Nintendo confirms data stolen in WebMD subsidiary cyberattack
F5 Patches Two Critical NGINX Open Source Flaws Enabling Remote Code Execution
The vulnerabilities are listed below –
CVE-2026-42530 (CVSS v4 score: 9.2) – A use-after-free vulnerability in the ngx_http_v3_module that could be triggered by a remote unauthenticated attacker when NGINX Open Source is
Majority of Internet-Accessible REDCap Servers Outdated
These servers are regularly targeted by China-linked UNC6508 for initial access and backdoor deployment.
The post Majority of Internet-Accessible REDCap Servers Outdated appeared first on SecurityWeek.
USB worm spreads crypto-stealing malware via Windows shortcut files
Microsoft Details Windows Clipper Malware Campaign Using USB LNK Worm and Tor-Based C2
“The clipper in this campaign relies on Windows Script Host and ActiveX-driven logic to launch a bundled Tor proxy and poll a hidden-service C2 [command-and-control] server,” the Microsoft Defender Security Research Team said in an analysis published Tuesday. “It
Klue OAuth breach linked to ‘Icarus’ Salesforce data theft attacks
INC Ransomware Emerges as Major RaaS Threat in 2026 with 830+ Victims Since 2023
“The disruption of LockBit and the shutdown of BlackCat created opportunities for INC to expand as affiliates migrated to alternative ransomware operations,” Acronis
5 reasons Microsoft 365 backup isn’t enough for business data protection
DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic
According to findings from Broadcom-owned Symantec and Carbon Black, the backdoor was deployed against a major U.S. services firm. The name of the company was
