92Articles
8Categories
2026-04-13Date
🚨
CISA Adds Seven Known Exploited Vulnerabilities to CatalogCISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2012-1854 Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability CVE-2020-9715 Adobe Acrobat Use-After-Free Vulner…
KEV
🐛
Adobe Fixes Actively Exploited Zero-Day in Acrobat Reader
KEV
🐛
WordPress Plugin Vulnerability Enables Admin Takeover via Auth Bypass
🐛
Marimo RCE Vulnerability Exploited Within 10 Hours of Public Disclosure
KEV
🐛
Critical Axios Vulnerability Enables Remote Code Execution, PoC Released
🐛
Seven IBM WebSphere Liberty flaws can be chained into full takeover
🐛
Critical flaw in Marimo Python notebook exploited within 10 hours of disclosure
KEV
🐛
Adobe rolls out emergency fix for Acrobat, Reader zero-day flaw
⚠️
Banks Panic As Anthropic Mythos Exposes Software Vulnerabilties
⚠️
Apache Tomcat Flaws Enable EncryptInterceptor Bypass
⚠️
CISOs tackle the AI visibility gap
⚠️
We catch up on the news, including AI vuln hunting; also more RSAC interviews! - ESW #454
⚠️
AI Chatbots and Trust
⚠️
International Operation Targets Multimillion-Dollar Crypto Theft Schemes
⚠️
Hackers Exploit MSBuild LOLBin to Evade Detection in Fileless Windows Attacks
⚠️
Critical Marimo pre-auth RCE flaw now under active exploitation
⚠️
Your MTTD Looks Great. Your Post-Alert Gap Doesn't
⚠️
⚡ Weekly Recap: Fiber Optic Spying, Windows Rootkit, AI Vulnerability Hunting and More
⚠️
Too Many Vulnerabilities to Fix
⚠️
From Compliance to Code: Rethinking Cloud Security - Richard Marcus - CSP #223
⚠️
On Anthropic’s Mythos Preview and Project Glasswing
⚠️
Anthropic's Mythos Preview: Why the Human Layer Matters More, Not Less
⚠️
Anthropic’s Mythos signals a structural cybersecurity shift
⚠️
March 2026 CVE Landscape: 31 High-Impact Vulnerabilities Identified, Interlock Ransomware Group Exploits Cisco FMC Zero-Day
⚠️
Simply opening a PDF could trigger this Adobe Reader zero-day
KEV
⚠️
Citizen Lab: Webloc tracked 500M devices for global law enforcement
⚠️
GrafanaGhost: The AI That Leaked Everything Without Being Hacked
⚠️
Get Secure Cloud Storage on a 2TB Lifetime Plan with Internxt for $100
⚠️
Rockstar Games confirms data breach as ShinyHunters leaks 78 million records
⚠️
Booking.com data breach exposed users’ reservation details
⚠️
Standard fiber optic cables can be turned into remote microphones
⚠️
Hallmark data breach exposed information of 1.7 million accounts
📢
Google Brings End-to-End Encrypted Gmail to Android and iPhone
📢
New Nginx 1.29.8 and FreeNginx Versions Patch Critical Security Flaws
📢
[Control systems] CISA ICS security advisories (AV26–339)
📢
Ubuntu security advisory (AV26-338)
📢
Adobe Acrobat security advisory (AV26-340)
📢
IBM security advisory (AV26-342)
📢
Red Hat security advisory (AV26-341)
🔥
EDR Killers Broaden Ransomware Tactics, ESET Warns
🔥
APT37 Uses Facebook, Telegram, and Trojanzied Installer in New Targeted Cyberattack
🔥
OpenAI Revokes macOS App Certificate After Malicious Axios Supply Chain Incident
🔥
Basic-Fit Suffers Data Breach Affecting Millions Across Multiple Nations
🔥
CPUID Hacked to Serve Trojanized CPU-Z and HWMonitor Downloads
🔥
How to protect your privacy while using smart sex toys | Kaspersky official blog
🔥
Nearly 4,000 US industrial devices exposed to Iranian cyberattacks
🔥
OpenAI Impacted by North Korea-Linked Axios Supply Chain Hack
🔥
Hacker Used Claude Code, GPT-4.1 to Exfiltrate Hundreds of Millions of Mexican Records
🔥
Hack at Anodot leaves over a dozen breached companies facing extortion
🔥
Booking.com confirms hackers accessed customers’ data
🔥
Rockstar Games receives “pay or leak” warning after cyberattack
🔥
Iran-linked group Handala claims to have breached three major UAE organizations
🔥
CPUID watering hole attack spreads STX RAT malware
🔥
Booking.com Hack Exposes Customer Data, Sparks Travel Scam Fears
🕵️
ISC Stormcast For Monday, April 13th, 2026 https://isc.sans.edu/podcastdetail/9888, (Mon, Apr 13th)
🕵️
WhatsApp’s “End-to-End Encryption by Default” Claim Called Consumer Fraud by Pavel Durov
🕵️
Elon Musk Announces XChat Launch With Self-Destructing Messages
🕵️
Gmail Brings End-to-End Encryption to Android and iOS for Enterprise Users
🕵️
VIPERTUNNEL Python Backdoor Hidden in Fake DLL, Obfuscated Loader Chain
🕵️
Fake Claude Website Distributes PlugX RAT
🕵️
North Korea's APT37 Uses Facebook Social Engineering to Deliver RokRAT Malware
🕵️
Iran-Linked CyberAv3ngers Target Water Utilities, Industrial Controllers
🕵️
Juniper Networks Patches Dozens of Junos OS Vulnerabilities - SecurityWeek
🕵️
Microsoft: Canadian employees targeted in payroll pirate attacks
🕵️
New Phishing Kit Streamlines ClickFix Attacks
🕵️
GitHub and Jira Alerts Hijacked for Trusted-SaaS Phishing
🕵️
BrowserGate: Claims of LinkedIn ‘Spying’ Clash With Security Research Findings
🕵️
Booking.com Says Hackers Accessed User Information
🕵️
The Risk of Trusted System Access
🕵️
Outlook Breaks on Moon Mission
🕵️
Just 21 IP Addresses Are Now Behind Nearly Half of All RDP Scanning on the Internet
🕵️
Google’s ‘Tap to Share’ Could Finally Give Android Its AirDrop Moment
🕵️
Google Rolls Out End-to-End Encryption to Eligible Gmail Users on Mobile
🕵️
Own Windows 11 Pro and Microsoft Office 2024 for just $105
🕵️
Your Data, Always Within Reach – 2TB of Lifetime Cloud Storage Is $75
🕵️
Apple Car Key Support Coming to Lexus Vehicles: What We Know So Far
🕵️
Surfshark unveils new Dausos VPN protocol with dedicated user tunnels
🌐
The silent “Storm”: New infostealer hijacks sessions, decrypts server-side
🌐
JanelaRAT Malware Targets Latin American Banks with 14,739 Attacks in Brazil in 2025
🌐
A week in security (April 6 – April 12)
🌐
JanelaRAT: a financial threat targeting users in Latin America
🌐
iPhone forensics expose Signal messages after app removal in U.S. case
🌐
„ClickFix“-Angriffe auf macOS jetzt auch via Script Editor
📡
Scans for EncystPHP Webshell, (Mon, Apr 13th)
📡
FBI and Indonesian Police Dismantle W3LL Phishing Network Behind $20M Fraud Attempts
📡
FBI announces takedown of phishing operation that targeted thousands of victims
📡
The Iran War: What You Need to Know
📡
Hackers access Booking.com user data, company secures systems
📡
KI-Betrug: Deutsche überschätzen ihre Fähigkeit, Deepfakes zu entlarven
📡
Fitnesskette Basic-Fit: Rund eine Million Mitglieder von Datenleck betroffen
📡
SSL-Konfigurationsfehler gefährdet VMware Tanzu Spring Cloud Gateway
📡
Angreifer attackieren Python-Notebook Marimo