Ruflo MCP flaw: unauthenticated remote command execution
A critical Ruflo MCP flaw (CVE-2026-59726) lets attackers run commands without authentication. The impact includes API key theft and poisoning of persistent AI memory.
A critical Ruflo MCP flaw (CVE-2026-59726) lets attackers run commands without authentication. The impact includes API key theft and poisoning of persistent AI memory.
A cybercriminal group, Silver Fox, targeted a Japanese organization in the industrial manufacturing sector. With BYOVD and DLL sideloading, ValleyRAT is delivered for long-term remote access.
CISA added a Cisco FMC zero-day to its KEV catalog after reports of active exploitation. The flaw involves static credentials that could let attackers access sensitive data.
Researchers identified malicious npm packages that smuggled a cross-platform RAT into environments using Alibaba developer tools. The chain can persist, steal data, and move laterally.
Unit 42 investigated how malware on a Windows PC can abuse passkey-protected accounts via Google Password Manager in Chrome. The attack is post-compromise: it only starts once the device has already been taken over.
Resecurity reports that INC ransomware has been claiming victims faster since the beginning of August 2026 via SonicWall SMA 1000. The chain appears to be driven by zero-days that, among other things, abuse MFA seeds and credentials.
Visa gaat BioCatch overnemen voor $2,4 miljard. De stap vergroot Visa’s behavioral fraud intelligence om fraud en financiële criminaliteit eerder te herkennen dan bij betaling.
Liechtenstein reports that a cyberattack accessed the economic beneficiaries register, impacting around 31,000 people. Authorities say they took immediate steps and saw no signs of data tampering.
AI can speed up exploit timelines, but the real vulnerability management problem is usually prioritization. Learn why attack-path prioritization beats CVSS-only backlogs.
BTMOB RAT began as malware-as-a-service for Android, but evolved into a fragmented ecosystem with resellers, source code buyers, and alleged imitators. Flare followed the evolution of 2025 to 2026 in underground forums and chat channels.