π¨ UK Energy Sector Hit
Iran-linked hackers reportedly disrupted a small British power plant for 4 days marking a rare cyberattack against UK energy infrastructure.
β οΈThe incident highlights growing risks to critical infrastructure.
π https://t.co/DkoQcNRBhi
#Irannews
π¨ WordPress Security Alert
Avada Theme flaws are being chained to gain remote code execution, putting vulnerable WordPress sites at risk of full takeover.
β οΈ Update Avada and check for signs of compromise.
π https://t.co/WCb5COj7y5
#WordPress#CyberSecurity#RCE
π¨ Fake Gemini Alert
Attackers are using a fake Google Gemini installer hosted on Google Colab to deliver Vidar stealer, targeting saved browser passwords and session data.
β οΈ Trusted platforms can still host malicious files.
π https://t.co/lMbjozkgJm
#Malware#InfoSec
π¨ Android Car Malware Alert
Researchers uncovered malware targeting Android car head units, turning infected infotainment systems into BADBOX proxy nodes that can hide attacker traffic and abuse your device.
π https://t.co/BvEQyKN9P0
#CyberSecurity#Android#BADBOX
π¨ Fake AI Tools Alert
Attackers are using fake ChatGPT, Claude & Copilot installers to spread malware, steal credentials, and compromise users searching for popular AI tools.
π https://t.co/xFwUzKlzwH
#CyberSecurity#Malware#InfoSec
π¨ Fake PoC Warning
Attackers are uploading fake AI vulnerability PoCs to GitHub, using popular CVE names to trick researchers into downloading malware disguised as exploit code.
π https://t.co/Blix5XGlDB
#CyberSecurity#GitHub#Malware
π¨ China-Linked Espionage Alert
SilkParasite is targeting Central Asian organizations with seven custom RAT families, using advanced persistence and stealth techniques for long-term espionage.
π https://t.co/ROezr5ueRO
#CyberSecurity#APT#ThreatIntel
π¨ Camera Security Alert
Operation CameraSwarm targets exposed Dahua cameras through a P2P vulnerability, allowing attackers to hijack devices, spy on video feeds, and build large-scale surveillance networks.
π https://t.co/rzrBYUZy8S
#CyberSecurity#IoT#Dahua
π¨ Microsoft 365 Phishing Alert
Mirage2FA uses AiTM phishing to bypass MFA and steal authenticated Microsoft 365 session cookiesβgiving attackers access even when MFA is enabled.
β οΈ 2FA alone may not stop it.
π https://t.co/uaP9KVxHrK
#CyberSecurity#Phishing#MFA
π¨ Medusa Ransomware Alert
Medusa is exploiting CVE-2026-1731 in BeyondTrust to gain access, steal credentials, and move deeper into victim networks.
β οΈ CISA added the flaw to its KEV catalog.
π https://t.co/4JjZnszhdZ
#Ransomware#CyberSecurity#CVE
π¨ npm Supply Chain Attack
ChainDrop uses an SLSA bypass and Ethereum-based C2 to spread a self-propagating npm worm, stealing developer credentials and spreading through compromised packages.
π https://t.co/TWVR7Pk0Rd
#CyberSecurity#npm#SupplyChain#InfoSec
π¨ Spyware Alert
GhostDesk is spreading through fake CCleaner downloads, abusing Chrome extensions to steal browser data and maintain persistence on infected Windows systems.
π https://t.co/arxDTifF2q
#CyberSecurity#Spyware#Malware#InfoSec
π¨ Supply Chain Attack
Dragon Breath abused a stolen DigiCert certificate to sign RONINGLOADER, using trusted signatures to bypass security controls and deliver malware through trojanized installers.
π https://t.co/e1gYNSaBF3
#CyberSecurity#Malware#ThreatIntel#InfoSec
π¨ Phishing Campaign Alert
UNC6671 is using vishing and AiTM phishing to steal Microsoft 365 credentials and session tokens, targeting users through fake IT support and malicious WorkPanel pages.
π https://t.co/pf4gnYtFD6
#CyberSecurity#Phishing#AiTM#InfoSec
π¨ macOS Malware Alert
Overlord RAT is spreading through fake Zoom updates, using a .NET-based loader to compromise macOS devices and steal sensitive data while maintaining remote access.
π https://t.co/s9AaLKIJk8
#CyberSecurity#macOS#Malware#InfoSec
π¨ New Oracle Threat
Khunt abuses SQL injection to gain RCE on Oracle databases, deploys a stealthy toolkit, and maintains long-term access for espionage and data theft.
π https://t.co/Lp36YFj4xj
#CyberSecurity#Oracle#ThreatIntel#InfoSec