New Manic Android malware can exfiltrate data through nearby devices

New Manic Android malware can exfiltrate data through nearby devices

A new Android malware named Manic targeting users in multiple European countries has a fallback mechanism for exfiltrating data through nearby infected devices. The malware has been active since at least February and combines spyware, banking fraud, and remote control capabilities. It targets at least 169 banking, government/eID, payment, crypto

Read More »
Critical Elementor Pro bug exposes WordPress sites to RCE attacks

Critical Elementor Pro bug exposes WordPress sites to RCE attacks

A critical vulnerability in the Elementor Pro WordPress plugin could allow attackers to upload executable files for remote code execution on the server. Identified as CVE-2026-32475, the flaw affects Elementor Pro versions before 4.2.2 and stems from the File Upload module, which uses separate loops for file validation and processing

Read More »
ClickFix attack pushes macOS infostealer for crypto theft attacks

ClickFix attack pushes macOS infostealer for crypto theft attacks

A Go-based malware delivered in ClickFix attacks targeting macOS users is stealing cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials. ​The malware can intercept and redirect transactions with various cryptocurrencies. Although it can empty wallets entirely, it can also calculate the total value of a transaction to determine

Read More »
Swiss government SharePoint breach compromised 200 accounts

Swiss government SharePoint breach compromised 200 accounts

Switzerland’s federal IT office says hackers exploited vulnerabilities to breach its Microsoft SharePoint servers and compromised approximately 200 accounts. The Federal Office for Information Technology and Telecommunication (BIT) detected the cyberattack after security specialists noticed unusual activity on its SharePoint servers on July 28. After confirming the breach, BIT blocked

Read More »
How AI Exposed a Browser Security Gap that Enterprises Cannot Ignore

How AI Exposed a Browser Security Gap that Enterprises Cannot Ignore

For decades, enterprise security was largely focused on endpoints and networks. By protecting corporate end-user devices, establishing secure connectivity, and controlling access to on-premises resources, teams could effectively keep their centralized servers secure from intrusion. Eventually, these priorities evolved as enterprises embraced software-as-a-service (SaaS) models and cloud services, shifting to

Read More »
Canadian pleads guilty to Snowflake cloud data-theft attacks

Canadian pleads guilty to Snowflake cloud data-theft attacks

A Canadian man pleaded guilty today to his role in accessing company accounts at cloud storage provider Snowflake and stealing data from at least 165 organizations in a scheme to extort millions of dollars from victims. ​26-year-old Connor Riley Moucka, also known as Alexander Moucka and Waifu, was arrested on

Read More »
Man gets six years for hacking 750 women's Snapchat accounts

Man gets six years for hacking 750 women’s Snapchat accounts

An Illinois man was sentenced on Tuesday to 76 months in prison and three years of supervised release for hacking the Snapchat accounts of over 750 women to steal nude photos, which he later traded or sold online. After being charged in December, 26-year-old defendant Kyle Svara admitted in February

Read More »