Cybersecurity
Latest news, analysis, and updates in cybersecurity.

Russian Hackers Turn Jaguar Land Rover Hack Into $2.5B Hit
Russian hackers were reportedly tied to a Jaguar Land Rover breach that cost the U.K. economy $2.5B and forced a bailout.

Fake Receipts Hijack Shop App in Callback Phishing Trap
Scammers are planting fake receipts inside Shop, turning trusted order histories into phone scam bait.

StockStay Backdoor Lets Turla Haunt Ukraine Networks
Turla’s StockStay backdoor is built for quiet persistence inside Ukrainian government and military networks, not noisy disruption.

Self-Destructing Mistic Backdoor Hides Ransomware Footholds
Mistic runs payloads in memory, then erases itself, giving suspected access brokers cleaner footholds for ransomware crews.

Dissident iPhone Cracks Cellebrite Russia Cutoff Claim
Researchers say Cellebrite tools unlocked a Russian dissident's iPhone weeks after the company claimed it cut off Russia.

Edgecution Malware Hijacks Edge to Open a Backdoor
Edgecution turned Microsoft Edge’s Native Messaging into a relay to a Python backdoor after a fake Teams IT support lure.

$600K DraftKings Hacker Snoopy Draws 18 Months in Prison
Nathan Austad, alias Snoopy, got 18 months for a DraftKings credential-stuffing scheme that stole $600K from 1,600 accounts.

Rogue Root Account Exposes Cisco SD-WAN Zero-Day Hack
Mandiant says attackers used CVE-2026-20245 to plant a rogue root account on Cisco SD-WAN devices.

Riot Vanguard Sheds Always-On Grip for Some Players
Riot Vanguard can go on-demand for eligible players, but only 35% qualify without changing PC security settings.

Cisco Unified CM Flaw Now Hands Attackers a Root Path
CVE-2026-20230 is now being exploited, pushing Cisco Unified CM teams from routine patching to active compromise checks.

1.4 Million Exposed as Xsolis Data Breach Leaks SSNs
A phishing attack at Xsolis exposed sensitive health and identity data for nearly 1.4 million people.

Fake CAPTCHA Turns macOS ClickFix Attack Into Mac Heist
A fake CAPTCHA pushes Mac users into Terminal, launching AMOS to steal browser, wallet, Keychain and app data.