Threats & incidents
-
Pegasus found on Serbian protest activist’s iPhone
Citizen Lab has forensically confirmed Pegasus spyware on a Serbian student activist’s iPhone after an iMessage zero-click attack, while the identity of the operator remains unknown.
-
Dustin shuts systems after unauthorised access
Nordic IT supplier Dustin has shut parts of its internal environment after detecting unauthorised access, with the scope of the incident and any data exposure still under investigation.
-
Public exploit raises Cleo Harmony exposure
Exploit material has been published for a newly disclosed Cleo Harmony authentication weakness, increasing exposure around a managed-file-transfer platform with a history of criminal targeting.
-
SonicWall confirms SMA1000 zero-days under attack
SonicWall says two vulnerabilities affecting SMA1000 secure-access appliances are being actively exploited, including a critical pre-authentication SSRF flaw and a post-authentication code-execution weakness.
-
PaperCut attacks enter second wave
PaperCut says attacks against unpatched internet-facing NG/MF servers have entered a second wave, with more sophisticated post-compromise behaviour and confirmed customer incidents.
-
International operation disrupts Sality botnet
Authorities in Bulgaria, Hungary, Romania, and the US have joined private-sector partners in a coordinated operation to disrupt the long-running Sality malware network.
-
BGP hijack poisoned Virtualizor update traffic
A routing hijack affecting Softaculous infrastructure redirected traffic to an attacker-controlled server, enabled fraudulent TLS certificates, and delivered a malicious Virtualizor update to some installations.
-
Langflow attacks target cloud and AI secrets
Attackers are exploiting a critical Langflow code-execution flaw and probing compromised environments for OpenAI keys, AWS credentials, and other sensitive secrets.
-
JFrog Artifactory flaw reportedly exploited in wild
A critical Artifactory authentication bypass is reportedly being exploited days after disclosure, creating a potentially serious route into self-managed software artefact infrastructure.
-
TerminalFix turns fake CAPTCHA into network access
Microsoft has documented a ClickFix variant that moves from fake CAPTCHA prompts to persistence, Active Directory reconnaissance, and an encrypted reverse tunnel through compromised endpoints.










