A major security incident has struck the npm ecosystem: the package @7nohe/openapi-react-query-codegen, downloaded over 150,000 times per week, is being used as a channel for […]
Month: August 2026
Fire Ant Affects Cisco Routers to Steal Credentials, Erases Logs
Fire Ant, a cyber espionage group with ties to China, has escalated its operations by compromising Cisco IOS XR routers, TACACS servers, and Linux management […]
Microsoft Acknowledges False Defender “Turned Off” Alerts Bug Across Windows Devices
Microsoft has confirmed that warnings claiming its built-in antivirus protection—Microsoft Defender—has been turned off are triggering incorrectly on many Windows systems. The company insists this […]
DoJ Revises Statement on China Cyber Ops: Agencies Were Targets, Not Confirmed Victims
The U.S. Department of Justice has modified a recent public statement regarding alleged cyber intrusions by a Chinese-linked hacking group known as QTFY (also referred […]
Composer Flaw Lets Packages Alter SSH Keys, Expose Sensitive Files
A serious vulnerability has been discovered in Composer, the popular PHP dependency manager, that could allow malicious or hijacked packages to change permissions on files […]
Microsoft UFO Vulnerability Exposes Android Devices to Remote Control
Microsoft has patched a vulnerability in its open-source UFO automation framework that allowed unauthenticated attackers to view and control Android devices remotely. The flaw, tracked […]
OpenClaw 2.0 Overhauls Agent Security with Harder Credential Protections
OpenClaw has shipped its most significant update yet—version 2026.8.1 (aka OpenClaw 2.0)—featuring sweeping security enhancements aimed at AI agents, plugins, credentials, and enterprise workflows. Built […]
Ethereum Testnet Abuse: How ‘HexMage’ Stole Credit Cards from Legit E-Commerce Sites
Starting around April 2026, hackers launched a sophisticated campaign targeting more than 40 online merchant sites in at least 15 countries, using a novel blend […]
Gryxa Malware Uses AI to Restore Itself and Spy on Cleanup Efforts
A newly uncovered Windows malware strain named Gryxa is pushing cybercriminal innovation to new heights. It not only steals credentials from Chromium-based browsers but is […]
Attackers’ Malware Backfires: Blind Eagle RAT Infrastructure Revealed
An unexpected malware infection has thrown hackers into the spotlight, exposing tools, infrastructure, and phishing materials connected to a Blind Eagle-linked campaign targeting Colombia. The […]