107Articles
10Categories
2026-04-08Date
🚨
TeamPCP Supply Chain Campaign: Update 007 - Cisco Source Code Stolen via Trivy-Linked Breach, Google GTIG Tracks TeamPCP as UNC6780, and CISA KEV Deadline Arrives with No Standalone Advisory, (Wed, Apr 8th)This is the seventh update to the TeamPCP supply chain campaign threat intelligence report,&#;x26;#;xc2;&#;x26;#;xa0; "When the Security Scanner Became the Weapon" &#;x26;#;xc2;&#;x26…
KEV
🚨
CISA Adds One Known Exploited Vulnerability to CatalogCISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-1340 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability This type of vulnerability is a frequent attack vector for malici…
KEV
🐛
Claude Identifies Critical 13-Year-Old RCE Vulnerability in Apache ActiveMQ
🐛
CVE-2026-34982 Vim modeline bypass via various options affects Vim < 9.2.0276
🐛
CVE-2026-35177 Path traversal issue with zip.vim in Vim
🐛
Docker Authorization Bypass Flaw Exposed Hosts to Potential Attackers
🐛
Multiple OpenSSL Flaws Expose Sensitive Data in RSA KEM Handling
🐛
Hackers exploit a critical Flowise flaw affecting thousands of AI workflows
🐛
Docker CVE-2026-34040 Lets Attackers Bypass Authorization and Gain Host Access
⚠️
Cybercriminals Use Fake Zoom, Teams Calls to Deliver Malware
⚠️
Claude Code Leak Exploited to Spread Vidar and GhostSocks via GitHub Releases
⚠️
Remus Infostealer Debuts With Stealthy New Credential-Theft Tactics
⚠️
Assessing Claude Mythos Preview’s cybersecurity capabilities
⚠️
GreyNoise Launches C2 Detection for Exploited Edge Devices
⚠️
Top 10 Best Multi-Factor Authentication (MFA) Providers in 2026
⚠️
The tabletop exercise grows up
⚠️
Microsoft’s new Agent Governance Toolkit targets top OWASP risks for AI agents
⚠️
Anthropic's Claude Mythos Finds Thousands of Zero-Day Flaws Across Major Systems
⚠️
The zero-day timeline just collapsed. Here’s what security leaders do next
⚠️
US Disrupts Russian Espionage Operation Involving Hacked Routers and DNS Hijacking
⚠️
LLM-generated passwords are indefensible. Your codebase may already prove it
⚠️
Forest Blizzard leverages router compromises to launch AiTM attacks, target Outlook sessions
⚠️
Hackers Targeting Ninja Forms Vulnerability That Exposes WordPress Sites to Takeover
⚠️
Hackers Target Adobe Reader Users With Sophisticated Zero-Day Exploit
⚠️
Iran‑linked PLC attacks cause real‑world disruption at critical US infra sites
⚠️
Massachusetts Hospital Diverts Ambulances as Cyberattack Causes Disruption
⚠️
Anthropic Launches Claude Mythos Preview Focused on Zero-Day Vulnerability Discovery
⚠️
Russian State-Linked APT28 Exploits SOHO Routers in Global DNS Hijacking Campaign
⚠️
Voice Phishing is a Growing Social Engineering Threat
⚠️
Joint advisory on Russian GRU exploiting vulnerable routers to steal sensitive information
⚠️
RCE Bug Lurked in Apache ActiveMQ Classic for 13 Years
⚠️
GrafanaGhost Exploit Bypasses AI Guardrails for Silent Data Exfiltrati
⚠️
Developer of VeraCrypt encryption software says Windows users may face boot-up issues after Microsoft locked his account
⚠️
Data Leakage Vulnerability Patched in OpenSSL
⚠️
Yael Nardi joins Minimus as Chief Business Officer to drive hyper-growth
⚠️
Legit Login Flow Turned Attack
⚠️
13-year-old bug in ActiveMQ lets hackers remotely execute commands
⚠️
How botnet-driven DDoS attacks evolved in 2H 2025
⚠️
CISA orders feds to patch exploited Ivanti EPMM flaw by Sunday
⚠️
Arelion employs NETSCOUT Arbor DDoS protection products
⚠️
WireGuard VPN developer can’t ship software updates after Microsoft locks account
⚠️
Hackers use pixel-large SVG trick to hide credit card stealer
⚠️
[webapps] FortiWeb 8.0.2 - Remote Code Execution
⚠️
[webapps] xibocms 3.3.4 - RCE
⚠️
[webapps] Horilla v1.3 - RCE
⚠️
Risky Business #832 -- Anthropic unveils magical 0day computer God
📋
IBM Security Verify Access Flaws Let Remote Attackers Access Sensitive Data
📢
HPE security advisory (AV26-325)
📢
CUPS security advisory (AV26-326)
📢
GitLab security advisory (AV26-327)
📢
Mitel security advisory (AV26-328)
📢
OpenSSL security advisory (AV26-329)
📢
Ivanti security advisory (AV26-068) – Update 2
📢
Apache ActiveMQ security advisory (AV26-330)
📢
Palo Alto Networks security advisory (AV26-331)
📢
SonicWall security advisory (AV26-332)
📢
A framework for securely collecting forensic artifacts into S3 buckets
📢
Russian hacking group targets home and small office routers to spy on users
🔥
Snowflake customers hit in data theft attacks after SaaS integrator breach
🔥
My Lovely AI - 106,271 breached accounts
🔥
FBI Takes Down Russian Campaign That Compromised Thousands of Routers
🔥
Zero Trust Readiness and Two RSAC 2026 Interviews from Fenix24 and Absolute Security - BSW #442
🔥
Hackers steal and leak sensitive LAPD police documents
🔥
Thousands of consumer routers hacked by Russia's military
🕵️
ISC Stormcast For Wednesday, April 8th, 2026 https://isc.sans.edu/podcastdetail/9884, (Wed, Apr 8th)
🕵️
Iran-Linked Hackers Disrupt US Critical Infrastructure via PLC Attacks
🕵️
ComfyUI Servers Hijacked for Cryptomining, Proxy Botnet Ops
🕵️
Fiber Optic Cables Turned Into Hidden Microphones to Spy on Private Conversations
🕵️
Russian Threat Actors Abuse Home Routers in Expanding DNS Hijacking Wave
🕵️
Minimum Release Age is an Underrated Supply Chain Defense
🕵️
N. Korean Hackers Spread 1,700 Malicious Packages Across npm, PyPI, Go, Rust
🕵️
Python Supply-Chain Compromise
🕵️
Masjesu Botnet Targets Routers in Commercial DDoS Attacks
🕵️
Evasive Masjesu DDoS Botnet Targets IoT Devices
🕵️
EvilTokens Uses Stolen Microsoft 365 Tokens, AI to Supercharge BEC
🕵️
Anthropic Unveils ‘Claude Mythos’ – A Cybersecurity Breakthrough That Could Also Supercharge Attacks
🕵️
What are You Working on Wednesday
🕵️
FBI: Cybercrime Losses Neared $21 Billion in 2025
🕵️
Major outage cripples Russian banking apps and metro payments nationwide
🕵️
LLMs vs Machine Learning for Security
🕵️
APT28 Deploys PRISMEX Malware in Campaign Targeting Ukraine and NATO Allies
🕵️
6 Winter 2026 G2 Leader Badges prove this DDoS protection stands out
🕵️
VeraCrypt lockdown
🕵️
Don’t Know Your Data? Problem
🕵️
Google: New UNC6783 hackers steal corporate Zendesk support tickets
🕵️
Announcing ADEM Universal Agent
🕵️
Understanding and Anticipating Venezuelan Government Actions
🕵️
Building Phishing Detection That Works: 3 Steps for CISOs
🌐
Iran-Linked Hackers Disrupt U.S. Critical Infrastructure by Targeting Internet-Exposed PLCs
🌐
Masjesu Botnet Emerges as DDoS-for-Hire Service Targeting Global IoT Devices
🌐
New Chaos Variant Targets Misconfigured Cloud Deployments, Adds SOCKS Proxy
🌐
New macOS stealer campaign uses Script Editor in ClickFix attack
🌐
Hack-for-hire group caught targeting Android devices and iCloud backups
🌐
Financial cyberthreats in 2025 and the outlook for 2026
🎙️
Smashing Security podcast #462: LinkedIn is spying on you, and you agreed to nothing
📡
Weekly Threat Bulletin – April 8th, 2026
📡
Microsoft rolls out fix for broken Windows Start Menu search
📡
Shrinking the IAM Attack Surface through Identity Visibility and Intelligence Platforms (IVIP)
📡
Is a $30,000 GPU Good at Password Cracking?
📡
Final 3 days to save up to $500 on your TechCrunch Disrupt 2026 pass
📡
More Honeypot Fingerprinting Scans, (Wed, Apr 8th)
📡
Hardening security management console settings | Kaspersky official blog
📡
[local] 7-Zip 24.00 - Directory Traversal
📡
[local] SQLite 3.50.1 - Heap Overflow
📡
[local] Microsoft MMC MSC EvilTwin - Local Admin Creation
📡
Your extensions leak clues about you, so we made sure Browser Guard doesn&#8217;t
📡
Timeshare owners warned to watch out for cartel-linked scams