Skip to content
Trump Memo Paves Way for U.S. Firms to Hack and Disrupt Foreign Crime Groups

Trump Memo Paves Way for U.S. Firms to Hack and Disrupt Foreign Crime Groups

Ravie LakshmananAug 14, 2026Cybercrime / Offensive Operation A new White House memo signed by U.S. President Donald Trump has instructed the National Coordination Center (NCC) to establish a program that would allow private sector companies… 

China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud

China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud

The China-linked threat actor known as Jewelbug has been observed carrying out cyber espionage operations targeting governments and militaries, while simultaneously engaging in cryptocurrency fraud. “Both missions are administered from a single control panel, XG-Web,… 

GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE

GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE

A newly disclosed zero-day flaw in GeoServer is seeing active exploitation efforts, per watchTowr. The vulnerability, which has yet to be assigned a CVE identifier, is an SQL injection vulnerability in the open-source platform that… 

New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure

New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure

Afghan telecom providers and South Asian critical infrastructure organizations have emerged as the target of a new ongoing campaign that delivers a previously undocumented backdoor called PATCHCORD. According to Acronis Threat Research Unit (TRU), the… 

AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS

AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS

Cybersecurity researchers have disclosed details of a new macOS-oriented, Rust-based information stealer called AmnesiaStealer that’s capable of hijacking Chromium web browsers to steal session data. The multi-stage stealer is spread via a counterfeit GitHub download… 

WindRelay Android Malware Turns Victims’ Phones Into NFC Relays for Payment Fraud

WindRelay Android Malware Turns Victims’ Phones Into NFC Relays for Payment Fraud

Ravie LakshmananAug 13, 2026Malware / Mobile Security A previously unseen Android near field communication (NFC) relay malware family dubbed WindRelay is being deployed in conjunction with a known remote access trojan (RAT) called SpyNote as… 

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

Ravie LakshmananAug 13, 2026Vulnerability / Enterprise Security Threat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) code. The vulnerability in question is CVE-2026-55040 (CVSS score:… 

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

Ravie LakshmananAug 12, 2026Vulnerability / Cyber Espionage The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a…