
Rapid7 deployed right the first time.
Full-platform Rapid7 rollouts - InsightVM, InsightIDR, event sources, agents, tuning - by a Registered Partner who has done it at state-agency scale, including OT/SCADA.
Talk deployment
Google's passkeys, touted as a secure alternative to passwords, have been found to have flaws that can be exploited by malware, allowing hackers to access sensitive information. Researchers have discovered three techniques, dubbed Pass-ta-key, that let attackers abuse Google Password Manager's synced passkeys on compromised Windows devices.

Meet DOUBLECUP, a sneaky Russian loader service that's been hiding in plain sight since June 2026, using browser cache tricks to deliver malware to unsuspecting victims. Its clever ClickFix campaigns conceal malicious code within innocent-looking PNG images, deploying nasty payloads like CountLoader and DeviceManager RAT on Windows and macOS devices.

Roblox players beware: a sneaky malware campaign has been targeting gamers with a fake Xeno Script Launcher, infecting them with a RAT and infostealer since the start of the year. The malware was cleverly spread through gaming forums, Discord, and compromised accounts, masquerading as an "undetected" cheat to evade Roblox's anti-cheat protections.

Brazilian schools are under cyberattack, with weak credentials and outdated systems leaving them vulnerable to hackers. New data reveals a hotbed of incidents in São Paulo, Rio de Janeiro, and Pernambuco, with private institutions bearing the brunt of high-severity ransomware attacks.

Malware is now exploiting Google's Passkey ecosystem to hijack accounts, with researchers uncovering three new attack classes that allow hackers to take control of passkey-protected accounts. This alarming vulnerability lets malware running on a victim's device authenticate without needing user interaction or elevated permissions.

Artificial intelligence has taken a dark turn, now serving as both a powerful tool and prime target for cyber attackers, with AI-driven malicious activity skyrocketing 89% in just one year. This emerging threat landscape demands attention, as adversaries harness AI to supercharge their attacks.

INC Ransomware has rapidly become a major player in the cyber threat landscape, exploiting SonicWall SMA 1000 flaws to claim a staggering 885 victims worldwide as of August 2, 2026. The group's activity has surged since early August, with multiple victims listed on its data leak site.

Malware on a Windows machine can secretly hijack your passkey-protected accounts, allowing hackers to sign in without needing your fingerprint, PIN, or any other verification. This shocking exploit targets Google Password Manager, revealing a vulnerability that puts your digital security at risk.

Full-platform Rapid7 rollouts - InsightVM, InsightIDR, event sources, agents, tuning - by a Registered Partner who has done it at state-agency scale, including OT/SCADA.
Talk deployment
A critical authentication bypass vulnerability, CVE-2026-18577, is under active attack, putting N-able's N-central servers at risk - but a hotfix (2026.3.1.7) is now available to prevent further exploitation. This flaw is linked to an earlier, incomplete patch for CVE-2026-18576, which also threatened administrative account takeovers.

China-linked hackers, specifically Vault Panda and Genesis Panda, are exploiting vulnerabilities at lightning-fast speeds, rapidly validating and weaponizing newly disclosed flaws into active intrusions. This swift response highlights their sophisticated approach to staying ahead of the constantly changing attack surface.

Microsoft uncovered a sneaky malware plot by Russian spies, who turned Wi-Fi networks at hotels and conference centers into a backdoor to steal valuable credentials and gain access to victims' cloud environments. The clever attack, attributed to the notorious SVR's Midnight Blizzard group, went undetected for months.

The BTMOB malware ecosystem has shattered into a patchwork of fragmented offerings, morphing from a single, centrally operated service to a chaotic mix of official releases, private servers, and reseller panels. This dramatic shift comes after the source code was exploited, sending the once-coordinated operation into a tailspin.

Malicious hackers from Midnight Blizzard have hijacked hotel Wi-Fi networks to spread espionage malware, using a sneaky tactic called CaptiveCrunch that's been flying under the radar since early May. By taking over captive portals, attackers tricked victims into downloading fake updates that actually served up malicious software.

Clever attackers have found a way to slip past Microsoft Defender by using a fake Python DLL, effectively creating a trusted execution lane that evades detection. They set the stage for this trick by first gaining elevated access through a sneaky spear-phishing link.

A Chinese threat actor has cleverly exploited a leaked DarkSword kit to deploy GHOSTBLADE on iOS devices, with hosting concentrated in Hong Kong but reaching as far as Japan, the US, and Europe. This surprising attack follows the kit's public leak, which has been rapidly reused to target Apple devices running iOS versions 18.4 through 18.7.

If you're using a Coldcard hardware wallet, take immediate action to protect your funds - an ongoing exploit has already drained an estimated $89 million from thousands of victim addresses. Move your single-sig Coldcard funds to a safe location ASAP to avoid losses.

Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scramble
N-able's servers were compromised due to an incomplete fix for a critical vulnerability, allowing attackers to exploit an authentication bypass and gain remote administrative access to on-premises servers and customer systems. The incident highlights the importance of thorough patching, as N-able's initial fix failed to fully address the issue.

In a shocking heist, hackers exploited a flaw in COLDCARD Wallet firmware to steal approximately $70.2 million worth of Bitcoin in a mere 41 minutes, targeting 1,196 addresses in a single wave of automated transactions. The attackers used a telltale signature - overpaying 30-75 times the median transaction fee - that pointed to their use of an automated tool.

A sneaky attacker just pulled off a massive $70 million Bitcoin heist by exploiting a flaw in a popular hardware wallet, draining 1,196 addresses in a lightning-fast 41 minutes. The thief's clever move has left experts warning of a potential vulnerability in the widely-used Coldcard wallet.

Beware: hackers have cleverly manipulated a popular ad script to swap crypto wallet addresses, allowing them to intercept your transactions even if you double-check and recopy the address. This sneaky tactic uses a cleverly hidden code to override your wallet details in real-time.

Hackers have found a sneaky way to hijack hotel Wi-Fi, using a simple trick to redirect guests to a fake login page that can deliver surveillance malware and even bypass multi-factor authentication. This clever hack starts with attackers taking control of a hotel's Wi-Fi gateway, allowing them to forge DNS answers and route traffic to their own servers.

A Chinese hacker leveraged the DeepSeek AI model to supercharge their vulnerability attacks, using an open-source AI framework to rapidly scan, research, and exploit targets with alarming speed and scale. This alarming automation was achieved through a clever combination of tools, including the Hermes Agent and Telegram.

To protect its users, Arch Linux has temporarily disabled package adoption on its Arch User Repository (AUR) due to a surge in malware takeovers. The move is a temporary measure to handle the situation, with the team promising to reinstate the feature once it's safe to do so.

A security breach at Adform has led to a malicious script that can compromise your device with cryptocurrency-stealing malware, simply by visiting a website that uses their ad tech. This sneaky malware can infiltrate your device through seemingly harmless websites, just by embedding a compromised Adform script.