Chinese hackers develop LONGLEASH malware to expand ORB network
County Government Reportedly Paid $1 Million to Cyber Extortion Group
The alleged victim, believed to be a small Ohio county, reportedly paid the extortion group to prevent the public release of sensitive stolen data.
The post County Government Reportedly Paid $1 Million to Cyber Extortion Group appeared first on SecurityWeek.
Hidden backdoor in Tenda router firmware grants admin access
Critical Gitea Flaw Under Active Exploitation, Researchers Warn
Attackers are exploiting the critical Gitea vulnerability CVE-2026-20896 to bypass authentication with a single HTTP header and access vulnerable repositories and secrets.
The post Critical Gitea Flaw Under Active Exploitation, Researchers Warn appeared first on SecurityWeek.
RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service
Zimperium’s zLabs, which found the operation, says it looks like a new variant of Oblivion, a $300-a-month rent-a-malware tool
Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots
From there, they could read live conversations, steal the data users shared, and make the bots send attacker-written messages, including requests to re-enter a password.
Security firm Varonis found it
Spain arrests suspected member of pro-Russian hacktivist groups
DEBULL Tooling Abuses Microsoft Device-Code Flow to Target M365 Accounts
“The campaign did not depend on a fake Microsoft password page. It used a malicious collaboration-style lure to push users into the legitimate Microsoft device login experience,
Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data
The attacker needs only to open a normal-looking issue on a public repository, with no stolen credentials and no access to the organization. If that organization has given the agent read access across its repositories, private ones
