Latest from the feed

Content is curated from many trusted industry sources, including vendor advisories, security blogs, bug bounty programs, and conference organizers worldwide.

  • Hidden Meta Muse Setting Turns AI Assistant into a Backdoor

    Security researcher Patrick Wardle demonstrated a proof-of-concept showing malware already present on macOS can seize control of Meta's Muse assistant by abusing the app's broad permissions. The attack toggles a hidden setting so that spoken prompts captured from the microphone are routed to the attacker instead of Meta, compromising user privacy. The flaw is in

    Source: The Hacker News

  • Comment2Shell: Anonymous WordPress Comments Trigger Admin RCE

    A WordPress core flaw allowed an anonymous commenter to plant a hidden script on a page; when a logged-in administrator later opened that page, the script could execute code on the server. The issue, CVE-2026-93485 dubbed "Comment2Shell," was fixed in WordPress 7.1.1 on Sept. 17, with a patch and urgent update guidance for site owners. Update now.

    Source: The Hacker News

  • Guwahati Rises as Major North East Cybercrime Hub

    Guwahati’s Joint Cyber Coordination Team has become a pivotal cybercrime control hub after recent operations, tracing suspected fraud proceeds across India and exposing financial networks extending beyond Assam. Operating under the Indian Cyber Crime Coordination Centre, it coordinates nationwide investigations for enhanced cybercrime response.

    Source: The 420

  • North Korean Hackers Turn Developer Projects Into Malware Traps

    North Korean actor Jade Sleet has been linked to the compromise of an India-based IT services provider, where attackers deployed two macOS backdoors, FLATROOF and ROOFDECK. The campaign targeted developers, utilizing social engineering and compromised development infrastructure to gain access and establish persistence across victim systems.

    Source: The 420

  • CISA: Active Exploitation of Three Linux Kernel Flaws

    The US CISA warns hackers are actively exploiting three Linux kernel vulnerabilities, including a critical flaw. Federal agencies must prioritize fixes, patch affected systems, and monitor for signs of exploitation. The advisory notes separate disclosures and urges rapid assessment to contain threat and reduce risk. Agencies share IOCs.

    Source: The 420

  • BigCommerce Breach: Third-Party Apps Expose Customer Data

    BigCommerce disclosed that attackers compromised credentials for third-party apps, enabling malicious script injections into stores and possible exposure of customer data. The cloud platform confirmed the breach on Sept 17 and promptly removed the affected apps to protect users, underscoring supply-chain risks from linked integrations. It matters.

    Source: The 420

  • Active Exploitation Hits Zyxel Switches, Veeam Flaws

    CISA added a now-patched vulnerability affecting Zyxel GS1900 switches to its KEV catalog, citing evidence of active exploitation. Tracked as CVE-2026-7273 (CVSS 8.8), it is a stack-based buffer overflow that could enable arbitrary code execution, threatening device integrity, confidentiality, and availability.

    Source: The Hacker News

  • Lending Your SIM Could Land You in Legal Trouble, DoT Warns

    DoT warns mobile users not to lend or share SIMs issued in their name, outlining legal risks from fraudulent SIM issuance, misuse of telecom identifiers, and tampering with IMEI. Subscribers should regularly review numbers registered to their identity and report suspicious or unauthorized connections to prevent abuse.

    Source: The 420

  • Fake CBI Officer Traps Elderly Woman, ₹60 Lakh Lost

    Delhi Police traced a money trail from a cyber fraud case to a senior citizen in Janakpuri who had allegedly transferred about ₹60 lakh to scammers. Investigators found she remained under pressure from fraudsters posing as law enforcement officials; the case underscores digital arrest fraud targeting the elderly. Authorities warn against responding to such calls and verify through official channels.

    Source: The 420

  • Fake IRS Officer Profile Tricks Men Into Marriage Scams

    A man used fake female profiles on matrimonial sites, posing as Aishwarya with a woman's photos and a female voice to lure men seeking marriage. He claimed Aishwarya was undergoing IRS training to deflect scrutiny, duping victims. Police are investigating his motives and methods. The case highlights online impersonation risks and fraud in dating networks. End.

    Source: The 420

  • AIIMS Patna Founder Hit by ₹3.22 Lakh Cyber Fraud

    Cybercriminals siphoned ₹3,22,408 from Dr. Girish Kumar Singh, AIIMS Patna’s founding director and senior orthopaedic specialist, through unauthorized withdrawals over more than two months. The 72-year-old physician, now with the Prasad Institute of Medical Sciences, faces ongoing fraud losses and investigations.

    Source: The 420

  • Paybis as crypto on-ramp in 2026: fees, wallets, checks

    Paybis provides crypto on-ramp and off-ramp services with card payments, bank transfers, and wallet transfers. This overview explains fees, verification steps, security measures, and regional availability to help users assess costs, eligibility, and compliance before buying or selling crypto. It notes regional fee variation and verification needs.

    Source: Hack Read

Real-time threat intelligence1612 signals

Latest Intelligence

Hidden Meta Muse Setting Turns AI Assistant into a Backdoor
News

Hidden Meta Muse Setting Turns AI Assistant into a Backdoor

Security researcher Patrick Wardle demonstrated a proof-of-concept showing malware already present on macOS can seize control of Meta's Muse assistant by abusing the app's broad permissions. The attack toggles a hidden setting so that spoken prompts captured from the microphone are routed to the attacker instead of Meta, compromising user privacy. The flaw is in

Comment2Shell: Anonymous WordPress Comments Trigger Admin RCE
News

Comment2Shell: Anonymous WordPress Comments Trigger Admin RCE

A WordPress core flaw allowed an anonymous commenter to plant a hidden script on a page; when a logged-in administrator later opened that page, the script could execute code on the server. The issue, CVE-2026-93485 dubbed "Comment2Shell," was fixed in WordPress 7.1.1 on Sept. 17, with a patch and urgent update guidance for site owners. Update now.

News

Guwahati Rises as Major North East Cybercrime Hub

Guwahati’s Joint Cyber Coordination Team has become a pivotal cybercrime control hub after recent operations, tracing suspected fraud proceeds across India and exposing financial networks extending beyond Assam. Operating under the Indian Cyber Crime Coordination Centre, it coordinates nationwide investigations for enhanced cybercrime response.

News

North Korean Hackers Turn Developer Projects Into Malware Traps

North Korean actor Jade Sleet has been linked to the compromise of an India-based IT services provider, where attackers deployed two macOS backdoors, FLATROOF and ROOFDECK. The campaign targeted developers, utilizing social engineering and compromised development infrastructure to gain access and establish persistence across victim systems.

News

CISA: Active Exploitation of Three Linux Kernel Flaws

The US CISA warns hackers are actively exploiting three Linux kernel vulnerabilities, including a critical flaw. Federal agencies must prioritize fixes, patch affected systems, and monitor for signs of exploitation. The advisory notes separate disclosures and urges rapid assessment to contain threat and reduce risk. Agencies share IOCs.

News

BigCommerce Breach: Third-Party Apps Expose Customer Data

BigCommerce disclosed that attackers compromised credentials for third-party apps, enabling malicious script injections into stores and possible exposure of customer data. The cloud platform confirmed the breach on Sept 17 and promptly removed the affected apps to protect users, underscoring supply-chain risks from linked integrations. It matters.

Active Exploitation Hits Zyxel Switches, Veeam Flaws
News

Active Exploitation Hits Zyxel Switches, Veeam Flaws

CISA added a now-patched vulnerability affecting Zyxel GS1900 switches to its KEV catalog, citing evidence of active exploitation. Tracked as CVE-2026-7273 (CVSS 8.8), it is a stack-based buffer overflow that could enable arbitrary code execution, threatening device integrity, confidentiality, and availability.

News

Lending Your SIM Could Land You in Legal Trouble, DoT Warns

DoT warns mobile users not to lend or share SIMs issued in their name, outlining legal risks from fraudulent SIM issuance, misuse of telecom identifiers, and tampering with IMEI. Subscribers should regularly review numbers registered to their identity and report suspicious or unauthorized connections to prevent abuse.

News

Fake CBI Officer Traps Elderly Woman, ₹60 Lakh Lost

Delhi Police traced a money trail from a cyber fraud case to a senior citizen in Janakpuri who had allegedly transferred about ₹60 lakh to scammers. Investigators found she remained under pressure from fraudsters posing as law enforcement officials; the case underscores digital arrest fraud targeting the elderly. Authorities warn against responding to such calls and verify through official channels.

News

Fake IRS Officer Profile Tricks Men Into Marriage Scams

A man used fake female profiles on matrimonial sites, posing as Aishwarya with a woman's photos and a female voice to lure men seeking marriage. He claimed Aishwarya was undergoing IRS training to deflect scrutiny, duping victims. Police are investigating his motives and methods. The case highlights online impersonation risks and fraud in dating networks. End.

News

AIIMS Patna Founder Hit by ₹3.22 Lakh Cyber Fraud

Cybercriminals siphoned ₹3,22,408 from Dr. Girish Kumar Singh, AIIMS Patna’s founding director and senior orthopaedic specialist, through unauthorized withdrawals over more than two months. The 72-year-old physician, now with the Prasad Institute of Medical Sciences, faces ongoing fraud losses and investigations.

Paybis as crypto on-ramp in 2026: fees, wallets, checks
News

Paybis as crypto on-ramp in 2026: fees, wallets, checks

Paybis provides crypto on-ramp and off-ramp services with card payments, bank transfers, and wallet transfers. This overview explains fees, verification steps, security measures, and regional availability to help users assess costs, eligibility, and compliance before buying or selling crypto. It notes regional fee variation and verification needs.

Download Secwiser App