๐จ AI Account Theft Alert
Infostealers are now targeting Claude AI sessions, stealing browser tokens that can let attackers hijack active accounts without needing the user's password.
๐ https://t.co/FSWSdaJQbG
#CyberSecurity#AI#Infostealer
๐จ Cisco Router Attack
Fire Ant turned Cisco IOS XR routers, TACACS servers and Linux hosts into an espionage control planeโusing trusted infrastructure to pivot toward high-value networks.
๐ https://t.co/5rnrBlwNCV
#CyberSecurity#Cisco#ThreatIntel
๐จ Blind Eagle Exposed
Researchers uncovered Blind Eagleโs GitHub infrastructure, revealing malware loaders, multiple RAT families, and an organized setup built for rapid deployment and espionage.
๐ https://t.co/DaqOCOom5o
#CyberSecurity#APT#ThreatIntel
๐จ UK Energy Sector Hit
Iran-linked hackers reportedly disrupted a small British power plant for 4 days marking a rare cyberattack against UK energy infrastructure.
โ ๏ธThe incident highlights growing risks to critical infrastructure.
๐ https://t.co/DkoQcNRBhi
#Irannews
๐จ WordPress Security Alert
Avada Theme flaws are being chained to gain remote code execution, putting vulnerable WordPress sites at risk of full takeover.
โ ๏ธ Update Avada and check for signs of compromise.
๐ https://t.co/WCb5COj7y5
#WordPress#CyberSecurity#RCE
๐จ Fake Gemini Alert
Attackers are using a fake Google Gemini installer hosted on Google Colab to deliver Vidar stealer, targeting saved browser passwords and session data.
โ ๏ธ Trusted platforms can still host malicious files.
๐ https://t.co/lMbjozkgJm
#Malware#InfoSec
๐จ Android Car Malware Alert
Researchers uncovered malware targeting Android car head units, turning infected infotainment systems into BADBOX proxy nodes that can hide attacker traffic and abuse your device.
๐ https://t.co/BvEQyKN9P0
#CyberSecurity#Android#BADBOX
๐จ Fake AI Tools Alert
Attackers are using fake ChatGPT, Claude & Copilot installers to spread malware, steal credentials, and compromise users searching for popular AI tools.
๐ https://t.co/xFwUzKlzwH
#CyberSecurity#Malware#InfoSec
๐จ Fake PoC Warning
Attackers are uploading fake AI vulnerability PoCs to GitHub, using popular CVE names to trick researchers into downloading malware disguised as exploit code.
๐ https://t.co/Blix5XGlDB
#CyberSecurity#GitHub#Malware
๐จ China-Linked Espionage Alert
SilkParasite is targeting Central Asian organizations with seven custom RAT families, using advanced persistence and stealth techniques for long-term espionage.
๐ https://t.co/ROezr5ueRO
#CyberSecurity#APT#ThreatIntel
๐จ Camera Security Alert
Operation CameraSwarm targets exposed Dahua cameras through a P2P vulnerability, allowing attackers to hijack devices, spy on video feeds, and build large-scale surveillance networks.
๐ https://t.co/rzrBYUZy8S
#CyberSecurity#IoT#Dahua
๐จ Microsoft 365 Phishing Alert
Mirage2FA uses AiTM phishing to bypass MFA and steal authenticated Microsoft 365 session cookiesโgiving attackers access even when MFA is enabled.
โ ๏ธ 2FA alone may not stop it.
๐ https://t.co/uaP9KVxHrK
#CyberSecurity#Phishing#MFA
๐จ Medusa Ransomware Alert
Medusa is exploiting CVE-2026-1731 in BeyondTrust to gain access, steal credentials, and move deeper into victim networks.
โ ๏ธ CISA added the flaw to its KEV catalog.
๐ https://t.co/4JjZnszhdZ
#Ransomware#CyberSecurity#CVE
๐จ npm Supply Chain Attack
ChainDrop uses an SLSA bypass and Ethereum-based C2 to spread a self-propagating npm worm, stealing developer credentials and spreading through compromised packages.
๐ https://t.co/TWVR7Pk0Rd
#CyberSecurity#npm#SupplyChain#InfoSec
๐จ Spyware Alert
GhostDesk is spreading through fake CCleaner downloads, abusing Chrome extensions to steal browser data and maintain persistence on infected Windows systems.
๐ https://t.co/arxDTifF2q
#CyberSecurity#Spyware#Malware#InfoSec
๐จ Supply Chain Attack
Dragon Breath abused a stolen DigiCert certificate to sign RONINGLOADER, using trusted signatures to bypass security controls and deliver malware through trojanized installers.
๐ https://t.co/e1gYNSaBF3
#CyberSecurity#Malware#ThreatIntel#InfoSec