Skip to content
Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control

Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control

The Hacker NewsSep 02, 2026Malvertising / Mobile Security Cybersecurity researchers have disclosed details of a new Android banking trojan called StreamRat that was promoted to Spanish-speaking users through a fake television-streaming campaign on Meta and… 

Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain

Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain

Ravie LakshmananSep 02, 2026Vulnerability / Network Security SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day attacks. The… 

GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends

GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends

Swati KhandelwalSep 02, 2026Vulnerability / Web Security Two vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog, which sits behind many government and agency geoportals.… 

Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands

Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands

Swati KhandelwalSep 02, 2026Malware / Cybercrime The U.S. Department of Justice (DoJ) has charged a Russian national, extradited from Cyprus on August 28, with using roughly 255 fake accounts on a freelance platform to send… 

Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another

Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another

Forescout Research – Vedere Labs said it used Anthropic’s Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another, executing attacker-supplied ARM shellcode on live… 

Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials

Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials

Ravie LakshmananSep 02, 2026Vulnerability / Network Security Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution. The vulnerability in question is CVE-2026-9586… 

Authorities Turn Sality’s P2P Network Against Itself, Cutting Off New Malware Payloads

Authorities Turn Sality’s P2P Network Against Itself, Cutting Off New Malware Payloads

The U.S. Department of Justice (DoJ) on Tuesday announced the takedown of a long-standing peer-to-peer (P2P) botnet known as Sality as part of a coordinated law enforcement operation. The effort was undertaken on August 31,… 

Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure

Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure

Ravie LakshmananSep 01, 2026Vulnerability / Supply Chain Attack Threat actors are exploiting a newly patched critical security flaw impacting JFrog Artifactory merely days after public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-82329… 

Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems

Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems

Ravie LakshmananSep 01, 2026Cybercrime / Malware Brazilian financial services, retail, and e-commerce organizations have become the target of a financially motivated threat actor dubbed Breeze Comet (formerly UNC5669) since 2024. Google Threat Intelligence Group (GTIG)…