Skip to content
CTM360 Uncovers Over 3,000 Recruitment Phishing URLs Using Browser-in-the-Browser (BitB) Credential Traps

CTM360 Uncovers Over 3,000 Recruitment Phishing URLs Using Browser-in-the-Browser (BitB) Credential Traps

Cybersecurity researchers have uncovered a large-scale, global recruitment-themed phishing campaign that uses fake interview scheduling pages and Browser-in-the-Browser (BitB) windows to steal Google and Facebook credentials and, in more advanced cases, relay multi-factor authentication (MFA)… 

Apple Warns Users in 110 Countries They May Be Targets of Mercenary Spyware

Apple Warns Users in 110 Countries They May Be Targets of Mercenary Spyware

Ravie LakshmananAug 14, 2026Spyware / Cyber Espionage Apple on Thursday sent a fresh batch of notifications to customers whom it suspects may have been targeted by mercenary spyware attacks. In a statement shared with TechCrunch,… 

Trump Memo Paves Way for U.S. Firms to Hack and Disrupt Foreign Crime Groups

Trump Memo Paves Way for U.S. Firms to Hack and Disrupt Foreign Crime Groups

Ravie LakshmananAug 14, 2026Cybercrime / Offensive Operation A new White House memo signed by U.S. President Donald Trump has instructed the National Coordination Center (NCC) to establish a program that would allow private sector companies… 

China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud

China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud

The China-linked threat actor known as Jewelbug has been observed carrying out cyber espionage operations targeting governments and militaries, while simultaneously engaging in cryptocurrency fraud. “Both missions are administered from a single control panel, XG-Web,… 

GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE

GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE

A newly disclosed zero-day flaw in GeoServer is seeing active exploitation efforts, per watchTowr. The vulnerability, which has yet to be assigned a CVE identifier, is an SQL injection vulnerability in the open-source platform that… 

New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure

New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure

Afghan telecom providers and South Asian critical infrastructure organizations have emerged as the target of a new ongoing campaign that delivers a previously undocumented backdoor called PATCHCORD. According to Acronis Threat Research Unit (TRU), the… 

AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS

AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS

Cybersecurity researchers have disclosed details of a new macOS-oriented, Rust-based information stealer called AmnesiaStealer that’s capable of hijacking Chromium web browsers to steal session data. The multi-stage stealer is spread via a counterfeit GitHub download… 

WindRelay Android Malware Turns Victims’ Phones Into NFC Relays for Payment Fraud

WindRelay Android Malware Turns Victims’ Phones Into NFC Relays for Payment Fraud

Ravie LakshmananAug 13, 2026Malware / Mobile Security A previously unseen Android near field communication (NFC) relay malware family dubbed WindRelay is being deployed in conjunction with a known remote access trojan (RAT) called SpyNote as…