Modern ransomware campaigns are rapidly evolving, and JadePuffer demonstrates just how significant that shift has become. Security researchers have identified what is believed to be the first documented ransomware attack orchestrated almost entirely by an autonomous AI agent, capable of…
A newly disclosed attack chain, dubbed SearchLeak, demonstrated how threat actors could transform Microsoft 365 Copilot Enterprise into a powerful one-click data exfiltration tool. By exploiting a sequence of vulnerabilities, attackers were able to extract sensitive corporate information from Microsoft…
The source code of Miasma, a sophisticated credential-stealing framework designed to compromise software supply chains, was recently exposed on GitHub through multiple compromised developer accounts. The incident offers a rare glimpse into how modern threat actors automate large-scale attacks against…
Threat actors exploited a critical zero-day vulnerability in KnowledgeDeliver to achieve unauthenticated remote code execution and deploy the Godzilla web shell, a powerful post-exploitation tool commonly used in advanced cyber intrusions. The vulnerability, tracked as CVE-2026-5426, stems from insecure ASP.NET…
The Russian-linked cyber-espionage group known as Secret Blizzard has significantly upgraded its long-running Kazuar malware framework, transforming it into a highly modular peer-to-peer (P2P) botnet optimized for stealth, persistence, and intelligence collection. The latest Kazuar variant introduces decentralized communications, internal…
Security researchers have disclosed a new Linux zero-day vulnerability chain dubbed Dirty Frag, a high-severity local privilege escalation exploit that allows attackers to obtain root access on most major Linux distributions using a single command. The exploit affects the Linux…
A sophisticated software supply-chain attack has compromised multiple versions of DAEMON Tools, resulting in the distribution of trojanized installers that deployed a stealth backdoor to thousands of devices worldwide. The malicious installers were reportedly distributed through the software’s official website…
A widely used WordPress plugin, Quick Page/Post Redirect, has been found to contain a long-standing backdoor capable of enabling arbitrary code execution on affected websites. The plugin, installed on over 70,000 sites, was temporarily removed from the official directory after…
A supply-chain attack has impacted the widely used PyPI package elementary-data, after attackers published a malicious release designed to steal developer secrets, cloud credentials, and cryptocurrency wallet data. The compromised version, 0.23.3, was distributed through both PyPI and the project’s…




