Skip to content
Wildcat Cyber Patrol
Free Download

Author: Mash

BGP Hijack Delivers Malicious Virtualizor Update to Limited Installations

Attackers successfully hijacked BGP routing for Softaculous's update infrastructure, redirecting update requests to malicious servers and delivering a tainted Virtualizor [...]
  • News
Posted on September 2, 2026 by Mash

Malicious Browser Extensions Delivered Modular Crypto-Stealing Framework

Researchers uncovered 19 malicious extensions for Chrome and Edge that deployed a modular malware framework capable of stealing cryptocurrency, sensitive [...]
  • News
Posted on September 1, 2026 by Mash

Head Mare Exploits TrueConf Vulnerabilities to Distribute Backdoored Installers

The Head Mare hacktivist group has been targeting unpatched TrueConf video conferencing servers by exploiting vulnerabilities tracked as KLCERT-26-057 and [...]
  • News
Posted on August 29, 2026 by Mash

PowerToys Update Introduces App-Specific Window Switching

Microsoft has added a new utility called Window Hopper to its PowerToys toolkit, allowing users to switch between windows of [...]
  • News
Posted on August 27, 2026 by Mash

Microsoft Rolls Out Policy to Auto-Block External Bots in Teams Meetings

Microsoft is introducing a new Teams meeting policy that automatically blocks all detected external bots from joining, eliminating the need [...]
  • News
Posted on August 26, 2026 by Mash

Microsoft Addresses Critical Cloud Vulnerabilities in Entra ID and Azure Services

Microsoft has patched multiple maximum-severity security flaws affecting Entra ID, Azure Arc, Exchange Online, and Azure Managed Instance for Apache [...]
  • News
Posted on August 24, 2026 by Mash

Microsoft Removes WMIC Tool from Windows to Strengthen Security

Microsoft has officially removed the legacy WMIC command-line tool from Windows 11 versions 24H2 and 25H2 as part of a [...]
  • News
Posted on August 20, 2026 by Mash

Hundreds of Malicious Chrome VPN Extensions Route Traffic Through Proxy

Over 737 Chrome Web Store extensions impersonated legitimate VPN services like Proton VPN, NordVPN, and Cloudflare, redirecting user traffic through [...]
  • News
Posted on August 14, 2026 by Mash

Sandworm Targets IT Pros via Fake Job Offers and Trojanized VPN Clients

Russian threat group Sandworm, tracked as UAC-0145, has been targeting system administrators since May through fake job offers impersonating IT [...]
  • News
Posted on August 13, 2026 by Mash

Former Medusa Affiliate Deploys New StormEncryptor Ransomware

A China-linked threat actor tracked as Storm-1175, previously associated with Medusa ransomware, has shifted to deploying a new encryptor called [...]
  • News
Posted on August 12, 2026 by Mash

New TONTOU Attack Bypasses Spectre v2 Mitigations on Modern CPUs

Researchers from MIT CSAIL have discovered a new Spectre v2 attack technique called TONTOU that bypasses current mitigations on AMD [...]
  • News
Posted on August 8, 2026 by Mash

AI Agents Conducted Unauthorized Real-World Attacks During Safety Tests

OpenAI and Anthropic confirmed separate incidents where AI models took unsanctioned actions on the live internet during cybersecurity evaluations. During [...]
  • News
Posted on August 5, 2026 by Mash

CrashStealer Malware Disguises as Videoconferencing App, Bypasses Apple Notarization

CrashStealer is a macOS infostealer disguised as a videoconferencing application called Werkbit Setup, which successfully passed Apple's notarization process, allowing [...]
  • News
Posted on August 4, 2026 by Mash

Critical vBulletin Vulnerability Allows Unauthenticated Code Execution

A critical remote code execution flaw tracked as CVE-2026-61511 affects vBulletin versions 5.x up to 5.7.5 and 6.x up to [...]
  • News
Posted on July 30, 2026 by Mash

Microsoft Plans WinUI Performance Optimizations Before Start Menu Rewrite

Microsoft is prioritizing memory management and performance improvements for the WinUI framework before rewriting core Windows 11 components like the [...]
  • News
Posted on July 28, 2026 by Mash

Hotel Wi-Fi DNS Hijacking Campaign Targets Microsoft 365 Accounts

Hackers have been compromising Wi-Fi gateways at hotels and conference centers since June, redirecting users to fake Microsoft 365 login [...]
  • News
Posted on July 25, 2026 by Mash

msaRAT Backdoor Routes C2 Traffic Through Chrome and Edge Browsers

The Chaos ransomware gang is using a new Rust-based backdoor called msaRAT that hides command-and-control communication by routing traffic through [...]
  • News
Posted on July 24, 2026 by Mash

7-Zip Patch Addresses Remote Code Execution via Malicious Archives

A remote code execution vulnerability in 7-Zip tracked as CVE-2026-40087 has been patched in version 26.02, affecting the software's handling [...]
  • News
Posted on July 19, 2026 by Mash

LegacyHive Zero-Day Exploit Released for Windows Privilege Escalation

Security researcher Nightmare Eclipse released a Windows zero-day exploit called LegacyHive hours after Microsoft's July 2026 Patch Tuesday, allowing privilege [...]
  • News
Posted on July 19, 2026 by Mash

OkoBot Framework Steals Hardware Wallet Seed Phrases by Injecting Phishing Into Legitimate Apps

A malware framework called OkoBot has been active on Windows since April 2025, with a module named SeedHunter that injects [...]
  • News
Posted on July 16, 2026 by Mash

CrashStealer Malware Disguised as Apple Crash Reporting Tool

A new macOS information stealer called CrashStealer pretends to be Apple's CrashReporter application, using the tool's name, icon, and metadata [...]
  • News
Posted on July 15, 2026 by Mash

RedHook Android Malware Exploits Wireless ADB for Shell Access

A new RedHook variant abuses Android Wireless Debugging to gain shell-level privileges without requiring a computer connection by tricking victims [...]
  • News
Posted on July 13, 2026 by Mash

Injective SDK Compromised to Steal Cryptocurrency Wallet Keys

Hackers compromised the Injective Labs SDK GitHub repository and published a malicious version 1.20.21 on npm that steals cryptocurrency wallet [...]
  • News
Posted on July 10, 2026 by Mash

Microsoft Patches RoguePlanet Defender Zero-Day Following Researcher Disclosure

Microsoft has released a security patch for a Defender zero-day vulnerability called RoguePlanet, tracked as CVE-2026-50656, which was disclosed by [...]
  • News
Posted on July 9, 2026 by Mash

EtherRAT Delivered via Fake IT Support Calls on Microsoft Teams

A campaign reported by Palo Alto Networks' Unit 42 combines phishing emails with Microsoft Teams voice calls impersonating corporate IT [...]
  • News
Posted on July 7, 2026 by Mash

ClickFix and ConsentFix Exploit User Habits to Hijack Microsoft 365 Accounts

Modern attacks like ClickFix and ConsentFix prey on routine user behaviors, tricking victims into performing actions that compromise their accounts [...]
  • News
Posted on July 4, 2026 by Mash

Clean GitHub Repository Exploits AI Coding Agents to Execute Hidden Malware

Researchers at Mozilla's 0DIN platform discovered a technique where seemingly benign GitHub repositories trick AI coding agents into executing malicious [...]
  • News
Posted on June 29, 2026 by Mash

Edgecution Malicious Extension Abuses Native Messaging to Deploy Python Backdoor

A malicious Microsoft Edge extension called Edgecution has been used in ransomware attacks to escape browser sandboxes by leveraging Chrome's [...]
  • News
Posted on June 25, 2026 by Mash

WhatsApp Campaign Delivers VBScript Malware via Compromised Accounts

An ongoing malware campaign targets WhatsApp users across multiple countries with messages containing obfuscated VBScript files disguised as business documents, [...]
  • News
Posted on June 23, 2026 by Mash

AryStinger Botnet Compromises Thousands of Outdated D-Link Routers

A previously undocumented malware botnet called AryStinger has infected more than 4,000 outdated D-Link routers, primarily DIR-850L and DIR-818LW models, [...]
  • News
Posted on June 22, 2026 by Mash

USB Worm Spreads Cryptocurrency-Stealing Malware via Shortcut Files

A campaign targeting cryptocurrency users distributes clipboard-stealing malware via LNK shortcut files on USB drives, active since at least February, [...]
  • News
Posted on June 19, 2026 by Mash

Attackers Weaponize claude.ai Shared Chat for ClickFix Malvertising Campaign

TrendAI Research tracked a sustained malvertising campaign from April to June 2026 that used Google Ads to deliver ClickFix social [...]
  • News
Posted on June 18, 2026 by Mash

GhostTree Attack Exploits Recursive Windows Junctions to Evade Security Scans

Researchers have discovered an attack technique called GhostTree that abuses NTFS junctions and symbolic links to hide malware from security [...]
  • News
Posted on June 17, 2026 by Mash

Miasma Worm Source Code Briefly Leaked on GitHub via Compromised Accounts

The source code for the Miasma credential-stealing worm, an evolution of the earlier Shai-Hulud malware, was intentionally leaked on GitHub [...]
  • News
Posted on June 12, 2026 by Mash

CISA Warns of Active Exploitation of SolarWinds Serv-U Denial-of-Service Flaw

The Cybersecurity and Infrastructure Security Agency has added a recently patched high-severity vulnerability in SolarWinds Serv-U to its Known Exploited [...]
  • News
Posted on June 7, 2026 by Mash

DriveSurge Hijacks Thousands of Sites for ClickFix and FakeUpdate Malware Campaigns

A threat actor known as DriveSurge operates large-scale malware distribution campaigns by compromising thousands of legitimate websites and redirecting visitors [...]
  • News
Posted on June 3, 2026 by Mash

Unpatched WP Maps Pro Flaw Allows Unauthenticated Admin Account Creation

A critical vulnerability in WP Maps Pro versions 6.1.0 and older, tracked as CVE-2026-8732, allows attackers to create rogue administrator [...]
  • News
Posted on June 1, 2026 by Mash

Active Exploitation of Palo Alto GlobalProtect Auth Bypass Underway

Palo Alto Networks warns that attackers are exploiting an authentication bypass flaw in PAN-OS GlobalProtect VPN devices, tracked as CVE-2026-0257, [...]
  • News
Posted on June 1, 2026 by Mash

Attackers Abuse ChatGPT Share Links to Deliver Malware via Fake Outage Pages

A campaign called LLMShare exploits ChatGPT's content-sharing feature to display fake OpenAI outage notices directing users to download malware disguised [...]
  • News
Posted on May 30, 2026 by Mash

Cryptojacking Campaign Spreads Through SEO Poisoning and AI Chatbots

An ongoing cryptojacking operation targets high-performance computers by manipulating search rankings and AI chatbot recommendations to promote malicious download pages [...]
  • News
Posted on May 28, 2026 by Mash

Posts navigation

Older posts
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.
For full details read our   Cookie Policy

Categories

  • Apps
  • Chrome
  • Firefox
  • guide-how-to
  • Guides
  • How to Remove
  • How-to
  • Lessons
  • Microsoft Edge
  • News
  • Security
  • Security Tools
  • Tracing Tools
  • UnHackMe
  • Virus Tricks
  • Windows
  • Windows Defender
  • Windows Updates

© 2026 Greatis Software