
Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverage
Meet a sneaky new attack that can trick chatbots into spilling your secrets: Cryptographic Context Injection, a clever hack that forces AI to reveal sensitive info. This attack, successfully tested on xAI's Grok web chat, can expose user data like names, locations, and conversation history.

A critical Zimbra SNMP flaw, CVE-2026-73570, with a CVSS score of 8.9, is under active exploitation, allowing attackers to execute remote code. This vulnerability can be triggered by sending specially crafted SNMP requests, putting unpatched Zimbra Collaboration systems at risk.

In a shocking twist, a ransomware affiliate is turning the tables on its own gang by posing as a recovery service, offering victims a way out for a fraction of the original ransom demand. The scammer, operating under the guise of "Ransom Busters," claims to have infiltrated the ransomware gangs' infrastructure and recovered stolen data.

AI-powered phishing attacks have transformed from a filtering issue to a detection challenge, with Kaseya warning that the numbers are stark. AI now turbocharges every stage of a phishing campaign, from lightning-fast reconnaissance to convincing content generation and evasive post-compromise activity.

Meet Manic, a potent Android banking malware that can infect offline phones by exploiting nearby infected devices, putting financial institutions and users at risk. This sneaky threat combines financial fraud with advanced surveillance and device control features, making it a major concern for banks, governments, and fintech services worldwide.

A newly discovered flaw in HTTP/3 leaves CDNs vulnerable to devastating tsunami attacks, including two denial-of-service techniques called HTTP/3 Bandwidth Amplification and Connection Amplification. By exploiting this weakness, attackers can turn a small amount of malicious traffic into a massive flood that overwhelms its target.

Imagine a scenario where an attacker can secretly instruct an AI model to decrypt and execute malicious code, simply by embedding encrypted instructions and a decryption key on a web page. This is now a reality with cryptographic context injection, a new attack technique that bypasses traditional model guardrails.

Meet the Zombie Card Attack, a sneaky hack that brings expired Visa cards back to life - literally, allowing researchers to make a $500 purchase with a card that was supposed to be dead. By rewriting the expiration date, University of Massachusetts Amherst researchers showed how easily this loophole can be exploited.

Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverage
Beware of malicious Firefox extensions that have been targeting Web3 wallets as part of a large-scale campaign, with 40 confirmed malicious add-ons and 37 working together to steal your cryptocurrency. This coordinated threat, known as Offside Wallet Theft Factory, has been active since March 2026.

Meet ToxicPanda 2.0, a highly sophisticated Android banking trojan that's taking global attacks to the next level with an arsenal of 167 remote commands and advanced PIN-harvesting capabilities. This upgraded malware can infiltrate over 140 banking and crypto apps, putting your sensitive info at risk.

US agencies are sounding the alarm: hackers are now using artificial intelligence to launch targeted attacks on Siemens PLC operators, making it easier for them to breach industrial systems. This emerging threat has prompted a joint warning from CISA, the FBI, and partner agencies.

Hackers are actively exploiting a critical vulnerability in MLflow, a popular open-source AI engineering platform, that could compromise your AI applications. Federal agencies have been ordered to patch exposed instances within two weeks to avoid potential attacks.

Meet ToxicPanda 2.0, a sneaky new Android banking Trojan that's expanded its target list to over 140 banking and crypto apps, allowing attackers to swipe PINs, lock devices, and gain shell-level access. This upgraded malware is particularly alarming, as it operates seamlessly within Android, making it a stealthy threat.

Meet Manic, a sneaky new Android malware that's using a clever fallback strategy to steal sensitive data from nearby devices, even when they have no internet connection. It captures credentials and in-app secrets by combining spyware, banking fraud, and remote-control capabilities into one powerful payload.

A critical vulnerability in the Zimbra Collaboration Suite is under active attack, putting over 12,100 exposed servers worldwide at risk, with most located in Europe and Asia. Attackers can exploit this flaw, tracked as CVE-2026-73570, to execute remote code without authentication, simply by sending specially crafted SMTP requests.

Threat actors are now using AI to supercharge their attacks on industrial control systems, dramatically lowering the bar for technical expertise and development time. This alarming evolution puts critical facilities like water, energy, and food production at risk.

Full-platform Rapid7 rollouts - InsightVM, InsightIDR, event sources, agents, tuning - by a Registered Partner who has done it at state-agency scale, including OT/SCADA.
Talk deployment
Meet the scammers who pose as heroes: after a ransomware attack, a fake recovery firm called Ransom Busters claims to have the decryption key and stolen data - for a hefty fee. They promise to delete stolen data from ransomware servers, but it's all a ruse.

A new scam is targeting ransomware victims, with a fake recovery service called Ransom Busters offering to provide decryption keys and delete stolen data for a hefty fee of $20,000 to $60,000. The impostors are preying on people's trust, contacting them via email and claiming to have access to sensitive information.

In just 35 days, hackers compromised a staggering 14,530 Dahua IP cameras worldwide, with a surprising focus on Russian and CIS telecom networks. The massive operation, dubbed CameraSwarm, exposed a vast amount of sensitive data, revealing the intruders' tactics and targets.

Clop's latest large-scale data theft spree exploited a critical PTC zero-day vulnerability, CVE-2026-12569, affecting supply chain systems used by manufacturers, retailers, and industries like aerospace and automotive. This attack continues Clop's trend of targeting SaaS logistics companies with zero-days to carry out mass-exploitation campaigns.

Cyber attackers have launched a sneaky campaign that combines ErrTraffic and ClickFix to outsmart endpoint security, starting with compromised WordPress sites that inject obfuscated JavaScript to evade detection. This clever tactic uses the Ethereum blockchain to stay one step ahead of security tools.

Mexico is in the crosshairs of a revived Grandoreiro malware campaign, accounting for 40% of detections in May 2026, with attackers using clever tactics like DLL sideloading to execute the banking trojan through legitimate software. The malware is abusing a trusted application, Duplicate Files Finder, by loading a malicious library alongside its legitimate dependencies.

Hackers are taking advantage of weaknesses in multi-factor authentication, launching a staggering 155 times more password spraying attacks in the first half of 2026. These attacks aren't about fancy new tools, but rather exploiting old authentication paths that slip past security defenses.

Over 14,530 Dahua devices were compromised in a massive cyberattack, dubbed Operation CameraSwarm, which used credential attacks and authentication bypasses to gain control of cameras and other devices. The attackers hit hard in Ukraine and Russia, infiltrating devices via exposed credentials, flaws, and peer-to-peer relay tech.