The ClickFix social engineering technique has become the leading means of cybercriminals delivering malware to victims. According to analysis by researchers at ReliaQuest, which examined cyber-attacks taking place between March 1 and May 31, 2026, ClickFix dominated malware delivery. ClickFix… Read More "ClickFix Now Cybercriminals’ Favorite Malware Delivery Technique"
Critical SimpleHelp Vulnerability Exploited For Malware Delivery
A critical authentication bypass in SimpleHelp’s remote monitoring and management (RMM) software has been exploited to deliver two previously unseen malware families, after attackers forged a login token to seize control of a managed network. New analysis from security firm… Read More "Critical SimpleHelp Vulnerability Exploited For Malware Delivery"
Nissan Discloses Employee Data Breach Linked to Oracle Zero-Day
Nissan has disclosed that current and former employees may have had sensitive personal data stolen, including Social Security numbers, banking details and tax records, after attackers exploited a zero-day flaw in Oracle’s PeopleSoft software. The carmaker said in a breach… Read More "Nissan Discloses Employee Data Breach Linked to Oracle Zero-Day"
Insurance Giant Aflac Discloses Data Breach Impacting Millions
US insurer Aflac has disclosed a major data breach after hackers managed to access highly sensitive personal and financial information. The company’s Aflac Japan subsidiary discovered the intrusion on June 25, it said in a filing with the SEC yesterday… Read More "Insurance Giant Aflac Discloses Data Breach Impacting Millions"
China-Linked APT Expands Proxy Network With New Malware
A China-linked hacking group has been observed expanding a network of hijacked devices used to disguise cyber-attacks, arming it with several newly discovered pieces of custom malware, researchers have found. Cisco Talos said the actor, an advanced persistent threat (APT)… Read More "China-Linked APT Expands Proxy Network With New Malware"
RedWing Android Spyware Sold as a Service on Telegram
A new Android spyware strain has been observed being rented out to criminals through Telegram, giving even low-skilled attackers the tools to hijack phones and steal banking credentials, researchers have found. Zimperium’s zLabs named the malware RedWing and described it… Read More "RedWing Android Spyware Sold as a Service on Telegram"
Cybercriminals Plant Malicious AI Agents in Open Source Tools
Cybercriminals are increasingly turning to AI agents and chatbots to autonomously plan and carry out cyber-attacks, according to new analysis of hacker activity. Cybersecurity researchers at ESET examined 900,000 AI skills, small functional components used by AI agents, listed in… Read More "Cybercriminals Plant Malicious AI Agents in Open Source Tools"
New AI Security Charter Backed by Over 70 Cyber Firms
Over 70 cybersecurity organizations have signed a new charter, vowing a responsible use of AI for cybersecurity purposes. The AI Charter, launched by cyber industry body CREST on July 9, is built around nine principles for AI-enabled cybersecurity activities that… Read More "New AI Security Charter Backed by Over 70 Cyber Firms"
GhostApproval Flaw Hits Six Major AI Coding Assistants
Six major AI coding assistants have been found to share a flaw that turns their approval prompts into a rubber stamp, letting a malicious repository write to sensitive files on a developer’s machine and, in the worst case, achieve remote… Read More "GhostApproval Flaw Hits Six Major AI Coding Assistants"
NHS Warns Staff Over Unauthorized Access to Patient Data
Britain’s health service has warned staff that they could face jail time if found guilty of accessing patient data without a legitimate reason. Head of the NHS, Jim Mackey, said inappropriate access of medical records was “wholly unacceptable, a disgraceful… Read More "NHS Warns Staff Over Unauthorized Access to Patient Data"