and, through the in-call background editor, browse the device's entire photo gallery...
High-Severity Cleo Harmony Bug Lets Attackers Forge Their Way to Admin Access
A high-severity flaw in Cleo Harmony's JWT refresh-token handling, tracked as CVE-2026-84115, lets remote attackers escalate privileges to admin level with a working exploit already public. Cleo has...
BREEZE COMET Hackers Use AI-Written Tools to Speed-Run Brazilian Bank Fraud
Google Cloud researchers detail how the financially motivated BREEZE COMET group has spent two years infiltrating Brazilian banks and retailers, combining social engineering and rogue hardware with generative-AI-assisted...
Fake Software Installers Are Quietly Disarming Microsoft Defender in New Silver Fox Campaign
A Silver Fox-linked campaign is distributing counterfeit installers for brands like Razer, Microsoft Edge, and Kaspersky that use SYSTEM-level scheduled tasks to strip Microsoft Defender protections and delete...
Critical Artifactory Bypass Is Being Used to Mint Administrator Tokens
A critical JFrog Artifactory authentication bypass is under active exploitation, with attackers reportedly creating administrator tokens on vulnerable servers. Self-hosted customers should upgrade immediately, revoke suspicious credentials and...