Application Security

ToxicPanda and GoldDigger Elevate Android Banking Threats
Endpoint & Device Security ToxicPanda and GoldDigger Elevate Android Banking Threats

Sophisticated malware strains like ToxicPanda 2.0 leverage Android Accessibility Services to see and act on behalf of the user during financial sessions. This shift marks a significant departure from historical data-stealing trojans that focused primarily on intercepting SMS messages or displaying

How Does SilkParasite Use Google Drive for Cyberespionage?
Infrastructure & Network Security How Does SilkParasite Use Google Drive for Cyberespionage?

The modular design of DriveSilkRAT enables it to poll Google Drive for specialized tools designed for file manipulation and network enumeration on demand. This advanced capability marks a significant shift in how state-sponsored actors maintain persistence while evading traditional security

Google Releases Chrome 151 to Patch Critical Security Flaws
Infrastructure & Network Security Google Releases Chrome 151 to Patch Critical Security Flaws

Security researchers identified a critical authorization flaw in the Workers framework that could compromise how the browser manages background script resources. This significant discovery highlights the growing complexity in web application architectures where background processes often operate

How Secure Is Your Password Manager Against Token Leakage?
Identity & Access Management How Secure Is Your Password Manager Against Token Leakage?

The insecure implementation of the window.postMessage mechanism in the Passportal extension highlights how internal communication channels can inadvertently expose sensitive authentication tokens to malicious websites. Cybersecurity professionals have long warned about the inherent risks associated

How Is StopAndProtect Hijacking WordPress for Crypto Theft?
Infrastructure & Network Security How Is StopAndProtect Hijacking WordPress for Crypto Theft?

Data recovered from exposed logs shows a high concentration of victims located in the United States and Russia who fell for deceptive identity verification prompts. This specific wave of attacks targets the administrative backend of WordPress websites, turning them into delivery vehicles for

Is Your Supply Chain Safe From the TeamCity Security Flaw?
Infrastructure & Network Security Is Your Supply Chain Safe From the TeamCity Security Flaw?

The Australian Cyber Security Centre is sounding an urgent alarm regarding CVE 2026-63077, a critical security flaw currently being weaponized against JetBrains TeamCity On-Premises servers. This vulnerability allows unauthenticated attackers to bypass security protocols, granting them

Loading

Subscribe to our weekly news digest.

Join now and become a part of our fast-growing community.

Invalid Email Address
Thanks for Subscribing!
We'll be sending you our best soon!
Something went wrong, please try again later