Aggregator
Nation-State Actor Embraces AI Malware Assembly Line
Defending Against Iranian Cyber Threats in the Wake of Operation Epic Fury
On February 28, 2026, the United States and Israel launched Operation Epic Fury (U.S.) and Operation Roaring Lion (Israel), a coordinated military and cyber campaign targeting Iranian military installations, IRGC leadership, and government infrastructure. U.S. Cyber Command was designated the "first mover," with cyber operations beginning before any kinetic weapons were deployed. In the first 48 hours, U.S. and allied forces struck more than 1,250 targets across Iran, while Israel conducted what has been described as the largest cyberattack in history, collapsing Iran's internet connectivity to 1-4% of normal levels through multi-layered attacks on BGP routing, DNS infrastructure, and SCADA/ICS systems.
The post Defending Against Iranian Cyber Threats in the Wake of Operation Epic Fury appeared first on AttackIQ.
The post Defending Against Iranian Cyber Threats in the Wake of Operation Epic Fury appeared first on Security Boulevard.
Tycoon 2FA Goes Boom as Europol, Vendors Bust Phishing Platform
ShinyHunters Claims Woflow Breach: What It Means for SaaS Supply Chain Security
Learn the security risks in SaaS supply chains and about ShinyHunters’ evolving extortion tactics behind the alleged Woflow breach.
The post ShinyHunters Claims Woflow Breach: What It Means for SaaS Supply Chain Security appeared first on AppOmni.
The post ShinyHunters Claims Woflow Breach: What It Means for SaaS Supply Chain Security appeared first on Security Boulevard.
CVE-2025-14711 | FantasticLBP Hotels Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0 hotelList.php pickedHotelName/type sql injection (EUVD-2025-203356)
CVE-2026-2130 | BurtTheCoder mcp-maigret up to 1.0.12 search_username src/index.ts Username command injection (EUVD-2026-5818)
CVE-2026-2131 | XixianLiang HarmonyOS-mcp-server 0.1.0 input_text os command injection (EUVD-2026-5817)
CVE-2026-25858 | macrozheng mall up to 1.0.3 password recovery (Issue 946 / EUVD-2026-5713)
CVE-2026-2122 | Xiaopi Panel up to 20260126 WAF Firewall /demo.php ID sql injection (EUVD-2026-5825 / CNNVD-202602-1243)
CVE-2026-25857 | Tenda G300-F up to 16.01.14.2 Management Interface formSetWanDiag os command injection (EUVD-2026-5714)
CVE-2026-2113 | yuan1994 tpadmin up to 1.3.12 WebUploader preview.php deserialization (EUVD-2026-5715)
CVE-2026-2110 | Tasin1025 SwiftBuy up to 0f5011372e8d1d7edfd642d57d721c9fadc54ec7 /login.php excessive authentication (EUVD-2026-5717)
CVE-2026-1991 | libuvc up to 0.0.7 UVC Descriptor src/device.c uvc_scan_streaming null pointer dereference (Issue 300 / EUVD-2026-5585)
CVE-2026-2065 | Flycatcher Toys smART Pixelator 2.0 Bluetooth Low Energy Interface missing authentication (EUVD-2026-5594)
CVE-2026-1709 | Keylime 7.12.0 TLS Authentication key exchange without entity authentication (EUVD-2026-5599 / Nessus ID 298275)
CVE-2025-68146 | tox-dev filelock up to 3.20.0 on Python UnixFileLock/WindowsFileLock os.open toctou (GHSA-w853-jp5j-5j7f / Nessus ID 282543)
CVE-2025-69195 | GNU wget URL memory corruption (Nessus ID 281492 / WID-SEC-2025-2935)
Один перевод через СБП – и 300 тысяч исчезли. Как пользоваться банковскими приложениями безопасно и что настроить прямо сейчас
Cryptohack Roundup: Ariomex Leak Flags Iran Sanction Risks
Iran exchange leak raises sanctions risks, $580M frozen in scam crackdown, $61M romance scam funds seized, feds seek $327K in dating scam case, Russia exploit broker sanctioned, South Korean wallet recovery phrase exposure and arrest in custody bitcoin theft, Axiom data misuse and Uniswap lawsuit ends.