Security researchers have confirmed active attacks targeting Cisco CVE-2026-20230, a high-severity vulnerability affecting Cisco Unified Communications Manager (Unified CM) and Unified Communications Manager Session Management Edition (Unified CM SME). Cisco disclosed the flaw earlier this month and warned that attackers could ultimately gain root-level access to vulnerable systems. The confirmation of real-world exploitation increases the…
The JaredFromSubway hack has resulted in nearly $15 million in losses after attackers compromised infrastructure linked to one of Ethereum’s most successful MEV operations. Researchers say the incident allowed threat actors to intercept profits that would normally have gone to the bot’s operator. The attack did not target Ethereum itself. Instead, it focused on systems…
Microsoft has linked the recent Mastra supply chain attack to Sapphire Sleet, a North Korean threat group also known as BlueNoroff. The campaign compromised more than 140 npm packages after attackers hijacked a maintainer account and inserted malicious code into trusted software updates. The incident affected the Mastra AI ecosystem and exposed developers to malware…
Security researchers have uncovered a cryptocurrency-stealing malware campaign that spreads through infected USB drives and malicious Windows shortcut files. The operation targets cryptocurrency users by monitoring clipboard activity and replacing wallet addresses before victims complete transactions. Microsoft researchers have tracked the campaign since February 2026. The malware combines worm-like propagation, clipboard theft, remote command execution,…
International law enforcement agencies have dismantled AudiA6, a cryptocurrency laundering service that allegedly helped cybercriminals move and conceal hundreds of millions of dollars in illicit funds. Authorities say the platform served as a key financial pipeline for ransomware operators and other criminal groups seeking to convert stolen cryptocurrency into assets that appeared legitimate. The operation…
Microsoft has finally patched three Windows zero-days that remained publicly exposed for months after a security researcher released technical details and proof-of-concept exploits online. The vulnerabilities, known as YellowKey, GreenPlasma, and MiniPlasma, attracted significant attention because they affected fully updated systems and exposed weaknesses in core Windows components. The fixes arrived as part of Microsoft’s…
A compromised update for Hola Browser exposed Windows users to a cryptocurrency mining malware campaign after attackers tampered with an official software package. Researchers discovered that threat actors inserted a cryptominer into a Hola Browser installation file distributed to users. Because the malware arrived through a legitimate software update channel, affected users had little reason…
The United States has imposed sanctions on Nobitex, Iran’s largest cryptocurrency exchange, accusing the platform of helping ransomware operators, sanctioned organizations, and other illicit actors move digital assets. The Treasury Department described Nobitex as a key part of Iran’s cryptocurrency ecosystem and alleged that the exchange processed transactions for groups already under US sanctions. The…
Microsoft has unveiled its first AI agent powered by OpenClaw, the open-source platform that has rapidly become one of the most influential projects in the emerging agentic AI market. Called Scout, the new assistant can schedule meetings, manage tasks, and work across Microsoft 365 applications, desktop environments, and the web. The announcement came during Microsoft’s…
An anonymous cryptocurrency wallet permanently destroyed 107 bitcoins after sending the funds to a burn address that nobody can access. The unusual transfer quickly attracted attention across the crypto industry because the assets can never be recovered. At current market prices, the destroyed bitcoin was worth millions of dollars. Blockchain researchers continue investigating the transfer,…