Google Dismantles NetNut-Linked “Popa” Residential Proxy Botnet That Hijacked 2 Million Home Devices
Google, working with the FBI, Lumen Technologies, and other partners, has taken action against the NetNut residential proxy network - also tracked as "Popa" - estimated to have...
AsyncRAT Trojan Hidden in 90+ Fake Software Download Sites via DLL Sideloading and ScreenConnect
A stealthy campaign is hiding the AsyncRAT trojan inside fake installers for popular free software, using DLL sideloading and the legitimate ScreenConnect remote-access tool to slip past security...
New CitrixBleed-Class Vulnerability in Citrix NetScaler Exploited Within 24 Hours of Disclosure
CVE-2026-8451, the latest entry in the CitrixBleed family of NetScaler memory-disclosure flaws, came under active exploitation less than a day after public disclosure. Decoy infrastructure operator Lupovis tracked...
DHS Confirms Hackers Breached HSIN, the Government’s Emergency Information-Sharing Platform
The Department of Homeland Security has confirmed a breach of the Homeland Security Information Network (HSIN), the unclassified platform used by federal, state, local, and international partners to...
DuneSlide: Critical Zero-Click RCE Bugs in Cursor IDE Put Fortune 500 Developer Machines at Risk
Two critical zero-click RCE vulnerabilities (CVE-2026-50548, CVE-2026-50549) in Cursor IDE, dubbed DuneSlide, allow attackers to escape the AI coding agent sandbox via prompt injection with no user interaction...
Apple’s Unpatched ‘Hide My Email’ Flaw Has Exposed User Identities for Over a Year
An unpatched vulnerability in Apple's Hide My Email feature can expose users' real email addresses behind their iCloud+ anonymization aliases, researcher Tyler Murphy and 404 Media have confirmed....
Four New CVEs in Fluentd Expose Millions of Cloud and Kubernetes Logging Pipelines to RCE and Data Leaks
Four new CVEs in the widely deployed Fluentd log collector — including a critical RCE vulnerability (CVE-2026-44024) exploitable via crafted log entries — put cloud and Kubernetes logging...
81 Million Login Attempts: Massive Password Spray Campaign Bypasses MFA to Compromise Azure and Microsoft 365 Accounts
A massive automated campaign made 81 million login attempts against Microsoft 365 and Azure CLI accounts between June 12 and June 26, 2026, successfully compromising 78 accounts across...