Security news

Latest security news

Tue, 11 Aug 2026

  1. Kimwolf v7: An Evolution of the Kimwolf Botnet

    Discover how Kimwolf v7 targets Android IoT devices with HTTP/2 DDoS fingerprinting, Ethereum ENS C2 resolution and Tor backup routing.

    Unit 42Android

Mon, 10 Aug 2026

  1. The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications

    Analysis of the Aeternum botnet loader, a threat leveraging Polygon blockchain smart contracts for decentralized C2 infrastructure and payload execution.

    Unit 42
  2. 10th August – Threat Intelligence Report

    For the latest discoveries in cyber research for the week of 10th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES North Carolina Ports, the US authority operating the ports of Wilmington, Morehead City and others, has suffered a cyberattack that forced some operations onto manual processes. The authority claims it has contained

    Check Point Research

Fri, 7 Aug 2026

  1. Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)

    Overview On July 27, 2026, JetBrains published a security advisory for CVE-2026-63077 , a critical unsafe deserialization vulnerability affecting JetBrains TeamCity . An attacker who can reach a TeamCity server over HTTP or HTTPS can exploit the agent polling protocol without credentials and execute operating system commands with the privileges of the TeamCity server process. JetBrains reported no known active exploitation when it disclosed the vulnerability. However, on August 5, 2026, CISA added CVE-2026-63077 to its Known Exploited Vulnerabilities (KEV) catalog, confirming exploitation in the wild. Our analysis finds that a vulnerable TeamCity server creates a permissive XStream allowlist. This allowlist is intended to restrict which Java classes can be deserialized when servicing unauthenticated agent requests. However, this allowlist incorrectly adds TeamCity protocol classes without removing XStream's existing default permissions. This introduces an unsafe deserialization issue. A patched TeamCity server remediates this by adding NoTypePermission.NONE before the TeamCity allowlist, which removes the default permissions and makes the allowlist exclusive. Rapid7 Labs has verifi

    CriticalUsed in attacksRapid7 BlogJetBrains
  2. Google Links Redact Extortion Group to BlackFile Rebrand

    BlackFile has rebranded as Redact after an alleged affiliate hijack, with Google linking the group to ongoing vishing and extortion campaigns

    Infosecurity MagazineGoogle

Thu, 6 Aug 2026

  1. ChainDrop: Inside a Self-Propagating npm Worm

    Analysis of ChainDrop, an npm supply chain worm extracting GitHub Actions runner secrets and using Ethereum smart contracts for C2 routing.

    Unit 42GitHub
  2. Canadian Man Pleads Guilty in Snowflake Extortions

    A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage provider Snowflake. Connor Riley Moucka, of Kitchener, Ontario, also admitted to stealing call and text history records of more than 100 million AT&T customers.

    Krebs on Security
  3. Canadian Hacker Pleads Guilty Over Snowflake Extortion Campaign

    A Canadian hacker has admitted involvement in the widespread compromise of 165 Snowflake customer accounts used to steal data and extort victims

    Infosecurity Magazine

Wed, 5 Aug 2026

  1. Fake Bank of America Phishing Scam Installs Remote Access Malware

    Cybercriminals are using a fake Bank of America phishing campaign to trick users into downloading a malicious script that installs ScreenConnect, enabling remote access and persistence on compromised systems

    Infosecurity Magazine

Tue, 4 Aug 2026

  1. Cloud and SaaS Environments Now Top Targets for Attackers

    Cloud and SaaS are now the preferred operating environments for threat actors, amid a continued shift to identity attacks

    Infosecurity Magazine

About this news

1,259
Stories
34
Added in the last 24 hours
17
Critical in the last 7 days
4
Reported by several outlets