
Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverage
Hackers are exploiting "dropcatch domains" - previously owned domains that are re-registered by new owners - to redirect traffic to scams and malware, taking advantage of the reputation and connections they inherit from their past life. With nearly one in five new domain registrations being a re-registration of an expired name, the threat is more widespread than you might think.

Apple just released emergency updates to fix a critical flaw in macOS Screen Sharing that hackers were using to secretly install Monero miners on vulnerable Macs. The updates, available for macOS Tahoe, Sequoia, and Sonoma, patch a vulnerability that allowed attackers to bypass authentication and gain unauthorized access.

SAP Commerce Cloud has a critical vulnerability, known as CVE-2026-58231, that allows unauthenticated attackers to wreak havoc by executing arbitrary code and compromising internal components. This maximum-severity flaw, scoring a perfect 10.0 on the CVSS scale, stems from weak authorization checks and input validation.

A China-linked APT group has been exploiting a recently patched VMware vCenter vulnerability to deploy ransomware in a widespread campaign that hit 361 victims across 47 countries. The attackers used the flaw to gain root access and, in some cases, installed a Babuk-derived ransomware that locks files with a ".babyk" extension.

Meet Evooo1Bot, a sneaky new Linux botnet that's been quietly hijacking edge devices since July 2026, turning them into SOCKS5 proxies by exploiting known vulnerabilities. This cunning botnet is built on the Mirai codebase, but with a range of upgraded capabilities that make it a formidable foe.

Cybercriminals have supercharged their credential-harvesting capabilities, with infostealer malware infecting 7.4 million devices and snagging a staggering 1.7 billion credentials in just six short months. This automated threat landscape redefines the speed and scale of a breach.

Threema, a popular secure messaging service, was hit by a massive disruption on Tuesday evening, initially attributed to a network outage at a colocation partner, but later revealed to be the result of large-scale DDoS attacks. The attacks caused significant interruptions to the service, affecting users worldwide.

This sneaky malware takes remote control of your macOS browser sessions, allowing hackers to live-stream your screen and even drive your cursor - all without you knowing. They can basically take the reins, controlling your keyboard, mouse, and navigation.

Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverage
Meet Evooo1Bot, a sneaky malware that's turning routers worldwide into unwitting traffic relays, harvesting credentials, and launching devastating DDoS attacks. This modular Linux botnet is packed with powerful tools, including encrypted communication, SSH brute-forcing, and exploit arsenals to take down vulnerable devices.

Meet the upgraded CoolClient Backdoor, now packing a kernel-level rootkit courtesy of the sneaky HoneyMyte APT Group - and it's hiding in plain sight with a legit digital signature. This clever malware uses a Windows service and a kernel-mode driver to evade detection.

Hackers are exploiting a recently fixed macOS security flaw to secretly deploy Monero miners, and experts warn that public exploit code is now available, putting users at risk. This vulnerability, affecting macOS's built-in Screen Sharing feature, allows attackers to gain access without valid credentials.

The threat of autonomous AI attacks on critical infrastructure is no longer a distant possibility, but a looming reality that could unleash devastating kinetic disasters, warns Tom Kellermann, VP of AI security and threat research at TrendAI. The perfect storm of rising geopolitical tension and increasingly powerful off-the-shelf AI agents makes a crippling attack on our infrastructure not just plausible, but imminent.

Hackers are actively exploiting a critical vulnerability in SAP Commerce Cloud, allowing them to remotely execute code without any login credentials. This severe flaw, tracked as CVE-2026-58231, was patched by SAP just three days before attacks began.

Meet Evooo1Bot, a newly identified Mirai-derived Linux botnet that's turning devices into proxies by exploiting vulnerabilities, and has been actively targeting internet-facing devices since July 2026. Its operators have been using a single loader URL to launch attacks, allowing researchers to track and identify the malware.

Mac users beware: a new threat called AmnesiaStealer is targeting macOS devices through clever social engineering tactics known as ClickFix, tricking victims into installing malware via a fake GitHub download page. One wrong click could compromise your entire system.

A 27-year-old data analyst turned cyber villain, threatening to spill sensitive salary info to the SEC unless his employer paid up - in a brazen $2.5 million extortion scheme that landed him in hot water. He made his demands in chilling messages, including one that read: We will commence the process of disseminating salary information starting January 1, 2024 in phases to all employees and will report you to the SEC after for not reporting the breach.

No IT department, no security budget, real exposure. Nubivance builds right-sized security foundations for small companies. Send them this.
Send it along
Got a warning from Apple about a mercenary spyware attack on your iPhone? This means hackers are trying to secretly access your device, and Apple is stepping in to alert and protect you.

Cyber attackers have found a sneaky way to bypass EDR protections by exploiting Safe Mode, leaving security systems blind to their malicious activities. In one recent incident, an exposed SonicWall VPN with no multi-factor authentication was all it took for hackers to gain entry and start wreaking havoc.

Meet the Armored Likho group, a cyber-espionage mastermind that's just leveled up its game with a suite of sneaky new implants that can hijack Telegram sessions and eavesdrop on conversations. The latest campaign, uncovered in May 2026, uses a cunning fake donation app to infiltrate targets across Russia.

A critical VMware vCenter flaw, CVE-2026-59310, is being exploited globally, with 361 Internet-connected systems across 47 countries already compromised. This severe vulnerability allows unauthenticated attackers to execute arbitrary code, making swift action essential to prevent further breaches.

Within days of Broadcom's advisory, a critical VMware vCenter flaw, CVE-2026-59310, was exploited, putting 361 victim IP addresses across 47 countries at risk. This severe vulnerability allowed attackers to turn a logging service into a gateway to infiltrate operating systems worldwide.

Meet the Akira ransomware affiliate who got thwarted by a clever evasion tactic, but not before attempting to pull off a classic double extortion scam by stealing and leaking sensitive files. The attacker gained initial access through a vulnerable SonicWall SSL VPN, highlighting the importance of multifactor authentication.

Ransomware attacks are taking a new and more personal approach, with a whopping 80% now targeting identities rather than software flaws. Malicious emails, phishing, and compromised credentials are the top entry points, making identity-based exploits the new favorite tactic of ransomware operators.

Microsoft warned that a critical SharePoint flaw, patched in July 2026, could allow attackers to bypass authentication and disclose files or modify data. This vulnerability, tracked as CVE-2026-55040, has now been exploited by attackers following the public release of a proof-of-concept exploit.