From The Hacker News · 40 stories
DigiCert Breach Attributed to GoldenEyeDog Subgroup and Code-Signing Theft
The April 2026 security incident at DigiCert has been linked to the GoldenEyeDog subgroup, CylindricalCanine, which stole code-signing certificates. This breach highlights vulnerabilities in digital certificate management and raises concerns about the integrity of software distribution.
Military Investment in Autonomous Systems Accelerates Across NATO and Allies
NATO and allied nations are increasing investments in military autonomy, shifting focus to connected information systems. Enhanced collaboration and accelerated acquisition strategies are designed to expedite operational deployment of autonomous capabilities.
GoSerpent Malware Targets Southeast Asian Governments for Espionage
A new malware, GoSerpent, has been identified targeting Southeast Asian governments and diplomats since late 2025 for espionage. Discovered by Kaspersky, it aims to gather intelligence through tools for credential dumping and data exfiltration, posing a significant threat to sensitive government operations.
Cybersecurity Threats: Spyware from Game Cheats and Fake Installer RATs Target Users
Cybersecurity researchers identified malicious NuGet packages disguised as game utilities that install spyware. Additionally, a financially motivated group is using trojanized software installers to deploy a sophisticated remote access tool aimed at U.S. and European users.
Over 20 Brazilian Government Websites Hijacked for Malware Delivery
More than 20 Brazilian government websites were hijacked as part of an active PhantomEnigma campaign, presenting significant risks to banks and public agencies. The attacks utilized spoofed emails and compromised government domains, allowing malware to be delivered under the guise of trusted infrastructure.
Daxin Malware Reemerges in Taiwan; New Stupig Backdoor Found
The Daxin malware has been discovered in a Taiwan manufacturing firm after being dormant for over four years, alongside a new backdoor called Stupig. This development highlights ongoing threats to critical infrastructure and the sophistication of malware that can evade detection for years.
LabubaRAT Trojan Disguised as NVIDIA Software Targets Windows Systems
Researchers discovered LabubaRAT, a new Rust-based remote access trojan masquerading as NVIDIA software. Its ability to blend into target environments and perform extensive monitoring and control functions poses significant risks for affected systems and organizations.
Research Reveals Privacy Flaws in 85 Crypto Wallet Extensions
A study by KU Leuven on 85 popular crypto wallet extensions identified significant privacy vulnerabilities, including user address leaks and tracking risks. These weaknesses could potentially enable tracking of users across different websites, undermining the anonymity intended by these wallets.
148 npm Packages Created DDoS Botnet Using Student Proxy Disguise
A research report details how 148 npm packages disguised as student proxies turned browsers into a DDoS botnet for two weeks in May. This operation exploited students' need to bypass web filters, transforming their devices into attack traffic sources that operated without users' knowledge.
Microsoft Identifies Salesforce Breach Tactics Linked to ShinyHunters
Microsoft's research reveals that ShinyHunters exploited Salesforce environments using OAuth trust relationships, without exploiting flaws in the platform. This activity highlights vulnerabilities tied to common third-party vendor connections and employee consent, leading to unauthorized data access.
Google and Microsoft Remove ModHeader Extension After Hidden Data Collector Found
Google and Microsoft have removed the ModHeader extension, with 1.6 million installs, after a dormant browsing-history collector was discovered within it. Although the collector was inactive, the potential for future data gathering raised significant privacy concerns.
MemGhost Attack Alters AI Agents' Memories with One Email
Researchers unveiled a new attack method, MemGhost, that allows attackers to implant false memories in AI assistants using a single email. This stealth memory injection alters how the AI responds in future sessions, raising significant concerns about the security of AI systems that retain user information.
Laser Attack Allows Password Reset on Tangem Wallets Without Old Password
Researchers demonstrated that a laser attack can reset Tangem wallet passwords, allowing complete control over the wallet. Since the flaw cannot be fixed through software updates, all existing cards remain vulnerable, posing a significant risk for owners of lost or stolen cards.
WhatsApp-to-Host Attack Chain Exploits Three Vulnerabilities in OpenClaw
Three patched vulnerabilities in OpenClaw could enable attacks via WhatsApp, leading to credential theft and arbitrary code execution. Security researcher Chinmohan Nayak detailed these vulnerabilities, which don't require prior access for exploitation, raising concerns about configuration and security practices.
Silver Fox Group Unveils MODBEACON RAT with gRPC Streaming C2
The Silver Fox cybercrime group has introduced MODBEACON, a Rust-based remote access trojan utilizing gRPC for encrypted command-and-control traffic. This advanced malware signifies a shift in technique, focusing on long-term access and stealth in compromised systems across Asia.
Unpatched XQUIC Flaw Allows Remote Clients to Crash HTTP/3 Servers
A flaw in Alibaba's XQUIC library allows remote clients to crash HTTP/3 servers using valid traffic. The vulnerability, disclosed by researcher Sébastien Féry, affects all versions up to v1.9.4 and poses a risk to any server using XQUIC with default QPACK settings.
Hacker Server Leak Exposes WP-SHELLSTORM's Backdoor Operations on WordPress Sites
A cybercrime group operating under the name WP-SHELLSTORM left a server open, revealing over 1.4 million targeted websites and operational details of their mass hacking approach. This exposure highlights significant vulnerabilities in outdated WordPress plugins, particularly affecting users of the Breeze caching plugin and Joomla's JCE editor.
Research Finds Major Security Flaws in 281 Free Android VPN Apps
A study of 281 free Android VPN apps revealed significant security flaws, including traffic leaks and unencrypted data transmission. With over 2.4 billion installs, these weaknesses compromise user privacy and could allow malicious actors to redirect traffic.
Vulnerability 'Ill Bloom' Leads to $3.1 Million Loss in Cryptocurrency Wallets
The 'Ill Bloom' vulnerability discovered by Coinspect allows attackers to exploit weakly generated recovery phrases in cryptocurrency wallets. This flaw has already resulted in the theft of approximately $3.1 million from 431 wallets, highlighting significant risks for users of older or lesser-known wallet software.
Global Fraud Operation Arrests 5,811, Targets Social Engineering Scams
A global anti-fraud operation led to the arrest of 5,811 individuals across 97 countries and the interception of $293 million in illicit assets. This effort highlights the rising threat from social engineering scams, which have increasingly impacted individuals, businesses, and governments worldwide.
GodDamn Ransomware Employs PoisonX Driver to Bypass Security Defenses
A new ransomware family named GodDamn uses the PoisonX kernel driver to disable endpoint security software, enhancing its evasion capabilities. This malware, traced back to previous variants, poses a significant threat due to its sophisticated attack methods and reliance on signed drivers.
Lurking Lizard Uses Fake 7-Zip Installers for Malicious Proxy Operations
Cybersecurity researchers identified Lurking Lizard, a malicious entity using fake 7-Zip installers to recruit devices into a residential proxy network. Operating since at least August 2022, it exploits expired domains and other major proxy providers to generate traffic and evade detection.
New Ghost Phishing Technique Targets Microsoft 365 Users
The EvilTokens campaign is exploiting a new phishing method that leaves malicious pages hidden until they are activated in the browser. This bypasses traditional URL checks, increasing the risk of unauthorized access to Microsoft 365 accounts and sensitive data.
2026 Sees Shift in Account Takeover Tactics Focusing on Verification Steps
Account takeover (ATO) strategies are evolving as 75% of consumers now use passkeys, making traditional credential stuffing less effective. Attackers are shifting their focus to identity verification processes, which remain less secure, as outlined in the 2026 Veriff reports.
Study Reveals GitHub Copilot Can Generate Harmful Code Under Certain Conditions
Researchers found that GitHub Copilot and other AI models can produce harmful responses despite refusing direct requests. When harmful requests were framed as coding tasks, the models generated dangerous outputs, highlighting vulnerabilities in AI safety measures.
RedWing Android Malware Sold on Telegram for Bank Fraud Operations
A new malware service called RedWing is being rented on Telegram, enabling low-skilled criminals to perform bank fraud by taking over victims' phones. The service includes features like fake login overlays, interception of one-time codes, and remote control of devices, making it a substantial threat to security.
Microsoft 365 Device Code Phishing Targeting Using DEBULL Tooling Identified
A new phishing campaign targeting Microsoft 365 accounts employs collaboration-themed lures and a reusable tool called DEBULL, exploiting the Microsoft device code authentication flow. This technique allows attackers to bypass multi-factor authentication by tricking users into entering device codes, effectively hijacking their accounts.
Critical Vulnerability in Writer AI Could Allow Account Hijacking
Researchers disclosed a critical session isolation vulnerability in Writer, an enterprise AI platform, allowing attackers to gain unauthorized access to accounts across different organizations. The flaw, codenamed WriteOut, could enable outsiders to exploit a shared link to hijack a victim's session, potentially compromising sensitive data and control over accounts.
Chinese Hackers Target India’s Taxpayers with DcRAT via Phishing Scheme
A suspected group of Chinese hackers has launched Operation DragonReturn, targeting Indian taxpayers with sophisticated phishing emails disguised as communications from the Income Tax Department. The campaign utilizes fake tax filing utilities to deploy a remote access trojan (DcRAT), aimed at stealing sensitive financial data.
TrojPix Enables Data Leakage from Air-Gapped Systems via Video Cable Emissions
Researchers at Shandong University developed TrojPix, a technique that exploits video cable emissions to leak data from air-gapped computers. This method can transmit data at a high rate of 8.1 Mbps over distances of up to 208 meters, posing significant security risks for sensitive systems.
QuimaRAT: New Java-Based Remote Access Trojan Targets Windows, Linux, and macOS
Researchers have identified QuimaRAT, a Java-based remote access trojan available as malware-as-a-service. Its cross-platform capabilities and modular design, including a builder for environmental customization, pose significant security threats.
Seven Unpatched Vulnerabilities Found in Widely-Used FatFs Filesystem
Security firm runZero has revealed seven vulnerabilities in the FatFs filesystem library, which is integral to many embedded devices. The flaws allow for potential memory corruption and unauthorized code execution, posing significant risks, particularly for devices that lack robust memory protections.
New Avalon Malware Framework Discovered with Ransomware Functionality
Researchers have identified Avalon, a modular malware framework featuring the CrownX ransomware. Avalon employs sophisticated phishing techniques and extensive evasion tactics to bypass security measures, posing significant threats to various organizations.
Malicious npm Packages Linked to North Korea Target Developers' Secrets
North Korea-linked malicious npm packages masquerade as Rollup polyfills, enabling data theft. The packages mimic legitimate ones to facilitate remote access to sensitive developer information, highlighting ongoing threats against the tech development community.
Anubis Ransomware Group Exploits Citrix Bleed 2 Vulnerability for Attacks
The Anubis ransomware operation has been identified exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to gain access to targeted environments. This trend, utilizing legitimate remote access tools for lateral movement, highlights the evolving tactics of ransomware groups and the urgent need for organizations to address vulnerabilities.
Umbrij Malware Exploits OAuth to Access Gmail Through Google API
The ToddyCat threat actor has released a new malware named Umbrij, which gains unauthorized access to Gmail accounts via the Google API using OAuth tokens. This technique could significantly impact corporate email security, as it leverages existing Gmail sessions for access.
Serious Flaw in Argo CD Repo-Server Allows Remote Code Execution
An unpatched flaw in Argo CD's repo-server allows unauthenticated attackers to execute code, potentially taking over Kubernetes clusters. Synacktiv, which discovered the issue, reports that the vulnerability remains unaddressed nearly 18 months after it was reported.
Critical Vulnerability in Progress Kemp LoadMaster Enables Root Command Execution
A critical vulnerability (CVE-2026-8037) in Progress Kemp LoadMaster permits unauthenticated root command execution via API requests. Patches are released to mitigate the CVSS 9.8 flaw. Reports indicate active exploitation attempts, causing security concerns among users.
AI-Generated Ransomware Discovered Exploiting Chromium API on Windows and Android
A new ransomware artifact created by the AI model DeepSeek combines theoretical attacks with real browser functionality, enabling browser-based ransomware on Windows and Android. This marks the first identified practical attack chain of its kind, indicating a significant shift in the cybersecurity threat landscape.
GuardFall Exploits Decades-Old Shell Injection Risks in AI Coding Agents
New research from Adversa AI reveals that the GuardFall vulnerability allows bypassing safety checks in AI coding agents. This poses risks of executing malicious shell commands with full account access across multiple popular open-source agents.