Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Indonesia is being hit by an Android banking app-cloning campaign where attackers create fake versions of popular banking apps. The malware steals credentials, intercepts SMS two-factor codes, and can initiate fraudulent transactions, targeting users of major Indonesian banks.
Sophos researchers identified a new variant of the Cyclops Blink botnet with extended capabilities, targeting a broader range of network devices. The malware, attributed to Russian state-sponsored actors, incorporates improved persistence and evasion mechanisms.
A new Android malware variant has been discovered that encrypts files, steals data, and has ransomware capabilities, locking devices and demanding ransom payments. It spreads through malicious apps disguised as legitimate software on third-party app stores.
This article reports that the US Treasury Department is urging banks to file cyber scam reports more aggressively, citing nearly $13 billion in losses since 2023. It highlights a new rule requiring financial institutions to report cyber-enabled fraud, with a focus on threats like business email compromise, ransomware, and AI-powered social engineering.
This article describes how voice callers exploit BYOD policies to bypass security controls and access Microsoft 365 and corporate networks. By spoofing identity and manipulating help desks, attackers circumvent MFA and endpoint protections.
This article details that September 2026 Windows Server security updates break Remote Desktop Services on multiple server versions, causing connection failures. In some cases, a hard reset is necessary to restore functionality.