Skip to content
AttackFeed by Joe Wagner | Cybersecurity News from Across the Internet

AttackFeed by Joe Wagner

Cybersecurity News from Across the Internet

  • Attack/News Feeds
  • Gov Alerts/ISAC Feeds
  • Vulnerability Alerts
  • Privacy/Governance Feeds
  • Fraud Feeds
  • iOS App
  • Android App
AttackFeed by Joe Wagner | Nine CrackArmor Flaws in Linux AppArmor Enable Root Escalation, Bypass Container Isolation  - The Hacker News
Attack Feeds
Nine CrackArmor Flaws in Linux AppArmor Enable Root Escalation, Bypass Container Isolation  – The Hacker News
March 13, 2026
AttackFeed by Joe Wagner | Iran-Backed Hackers Claim Wiper Attack on Medtech Firm Stryker  - Krebs on Security
Attack Feeds
Iran-Backed Hackers Claim Wiper Attack on Medtech Firm Stryker  – Krebs on Security
March 11, 2026
AttackFeed by Joe Wagner | ShinyHunters Claims 350GB Data Breach at European Commission  - Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds
ShinyHunters Claims 350GB Data Breach at European Commission  – Hackread – Cybersecurity News, Data Breaches, AI and More
March 28, 2026
AttackFeed by Joe Wagner | How Fintech APIs Are Modernizing Business Cash Flow Management  - Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds
How Fintech APIs Are Modernizing Business Cash Flow Management  – Hackread – Cybersecurity News, Data Breaches, AI and More
May 14, 2026
AttackFeed by Joe Wagner | Phishing in 2026: 3 Attack Tactics That Beat Most Enterprise Defenses  - Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds
Phishing in 2026: 3 Attack Tactics That Beat Most Enterprise Defenses  – Hackread – Cybersecurity News, Data Breaches, AI and More
March 4, 2026
AttackFeed by Joe Wagner | Trump officials are steering a cybersecurity scholarship program toward AI  - CyberScoop
Attack Feeds
Trump officials are steering a cybersecurity scholarship program toward AI  – CyberScoop
May 7, 2026

Adobe to Pay $150 Million Over Hidden Fees and Hard-to-Cancel Subscriptions  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on March 16, 2026 By Waqas
Adobe to Pay $150 Million Over Hidden Fees and Hard-to-Cancel Subscriptions  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

The Justice Department says Adobe buried the real cost of cancelling a subscription where most customers would never think to look.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

⚡ Weekly Recap: Chrome 0-Days, Router Botnets, AWS Breach, Rogue AI Agents & More  – The Hacker News

Posted on March 16, 2026 By [email protected] (The Hacker News)
⚡ Weekly Recap: Chrome 0-Days, Router Botnets, AWS Breach, Rogue AI Agents & More  – The Hacker News
Attack Feeds

Some weeks in security feel normal. Then you read a few tabs and get that immediate “ah, great, we’re doing this now” feeling. This week has that energy. Fresh messes, old problems getting sharper, and research that stops feeling theoretical real fast. A few bits hit a little too close to real life, too. There’s … Read More “⚡ Weekly Recap: Chrome 0-Days, Router Botnets, AWS Breach, Rogue AI Agents & More  – The Hacker News” »

Researchers Warn of Global Surge in Fake Shipment Tracking Scams –

Posted on March 16, 2026 By Joe-W
Researchers Warn of Global Surge in Fake Shipment Tracking Scams –
Privacy/Governance Feed

Some of these campaigns are linked to Darcula, a Chinese-language phishing-as-a-service platform – Read More  –  

CrackArmor Flaws Expose Linux Systems to Privilege Escalation –

Posted on March 16, 2026 By Joe-W
CrackArmor Flaws Expose Linux Systems to Privilege Escalation –
Privacy/Governance Feed

CrackArmor AppArmor flaws let local Linux users gain root, break containers and enable DoS attacks – Read More  –  

ClickFix Campaigns Spread MacSync macOS Infostealer via Fake AI Tool Installers  – The Hacker News

Posted on March 16, 2026 By [email protected] (The Hacker News)
ClickFix Campaigns Spread MacSync macOS Infostealer via Fake AI Tool Installers  – The Hacker News
Attack Feeds

Three different ClickFix campaigns have been found to act as a delivery vector for the deployment of a macOS information stealer called MacSync. “Unlike traditional exploit-based attacks, this method relies entirely on user interaction – usually in the form of copying and executing commands – making it particularly effective against users who may not appreciate … Read More “ClickFix Campaigns Spread MacSync macOS Infostealer via Fake AI Tool Installers  – The Hacker News” »

Why Security Validation Is Becoming Agentic  – The Hacker News

Posted on March 16, 2026 By [email protected] (The Hacker News)
Why Security Validation Is Becoming Agentic  – The Hacker News
Attack Feeds

If you run security at any reasonably complex organization, your validation stack probably looks something like this: a BAS tool in one corner. A pentest engagement, or maybe an automated pentesting product, in another. A vulnerability scanner feeding an attack surface management platform somewhere else. Each tool gives you a slice of the picture. None … Read More “Why Security Validation Is Becoming Agentic  – The Hacker News” »

Security Flaw in AWS Bedrock Code Interpreter Raises Alarms –

Posted on March 16, 2026 By Joe-W
Security Flaw in AWS Bedrock Code Interpreter Raises Alarms –
Privacy/Governance Feed

DNS-based attack in AWS Bedrock AgentCore lets AI sandboxes exfiltrate cloud data – Read More  –  

Kevuru Games Outlines the Shift Toward Flexible Art Production in the Games Industry  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on March 16, 2026 By CyberNewswire
Kevuru Games Outlines the Shift Toward Flexible Art Production in the Games Industry  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

Kyiv, Ukraine, 16th March 2026, CyberNewswire  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

New XWorm 7.1 and Remcos RAT Attacks Abuse Windows Tools to Evade Detection  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on March 16, 2026 By Deeba Ahmed
New XWorm 7.1 and Remcos RAT Attacks Abuse Windows Tools to Evade Detection  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

New XWorm 7.1 and Remcos RAT campaigns abuse trusted Windows tools to evade detection. The attacks exploit a WinRAR flaw and use process hollowing to spy on victims.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

FBI Calls for Help to Track Steam Malware Campaign –

Posted on March 16, 2026 By Joe-W
FBI Calls for Help to Track Steam Malware Campaign –
Privacy/Governance Feed

The FBI wants to hear from gamers who have downloaded Steam titles containing malware – Read More  –  

DRILLAPP Backdoor Targets Ukraine, Abuses Microsoft Edge Debugging for Stealth Espionage  – The Hacker News

Posted on March 16, 2026 By [email protected] (The Hacker News)
DRILLAPP Backdoor Targets Ukraine, Abuses Microsoft Edge Debugging for Stealth Espionage  – The Hacker News
Attack Feeds

Ukrainian entities have emerged as the target of a new campaign likely orchestrated by threat actors linked to Russia, according to a report from S2 Grupo’s LAB52 threat intelligence team. The campaign, observed in February 2026, has been assessed to share overlaps with a prior campaign mounted by Laundry Bear (aka UAC-0190 or Void Blizzard) … Read More “DRILLAPP Backdoor Targets Ukraine, Abuses Microsoft Edge Debugging for Stealth Espionage  – The Hacker News” »

Attackers are exploiting AI faster than defenders can keep up, new report warns  – CyberScoop

Posted on March 16, 2026 By Greg Otto
Attackers are exploiting AI faster than defenders can keep up, new report warns  – CyberScoop
Attack Feeds

Cybersecurity is entering “a new phase” as artificial intelligence tools have matured and given IT defenders significantly less time to respond to cyberattacks and other threats, according to a new report released Monday. The report, authored by federal contractor Booz Allen Hamilton, concludes that threat actors have adopted AI more quickly than governments and private … Read More “Attackers are exploiting AI faster than defenders can keep up, new report warns  – CyberScoop” »

The ransomware economy is shifting toward straight-up data extortion  – CyberScoop

Posted on March 16, 2026 By Matt Kapko
The ransomware economy is shifting toward straight-up data extortion  – CyberScoop
Attack Feeds

Ransomware remains a scourge that shows some signs of relenting, but incident responders and threat hunters are busier than ever as more financially-motivated attackers lean exclusively on data theft for extortion. Attacks that only involve data theft for extortion may not be more prevalent than traditional ransomware when attackers encrypt systems, but momentum is moving … Read More “The ransomware economy is shifting toward straight-up data extortion  – CyberScoop” »

UK: Companies House Web Glitch Exposes Corporate Details to Fraudsters –

Posted on March 16, 2026 By Joe-W
UK: Companies House Web Glitch Exposes Corporate Details to Fraudsters –
Privacy/Governance Feed

An issue with the Companies House website has put the personal and corporate information of millions at risk – Read More  –  

Washington is right: Cybercrime is organized crime. Now we need to shut down the business model  – CyberScoop

Posted on March 16, 2026 By Greg Otto
Washington is right: Cybercrime is organized crime. Now we need to shut down the business model  – CyberScoop
Attack Feeds

The recently released executive order targeting cybercrime, fraud, and predatory schemes uses language the federal government has often avoided. Now, for the first time, the Trump administration is echoing what the cybersecurity industry has been shouting for years: cyber-enabled fraud is a product of transnational organized crime. That distinction matters because organized crime requires an … Read More “Washington is right: Cybercrime is organized crime. Now we need to shut down the business model  – CyberScoop” »

Android 17 Blocks Non-Accessibility Apps from Accessibility API to Prevent Malware Abuse  – The Hacker News

Posted on March 16, 2026 By [email protected] (The Hacker News)
Android 17 Blocks Non-Accessibility Apps from Accessibility API to Prevent Malware Abuse  – The Hacker News
Attack Feeds

Google is testing a new security feature as part of Android Advanced Protection Mode (AAPM) that prevents certain kinds of apps from using the accessibility services API. The change, incorporated in Android 17 Beta 2, was first reported by Android Authority last week. AAPM was introduced by Google in Android 16, released last year. When … Read More “Android 17 Blocks Non-Accessibility Apps from Accessibility API to Prevent Malware Abuse  – The Hacker News” »

Gaming Clans Become Growth Engine for Playnance Ecosystem  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on March 15, 2026 By Owais Sultan
Gaming Clans Become Growth Engine for Playnance Ecosystem  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

Playnance partners with KGeN, connecting its Web3 gaming ecosystem to 53M gamers and 30K clans through community-driven platforms.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

OpenClaw AI Agent Flaws Could Enable Prompt Injection and Data Exfiltration  – The Hacker News

Posted on March 14, 2026 By [email protected] (The Hacker News)
OpenClaw AI Agent Flaws Could Enable Prompt Injection and Data Exfiltration  – The Hacker News
Attack Feeds

China’s National Computer Network Emergency Response Technical Team (CNCERT) has issued a warning about the security stemming from the use of OpenClaw (formerly Clawdbot and Moltbot), an open-source and self-hosted autonomous artificial intelligence (AI) agent. In a post shared on WeChat, CNCERT noted that the platform’s “inherently weak default security configurations,” coupled with its  – … Read More “OpenClaw AI Agent Flaws Could Enable Prompt Injection and Data Exfiltration  – The Hacker News” »

ShinyHunters Claims 1 Petabyte Data Theft from Telecom Giant Telus  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on March 14, 2026 By Deeba Ahmed
ShinyHunters Claims 1 Petabyte Data Theft from Telecom Giant Telus  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

ShinyHunters claims it stole up to 1 petabyte of data from Telus Digital, including support recordings, code, and employee records after a breach.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

GlassWorm Supply-Chain Attack Abuses 72 Open VSX Extensions to Target Developers  – The Hacker News

Posted on March 14, 2026 By [email protected] (The Hacker News)
GlassWorm Supply-Chain Attack Abuses 72 Open VSX Extensions to Target Developers  – The Hacker News
Attack Feeds

Cybersecurity researchers have flagged a new iteration of the GlassWorm campaign that they say represents a “significant escalation” in how it propagates through the Open VSX registry. “Instead of requiring every malicious listing to embed the loader directly, the threat actor is now abusing extensionPack and extensionDependencies to turn initially standalone-looking extensions into transitive  – … Read More “GlassWorm Supply-Chain Attack Abuses 72 Open VSX Extensions to Target Developers  – The Hacker News” »

Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution  – Cyber Security Advisories – MS-ISAC

Posted on March 14, 2026 By Joe-W
Gov/ISAC Feeds

Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user an attacker could then install programs; … Read More “Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution  – Cyber Security Advisories – MS-ISAC” »

INTERPOL Operation Synergia III Shuts Down 45,000 Malicious IPs, 94 Arrested  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on March 13, 2026 By Waqas
INTERPOL Operation Synergia III Shuts Down 45,000 Malicious IPs, 94 Arrested  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

INTERPOL’s Operation Synergia III led to 94 arrests and the takedown of 45,000 malicious IPs in 72 countries targeting phishing, malware, and fraud networks.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

‘CrackArmor’ Vulnerability in AppArmor Impacts 12.6M Linux Systems  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on March 13, 2026 By Deeba Ahmed
‘CrackArmor’ Vulnerability in AppArmor Impacts 12.6M Linux Systems  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

Qualys uncovers ‘CrackArmor’ vulnerabilities in AppArmor that could expose 12.6M Linux systems to root access and container escapes.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

Meta to Shut Down Instagram End-to-End Encrypted Chat Support Starting May 2026  – The Hacker News

Posted on March 13, 2026 By [email protected] (The Hacker News)
Meta to Shut Down Instagram End-to-End Encrypted Chat Support Starting May 2026  – The Hacker News
Attack Feeds

Meta has announced plans to discontinue support for end-to-end encryption (E2EE) for chats on Instagram after May 8, 2026. “If you have chats that are impacted by this change, you will see instructions on how you can download any media or messages you may want to keep,” the social media giant said in a help … Read More “Meta to Shut Down Instagram End-to-End Encrypted Chat Support Starting May 2026  – The Hacker News” »

Chinese Hackers Target Southeast Asian Militaries with AppleChris and MemFun Malware  – The Hacker News

Posted on March 13, 2026 By [email protected] (The Hacker News)
Chinese Hackers Target Southeast Asian Militaries with AppleChris and MemFun Malware  – The Hacker News
Attack Feeds

A suspected China-based cyber espionage operation has targeted Southeast Asian military organizations as part of a state-sponsored campaign that dates back to at least 2020. Palo Alto Networks Unit 42 is tracking the threat activity under the moniker CL-STA-1087, where CL refers to cluster, and STA stands for state-backed motivation. “The activity demonstrated strategic operational … Read More “Chinese Hackers Target Southeast Asian Militaries with AppleChris and MemFun Malware  – The Hacker News” »

Interpol’s ‘Operation Synergia III’ Nets 94 Arrests in Major Cybercrime Sweep –

Posted on March 13, 2026 By Joe-W
Interpol’s ‘Operation Synergia III’ Nets 94 Arrests in Major Cybercrime Sweep –
Privacy/Governance Feed

A new law enforcement operation against phishing and ransomware operators led to the takedown of 45,000 malicious IP addresses – Read More  –  

INTERPOL Dismantles 45,000 Malicious IPs, Arrests 94 in Global Cybercrime  – The Hacker News

Posted on March 13, 2026 By [email protected] (The Hacker News)
INTERPOL Dismantles 45,000 Malicious IPs, Arrests 94 in Global Cybercrime  – The Hacker News
Attack Feeds

INTERPOL on Friday announced the takedown of 45,000 malicious IP addresses and servers used in connection with phishing, malware, and ransomware campaigns, as part of the agency’s ongoing efforts to dismantle criminal networks, disrupt emerging threats, and safeguard victims from scams. The effort is part of an international law enforcement operation that involved 72 countries … Read More “INTERPOL Dismantles 45,000 Malicious IPs, Arrests 94 in Global Cybercrime  – The Hacker News” »

Investigating a New Click-Fix Variant  – The Hacker News

Posted on March 13, 2026 By [email protected] (The Hacker News)
Investigating a New Click-Fix Variant  – The Hacker News
Attack Feeds

Disclaimer: This report has been prepared by the Threat Research Center to enhance cybersecurity awareness and support the strengthening of defense capabilities. It is based on independent research and observations of the current threat landscape available at the time of publication. The content is intended for informational and preparedness purposes only. Read more blogs around … Read More “Investigating a New Click-Fix Variant  – The Hacker News” »

Storm-2561 Spreads Trojan VPN Clients via SEO Poisoning to Steal Credentials  – The Hacker News

Posted on March 13, 2026 By [email protected] (The Hacker News)
Storm-2561 Spreads Trojan VPN Clients via SEO Poisoning to Steal Credentials  – The Hacker News
Attack Feeds

Microsoft has disclosed details of a credential theft campaign that employs fake virtual private network (VPN) clients distributed through search engine optimization (SEO) poisoning techniques. “The campaign redirects users searching for legitimate enterprise software to malicious ZIP files on attacker-controlled websites to deploy digitally signed trojans that masquerade as trusted VPN clients  – Read More  … Read More “Storm-2561 Spreads Trojan VPN Clients via SEO Poisoning to Steal Credentials  – The Hacker News” »

US Agencies Face CISA Deadline Over Critical Cisco SD-WAN Flaw  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on March 13, 2026 By Deeba Ahmed
US Agencies Face CISA Deadline Over Critical Cisco SD-WAN Flaw  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

US agencies race to meet a CISA deadline after a critical Cisco SD-WAN Flaw exposed federal networks to long-term intrusion and forced security action.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

SQL Injection Vulnerability in Ally WordPress Plugin Exposes 200K+ Sites  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on March 13, 2026 By Waqas
SQL Injection Vulnerability in Ally WordPress Plugin Exposes 200K+ Sites  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

SQL injection flaw in Ally WordPress plugin exposes 200,000+ sites to data theft. Patch released, but most installations remain unpatched and vulnerable.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

AI-HealthTech Innovator Humata Health Partners with AccuKnox for Zero Trust CNAPP  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on March 13, 2026 By CyberNewswire
AI-HealthTech Innovator Humata Health Partners with AccuKnox for Zero Trust CNAPP  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

Menlo Park, California, USA, 13th March 2026, CyberNewswire  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

Nine CrackArmor Flaws in Linux AppArmor Enable Root Escalation, Bypass Container Isolation  – The Hacker News

Posted on March 13, 2026 By [email protected] (The Hacker News)
Nine CrackArmor Flaws in Linux AppArmor Enable Root Escalation, Bypass Container Isolation  – The Hacker News
Attack Feeds

Cybersecurity researchers have disclosed multiple security vulnerabilities within the Linux kernel’s AppArmor module that could be exploited by unprivileged users to circumvent kernel protections, escalate to root, and undermine container isolation guarantees. The nine confused deputy vulnerabilities have been collectively codenamed CrackArmor by the Qualys Threat Research Unit (TRU). The  – Read More  – The … Read More “Nine CrackArmor Flaws in Linux AppArmor Enable Root Escalation, Bypass Container Isolation  – The Hacker News” »

Google Fixes Two Chrome Zero-Days Exploited in the Wild Affecting Skia and V8  – The Hacker News

Posted on March 13, 2026 By [email protected] (The Hacker News)
Google Fixes Two Chrome Zero-Days Exploited in the Wild Affecting Skia and V8  – The Hacker News
Attack Feeds

Google on Thursday released security updates for its Chrome web browser to address two high-severity vulnerabilities that it said have been exploited in the wild. The list of vulnerabilities is as follows – CVE-2026-3909 (CVSS score: 8.8) – An out-of-bounds write vulnerability in the Skia 2D graphics library that allows a remote attacker to perform … Read More “Google Fixes Two Chrome Zero-Days Exploited in the Wild Affecting Skia and V8  – The Hacker News” »

Law Enforcement Dismantles SocksEscort Proxy Network in Operation Lightning –

Posted on March 13, 2026 By Joe-W
Law Enforcement Dismantles SocksEscort Proxy Network in Operation Lightning –
Privacy/Governance Feed

Operation Lightning sees international law enforcement partners shut down ‘SocksEscort,’ a major malicious proxy service used by cybercriminals worldwide – Read More  –  

Authorities Disrupt SocksEscort Proxy Botnet Exploiting 369,000 IPs Across 163 Countries  – The Hacker News

Posted on March 13, 2026 By [email protected] (The Hacker News)
Authorities Disrupt SocksEscort Proxy Botnet Exploiting 369,000 IPs Across 163 Countries  – The Hacker News
Attack Feeds

A court-authorized international law enforcement operation has dismantled a criminal proxy service named SocksEscort that enslaved thousands of residential routers worldwide into a botnet for committing large-scale fraud. “SocksEscort infected home and small business internet routers with malware,” the U.S. Department of Justice (DoJ) said. “The malware allowed SocksEscort to direct internet  – Read More  … Read More “Authorities Disrupt SocksEscort Proxy Botnet Exploiting 369,000 IPs Across 163 Countries  – The Hacker News” »

Veeam Patches 7 Critical Backup & Replication Flaws Allowing Remote Code Execution  – The Hacker News

Posted on March 13, 2026 By [email protected] (The Hacker News)
Veeam Patches 7 Critical Backup & Replication Flaws Allowing Remote Code Execution  – The Hacker News
Attack Feeds

Veeam has released security updates to address multiple critical vulnerabilities in its Backup & Replication software that, if successfully exploited, could result in remote code execution. The vulnerabilities are as follows – CVE-2026-21666 (CVSS score: 9.9) – A vulnerability that allows an authenticated domain user to perform remote code execution on the Backup Server. CVE-2026-21667 … Read More “Veeam Patches 7 Critical Backup & Replication Flaws Allowing Remote Code Execution  – The Hacker News” »

SEC Consult SA-20260224-0 :: Multiple vulnerabilities in CPSD CryptoPro Secure Disk for BitLocker (CVE-2025-10010)  – Full Disclosure

Posted on March 12, 2026 By Joe-W
SEC Consult SA-20260224-0 :: Multiple vulnerabilities in CPSD CryptoPro Secure Disk for BitLocker (CVE-2025-10010)  – Full Disclosure
Alert Feeds

  Posted by SEC Consult Vulnerability Lab via Fulldisclosure on Mar 12 SEC Consult Vulnerability Lab Security Advisory < 20260224-0 > ======================================================================= title: Multiple vulnerabilities             product: CPSD CryptoPro Secure Disk for BitLocker  vulnerable version: 7.6.4.16432 (76212) fixed version: 7.6.6 / 7.7.1 CVE number: CVE-2025-10010           … Read More “SEC Consult SA-20260224-0 :: Multiple vulnerabilities in CPSD CryptoPro Secure Disk for BitLocker (CVE-2025-10010)  – Full Disclosure” »

APPLE-SA-03-11-2026-1 iOS 16.7.15 and iPadOS 16.7.15  – Full Disclosure

Posted on March 12, 2026 By Joe-W
APPLE-SA-03-11-2026-1 iOS 16.7.15 and iPadOS 16.7.15  – Full Disclosure
Alert Feeds

  Posted by Apple Product Security via Fulldisclosure on Mar 12 APPLE-SA-03-11-2026-1 iOS 16.7.15 and iPadOS 16.7.15 iOS 16.7.15 and iPadOS 16.7.15 addresses the following issues. Information about the security content is also available at https://support.apple.com/126646. Apple maintains a Security Releases page at https://support.apple.com/100100 which lists recent software updates with security advisories. WebKit Available for: … Read More “APPLE-SA-03-11-2026-1 iOS 16.7.15 and iPadOS 16.7.15  – Full Disclosure” »

APPLE-SA-03-11-2026-2 iOS 15.8.7 and iPadOS 15.8.7  – Full Disclosure

Posted on March 12, 2026 By Joe-W
APPLE-SA-03-11-2026-2 iOS 15.8.7 and iPadOS 15.8.7  – Full Disclosure
Alert Feeds

  Posted by Apple Product Security via Fulldisclosure on Mar 12 APPLE-SA-03-11-2026-2 iOS 15.8.7 and iPadOS 15.8.7 iOS 15.8.7 and iPadOS 15.8.7 addresses the following issues. Information about the security content is also available at https://support.apple.com/126632. Apple maintains a Security Releases page at https://support.apple.com/100100 which lists recent software updates with security advisories. Kernel Available for: … Read More “APPLE-SA-03-11-2026-2 iOS 15.8.7 and iPadOS 15.8.7  – Full Disclosure” »

Cohesity TranZman Migration Appliance – 5 CVEs (command injection, LPE, unsigned patches, weak crypto)  – Full Disclosure

Posted on March 12, 2026 By Joe-W
Cohesity TranZman Migration Appliance – 5 CVEs (command	injection, LPE, unsigned patches, weak crypto)  – Full Disclosure
Alert Feeds

  Posted by GregD via Fulldisclosure on Mar 12 Hi, I’m disclosing five vulnerabilities discovered during an authorised security assessment of the Cohesity TranZman Migration Appliance (formerly Stone Ram TranZman), Release 4.0 Build 14614. CVE-2025-67840 – Web API Command Injection (CVSS 7.2 High) The /api/v1/scheduler/run and /api/v1/actions/run endpoints allow authenticated administrators to execute arbitrary commands … Read More “Cohesity TranZman Migration Appliance – 5 CVEs (command injection, LPE, unsigned patches, weak crypto)  – Full Disclosure” »

Alipay DeepLink+JSBridge Attack Chain: Silent GPS Exfiltration, 17 Vulns, 6 CVEs (CVSS 9.3)  – Full Disclosure

Posted on March 12, 2026 By Joe-W
Alipay DeepLink+JSBridge Attack Chain: Silent GPS Exfiltration,	17 Vulns, 6 CVEs (CVSS 9.3)  – Full Disclosure
Alert Feeds

  Posted by Feng Ning via Fulldisclosure on Mar 12 Subject: Alipay DeepLink+JSBridge Attack Chain: Silent GPS Exfiltration, 17 Vulns, 6 CVEs (CVSS 9.3) # Alipay DeepLink + JSBridge Attack Chain # Silent GPS Exfiltration via Crafted URL ## Overview Researcher: Jiqiang Feng / Innora AI Security Research Vendor: Ant Group (蚂蚁集团) / Alibaba Group … Read More “Alipay DeepLink+JSBridge Attack Chain: Silent GPS Exfiltration, 17 Vulns, 6 CVEs (CVSS 9.3)  – Full Disclosure” »

Defense in depth — the Microsoft way (part 96): yet another SAFER (SRPv1) and AppLocker (SRPv2) loophole  – Full Disclosure

Posted on March 12, 2026 By Joe-W
Defense in depth — the Microsoft way (part 96): yet another	SAFER (SRPv1) and AppLocker (SRPv2) loophole  – Full Disclosure
Alert Feeds

  Posted by Stefan Kanthak via Fulldisclosure on Mar 12 Hi @ll, about 2 months ago I posted <https://seclists.org/fulldisclosure/2025/Dec/29> “Defense in depth — the Microsoft way (part 94): SAFER (SRPv1 and AppLocker alias SRPv2) bypass for dummies” Here’s the continuation… About 23 years ago, 64-bit Windows introduced the WoW64 subsystem, which performs a transpatent redirection … Read More “Defense in depth — the Microsoft way (part 96): yet another SAFER (SRPv1) and AppLocker (SRPv2) loophole  – Full Disclosure” »

JSON Deserialiser Unconstrained Resource Consumption Quick Overview  – Full Disclosure

Posted on March 12, 2026 By Joe-W
JSON Deserialiser Unconstrained Resource Consumption Quick	Overview  – Full Disclosure
Alert Feeds

  Posted by Daniel Owens via Fulldisclosure on Mar 12 As previously mentioned, via “Struts2 and Related Framework Array/Collection DoS” (26 October 2025), hundreds of JavaScript object notation (JSON) libraries are vulnerable to unconstrained resource consumption through large JSON arrays, which, when deserialised, create arbitrarily large collections/arrays/data structures. This work looks specifically at the Apache … Read More “JSON Deserialiser Unconstrained Resource Consumption Quick Overview  – Full Disclosure” »

Stryker attack highlights nebulous nature of Iranian cyber activity amid joint U.S.-Israel conflict  – CyberScoop

Posted on March 12, 2026 By Tim Starks
Stryker attack highlights nebulous nature of Iranian cyber activity amid joint U.S.-Israel conflict  – CyberScoop
Attack Feeds

A cyberattack that an Iranian hacking group said it carried out against medical device manufacturer Stryker might mark Tehran’s first significant cyber action since the start of the joint U.S.-Israel conflict. But even that may have been a happy accident for Iranian hackers in what has been a low buzz of activity during that timeframe, … Read More “Stryker attack highlights nebulous nature of Iranian cyber activity amid joint U.S.-Israel conflict  – CyberScoop” »

Feds Takes Down SocksEscort Proxy Network Used in Global Fraud Schemes  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on March 12, 2026 By Waqas
Feds Takes Down SocksEscort Proxy Network Used in Global Fraud Schemes  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

European and US agencies dismantled the SocksEscort proxy network built on infected routers and used by cybercriminals in global fraud schemes.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

Hive0163 Uses AI-Assisted Slopoly Malware for Persistent Access in Ransomware Attacks  – The Hacker News

Posted on March 12, 2026 By [email protected] (The Hacker News)
Hive0163 Uses AI-Assisted Slopoly Malware for Persistent Access in Ransomware Attacks  – The Hacker News
Attack Feeds

Cybersecurity researchers have disclosed details of a suspected artificial intelligence (AI)-generated malware codenamed Slopoly put to use by a financially motivated threat actor named Hive0163. “Although still relatively unspectacular, AI-generated malware such as Slopoly shows how easily threat actors can weaponize AI to develop new malware frameworks in a fraction of the time it used … Read More “Hive0163 Uses AI-Assisted Slopoly Malware for Persistent Access in Ransomware Attacks  – The Hacker News” »

Hackers Use Cloudflare Human Check to Hide Microsoft 365 Phishing Pages  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on March 12, 2026 By Deeba Ahmed
Hackers Use Cloudflare Human Check to Hide Microsoft 365 Phishing Pages  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

Scammers are hijacking popular security tools like Cloudflare to hide fake Microsoft 365 login pages. Learn how this new invisible phishing campaign bypasses antivirus software and how you can stay safe.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

Rust-Based VENON Malware Targets 33 Brazilian Banks with Credential-Stealing Overlays  – The Hacker News

Posted on March 12, 2026 By [email protected] (The Hacker News)
Rust-Based VENON Malware Targets 33 Brazilian Banks with Credential-Stealing Overlays  – The Hacker News
Attack Feeds

Cybersecurity researchers have disclosed details of a new banking malware targeting Brazilian users that’s written in Rust, marking a significant departure from other known Delphi-based malware families associated with the Latin American cybercrime ecosystem. The malware, which is designed to infect Windows systems and was first discovered last month, has been codenamed VENON by Brazilian  … Read More “Rust-Based VENON Malware Targets 33 Brazilian Banks with Credential-Stealing Overlays  – The Hacker News” »

Bell Ambulance Confirms Data Breach Affecting 237,830 Individuals  – Hackread – Cybersecurity News, Data Breaches, AI and More

Posted on March 12, 2026 By Waqas
Bell Ambulance Confirms Data Breach Affecting 237,830 Individuals  – Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds

Bell Ambulance disclosed a data breach impacting 237,830 individuals after unauthorized access to its network exposed personal and medical data.  – Read More  – Hackread – Cybersecurity News, Data Breaches, AI and More 

Posts pagination

Previous 1 … 27 28 29 … 40 Next
  • Attack Feeds
  • Privacy/Governance Feed
  • Gov/ISAC Feeds
  • Alert Feeds
  • Privacy Policy
  • Wagner Cybersecurity

Copyright © 2026 AttackFeed by Joe Wagner.

Theme: Oceanly News Dark by ScriptsTown

We are using cookies for analytics purposes only.  We do not store, track or sell user information.

You can find out more about which cookies we are using or switch them off in .

AttackFeed by Joe Wagner
Powered by  GDPR Cookie Compliance
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.