- Researchers Uncover Long-Running Supply Chain Attack on QuickFox VPN
Cybersecurity researchers have uncovered a long-running supply chain attack that compromised QuickFox, a VPN and network acceleration application widely used by Chinese citizens living overseas. According to researchers at Fortinet FortiGuard Labs, attackers secretly modified the Windows installer for QuickFox to distribute a sophisticated backdoor known as FDMTP, malware previously associated with the Chinese state-linked… Read more: Researchers Uncover Long-Running Supply Chain Attack on QuickFox VPN - CISA Warns of Three Actively Exploited Security Flaws in KEV Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has expanded its Known Exploited Vulnerabilities (KEV) catalog by adding three newly confirmed security flaws that are actively being exploited by attackers. The update, published on August 5, 2026, serves as an urgent warning for organizations to patch affected systems before they become targets of ongoing cyberattacks.… Read more: CISA Warns of Three Actively Exploited Security Flaws in KEV Catalog - New Kali365 Phishing Campaign Targets Microsoft 365 Organizations
A sophisticated phishing toolkit known as Kali365 is exploiting Microsoft’s legitimate authentication process to compromise Microsoft 365 accounts, giving attackers potential access to corporate email, cloud storage, and other business resources. Unlike traditional phishing attacks that rely on fake login pages, Kali365 tricks victims into authenticating through Microsoft’s genuine device login portal. Because users interact… Read more: New Kali365 Phishing Campaign Targets Microsoft 365 Organizations - New NullReceiver Attack Uses Ethereum to Hide Malware C2 Servers
Cybersecurity researchers have uncovered a new blockchain-based technique that allows attackers to hide malware command-and-control (C2) server addresses in a way that is even more difficult to detect than previous methods. The technique, dubbed NullReceiver, was discovered in two malicious npm packages and is believed to be linked to North Korean threat actors. Researchers say… Read more: New NullReceiver Attack Uses Ethereum to Hide Malware C2 Servers - Paperclip Security Vulnerabilities Put AI Agent Platforms at Risk
Security researchers have disclosed three serious vulnerabilities in Paperclip, an open-source control platform designed to manage teams of AI agents. Two of the flaws could allow attackers to execute malicious commands on either a server or a developer’s local machine, while a third vulnerability may expose sensitive information through improperly protected API endpoints. Developers and… Read more: Paperclip Security Vulnerabilities Put AI Agent Platforms at Risk
Trending Stories
- Researchers Uncover Long-Running Supply Chain Attack on QuickFox VPN
Cybersecurity researchers have uncovered a long-running supply chain attack that compromised QuickFox, a VPN and network acceleration application widely used by Chinese citizens living overseas. According to researchers at Fortinet FortiGuard Labs, attackers secretly modified the Windows installer for QuickFox to distribute a sophisticated backdoor known as FDMTP, malware previously associated with the Chinese state-linked… Read more: Researchers Uncover Long-Running Supply Chain Attack on QuickFox VPN - CISA Warns of Three Actively Exploited Security Flaws in KEV Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has expanded its Known Exploited Vulnerabilities (KEV) catalog by adding three newly confirmed security flaws that are actively being exploited by attackers. The update, published on August 5, 2026, serves as an urgent warning for organizations to patch affected systems before they become targets of ongoing cyberattacks.… Read more: CISA Warns of Three Actively Exploited Security Flaws in KEV Catalog - New Kali365 Phishing Campaign Targets Microsoft 365 Organizations
A sophisticated phishing toolkit known as Kali365 is exploiting Microsoft’s legitimate authentication process to compromise Microsoft 365 accounts, giving attackers potential access to corporate email, cloud storage, and other business resources. Unlike traditional phishing attacks that rely on fake login pages, Kali365 tricks victims into authenticating through Microsoft’s genuine device login portal. Because users interact… Read more: New Kali365 Phishing Campaign Targets Microsoft 365 Organizations - New NullReceiver Attack Uses Ethereum to Hide Malware C2 Servers
Cybersecurity researchers have uncovered a new blockchain-based technique that allows attackers to hide malware command-and-control (C2) server addresses in a way that is even more difficult to detect than previous methods. The technique, dubbed NullReceiver, was discovered in two malicious npm packages and is believed to be linked to North Korean threat actors. Researchers say… Read more: New NullReceiver Attack Uses Ethereum to Hide Malware C2 Servers - Paperclip Security Vulnerabilities Put AI Agent Platforms at Risk
Security researchers have disclosed three serious vulnerabilities in Paperclip, an open-source control platform designed to manage teams of AI agents. Two of the flaws could allow attackers to execute malicious commands on either a server or a developer’s local machine, while a third vulnerability may expose sensitive information through improperly protected API endpoints. Developers and… Read more: Paperclip Security Vulnerabilities Put AI Agent Platforms at Risk
- Researchers Uncover Long-Running Supply Chain Attack on QuickFox VPN
Cybersecurity researchers have uncovered a long-running supply chain attack that compromised QuickFox, a VPN and network acceleration application widely used by Chinese citizens living overseas. According to researchers at Fortinet FortiGuard Labs, attackers secretly modified the Windows installer for QuickFox to distribute a sophisticated backdoor known as FDMTP, malware previously associated with the Chinese state-linked… Read more: Researchers Uncover Long-Running Supply Chain Attack on QuickFox VPN
Top Stories
- Researchers Uncover Long-Running Supply Chain Attack on QuickFox VPN
Cybersecurity researchers have uncovered a long-running supply chain attack that compromised QuickFox, a VPN and network acceleration application widely used by Chinese citizens living overseas. According to researchers at Fortinet FortiGuard Labs, attackers secretly modified the Windows installer for QuickFox to distribute a sophisticated backdoor known as FDMTP, malware previously associated with the Chinese state-linked… Read more: Researchers Uncover Long-Running Supply Chain Attack on QuickFox VPN - CISA Warns of Three Actively Exploited Security Flaws in KEV Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has expanded its Known Exploited Vulnerabilities (KEV) catalog by adding three newly confirmed security flaws that are actively being exploited by attackers. The update, published on August 5, 2026, serves as an urgent warning for organizations to patch affected systems before they become targets of ongoing cyberattacks.… Read more: CISA Warns of Three Actively Exploited Security Flaws in KEV Catalog - New Kali365 Phishing Campaign Targets Microsoft 365 Organizations
A sophisticated phishing toolkit known as Kali365 is exploiting Microsoft’s legitimate authentication process to compromise Microsoft 365 accounts, giving attackers potential access to corporate email, cloud storage, and other business resources. Unlike traditional phishing attacks that rely on fake login pages, Kali365 tricks victims into authenticating through Microsoft’s genuine device login portal. Because users interact… Read more: New Kali365 Phishing Campaign Targets Microsoft 365 Organizations - New NullReceiver Attack Uses Ethereum to Hide Malware C2 Servers
Cybersecurity researchers have uncovered a new blockchain-based technique that allows attackers to hide malware command-and-control (C2) server addresses in a way that is even more difficult to detect than previous methods. The technique, dubbed NullReceiver, was discovered in two malicious npm packages and is believed to be linked to North Korean threat actors. Researchers say… Read more: New NullReceiver Attack Uses Ethereum to Hide Malware C2 Servers
Cybersecurity News
- Researchers Uncover Long-Running Supply Chain Attack on QuickFox VPN
Cybersecurity researchers have uncovered a long-running supply chain attack that compromised QuickFox, a VPN and network acceleration application widely used by Chinese citizens living overseas. According to researchers at Fortinet FortiGuard Labs, attackers secretly modified the Windows installer for QuickFox to distribute a sophisticated backdoor known as FDMTP, malware previously associated with the Chinese state-linked… Read more: Researchers Uncover Long-Running Supply Chain Attack on QuickFox VPN - CISA Warns of Three Actively Exploited Security Flaws in KEV Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has expanded its Known Exploited Vulnerabilities (KEV) catalog by adding three newly confirmed security flaws that are actively being exploited by attackers. The update, published on August 5, 2026, serves as an urgent warning for organizations to patch affected systems before they become targets of ongoing cyberattacks.… Read more: CISA Warns of Three Actively Exploited Security Flaws in KEV Catalog - New Kali365 Phishing Campaign Targets Microsoft 365 Organizations
A sophisticated phishing toolkit known as Kali365 is exploiting Microsoft’s legitimate authentication process to compromise Microsoft 365 accounts, giving attackers potential access to corporate email, cloud storage, and other business resources. Unlike traditional phishing attacks that rely on fake login pages, Kali365 tricks victims into authenticating through Microsoft’s genuine device login portal. Because users interact… Read more: New Kali365 Phishing Campaign Targets Microsoft 365 Organizations
Threats & Attacks
- Researchers Uncover Long-Running Supply Chain Attack on QuickFox VPN
Cybersecurity researchers have uncovered a long-running supply chain attack that compromised QuickFox, a VPN and network acceleration application widely used by Chinese citizens living overseas. According to researchers at Fortinet FortiGuard Labs, attackers secretly modified the Windows installer for QuickFox to distribute a sophisticated backdoor known as FDMTP, malware previously associated with the Chinese state-linked… Read more: Researchers Uncover Long-Running Supply Chain Attack on QuickFox VPN - CISA Warns of Three Actively Exploited Security Flaws in KEV Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has expanded its Known Exploited Vulnerabilities (KEV) catalog by adding three newly confirmed security flaws that are actively being exploited by attackers. The update, published on August 5, 2026, serves as an urgent warning for organizations to patch affected systems before they become targets of ongoing cyberattacks.… Read more: CISA Warns of Three Actively Exploited Security Flaws in KEV Catalog - New Kali365 Phishing Campaign Targets Microsoft 365 Organizations
A sophisticated phishing toolkit known as Kali365 is exploiting Microsoft’s legitimate authentication process to compromise Microsoft 365 accounts, giving attackers potential access to corporate email, cloud storage, and other business resources. Unlike traditional phishing attacks that rely on fake login pages, Kali365 tricks victims into authenticating through Microsoft’s genuine device login portal. Because users interact… Read more: New Kali365 Phishing Campaign Targets Microsoft 365 Organizations
Technology
- Researchers Uncover Long-Running Supply Chain Attack on QuickFox VPN
Cybersecurity researchers have uncovered a long-running supply chain attack that compromised QuickFox, a VPN and network acceleration application widely used by Chinese citizens living overseas. According to researchers at Fortinet FortiGuard Labs, attackers secretly modified the Windows installer for QuickFox to distribute a sophisticated backdoor known as FDMTP, malware previously associated with the Chinese state-linked… Read more: Researchers Uncover Long-Running Supply Chain Attack on QuickFox VPN - CISA Warns of Three Actively Exploited Security Flaws in KEV Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has expanded its Known Exploited Vulnerabilities (KEV) catalog by adding three newly confirmed security flaws that are actively being exploited by attackers. The update, published on August 5, 2026, serves as an urgent warning for organizations to patch affected systems before they become targets of ongoing cyberattacks.… Read more: CISA Warns of Three Actively Exploited Security Flaws in KEV Catalog - New Kali365 Phishing Campaign Targets Microsoft 365 Organizations
A sophisticated phishing toolkit known as Kali365 is exploiting Microsoft’s legitimate authentication process to compromise Microsoft 365 accounts, giving attackers potential access to corporate email, cloud storage, and other business resources. Unlike traditional phishing attacks that rely on fake login pages, Kali365 tricks victims into authenticating through Microsoft’s genuine device login portal. Because users interact… Read more: New Kali365 Phishing Campaign Targets Microsoft 365 Organizations
