Malicious Commands in GitHub Codespaces Enable RCE Information Security Magazine 2 months 1 week ago Flaws in GitHub Codespaces allow RCE via crafted repositories or pull requests
Smartphones Now Involved in Nearly Every Police Investigation Information Security Magazine 2 months 1 week ago Cellebrite data confirms digital evidence is now central to almost all cases
New Hacking Campaign Exploits Microsoft Windows WinRAR Vulnerability Information Security Magazine 2 months 1 week ago Researchers at Check Point link ‘Amarath-Dragon’ attacks to prolific Chinese cyber-espionage operation
AI-Enabled Voice and Virtual Meeting Fraud Surges 1000%+ Information Security Magazine 2 months 1 week ago Pindrop warns of 1210% increase in AI-powered fraud last year
Global SystemBC Botnet Found Active Across 10,000 Infected Systems Information Security Magazine 2 months 1 week ago SystemBC malware linked to 10,000 infected IPs, posing risks to sensitive government infrastructure
New Technical Markers Reveal Expanding ShadowSyndicate Cybercriminal Infrastructure Information Security Magazine 2 months 1 week ago ShadowSyndicate cluster expands with new SSH fingerprints connecting servers to other ransomware ops
AI Drives Doubling of Phishing Attacks in a Year Information Security Magazine 2 months 1 week ago Cofense claims AI is making phishing emails more personalized and sophisticated
Two Critical Flaws in n8n AI Workflow Automation Platform Allow Complete Takeover Information Security Magazine 2 months 1 week ago Pillar Security discovered two new critical vulnerabilities in n8n that could lead to supply chain compromise, credential harvesting and complete takeover attacks
SolarWinds Web Help Desk Vulnerability Actively Exploited Information Security Magazine 2 months 1 week ago CISA has added a critical CVE in SolarWinds Web Help Desk to its KEV Catalog
Hundreds of Malicious Crypto Trading Add-Ons Found in Moltbot/OpenClaw Information Security Magazine 2 months 1 week ago A security researcher found 386 malicious ‘skills’ published on ClawHub, a skill repository for the popular OpenClaw AI assistant project
SQL Injection Flaw Affects 40,000 WordPress Sites Information Security Magazine 2 months 1 week ago 40,000 WordPress sites are vulnerable to SQL injection in Quiz and Survey Master plugin
DockerDash Exposes AI Supply Chain Weakness In Docker's Ask Gordon Information Security Magazine 2 months 1 week ago DockerDash vulnerability allows RCE and data exfiltration via unverified metadata in Ask Gordon
UK ICO Launches Investigation into X Over AI Generated Non-Consensual Sexual Imagery Information Security Magazine 2 months 1 week ago UK Data Protection Watchdog has “serious concerns” over data privacy on Elon Musk’s social platform
Researchers Warn of New “Vect” RaaS Variant Information Security Magazine 2 months 1 week ago A new ransomware-as-a-service operation dubbed “Vect” features custom malware
Cybercrime Unit of Paris Prosecutors Raid Elon Musk’s X Offices in France Information Security Magazine 2 months 1 week ago Elon Musk and X’s former CEO were summoned for voluntary interviews in Paris on April 20, 2026
New Password-Stealing Phishing Campaign Targets Corporate Dropbox Credentials Information Security Magazine 2 months 1 week ago Multi-stage attack begins with fake message relating to business requests and evades detection with link hidden in a PDF
Vibe-Coded Moltbook Exposes User Data, API Keys and More Information Security Magazine 2 months 1 week ago Wiz Security claims Moltbook misconfiguration allowed full read and write access
NSA Publishes New Zero Trust Implementation Guidelines Information Security Magazine 2 months 2 weeks ago NSA released new guidelines to help organizations achieve target-level Zero Trust maturity
Notepad++ Update Hijacking Linked to Hosting Provider Compromise Information Security Magazine 2 months 2 weeks ago A supply chain attack on Notepad++ update process was linked to compromised hosting infrastructure
Fancy Bear Exploits Microsoft Office Flaw in Ukraine, EU Cyber-Attacks Information Security Magazine 2 months 2 weeks ago Russia-linked hacking group Fancy Bear is exploiting a brand-new vulnerability in Microsoft Office, CERT-UA says