A new modular Linux botnet family based on publicly leaked source code from the Mirai botnet has been linked to exploitation attempts for several vulnerabilities in edge devices. A Taiwan-based security researcher at Fortinet’s FortiGuard Labs, Yi Ping (Cara) Lin,… Read More "New Mirai-Based Linux Botnet ‘Evooo1Bot’ Turns Victims Into Proxies"
23 Million User Records Compromised in Gyazo Data Breach
Japanese software company Helpfeel is notifying users of its Gyazo image-sharing service that hackers have accessed their information. Gyazo is a widely used cross-platform tool that lets users capture screenshots, GIFs, or short screen recordings and instantly generate shareable links.… Read More "23 Million User Records Compromised in Gyazo Data Breach "
Researchers Confirm ExfilSquad’s Access to Sensitive Data
New analysis of the ExfilSquad data extortion group has tied it to leaked data from at least 13 victims from sectors including government, education, financial services and manufacturing. Fortra Intelligence and Research Experts (FIRE) have reviewed data samples made public… Read More "Researchers Confirm ExfilSquad’s Access to Sensitive Data"
Microsoft Patches 18 Vulnerabilities in AI, Cloud Products
Microsoft released patches for 18 vulnerabilities on Thursday, spanning its Azure cloud portfolio and Copilot-branded AI products. Elevation of privilege flaws made up the bulk of the disclosures, affecting Azure ARC, Azure AI Foundry, Azure Logic Apps, Azure Billing, Azure… Read More "Microsoft Patches 18 Vulnerabilities in AI, Cloud Products"
WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage
Ravie LakshmananSep 18, 2026Malware / Web Security Cybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit. The new malware family, per OpenSourceMalware, exhibits functional overlaps with… Read More "WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage"
CISA Upgrades Vulnerability Reporting Platform with More Automation
The US Cybersecurity and Infrastructure Security Agency (CISA) has upgraded its vulnerability reporting and coordination platform to allow for more automation and streamlined processes, as well as new built-in tools that vulnerability researchers can use. Since 2020, CISA has been… Read More "CISA Upgrades Vulnerability Reporting Platform with More Automation"
Essential Components of an Effective TPRM Policy
Any organization that relies on third-party vendors for critical business functions should develop and maintain an effective third-party risk management (TPRM) policy. A TPRM policy is the first document an organization should create when establishing its TPRM program. TPRM policies… Read More "Essential Components of an Effective TPRM Policy"
NightmareStresser DDoS Service Disrupted in International Operation
NightmareStresser, one of the longest-running distributed denial-of-service (DDoS) for-hire services in the world, has been disrupted. The US Department of Justice announced this week that the FBI has seized the internet domains associated with the booter service. Visitors to nightmare-stresser[.]com… Read More "NightmareStresser DDoS Service Disrupted in International Operation"
Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer
Ravie LakshmananSep 18, 2026Malware / Cybercrime A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the npm package registry. “The developer likely wrote the malware using… Read More "Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer"
Infostealers Harvest 1.7 Billion Credentials in Six Months
Security researchers recorded 7.4 million devices infected with infostealer malware in the first half of 2026, a 27% increase from the previous six months, according to Flashpoint data. The threat intelligence company revealed the news in its 2026 Global Threat… Read More "Infostealers Harvest 1.7 Billion Credentials in Six Months"