“Greatness supports AiTM [adversary-in-the-middle] credential and
18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users
One of the packages in question is “lib-mtop,” an unscoped package with the same name as a private Alibaba package
Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk
These targeted organizations operate across several sectors, such as healthcare, research, government offices,
New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
Every 6.9 and 7.0 site was in range until Friday, when WordPress shipped 6.9.5 and 7.0.2 and enabled what it calls forced updates through its auto-update system.
Adam Kues at Assetnote, Searchlight Cyber’s attack surface management arm, found the flaw and reported
Two Scattered Spider Hackers Get 5.5 Years Each for £29 Million TfL Hack
The attack left 148 TfL systems inoperable and forced all 27,000 of the transport authority’s employees into an office to get their passwords reset in person. Both the NCA and the CPS put TfL’s losses and recovery
U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case
The odd part: the group that took the money calls itself Kairos, but it may not be a ransomware gang at all. Krishnan found no sign that it ever locked a single
Ukraine Says Russian Intelligence Used Fake Support Texts to Steal Messaging Credentials
The systematic cyber attacks aimed at stealing sensitive
FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation
The campaign, active since February 2026, involves collecting credential lists, searching for exposed services, brute-forcing accessible systems, and deploying bespoke
Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys
The vulnerability, tracked as CVE-2026-4020 (CVSS score: 5.3), is a medium-severity information disclosure flaw that can allow unauthenticated attackers to extract sensitive data, such as configuration data, API keys, secrets, and OAuth tokens
Unpatchable ‘usbliter8’ Exploit Breaks Apple A12 and A13 SecureROM Boot Chain
That code is burned into the silicon at manufacture. No software update can reach it. Affected devices will carry this flaw for as long as they stay in use.
This is not a remote attack. It requires
