CISA has added two vulnerabilities affecting PaperCut software, tracked as CVE-2026-82078 and CVE-2026-81578, to its Known Exploited Vulnerabilities (KEV) catalog. This addition indicates that these vulnerabilities are actively being exploited in the wild.
A new malware variant called Guildma, also known as Astaroth, has been observed infecting systems through emails written in Brazilian Portuguese. These emails likely contain malicious attachments or links designed to compromise the recipient's computer.
A threat actor successfully targeted users of Anthropic's Claude service by employing various infostealers. The attack aimed to steal session information, granting the attacker access to user accounts.
A new campaign dubbed 'TerminalFix' has been identified, utilizing PowerShell to conduct sophisticated, multistage attacks against enterprise networks. This campaign employs reverse tunnels to establish persistent access into compromised victim environments.
Microsoft has identified a new malware campaign called TerminalFix that leverages fake Cloudflare CAPTCHA pages on compromised websites. Victims are tricked into executing malicious PowerShell commands within Windows Terminal, which then establishes reverse tunnels for attackers.
A new malware campaign, dubbed "ClickFix," employs a multi-stage attack chain that conceals malicious code within PNG image files. Once executed, the malware establishes a custom reverse tunnel on the victim's machine, allowing attackers to maintain persistent access and exfiltrate data.
A new device is being distributed that promises free movies in exchange for users installing it. However, the device secretly turns home connections into part of a proxy network, potentially exposing users to risks.
Anthropic is taking action against a surge of compromised user accounts being used to illicitly mine AI tokens. Commodity malware is reportedly stealing authenticated sessions, enabling attackers to exploit victims' paid AI usage.
This article summarizes several cybersecurity incidents, including a router with a pre-installed backdoor, a fake check used to install malware, and the exploitation of old vulnerabilities. It also touches on issues with AI agents going off-task and the security implications of exposed systems and weak defaults.
Berlin's city administration has confirmed a data theft incident following a ransomware attack by the Rhysida gang. The cybercriminals are attempting to extort the city after listing it on their data leak site.
A threat actor named Silver Fox is distributing a backdoor called ValleyRAT. This malware is disguised as a signed Chinese adware application, specifically a legitimate desktop wallpaper tool called QN Wallpaper. By masquerading as trusted software, the attackers aim to bypass antivirus detections, particularly when users have added such applications to their antivirus exclusion lists.
AI company Anthropic is experiencing widespread infostealer malware infections affecting its Claude AI chatbot users. The company is proactively logging users out and removing payment information to prevent unauthorized use of the service.
Threat actors using Aurora ransomware have been observed incorporating SpaceX's AI coding assistant, Cursor, into their attack methods. Analyses of exposed infrastructure linked to the Russian-speaking cybercrime group revealed this novel usage of AI tools.
Attackers have weaponized legitimate browser extensions for Chrome and Edge by acquiring them from publishers and injecting malicious code through updates. This campaign affected 19 extensions, some with tens of thousands of users, and enabled the theft of cryptocurrency and sensitive user data.
The Rhysida ransomware group has claimed to have exfiltrated over 5TB of data, which includes personal information and credentials. Authorities in Berlin have stated they will not pay any ransom to the extortion group.
PaperCut NG/MF has a critical vulnerability allowing unauthenticated remote attackers to modify system configurations. This flaw can be combined with another vulnerability, CVE-2026-82078, and requires immediate mitigation according to vendor instructions and CISA guidance. Its exploitation for ransomware is currently unknown.
PaperCut NG/MF has an unsafe reflection vulnerability that allows attackers to execute arbitrary Java bytecode on the server process. This flaw can be chained with another vulnerability, CVE-2026-81578, and requires immediate mitigation according to vendor instructions and CISA guidance.
Anthropic has alerted Claude users to a threat where infostealer malware on their personal computers is hijacking active Claude login sessions. This allows attackers to gain unauthorized access to user accounts and consume their allocated Claude usage.
Multiple extensions available on the Chrome Web Store have been found to contain a malware framework. This framework deploys modules designed to steal cryptocurrency, sensitive user data, and browser history, and also injects deceptive 'ClickFix' lures.
Microsoft has disclosed details of a new malware variant called TerminalFix, which tricks users into running malicious commands within Windows Terminal or PowerShell. This variant is a successor to ClickFix, employing a similar technique but targeting more modern command-line interfaces to increase the likelihood of successful execution.
Multiple critical security vulnerabilities have been discovered in popular WordPress plugins and themes including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP. These flaws could allow attackers to bypass authentication, take over accounts, or execute arbitrary code on affected websites.
A critical vulnerability in the GiveWP WordPress donation plugin allows unauthenticated attackers to execute arbitrary commands on the hosting server. This flaw enables attackers to potentially gain full control over the affected websites.
Cybersecurity researchers have identified 19 browser extensions (18 for Chrome, 1 for Edge) that were recently published and contained malicious code designed to steal cryptocurrency wallets and drain funds. These extensions share similar coding techniques, suggesting a coordinated campaign.
The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has confirmed a major cyber incident that is being investigated by the Department of Justice. This confirmation follows a claim by a ransomware group that they were responsible for the attack.
Cybersecurity researchers have identified new campaigns targeting European government and diplomatic organizations in Romania, Spain, and Türkiye between late September 2025 and early April 2026. These campaigns have resulted in the deployment of a new backdoor named HOOKEDGE, which is a lightweight Windows batch script.
A cybersecurity analyst is sharing statistics on compilers used to generate malicious Portable Executable (PE) files, following up on previous data about 64-bit vs. 32-bit malware trends. They developed a Python script utilizing the pefile library to extract metadata from PE headers, noting that tools like Detect It Easy can also access this information.
Two members of the TeamPCP hacking group have been arrested in Australia. In other news, the Qilin ransomware has targeted a US firearms agency, and the US has seized two more Chinese botnets, with CISA noting that most cyber activity is opportunistic.
Australian law enforcement, with assistance from the FBI, has apprehended individuals suspected of being the masterminds behind the TeamPCP cybercrime group. This group is known for its involvement in the Shai-Hulud worm and other supply chain attacks.
The CRPx0 hacking service, designed for users with no technical background, claims to have seen its victim count more than quintuple. This indicates a concerning trend of increasingly accessible and user-friendly tools for malicious actors.
The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) is responding to a significant cybersecurity incident. This follows claims by a ransomware gang that they were responsible for the breach. The US Justice Department is now investigating the incident.
This article highlights several cybersecurity threats, including a 296,000-device IoT botnet, over 100 water systems targeted by attackers, and a remote code execution chain vulnerability in SharePoint. It also notes trends like botnets leveraging AI, malicious tools employing delayed execution, and shrinking exploit windows.
Australian authorities have arrested and charged two individuals suspected of being part of the TeamPCP hacking group. This group is known for conducting extensive supply chain attacks targeting software developers.
Two men in Western Australia have been charged by the Australian Federal Police for their alleged involvement in TeamPCP, a cybercrime group. This group is believed to be responsible for compromising open-source security scanners Trivy and Checkmarx KICS, as well as the AI gateway LiteLLM.
Russian state-sponsored hackers are reportedly targeting EU officials by shifting their phishing efforts from email to popular messaging applications like Signal and WhatsApp. This indicates a strategic move by threat actors to exploit new communication channels for malicious purposes.
Australian authorities have arrested two individuals in Western Australia who are believed to be members of the cybercrime group TeamPCP. This group is known for its extensive software supply chain attacks, where they allegedly created malicious open-source software to target thousands of businesses globally.
A new campaign is targeting individuals and organizations in Cambodia with an open-source remote access trojan (RAT) named Spark RAT. The attackers are using various lure themes, such as government notices and public health materials, to entice potential victims.
The author reviews polymorphic phishing pages that are caught in spam traps or sent to the Internet Storm Center. These pages are designed to change their appearance or behavior periodically to evade detection.
A new Go-based malware framework, GoCaracal, has been identified and linked to threat actors associated with Dark Caracal. This malware provides operators with remote shell access, payload execution, browser data theft, and keylogging capabilities.
The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has confirmed a "major incident" involving a system compromise, following claims by the Qilin ransomware gang that they breached the agency. The full scope and impact of the incident are still being investigated.
A report analyzes the state of ransomware attacks in the education sector, based on insights from 226 IT and cybersecurity leaders across 17 countries. The article focuses on organizations that experienced ransomware incidents in the past year.
Dark Caracal, a known threat actor, has introduced a new modular malware framework called GoCaracal. This new framework enhances their ability to steal data from victims and maintain persistent access to compromised systems.
Threat actors have begun targeting vehicle infotainment systems by exploiting their update mechanisms to spread malware. This new campaign leverages a known click-fraud botnet, indicating a shift towards more sophisticated and potentially lucrative targets.
Palo Alto Networks Unit 42 analyzed 405 malware samples created with AI assistance and discovered that only a small fraction, 12 samples, managed to reach production endpoints. This suggests that while AI may accelerate the development process, it does not necessarily increase the success rate of malware.
A new phishing toolkit named NovaCookies is being used to conduct adversary-in-the-middle (AitM) attacks. These attacks leverage legitimate DocuSign notifications to redirect Microsoft 365 sign-ins and steal authenticated sessions.
A new adversary-in-the-middle (AitM) phishing service called 'NovaCookies' is now available for $320 per month. This service significantly reduces the technical expertise required for threat actors to conduct sophisticated attacks. NovaCookies can steal active Microsoft 365 session cookies, bypassing multi-factor authentication and offering more than just credential theft.
INTERPOL's Operation Jackal IV, an eight-month global crackdown on West African organized crime, has resulted in 58 arrests and the identification of 263 suspects involved in cyber fraud. The operation involved 22 countries and targeted groups like Black Axe, highlighting the escalating global threat of these networks.
A new Windows backdoor named SLEEPWALKER has been discovered that remains dormant until it receives a specially crafted network packet. Upon activation, it executes commands written in its own proprietary 23-instruction bytecode language.
CISA has issued a warning about active exploitation of a critical remote code execution vulnerability in Gitea, identified as CVE-2026-60004. Attackers with repository write access can execute arbitrary shell commands. The vulnerability has a CVSS score of 9.8 and is reportedly being used to drop miner-like payloads.
A phishing-as-a-service platform called AnonyMousKIT is using AI voice agents to impersonate Apple Support. These AI agents call owners of stolen Apple devices, attempting to trick them into revealing passcodes and two-factor authentication codes to bypass Activation Lock.
A race condition vulnerability in Red Hat libuser (CVE-2015-3246) allows authenticated local users to corrupt the /etc/passwd file, potentially leading to denial of service or privilege escalation. Organizations are advised to apply vendor-provided mitigations and comply with CISA's guidance on prioritizing security updates.