“We are launching an economic onslaught against Iran’s financial connections around the globe. Our objective is to sever every economic lifeline that sustains this tyrannical regime
Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
The vulnerability in question is CVE-2026-55040 (CVSS score: 9.1), which refers to a critical security feature bypass that stems from weak authentication. It was patched by Microsoft as part of its July 2026 Patch Tuesday updates.
“The authentication
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
The activity, per Check Point Research, is part of Operation Dream Job, a long-running cyber espionage and
Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
“Greatness supports AiTM [adversary-in-the-middle] credential and
18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users
One of the packages in question is “lib-mtop,” an unscoped package with the same name as a private Alibaba package
Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk
These targeted organizations operate across several sectors, such as healthcare, research, government offices,
New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
Every 6.9 and 7.0 site was in range until Friday, when WordPress shipped 6.9.5 and 7.0.2 and enabled what it calls forced updates through its auto-update system.
Adam Kues at Assetnote, Searchlight Cyber’s attack surface management arm, found the flaw and reported
Two Scattered Spider Hackers Get 5.5 Years Each for £29 Million TfL Hack
The attack left 148 TfL systems inoperable and forced all 27,000 of the transport authority’s employees into an office to get their passwords reset in person. Both the NCA and the CPS put TfL’s losses and recovery
U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case
The odd part: the group that took the money calls itself Kairos, but it may not be a ransomware gang at all. Krishnan found no sign that it ever locked a single
Ukraine Says Russian Intelligence Used Fake Support Texts to Steal Messaging Credentials
The systematic cyber attacks aimed at stealing sensitive
