Iran-Linked Tortoiseshell Expands Espionage With TWOSTROKE Backdoor and Reverse SSH Tunnels
Researchers have linked new Windows malware and reverse SSH infrastructure to the Iran-associated Tortoiseshell threat group. The tools masquerade as a legitimate Windows library and support covert tunneling,...
One Malicious Webpage Can Hijack Your AI Coding Agent Through an NVIDIA NemoClaw Flaw
A critical flaw in NVIDIA's NemoClaw tooling exposes a local AI inference server to the open network, letting a single malicious website hijack an AI agent via DNS...
OpenSSL Updates Close Heap Corruption and Remote Crash Weaknesses
OpenSSL has released patched builds for a broad set of vulnerabilities affecting CMS, CMP, DTLS, QUIC and cryptographic operations. Several weaknesses are remotely triggerable, making dependency discovery and...
Core Werewolf Deploys Custom CoreRAT Against Russian Defense Targets
The Core Werewolf threat group is using a newly documented Windows remote access trojan in campaigns aimed at Russian public-sector and defense organizations. Telegram lures and forged official...
Actively Exploited SharePoint Flaw Combines With RCE for Server Takeover
Two on-premises SharePoint vulnerabilities can be chained to bypass authentication and execute code on vulnerable servers. With the authentication flaw already listed as exploited, administrators should patch exposed...
ToxNetV2 Botnet Adds AI-Guided Commands to Linux Attack Operations
Researchers have analyzed a peer-to-peer Linux botnet whose controller consults an NVIDIA-hosted AI model to propose operational actions. Human approval still gates the most consequential commands, but the...
Iran-Linked Hackers Knocked a UK Power Plant Offline for Four Days in a First-of-Its-Kind Attack
A small UK energy generator was forced completely offline for four days last month in what officials describe as the first successful cyberattack to shut down a British...
Fake Adobe Reader Site Powers a New Malware-as-a-Service Platform Targeting Windows Users
Researchers have uncovered a live malware-as-a-service operation hiding behind a convincing fake Adobe Acrobat Reader site, using a WebDAV trick and a disguised batch file to install information-stealing...