The Gentlemen ransomware, run by GOLD SHERWOOD, encrypts networks in under 24 hours. See the affiliate playbook and how to defend against it.
Related Posts:
PHP Web Server Rootkit Targets F5 BIG-IP Devices
StreamRat Banking Trojan Targets Spanish Android Users
Silver Fox Fake Software Installers Disable Windows Defender
The post The Gentlemen Ransomware Deploys in Under 24 Hours appeared first on Daily CyberSecurity.
A public announcement exists for the Cisco Secure Email vulnerability pair in S/MIME decryption, plus a Cisco phone SIP denial-of-service flaw.
Related Posts:
CVE-2026-75754 (CVSS 10): ASUS Control Center Root RCE
Apache Allura Security Vulnerabilities Patched in v1.21.0
CVE-2026-52924 PoC Exploit Disclosed: 9.8 CVSS Linux Root Privilege Escalation
The post Cisco Secure Email S/MIME Flaws Publicly Disclosed appeared first on Daily CyberSecurity.
AnonyMousKIT is an AI-powered PhaaS platform that phones iPhone theft victims as fake Apple Support to steal passcodes and beat Activation Lock.
Related Posts:
Dark Caracal Deploys New GoCaracal Malware Framework
Cambodia Malware Campaign Uses PNG Files to Deliver SparkRAT
BREEZE COMET Threat Actor Attacks Brazilian Banks
The post AnonyMousKIT Uses AI Voice Calls to Unlock Stolen iPhones appeared first on Daily CyberSecurity.
WeedHack malware still targets Minecraft gamers through fake client sites and Minecraft SEO poisoning, McAfee Labs warns.
Related Posts:
SynkLoader Malware Deploys Multi-Language Attack Tools
macOS ClickFix Malware Exploits Polygon C2
Cruciferra Malware Loader Uses ClickFix Lures to Kill EDR
The post WeedHack Malware Still Hits Minecraft Gamers via Fake Sites appeared first on Daily CyberSecurity.
Apache Tomcat fixed 11 vulnerabilities on August 25, 2026, including auth bypass (CVE-2026-68569) and HTTP/2 DoS flaws. Update to 11.0.25 now.
Related Posts:
GitLab Updates Fix Arbitrary Command Execution Vulnerability
FreeBSD Patches Eight Kernel Vulnerabilities
UniFi CVE-2026-77537 (CVSS 10.0): Command Injection Flaws Hit 22 Ubiquiti Products
The post Apache Tomcat Patches 11 Vulnerabilities in 11.0.25 Update appeared first on Daily CyberSecurity.
Group-IB exposed Balonx Sistema, a Mexican PhaaS platform bundling real-time phishing, an Android RAT, and AI-driven vishing against 20+ banks.
Related Posts:
Core Werewolf Deploys New CoreRAT Malware Against Russian Targets
StopAndProtect Malware Turns Hacked WordPress Sites Into a Botnet
Cisco Talos Exposes UAT-10147 Agentic AI Attacks
The post Balonx Sistema: Mexican PhaaS Adds AI Vishing and RAT appeared first on Daily CyberSecurity.
Four Spring vulnerabilities hit Spring Data REST and Spring AI, including CVE-2026-47849, a privilege escalation flaw. Patch to the fixed versions now.
Related Posts:
EverShop CVE-2026-72843 Flaw Allows Unauthenticated Account Takeover
CVE-2026-77806: SPIP Unauthenticated RCE Exploited in the Wild as Public Exploit Lands
CVE-2026-75501: Public PoC for Calix Router Flaw That Bypasses NAT and Firewall Protections
The post Spring Data REST and Spring AI Vulnerabilities: Four High-Severity Flaws
Four Spring vulnerabilities hit Spring Data REST and Spring AI, including CVE-2026-47849, a privilege escalation flaw. Patch to the fixed versions now.
NVIDIA Triton vulnerability CVE-2026-47627 scores CVSS 9.8. Learn how the denial of service flaw works and why you must update to 26.06 now.
Related Posts:
CVE-2026-47301: PoC Exploit Achieves SYSTEM-Level Code Execution in SCCM
CVE-2026-66780 (CVSS 9.9): MITM Flaw Hits Red Hat ACM
CVE-2026-76404: Critical Remote Code Execution Hits Splunk MCP Server App (CVSS 9.1)
The post CVE-2026-47627: CVSS 9.8 Denial of Service Hits NVIDIA Triton appeared first on Daily CyberSecurity.
CVE-2026-71290 (CVSS 9.1) is an Apache HttpClient TLS vulnerability that lets attackers intercept and modify traffic via MITM attacks. Update to 5.6.4.
Related Posts:
PoC Discloses for CVE-2026-64849: watchTowr Sees Attacks on MLflow SSRF
CVE-2026-75045: Unauthenticated Attacker Could Download YouTrack Database Backups
GeoServer Unauthenticated SQL Injection (CVSS 9.8) Exploited in the Wild, PoC Public
The post CVE-2026-71290: Apache HttpClient Flaw Lets Attackers Intercept and Modify Traffic
CVE-2026-71290 (CVSS 9.1) is an Apache HttpClient TLS vulnerability that lets attackers intercept and modify traffic via MITM attacks. Update to 5.6.4.
A public PoC for CVE-2026-66804 escalates a standard Windows user to SYSTEM via the Cross Device Service. Details and exploit code are now disclosed.
Related Posts:
CVE-2026-71290: Apache HttpClient Flaw Lets Attackers Intercept and Modify Traffic (CVSS 9.1)
PoC Discloses for CVE-2026-64849: watchTowr Sees Attacks on MLflow SSRF
CVE-2026-75045: Unauthenticated Attacker Could Download YouTrack Database Backups
The post CVE-2026-66804: PoC Exploit Gains SYSTEM via Cross Device Service appeared
Apache Struts DoS flaws span CVE-2026-73633, CVE-2026-73634, and CVE-2026-73635, plus two JSON plugin bugs. Upgrade to 7.3.0.
Related Posts:
CVE-2026-19188: Haiwell HMI Gateway Flaw Lets Attackers Execute Arbitrary OS Commands With Root Privileges (CVSS 10.0)
Linux AF_PACKET Race (03390aa): PoC Exploit Enables Local Privilege Escalation
Citrix NetScaler Pre-Auth RCE CVE-2026-8452 Gets Public Exploit Code
The post Apache Struts Patches Five Flaws Including Unauthenticated DoS Bugs appeared fir
The FBI is warning the public about sexual exploitation actors illegally accessing social media and personal accounts to steal explicit images and videos from adult and underage victims. The stolen material, also known as non-consensual intimate images (NCII), is being posted or sold on criminal marketplaces, often without the victim's knowledge.
According to the FBI, these actors use social engineering and cyber intrusion tactics to target specific individuals or general targets of opportunity
The FBI is warning the public about sexual exploitation actors illegally accessing social media and personal accounts to steal explicit images and videos from adult and underage victims. The stolen material, also known as non-consensual intimate images (NCII), is being posted or sold on criminal marketplaces, often without the victim's knowledge.
According to the FBI, these actors use social engineering and cyber intrusion tactics to target specific individuals or general targets of opportunity. After gaining access to accounts, they steal explicit content and share it through community forums or illicit marketplaces.
The FBI said personally identifiable information, including a victim's name, date of birth, email address, phone number and social media username, is often posted alongside the stolen material. This can expose victims to continued harassment and re-victimization.
How Sexual Exploitation Actors Access Accounts
The FBI has identified several methods used by sexual exploitation actors to gain access to victims' accounts.
Password and PIN Targeting
In password/PIN targeting, actors use high-volume password and PIN attempts against social media and personal accounts. The information used in these attempts can come from data leak sites, social media and open-source information.
When victims are known to the actors, curated lists may include personal details such as names, date of birth or variations of those details.
Social Media Customer Service Impersonation
Another tactic involves social media customer service impersonation through text messages. Victims may receive messages claiming their account is being disabled or locked unless they provide a verification code.
The actor then requests a password reset, causing a code to be sent to the victim. If the victim shares the code, the actor can reset the password and access the account.
Phishing Emails
The FBI also warns about phishing campaigns using look-alike domains and email accounts designed to appear as social media customer support.
These messages may claim there has been a new login and contain an embedded link asking the victim to change their password. Clicking the malicious link can give the actor access to the account.
Stolen Content Can Lead to Further Attacks
Once explicit content is stolen, sexual exploitation actors may post or sell it while including personal information about the victim. The FBI said victims can subsequently face harassment, sextortion, stalking or other targeted attacks.
The actors may also advertise stolen content through a victim's own social media page, increasing the potential for further exposure.
FBI Shares Steps to Protect Accounts
The FBI advises people to avoid storing sensitive images or videos on social media platforms or other internet-accessible sites.
It recommends using unique, complex passphrases and PINs along with multi-factor authentication (MFA). Password information directly associated with a person's identity, including names or birthdays, should be avoided.
Users should also be cautious with links received through emails and text messages. The FBI recommends going directly to the relevant website to address account concerns and checking URLs before clicking.
Unrequested temporary passwords, PIN resets or access codes should also be treated with caution. The FBI advises users not to share login information, even when someone claims to represent a platform or service.
People who believe their explicit content was stolen or leaked can provide information through the FBI's NCII reporting site. The FBI also advises the public to continue reporting fraud, scams and cyber threats to the Internet Crime Complaint Center or a local FBI Field Office.
Cloudflare says 805 DDoS attacks topped 1 Tbps in Q2 2026 as high-bandwidth attacks surged, raising new concerns for network defenses.
The post Cloudflare Report Shows Massive Spike in High-Volume DDoS Attacks: Here Is What the Data Shows appeared first on TechRepublic.
U.S. and South Korean authorities warn about the growing Gunra ransomware threat as the operation expands its capabilities and affiliate network.
The post US, South Korea Warn of Growing Gunra Ransomware Threat appeared first on TechRepublic.
Cisco confirms CVE-2026-20349, a Cisco ASA and FTD VPN vulnerability (CVSS 8.6), is exploited in the wild to crash firewalls. Patch now.
Related Posts:
Zero-Click File Drop Hits Xiaomi ShareMe: PoC Public
CVE-2026-65640: WordPress 7.0.4 Fixes Remote Code Execution
MariaDB Low-Privilege Remote Code Execution Chain: Full Details and PoC Exploit Code Publicly Disclosed
The post Cisco ASA and FTD VPN Flaw CVE-2026-20349 Exploited in the Wild appeared first on Daily CyberSecurity.
DOUBLECUP is a new Russian ClickFix Loader-as-a-Service that drops CountLoader and the DeviceManager RAT using steganography and EtherHiding.
Related Posts:
macOS ClickFix Campaign Hides Its Lure Behind a Fingerprinting Gate
Fake AI Tools Malware Targets Developers Through GitHub
Interlock Ransomware Abuses Volatility3 for Credential Theft
The post DOUBLECUP: New ClickFix Loader Drops CountLoader and DeviceManager RAT appeared first on Daily CyberSecurity.
Gunra ransomware has expanded its operations through a structured ransomware-as-a-service (RaaS) affiliate program, prompting the FBI, CISA and other agencies to issue a joint advisory warning organizations about the threat. The Gunra ransomware variant uses a double-extortion model, encrypting victim data while threatening to publish stolen information on a dedicated leak site if ransom demands are not met.
The FBI first observed Gunra in April 2025 as a double-extortion ransomware variant d
Gunra ransomware has expanded its operations through a structured ransomware-as-a-service (RaaS) affiliate program, prompting the FBI, CISA and other agencies to issue a joint advisory warning organizations about the threat. The Gunra ransomware variant uses a double-extortion model, encrypting victim data while threatening to publish stolen information on a dedicated leak site if ransom demands are not met.
The FBI first observed Gunra in April 2025 as a double-extortion ransomware variant derived from leaked Conti ransomware source code.
Gunra Ransomware Shifts to Affiliate Model
By early 2026, the group had expanded through a formal ransomware-as-a-service affiliate program advertised on dark web forums.
The program provides affiliates with a management panel, configurable ransomware builder, cross-platform locker payloads and affiliate documentation. The FBI also observed Gunra operating under new branding aliases, including Golden Community, while recruiting penetration testers and ethical hackers as initial access brokers.
Gunra initially focused on Windows environments before introducing a Linux variant and moving toward broader cross-platform targeting.
Victims observed on the group’s dedicated leak site include organizations across the Americas, Europe, the Middle East, Africa and the Asia-Pacific.
Targeted sectors include healthcare and public health, financial services and insurance, critical manufacturing, transportation, government services, utilities, academia, media and communications, retail, and professional and nonprofit services.
VPN Vulnerabilities Used for Initial Access
According to the advisory, Gunra actors primarily gained initial access by exploiting known vulnerabilities in internet-facing devices, including firewall and VPN gateways. The FBI observed exploitation of CVE-2024-55591 and CVE-2025-24472, authentication bypass vulnerabilities affecting specific FortiOS and FortiProxy versions.
The Republic of Korea’s National Police Agency also observed Gunra actors exploiting credential exposure and SSH access control weaknesses in internet-facing VPN gateways to obtain unauthorized remote access.
After gaining access, attackers used tools including Impacket utilities to move laterally through victim networks using SMB. In one case, actors compromised an SSL-VPN appliance using default credentials where account lockout controls were absent. They later used stolen session information to access internal virtual desktop infrastructure and move through systems including Active Directory servers and IT personnel workstations.
Data Theft Precedes Encryption
The double-extortion ransomware operation involves stealing sensitive information before encrypting systems. The FBI observed Gunra actors collecting business-critical documents, databases, personally identifiable information, and internal email communications.
In at least one case, the actors used a malicious executable called main.exe to exfiltrate data from Microsoft OneDrive and SharePoint. Compressed archives containing sensitive information were also transferred to the Mega file-sharing service, with the volume of exfiltrated data reaching tens of terabytes.
For encryption, Gunra uses ChaCha20 and RSA-4096 algorithms and has been observed using the .ENCRT extension for encrypted files. A documented sample from July 2025 used the .CRYPT extension. The ransomware also uses Windows Management Instrumentation to delete volume shadow copies before encryption, while one victim had backup and archived data deleted from both primary and disaster recovery infrastructure.
Agencies Urge Patching and Network Segmentation
The authoring agencies recommend that organizations prioritize patching known exploited vulnerabilities in internet-facing systems, including VPN gateways and RDP-exposed infrastructure. They also advise implementing and testing offline, immutable backups stored in physically separate and segmented locations.
Network segmentation is another key recommendation, intended to restrict lateral movement and limit the spread of ransomware between systems.
The agencies also recommend reviewing domain controllers, servers, workstations and Active Directory environments for unrecognized accounts, auditing administrative privileges, requiring MFA where possible and testing security controls against the Gunra techniques mapped to the MITRE ATT&CK framework.
The joint advisory was published August 10, 2026, as part of the ongoing #StopRansomware initiative.
Fake downloads of The Odyssey are spreading Lumma Stealer malware capable of stealing passwords, cookies, payment data, and cryptocurrency information.
The post Fake The Odyssey Downloads Are Hiding Password-Stealing Malware appeared first on TechRepublic.
Fake downloads of The Odyssey are spreading Lumma Stealer malware capable of stealing passwords, cookies, payment data, and cryptocurrency information.
Cisco disclosed seven ClamAV vulnerabilities that let a remote attacker crash scanning via crafted files. Details are public. Patch now.
Related Posts:
CVE-2026-27912: PoC Released for SYSTEM Privilege Flaw
CVE-2026-58231 (CVSS 10.0) and Code Injection RCE Flaws Top SAP August 2026 Patch Day
Windows PnP Attack Chain Turns a USB Plug Into SYSTEM: Details and PoC Now Public
The post Multiple ClamAV Flaws Let Remote Attackers Cause DoS appeared first on Daily CyberSecurity.
A scam is spreading through WhatsApp with the goal of taking over victims’ accounts entirely.
It starts with a message that feels harmless and familiar. Someone—often a contact whose account has already been compromised—asks you to support a friend or relative of theirs by voting in an online contest. The theme varies: a ballet performance, a dog competition, a school event. The wording is casual, sometimes urgent, and designed to get a quick click.
We spotted the scam showing up in o
A scam is spreading through WhatsApp with the goal of taking over victims’ accounts entirely.
It starts with a message that feels harmless and familiar. Someone—often a contact whose account has already been compromised—asks you to support a friend or relative of theirs by voting in an online contest. The theme varies: a ballet performance, a dog competition, a school event. The wording is casual, sometimes urgent, and designed to get a quick click.
We spotted the scam showing up in our anonymized Scam Guard submissions. WhatsApp is popular with cybercriminals, and the third most common channel where we see scams delivered, behind websites and email.
At first glance, nothing seems out of the ordinary. But the link doesn’t lead to a real voting page. Instead, it redirects to a page that appears to be related to WhatsApp, often involving the legitimate wa.me domain, where the real attack begins.
This scam works because it combines trust and curiosity. If the message comes from someone you know, you’re far less likely to question it and far more likely to follow through to do them a small favor.
In some versions of the scam, the link redirects you into a flow that abuses WhatsApp’s legitimate “Linked devices” feature.
Depending on your device, you may see what looks like a WhatsApp page prompting you to continue, verify, or connect. In some cases, the victim is guided through steps that resemble setting up WhatsApp Web or linking a new device.
The goal is to trick you into authorizing a new linked session that gives the attacker access to your WhatsApp account.
A typical flow looks like this:
You tap the “vote” link.
A page opens that appears to be related to WhatsApp.
You’re prompted to complete a connection or verification step.
That action links your WhatsApp account to a device controlled by the attacker.
Some versions of this scam take a less direct route. Instead of sending victims to a fake voting page, the message or the landing page instructs victims to open WhatsApp, go to “Connected Devices,” and enter a code supplied by the scammer.
These scammers aren’t trying to steal your password. Instead, they’re tricking you into giving them access to your account yourself.
How WhatsApp’s Linked devices feature works
WhatsApp allows you to use your account on multiple devices, including a web browser or desktop app, through its Linked devices feature.
Normally, this works by:
Opening WhatsApp on your phone.
Scanning a QR code displayed on another device.
Approving the connection.
Once linked, that secondary device can:
Read your messages.
Send messages as you.
Access your ongoing conversations in near real time.
But if you follow those steps, you could be giving an attacker access to your messages, contacts, and ongoing conversations.
This is a legitimate and widely used feature, especially for WhatsApp Web. But in this scam, attackers abuse it to gain the same level of access without your informed consent.
Once a scammer links their device to your WhatsApp account, they can continue accessing your conversations until that device is removed.
From there, they can:
Send messages pretending to be you, including forwarding the same scam to your contacts.
Ask friends or family for money or sensitive information.
Read your chats and harvest personal information.
Because this doesn’t involve a traditional login, there are no obvious signs like password reset emails or failed login alerts. The attacker’s device simply appears as another linked session on your account.
Unless you check your linked devices, the compromise can go unnoticed for quite some time.
How to stay safe
Scams like this rely on quick reactions and misplaced trust. A few simple precautions can make a big difference:
Be cautious with unexpected “vote” or “support” requests, even if they come from someone you know.
Don’t click unexpected links, especially if you’re immediately asked to verify, connect, or link your WhatsApp account.
Never follow instructions to link devices or scan QR codes unless you initiated the action yourself.
Regularly review your linked devices in WhatsApp (Settings > Linked devices) and log out of any you don’t recognize.
If a message feels off, verify it with the sender through another channel before acting.
Malwarebytes Scam Guard can also help spot scams like this. It’s included with the Malwarebytes Mobile Security app for Android and iPhone.
If you suspect your account has already been compromised, immediately log out of all linked devices and warn your contacts so they don’t fall for follow-up scams.
Indicators of Compromise (IOCs)
These domains are typically short-lived and quickly replaced. However, they may help you recognize similar scams if you encounter them: