Prove it. Don't just claim it.

'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month

Cybersecurity team reviewing a regional security update
Regional security update

Assess promptly

The adversary-in-the-middle (AitM) phishing service lowers the barrier to entry for actors to create attacks and steal more than just user credentials.

At a glance

  • The adversary-in-the-middle (AitM) phishing service lowers the barrier to entry for actors to create attacks and steal more than just user credentials.
  • SecurityTalent reviewed the linked official source and preserved its attribution.
Continue reading

Copyright

© SecurityTalent.com — original summary and analysis

  34 Hits

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

Cybersecurity team reviewing a regional security update
Regional security update

Assess promptly

Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages. "While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn't do harm, the threat actor’s use of npm isn't to infect developers who install it, but to use the

At a glance

  • Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages. "While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn't do harm, the threat actor’s use of npm isn't to infect developers who install it, but to use the
  • SecurityTalent reviewed the linked official source and preserved its attribution.
Continue reading

Copyright

© SecurityTalent.com — original summary and analysis

  42 Hits

Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight

Cybersecurity team reviewing a regional security update
Regional security update

Assess promptly

The spyware-equipped Manic, a persistent Grandoreiro campaign in Latin America and Europe, and an expanded ToxicPanda 2.0 malware. The post Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight appeared first on SecurityWeek.

At a glance

  • The spyware-equipped Manic, a persistent Grandoreiro campaign in Latin America and Europe, and an expanded ToxicPanda 2.0 malware. The post Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight appeared first on SecurityWeek.
  • SecurityTalent reviewed the linked official source and preserved its attribution.
Continue reading

Copyright

© SecurityTalent.com — original summary and analysis

  64 Hits

'Grandoreiro' Malware Resurfaces With Mexico Campaign

Cybersecurity team reviewing a regional security update
Regional security update

Assess promptly

The banking Trojan, post-law enforcement takedown, is sprucing itself up with features that make detection and analysis harder.

At a glance

  • The banking Trojan, post-law enforcement takedown, is sprucing itself up with features that make detection and analysis harder.
  • SecurityTalent reviewed the linked official source and preserved its attribution.
Continue reading

Copyright

© SecurityTalent.com — original summary and analysis

  64 Hits

40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets

Cybersecurity team reviewing a regional security update
Regional security update

Assess promptly

A set of 40 Mozilla Firefox extensions has been found to engage in cryptocurrency wallet theft by masquerading as OKX, Rabby Wallet, TronLink, and other Web3 products. According to the Socket Threat Research team, the extensions are part of a broader set of 77 browser add-ons that share source code and infrastructure overlaps. The campaign, dubbed Offside Wallet Theft Factory, is believed to

At a glance

  • A set of 40 Mozilla Firefox extensions has been found to engage in cryptocurrency wallet theft by masquerading as OKX, Rabby Wallet, TronLink, and other Web3 products. According to the Socket Threat Research team, the extensions are part of a broader set of 77 browser add-ons that share source code and infrastructure overlaps. The campaign, dubbed Offside Wallet Theft Factory, is believed to
  • SecurityTalent reviewed the linked official source and preserved its attribution.
Continue reading

Copyright

© SecurityTalent.com — original summary and analysis

  59 Hits

'Ransom Busters': Ransomware Actor Poses as Incident-Recovery Service

Cybersecurity team reviewing a regional security update
Regional security update

Assess promptly

A ransomware affiliate appears to be sidling up to victims with offers of aid, masking its true intention of diverting ransom payments.

At a glance

  • A ransomware affiliate appears to be sidling up to victims with offers of aid, masking its true intention of diverting ransom payments.
  • SecurityTalent reviewed the linked official source and preserved its attribution.
Continue reading

Copyright

© SecurityTalent.com — original summary and analysis

  52 Hits

16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets

Cybersecurity team reviewing a regional security update
Regional security update

Assess promptly

Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer. OpenSourceMalware, which discovered the activity on August 15, 2026, is tracking the threat under the moniker StubMaker. The complete list of packages published as part of the campaign is below - ubnuler ubnlder ri18nr reaker rakier orakw joxn

At a glance

  • Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer. OpenSourceMalware, which discovered the activity on August 15, 2026, is tracking the threat under the moniker StubMaker. The complete list of packages published as part of the campaign is below - ubnuler ubnlder ri18nr reaker rakier orakw joxn
  • SecurityTalent reviewed the linked official source and preserved its attribution.
Continue reading

Copyright

© SecurityTalent.com — original summary and analysis

  54 Hits

'Turf War' Between Claude Agents Leads to Self-Replicating Malware

Cybersecurity team reviewing a regional security update
Regional security update

Assess promptly

Three testing models with the same goal but different directives engaged in "increasingly aggressive" territorial attacks on one another, according to Anthropic.

At a glance

  • Three testing models with the same goal but different directives engaged in "increasingly aggressive" territorial attacks on one another, according to Anthropic.
  • SecurityTalent reviewed the linked official source and preserved its attribution.
Continue reading

Copyright

© SecurityTalent.com — original summary and analysis

  64 Hits

128 Seconds to disruption: Microsoft Defender stops ransomware at QNET

Cybersecurity team reviewing a regional security update
Regional security update

Assess promptly

Microsoft Defender automatically isolated a compromised QNET endpoint in 128 seconds, stopping a multi-stage attack before the payload could persist or spread. The post 128 Seconds to disruption: Microsoft Defender stops ransomware at QNET appeared first on Microsoft Security Blog.

At a glance

  • Microsoft Defender automatically isolated a compromised QNET endpoint in 128 seconds, stopping a multi-stage attack before the payload could persist or spread. The post 128 Seconds to disruption: Microsoft Defender stops ransomware at QNET appeared first on Microsoft Security Blog.
  • SecurityTalent reviewed the linked official source and preserved its attribution.
Continue reading

Copyright

© SecurityTalent.com — original summary and analysis

  47 Hits

New York Awards $9 Million to Strengthen Cybersecurity at 153 Water Systems

Cybersecurity team reviewing a regional security update
Regional security update

Assess promptly

The grants will help local governments assess and improve cyber defenses amid a multistate campaign targeting water and wastewater infrastructure. The post New York Awards $9 Million to Strengthen Cybersecurity at 153 Water Systems appeared first on SecurityWeek.

At a glance

  • The grants will help local governments assess and improve cyber defenses amid a multistate campaign targeting water and wastewater infrastructure. The post New York Awards $9 Million to Strengthen Cybersecurity at 153 Water Systems appeared first on SecurityWeek.
  • SecurityTalent reviewed the linked official source and preserved its attribution.
Continue reading

Copyright

© SecurityTalent.com — original summary and analysis

  49 Hits

Cisco Reports Limited Exploitation of Catalyst SD-WAN File Write Flaw

Security operations team reviewing Cisco Reports Limited Exploitation of Catalyst SD-WAN File Write Flaw
Actively exploited vulnerability

Patch immediately

Cisco PSIRT reported limited exploitation of CVE-2026-20262, an arbitrary file-write vulnerability in Catalyst SD-WAN Manager, and urged customers to move to fixed releases.

At a glance

  • Cisco says no workarounds are available.
  • The advisory includes indicators and fixed releases across supported SD-WAN branches.

Copyright

© SecurityTalent.com — original summary and analysis

  52 Hits

Chrome 149 Update Addresses Exploited CVE-2026-11645

Security operations team reviewing Chrome 149 Update Addresses Exploited CVE-2026-11645
Actively exploited browser flaw

Update immediately

Google's Chrome 149 stable-channel release included dozens of security fixes and identified CVE-2026-11645 as exploited in the wild.

At a glance

  • Browser exploitation status raises patch priority above routine cadence.
  • Enterprise teams should require a restart and verify the fixed build rather than only distributing the update.

Copyright

© SecurityTalent.com — original summary and analysis

  51 Hits

Cisco Confirms Active Exploitation of Catalyst SD-WAN Authentication Bypass

Security operations team reviewing Cisco Confirms Active Exploitation of Catalyst SD-WAN Authentication Bypass
Actively exploited vulnerability

Patch and investigate

Cisco confirmed active exploitation of CVE-2026-20133 in Catalyst SD-WAN and recommends fixed releases plus network restrictions around control components.

At a glance

  • Cisco became aware of active exploitation in April 2026.
  • Defenders should restrict management access and examine control-plane logs in addition to patching.

Copyright

© SecurityTalent.com — original summary and analysis

  54 Hits

Fortinet SSO Abuse Advisory Calls for Admin Account Review

Security operations team reviewing Fortinet SSO Abuse Advisory Calls for Admin Account Review
Actively exploited vulnerability

Investigate and patch

Fortinet documented active exploitation of CVE-2026-24858, including configuration theft and creation of persistent administrator accounts through FortiOS SSO abuse.

At a glance

  • Fortinet rates the issue critical and marks it known exploited.
  • Defenders should patch and search for unexpected administrator names and configuration downloads.

Copyright

© SecurityTalent.com — original summary and analysis

  46 Hits