Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows
According to ANY.RUN research, 48% of targeted email addresses were potentially compromised. Most of the affected companies are US-based.
Mirage2FA Campaign
24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages
“While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn’t do harm, the threat actor’s use of npm isn’t to infect developers who install it, but to use the
E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands
While threat actors are known to abuse legitimate services to point to additional command-and-control (C2) infrastructure and blend in with regular network traffic, the development
First Malware Built Specifically for Car Head Units Fuels Botnet
Kaspersky researchers have linked the malware to the BadBox botnet, which has ensnared millions of devices.
The post First Malware Built Specifically for Car Head Units Fuels Botnet appeared first on SecurityWeek.
Frontier AI: Vulnerability Management’s Systemic Revolution
Police arrests dozens of suspects in global cybercrime crackdown
Silent Patches Don’t Stop Attackers—They Blind Defenders
Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk.
The post Silent Patches Don’t Stop Attackers—They Blind Defenders appeared first on SecurityWeek.
Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access
The vulnerabilities, as disclosed by Patchstack, are listed below –
CVE-2026-61979 (CVSS score: 8.1) – An unauthenticated privilege escalation
Taiwan Charges 9 Over Illegal AI Server Exports to China, Including Nvidia and Super Micro Staff
AI infrastructure, including advanced semiconductors mostly made in Taiwan, has become a key point of competition between the U.S. and China.
The post Taiwan Charges 9 Over Illegal AI Server Exports to China, Including Nvidia and Super Micro Staff appeared first on SecurityWeek.
