Skip to content
Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal 8M

Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M

Swati KhandelwalSep 28, 2026Vulnerability / Cybercrime The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday.… 

RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims

RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims

RatHat’s operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April 2026. It said this… 

7M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats

$387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats

Ravie LakshmananSep 28, 2026Cybersecurity News / Hacking A domain used as harmless placeholder text showed up in roughly 1,700 repositories. Then somebody registered it and started serving malicious lures. That is the kind of week… 

Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent

Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent

Cybersecurity researchers have disclosed details of a new botnet malware called Carbonato that’s targeting exposed Docker daemons to deploy an open-source artificial intelligence (AI) agent framework called Hermes Agent. “The implant installs the framework unchanged,… 

JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources

JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources

The threat actor known as JADEPUFFER has been observed orchestrating destructive actions within a Microsoft Azure environment using compromised service principals. Microsoft, which is tracking the activity under the name Storm-3168, has called it an… 

CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally

CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally

Ravie LakshmananSep 28, 2026Vulnerability / Network Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Sunday added two critical Citrix NetScaler ADC and Gateway flaws to its Known Exploited Vulnerabilities (KEV) catalog, following reports… 

Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation

Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation

Swati KhandelwalSep 27, 2026Vulnerability / Network Security Two new unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances that allow remote code execution are being actively exploited in the wild, security firm watchTowr…