China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
Group-IB found the server in mid-April 2026 in Alibaba Cloud’s Singapore region; it was offline by the time the report
CISA, NSA, FBI and Partners Warn Zimbra Collaboration Suite Users of Ongoing Russian State-Supported Malicious Threat Activity
How Synthetic Identity Fraud is Coming for Machine Identities
New RefluXFS Linux flaw lets attackers gain root privileges
Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers
The activity involves malicious Packagist development versions spanning 10 packages associated with a legitimate PHP and DevOps developer, dinushchathurya, between July 12 and 13,
Upbound Group Says Data Breach Led to $13 Million in Fraudulent Contract Losses
Hackers recently obtained non-sensitive customer information and other documents from the company.
The post Upbound Group Says Data Breach Led to $13 Million in Fraudulent Contract Losses appeared first on SecurityWeek.
Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts
The selfie for sign-in, per the tech giant, is another option on top of existing recovery methods to log in to an account, including an email address or a phone number. The idea is to use a video selfie as a way to regain access if a user ever gets locked out or doesn’t have access
New msaRAT malware uses Chrome, Edge browsers to route C2 traffic
Assaf Keren Appointed New CISO of Meta
He replaces Guy Rosen, who announced his retirement from the company after 13 years.
The post Assaf Keren Appointed New CISO of Meta appeared first on SecurityWeek.
