News & Map
1,197 items on Cyberstrategy — showing 641–680 · 1,085 without coordinates · Across the network · RSS
Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks
Threat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicio...
No location · Sep 03, 2026 · WedgetailShai-Hulud's Reach Just Grew to 469 Credential Locations. Here's What That Means
In early August, GitGuardian researchers found that a recent Shai-Hulud infostealer worm variant had evolved to scan for...
No location · Sep 03, 2026 · WedgetailFBI Probes Possible Breach of 153 Million Driver’s Licenses
The FBI is investigating how scans of over 153 million driver’s licenses are being sold on the dark web
No location · Sep 03, 2026 · WedgetailPegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone
The iPhone belonging to a member of Serbia's student protest movement was infected with NSO Group's Pegasus spyware, acc...
No location · Sep 03, 2026 · WedgetailInternational Operation Disrupts Sality P2P Botnet
US-led action sinkholes machines caught up in Sality botnet
No location · Sep 03, 2026 · WedgetailResearcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon
The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has droppe...
No location · Sep 03, 2026 · WedgetailThe rising sophistication of Southeast Asia’s scam factories
Southeast Asia has quietly become the world’s largest manufacturing hub for financial fraud, and it’s no longer a distan...
No location · Sep 03, 2026 · WedgetailCISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Ex...
No location · Sep 03, 2026 · WedgetailCyber Campaigning: Mid-Tier States Can Leverage Civilian Cyber Power
States lacking vast nuclear and conventional capabilities should team with the private sector via letters of marque and ...
No location · Sep 02, 2026 · WedgetailImpersonating IT support: how threat actors turn a remote session into enterprise-wide access
Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collabor...
No location · Sep 02, 2026 · WedgetailImpersonating IT support: how threat actors turn a remote session into enterprise-wide access
Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collabor...
No location · Sep 02, 2026 · WedgetailAI's Vulnerability Surge May Be More Manageable Than First Feared
New research suggests the coming Vulnpocalypse may not be so overwhelming for enterprise security teams — if they have t...
No location · Sep 02, 2026 · WedgetailJail time for Maine child in 764 marks turning point in federal law enforcement
Researcher tracking 764 said the first-of-its-kind case has a wider impact that will cause ripples across the landscape ...
No location · Sep 02, 2026 · WedgetailHackers exploit Sangoma Switchvox flaw to deploy reverse shells
Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox...
No location · Sep 02, 2026 · WedgetailSonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE
The exploitation activity follows attacks earlier this summer on two other zero-day vulnerabilities in the vendor's edge...
No location · Sep 02, 2026 · WedgetailAI Gives Cybercriminals a Dangerous Time Advantage
Former cybercriminal Brett Johnson provides a look inside the mind of a threat actor and discusses where AI provides the...
No location · Sep 02, 2026 · WedgetailAI Needs a Ten Commandments
As artificial intelligence (AI) becomes increasingly autonomous, we need a simple set of rules that everyone—not just tec...
No location · Sep 02, 2026 · WedgetailWordPress backup plugin flaw exposes millions of sites to takeover attacks
An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticate...
No location · Sep 02, 2026 · WedgetailOpenAI's Hugging Face hack reveals questions about AI predictability
Ancient civilizations are most known for one thing: conquering. And that’s the worry. If OpenAI’s agents are Romans, hum...
No location · Sep 02, 2026 · WedgetailPentagon cyber strategy expected as soon as next week, sources say
Officials have previewed a blueprint emphasizing offensive operations, AI, and closer industry ties as the military reor...
No location · Sep 02, 2026 · WedgetailRussian national facing 20 years for malware campaign that infected 80,000 freelancers
Searzhudin Tamirlanovich Aktulaev appeared in a San Francisco federal court on Monday after being arrested in Cyprus in ...
No location · Sep 02, 2026 · WedgetailGoogle, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs
Google on Wednesday announced Gemini 3.8 Flash Cyber, which it described as its most capable cybersecurity model, and ha...
No location · Sep 02, 2026 · WedgetailHealth data of more than 9.5 million people leaked from Aesto record system
The healthcare data company Aesto informed federal regulators this week that more than 9.5 million people had sensitive ...
No location · Sep 02, 2026 · WedgetailDogged Russia-based botnet dismantled after 23-year run
Sality’s peer-to-peer infrastructure allowed it to evade system-wide disruption efforts for an exceptionally long period...
No location · Sep 02, 2026 · WedgetailThreat Gang 'Springs' Vishing Attacks on Microsoft Teams Users
The "Spring Ring" operation aims to compromise users of the collaboration suite to remotely access their sessions, sprea...
No location · Sep 02, 2026 · WedgetailFake Software Installers Disable Windows Update and Weaken Microsoft Defender
An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malic...
No location · Sep 02, 2026 · WedgetailHackers exploit critical JFrog Artifactory flaw to forge admin tokens
A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being exploited in attacks to cr...
No location · Sep 02, 2026 · WedgetailNew pro-Ukraine hacker group targets Russian companies with custom ransomware
The group, which calls itself VantaCore, has targeted at least seven known victims, Russian cybersecurity firm F6 said i...
No location · Sep 02, 2026 · WedgetailPegasus, NoviSpy variant spyware found on devices of Serbian activists
It’s the first Pegasus infection of 2026 that Citizen Lab is forensically confirming, and the SHARE Foundation said it’s...
No location · Sep 02, 2026 · WedgetailRussian Man Extradited Over Malware Campaign Targeting Freelancers
Russian man extradited to US over malware campaign that targeted 80,000 freelance users
No location · Sep 02, 2026 · WedgetailWyden seeks upgraded NSA security guidance on commercial VPN use
it’s the latest in a sequence of letters to feds from Sen. Ron Wyden, D-Ore., on commercial VPNs. The post Wyden seeks u...
No location · Sep 02, 2026 · WedgetailU.K. Supreme Court Opens Door for Spyware Victims to Sue Foreign States
Last month, the Supreme Court of the United Kingdom issued a highly anticipated decision in The Kingdom of Bahrain v. Sh...
No location · Sep 02, 2026 · WedgetailMalicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code
Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository's ...
No location · Sep 02, 2026 · WedgetailThe quiet regionalisation of AI governance
Superpower rivalry has stalled global AI rules, but regional blocs like ASEAN are moving fast enough to make rules stick...
No location · Sep 02, 2026 · WedgetailGambling Goblin Turns Brazilian Government Sites Into SEO Weapons
Gambling Goblin compromised Brazilian government sites to drive gambling traffic through SEO fraud
No location · Sep 02, 2026 · WedgetailMalicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages
A Chinese-speaking cybercrime cluster known as Gambling Goblin has been observed installing malicious Apache modules on ...
No location · Sep 02, 2026 · WedgetailBGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access
Virtualizor said hackers used a Border Gateway Protocol (BGP) hijack to divert Softaculous traffic. The hackers then use...
No location · Sep 02, 2026 · WedgetailMeta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control
Cybersecurity researchers have disclosed details of a new Android banking trojan called StreamRat that was promoted to S...
No location · Sep 02, 2026 · WedgetailAttackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain
SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 seri...
No location · Sep 02, 2026 · WedgetailNutex Health Says Patient Data Stolen, Hackers Threaten Leak
The US healthcare provider confirmed that sensitive patient and employee data, alongside financial and business informat...
No location · Sep 02, 2026 · Wedgetail1,085 of 1,197 items have no coordinates and so are listed but not mapped.