Software

Inside the Search for “Clean” Residential Proxies for Carding

Residential proxies are no longer treated as a simple anonymity tool in carding circles. They are increasingly discussed as one component of a broader identity-simulation stack, alongside device fingerprints, browser profiles, billing information, time zones, cookies, and transaction behavior. To better understand how criminal actors currently use and evaluate this infrastructure, Flare researchers analyzed 2,889 […]

Inside the Search for “Clean” Residential Proxies for Carding Read More »

HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload

A vulnerability dubbed HollowByte allows unauthenticated attackers to trigger a denial-of-service (DoS) condition on OpenSSL servers with a malicious payload of just 11 bytes. The OpenSSL team has silently fixed the vulnerability (no identifier assigned) and backported the patch to older releases. Because the OpenSSL software is the foundational backbone for secure internet communication, organizations

HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload Read More »

Ernst & Young discloses data breach after support system hack

Ernst & Young is notifying customers of a data breach caused by the compromise of a third-party support ticket system used by its IT personnel. According to the company, support tickets submitted through the platform may have included documents containing client tax information. Ernst & Young (EY) is among the world’s four largest auditing and

Ernst & Young discloses data breach after support system hack Read More »

Abbott probes two cyber incidents amid extortion claims

Abbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Sciences systems in its Cancer Diagnostics business, while also investigating a separate claim that attackers breached its LabCentral portal and stole company data. The company confirmed the Cancer Diagnostics incident after the ShinyHunters extortion gang added Abbott to its

Abbott probes two cyber incidents amid extortion claims Read More »

Microsoft warns of surge in ACR Stealer attacks on customers

Microsoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensitive documents from its enterprise customers. Between late April and mid-June, the threat actor used the ClickFix social-engineering method, WebDAV servers, and the MSHTA (Microsoft HTML Application Host) utility to deliver the info-stealing payload. ACR Stealer

Microsoft warns of surge in ACR Stealer attacks on customers Read More »

WordPress Core “wp2shell” RCE flaws get public exploits, patch now

Public exploits have been released for the critical “wp2shell” remote code execution vulnerabilities affecting WordPress Core, making it imperative that administrators patch their sites immediately. The wp2shell attack consists of two flaws, tracked as CVE-2026-63030 and CVE-2026-60137, that can be chained together to achieve pre-authentication remote code execution against WordPress installs running versions 6.9.x and

WordPress Core “wp2shell” RCE flaws get public exploits, patch now Read More »

Update now: 7-Zip fixes RCE flaw exploitable with malicious archives

7-Zip version 26.02 was released on June 25 to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open specially crafted compressed files. The vulnerability, disclosed by Lunbun researcher Landon Peng, exists in 7-Zip’s processing of XZ-compressed data. According to an advisory from the Zero Day

Update now: 7-Zip fixes RCE flaw exploitable with malicious archives Read More »

Hackers abuse ViPNet software to target Russian govt agencies

An advanced threat actor is abusing the update mechanism for the ViPNet private networking product suite to target Russian organizations, including government agencies. Dubbed HelloNet, the campaign has been active since at least May, deploying a malicious payload that acts as a proxy and loader for additional malware. According to Kaspersky researchers, HelloNet has impacted

Hackers abuse ViPNet software to target Russian govt agencies Read More »

AI music generator Suno has been hacked, detailing the data scraping of millions of songs from YouTube, Deezer, and Genius

According to 404 Media, a hacker has breached the company database of Suno, an online AI music generation tool. The hack is said to reveal multiple references to the training data it scraped from YouTube Music, Deezer, Genius, and others. Suno has previously admitted that its tool was trained on “essentially all music files of

AI music generator Suno has been hacked, detailing the data scraping of millions of songs from YouTube, Deezer, and Genius Read More »