Cybersecurity
Latest news, analysis, and updates in cybersecurity.

18 Severe Flaws Push Chrome 149 Update Into a Must-Do
Chrome 149 fixes 18 severe vulnerabilities, including four critical bugs. No active exploits are flagged, but the patch shouldn't wait.

Fake OpenAI Invites Lure Security Staff into ChatGPT Trap
Attackers are using real OpenAI invite emails to lure security staff into fake ChatGPT workspaces built for data theft.

Clean GitHub Repo Tricks AI Coding Agents Into Malware
A clean GitHub repo can trick AI coding agents into fixing setup errors that execute malware and open a reverse shell.

Gaslight macOS Malware Tricks the AI Tools Hunting It
Gaslight hides fake errors in a Rust binary to mislead AI analysis tools before defenders understand what the macOS malware does.

Russian Hackers Turn Jaguar Land Rover Hack Into $2.5B Hit
Russian hackers were reportedly tied to a Jaguar Land Rover breach that cost the U.K. economy $2.5B and forced a bailout.

Fake Receipts Hijack Shop App in Callback Phishing Trap
Scammers are planting fake receipts inside Shop, turning trusted order histories into phone scam bait.

StockStay Backdoor Lets Turla Haunt Ukraine Networks
Turla’s StockStay backdoor is built for quiet persistence inside Ukrainian government and military networks, not noisy disruption.

Self-Destructing Mistic Backdoor Hides Ransomware Footholds
Mistic runs payloads in memory, then erases itself, giving suspected access brokers cleaner footholds for ransomware crews.

Dissident iPhone Cracks Cellebrite Russia Cutoff Claim
Researchers say Cellebrite tools unlocked a Russian dissident's iPhone weeks after the company claimed it cut off Russia.

Edgecution Malware Hijacks Edge to Open a Backdoor
Edgecution turned Microsoft Edge’s Native Messaging into a relay to a Python backdoor after a fake Teams IT support lure.

$600K DraftKings Hacker Snoopy Draws 18 Months in Prison
Nathan Austad, alias Snoopy, got 18 months for a DraftKings credential-stuffing scheme that stole $600K from 1,600 accounts.

Rogue Root Account Exposes Cisco SD-WAN Zero-Day Hack
Mandiant says attackers used CVE-2026-20245 to plant a rogue root account on Cisco SD-WAN devices.