
Know a small business winging it on security?
No IT department, no security budget, real exposure. Nubivance builds right-sized security foundations for small companies. Send them this.
Send it along
Meet StreamRat, a sneaky new Android banking trojan that's giving hackers near-total control over infected devices - and it's been spreading through paid social media ads on Meta. This sophisticated threat is a major red flag for Android users, especially in Spain where the campaign was focused.

A recent BGP hijack attack targeted users of Virtualizor with malware that granted persistent root access, affecting a limited number of servers that received rerouted Softaculous update traffic during a 33-hour window. The attackers cleverly obtained a valid Let's Encrypt certificate, making the malicious server appear trustworthy to clients.

Brazilian government websites have been hijacked by malicious actors, redirecting traffic to betting sites in a sneaky campaign attributed to a Chinese-speaking cluster known as Gambling Goblin or Earth Berberoka. This multilingual scheme has been cleverly manipulating search engines and government systems since mid-2025.

Researchers have uncovered a shocking vulnerability in seven AI coding agents, where malicious Git configurations can trick the tools into running attacker-supplied code on a developer's machine. This flaw, linked to Git's core.fsmonitor setting, has already led to eight security flaws, with four still unpatched.

Meet Gambling Goblin, a Chinese-speaking cybercrime cluster that's been secretly hijacking Brazilian government and education websites to fuel a massive SEO fraud campaign since mid-2025. They're using sneaky Apache modules to disguise their malicious activity and stay under the radar.

MSPs are under siege from ransomware attacks, with 143 reported victims in 2025 alone, and it's clear that a robust defense requires more than just backup or endpoint detection - a comprehensive, integrated protection approach is needed. To stay safe, MSPs must bring together prevention, detection, response, and recovery into a cohesive, measurable service that delivers six critical outcomes.

In a recent ransomware attack, a human attacker used AI to breach an enterprise network in under 10 hours - compressing weeks of meticulous planning into a lightning-fast operation. This was achieved by leveraging autonomous agents that worked in parallel, methodically bypassing security layers to achieve a shared goal.

A massive malware campaign, involving around 255 fake accounts and 80,000 targeted users, has led to charges against a Russian national, Searzhudin Tamirlanovich Aktulaev, who has been extradited and charged by the U.S. Department of Justice. The campaign, which spread malware through infected Excel attachments, allegedly ran from June 2016 to November 2017, targeting freelancers and others.

No IT department, no security budget, real exposure. Nubivance builds right-sized security foundations for small companies. Send them this.
Send it along
A massive phishing campaign infected 80,000 freelancers with malware, using 255 fake accounts to spread malicious Excel attachments with hidden macros that downloaded additional software onto victims' systems. The cleverly designed scam exploited a popular freelance employment platform's online messaging feature to spread its digital damage.

In a major win for national security, authorities have successfully dismantled the Sality malware's peer-to-peer network, crippling its ability to spread and cause harm. By cleverly turning the malware's own protocols against it, law enforcement and private partners isolated infected hosts and rendered the threat actor powerless.

In a major win for cybersecurity, global authorities have joined forces to dismantle the notorious Sality botnet infrastructure, seizing key domains in the US and Europe. This coordinated crackdown, involving the US Department of Justice and international partners, has disrupted the malware's grip on thousands of infected computers.

In a major win for cybersecurity, CrowdStrike and international law enforcement agencies joined forces to dismantle the notorious Sality botnet, crippling its ability to communicate and operate by corrupting its core network. By targeting the botnet's peer list, they effectively isolated infected machines and brought the 23-year-old threat to a grinding halt.

Beware of a sneaky phishing scam that's targeting high-profile individuals, using a clever tactic to gain long-term access to their cloud accounts without needing their passwords. This sophisticated attack convinces victims to grant a malicious app permission to their accounts, allowing hackers to stay logged in for good.

Cyber attackers are leveraging a newly exploited Artifactory flaw in highly sophisticated, AI-driven campaigns - but are these threats coming from automated bots or human culprits? The line between human and machine is blurring in the world of cybercrime.

Hackers are using clever phishing lures disguised as invoices and business files to trick victims into installing malicious software, with over 457 endpoints compromised in just a month. They exploited a legitimate endpoint-management tool to gain remote control and install additional remote-access software.

Meet Breeze Comet, a financially motivated threat actor that's been wreaking havoc on Brazilian payment systems with hundreds of fraudulent transactions, exploiting customized malware and compromised websites to siphon off tens of thousands of dollars. Their tactics are evolving, and Latin American countries should beware of potential expansion.

Full-platform Rapid7 rollouts - InsightVM, InsightIDR, event sources, agents, tuning - by a Registered Partner who has done it at state-agency scale, including OT/SCADA.
Talk deployment
Attackers are actively exploiting a critical vulnerability in Langflow to harvest sensitive keys, including OpenAI and AWS credentials, by querying environment variables and reading secret files. This severe flaw, known as CVE-2026-0768, allows hackers to execute arbitrary Python code with root privileges, putting systems at risk.

Researchers uncovered 13 malicious packages on Packagist that inject JavaScript into popular Vietnamese streaming sites, unleashing a two-pronged attack that includes mobile ad-fraud and spyware installation on unpatched iPhones. This sneaky malware can steal crypto seeds and wreak havoc on unsuspecting users.

In a shocking security breach, threat actors made off with a whopping $600,000 in AI credits after exploiting a stolen API key from AI safety research group METR over just three weeks. The incident began with a researcher inadvertently leaving a public EC2 instance exposed, despite Google authentication, due to a fail-open flaw and a "vibe-coded" app storing a sensitive API key.

More than one in five organizations have fallen victim to AI-powered attacks, with 22% reporting a security incident in the past year where hackers used artificial intelligence to breach critical business platforms. This alarming trend highlights the urgent need for cybersecurity leaders to address the growing AI trust gap.

Malicious actors hijacked internet traffic to deliver fake Virtualizor updates to a small number of users, exploiting a vulnerability in the Border Gateway Protocol (BGP) to divert update requests to their own servers. This sneaky move allowed them to push malicious updates to unsuspecting users.

Iranian hackers are using clever tactics to deploy cross-platform malware, disguising it as coding challenges on LinkedIn and other job search platforms to trick developers into installing the threat. This malware, tracked as NodeRabbit and PollCat, can infect Windows, Linux, and macOS workstations, allowing hackers to gain remote access.

In a shocking 33-hour heist, a BGP hijack diverted traffic meant for Softaculous, delivering malware to unsuspecting users via a valid TLS certificate issued to the attacker. The clever hack exploited a weakness in internet routing, allowing the attacker to intercept and compromise Virtualizor installations.

Cyberattackers are ditching creative tactics for a straightforward, repeatable playbook - and it's surprisingly effective, with a simple trick called ClickFix accounting for 47% of attacks. This sneaky method involves guiding users through a CAPTCHA-style interaction, then tricking them into pasting a command into a terminal, all without needing attachments or vulnerabilities.