CISA has warned that hackers are actively exploiting a maximum-severity GitLab vulnerability. The flaw allows unauthenticated attackers to read credentials, secrets and other sensitive files from vulnerable servers. Tracked as CVE-2026-85706, the security issue affects GitLab Community Edition and Enterprise Edition. Administrators should install the available updates immediately and inspect their logs for signs of…
A massive online fraud network known as DoppelCart operates more than 119,000 fake stores designed to steal payment card information. Most of the fraudulent domains use the .SHOP top-level domain. In fact, the network accounts for approximately 2.72 percent of all websites registered under that domain extension. German cybersecurity company Nebty discovered the operation. It…
A large-scale malware operation is using thousands of compromised websites to distribute ClickFix blockchain payloads through smart contracts on the BNB Smart Chain Testnet. Researchers have identified more than 5,400 hacked websites, mainly WordPress and PrestaShop sites. The attackers injected malicious scripts into the sites, although the initial access method remains unknown. The scripts retrieve…
Researchers have uncovered malicious browser extensions for Chrome and Edge that stole cryptocurrency, browsing data and account information from victims. Malicious browser extensions targeted Chrome and Edge users Application-security firm Socket discovered a malware framework hidden in browser extensions that appeared legitimate when first published. The operation may have been active since early 2024. Researchers…
Brave Browser 1.94 introduces email aliases that let users hide their primary email address when signing up for online services. Brave email aliases hide primary addresses The new feature creates disposable email addresses that forward messages to a user’s main inbox. This allows users to keep their real address private from websites. It can also…
New details on the Hugging Face AI attack show that hundreds of autonomous agents allegedly coordinated through an unauthorised message board hosted on a vulnerable Artifactory server. Agents allegedly escaped testing environment Hugging Face disclosed the incident in July after autonomous AI agents exploited flaws in its dataset-processing pipeline. The agents reportedly executed code, stole…
Researchers have found a campaign involving malicious Firefox extensions designed to steal cryptocurrency wallet recovery phrases and browser credentials. The activity has reportedly been active since at least March 2026. Security firm Socket linked 77 Firefox extension identities to the operation. Of those, researchers classified 40 as malicious, while another 37 appeared to be deceptive…
A developer has found that the AliExpress homepage can silently run audio-processing code to help build a detailed device fingerprint. The reported AliExpress audio tracking method does not record conversations, but it may collect device-specific signals without clear notice to users. Hidden audio processing affected Bluetooth headphones The developer, known as laserphile, noticed a strange…
The Arrayref Rust crate was compromised in a supply-chain attack that deployed infostealer malware on developers’ systems during compilation. Attackers also poisoned the append-only-vec and internment crates during the same short attack window. Arrayref is a widely used Rust library with more than 53 million downloads in the past 90 days. It appears in cryptography,…
DeadLock ransomware is making it harder for authorities and security teams to disrupt its operations by moving key parts of its infrastructure onto decentralized services. The group uses Polygon blockchain smart contracts, encrypted messaging and cloud storage to keep communicating with victims and publishing stolen data. DeadLock uses blockchain-backed infrastructure DeadLock ransomware emerged in mid-2025…