Turla Transforms Kazuar Into Modular P2P Botnet
Russian state hackers Turla transformed their Kazuar backdoor into a stealthy P2P botnet for persistent access. FSB-linked group ups their game with modular malware.
Russian state hackers Turla transformed their Kazuar backdoor into a stealthy P2P botnet for persistent access. FSB-linked group ups their game with modular malware.
A critical memory corruption vulnerability dubbed “poolslip” (CVE-2024-7347) has been discovered in Nginx’s HTTP/3 QUIC implementation, affecting versions 1.25.0 through 1.27.0. The flaw allows remote attackers to trigger denial-of-service conditions and potentially execute arbitrary code through sp
A sophisticated macOS infostealer dubbed “Reaper” is actively exploiting Apple’s legitimate Script Editor application to harvest cryptocurrency wallet data and stored passwords from infected Mac systems. The malware bypasses traditional security controls by leveraging trusted system utilities, speci
Infostealers have emerged as the dominant payload in phishing campaigns, replacing ransomware as the preferred choice for cybercriminals. These stealthy malware variants focus on harvesting credentials, session cookies, cryptocurrency wallets, and browser data rather than encrypting files. The shift
A sophisticated malware campaign dubbed “Weedhack” is actively targeting Minecraft players through malicious YouTube videos promoting fake game cheats and hacks. The operation delivers CountLoader malware, which has infected over 86,000 systems, subsequently deploying cryptocurrency miners and infor
Cisco has released security patches for CVE-2026-20230, a critical SQL injection vulnerability in Unified Communications Manager (UCM) with a CVSS score of 9.8. The flaw allows unauthenticated remote attackers to execute arbitrary SQL queries and potentially gain complete system control. With proof-
Cybercriminals are exploiting NinjaOne, a legitimate Remote Monitoring and Management (RMM) software, to establish persistent access and execute malicious commands while evading traditional security defenses. By leveraging trusted administrative tools, attackers bypass signature-based detection and
A Russian national has been formally charged by U.S. authorities for their involvement in the Void Blizzard espionage campaign, a sophisticated cyber operation targeting government entities, critical infrastructure, and defense contractors. The indictment reveals a multi-year campaign leveraging cus
GitHub’s Advisory Database has reached unprecedented volume levels, with vulnerability submissions now exceeding the platform’s review capacity. The backlog has created significant delays in security advisory publication, potentially leaving thousands of open-source projects vulnerable while maintai
Sports organizations are deploying advanced surveillance systems including cameras, sensors, and 3D body scanning technology to create digital twin models of athletes. While designed to improve officiating accuracy and performance analytics, these systems collect highly sensitive biometric data that