ZCyberNews — Cybersecurity & Tech Intelligence
Star Blizzard Scales Phishing Attacks on Ukraine Supporters
Microsoft says FSB-linked Star Blizzard hit 100+ orgs in the US and UK, using a new RedFlick delivery chain that needs one click to drop CosmicPulse.
See more updates →4 min read
FBI Arrests Ransomware Negotiator in ShinyHunters Probe
FBI arrested CyberSteward co-founder Edward Dubrovsky on cyber extortion charges tied to ShinyHunters, the group that stole data on thousands of FBI agents.
CVE-2023-36036
ModeloRAT Campaign Abuses Microsoft Teams for Enterprise Intrusion
Rapid7 dissects an April 2026 intrusion where a fake IT Support Teams message delivered ModeloRAT via Dropbox, leading to privilege escalation, credential theft, and lateral...
Read →More from today
See all →- 1dIndustry NewsFBI Arrests Third ShinyHunters Suspect Over FBI Breach
- 1dIndustry NewsJapan Extradites Russian Qilin Ransomware Suspect to Germany
- 2dIndustry NewsDOJ Charges MonsterCloud CEO Zohar Pinhasi in Ransomware Fraud
- 2dMalwareMidnight Mimosa Malware Found Preinstalled on Cheap Android Phones
- 2dMalwareWeb3 C2 Powers Cloud Supply Chain Attacks, Unit 42 Finds
Threat Intel

Star Blizzard Scales Phishing Attacks on Ukraine Supporters
Microsoft says FSB-linked Star Blizzard hit 100+ orgs in the US and UK, using a new RedFlick delivery chain that needs one click to drop CosmicPulse.
NightEagle APT Hits Russian Firms With GhostContainer Backdoor
Kaspersky GERT ties NightEagle (APT-Q-95) to attacks on Russian firms, deploying the GhostContainer backdoor on Exchange via CVE-2020-0688 and BlueKeep CVE-2019-0708.
Mirage Kitten Deploys Node.js, JavaScript RATs in Aviation, FinTech
Mirage Kitten targets aviation and FinTech sectors across the Middle East and Africa with NodeRabbit and PollCat RATs, delivered via trojanized coding challenges on LinkedIn.
Vulnerabilities
—
informational
CISA Flags CVE-2026-102490 Zammad Root Escalation
CVE-2026-102490
9.8
critical
CISA Adds Cisco Catalyst SD-WAN Auth Bypass to KEV
CVE-2026-76504
8.1
high
CVE-2026-48842: Roundcube Pre-Auth SQLi Exploited in Wild
CVE-2026-48842
Malware
Midnight Mimosa
MALWARE
Midnight Mimosa Malware Found Preinstalled on Cheap Android Phones
Oct 8 · HIGH
Alluring Pisces
MALWARE
Web3 C2 Powers Cloud Supply Chain Attacks, Unit 42 Finds
Oct 8 · —
Tren de Aragua
MALWARE
Ploutus ATM Malware Suspect Pleads Not Guilty in Nebraska
Oct 7 · —
Industry News
FBI Arrests Ransomware
SHINYHUNTERS
FBI Arrests Ransomware Negotiator in ShinyHunters Probe
Oct 10 · INFO
FBI Arrests Third
SHINYHUNTERS
FBI Arrests Third ShinyHunters Suspect Over FBI Breach
Oct 9 · HIGH
Japan Extradites Russian
QILIN
Japan Extradites Russian Qilin Ransomware Suspect to Germany
Oct 9 · INFO
Tools & Techniques

Metasploit Adds Vim Plugin Persistence, Exploits for Three CVEs
Rapid7's Metasploit Framework adds Vim plugin persistence, exploits for CVE-2025-6793 (Marvell QConvergeConsole), CVE-2024-48760 (GestioIP), and CVE-2023-30253 (Dolibarr).
Signal Adds In-App Warnings to Block Russian-Linked Phishing Attacks
Signal introduced new in-app confirmations and warnings to counter phishing attacks linked to Russian state hackers who abused the Linked Device feature to hijack high-profile...
Anthropic Launches Claude Security for AI-Driven Exploit Defense
Anthropic released Claude Security, a defensive AI suite to counter autonomous exploit tools like Mythos that weaponize zero-days in minutes. Targets enterprise SOCs.
AI Security
OpenAI
PROVIDER
Wikimedia: OpenAI Agents Tried to Breach Etherpad, Edit Wikipedia
Oct 6 · INFO
OpenAI
PROVIDER
OpenAI Apologizes as Agents Breached Australian Government Sites
Sep 29 · HIGH
OpenAI
PROVIDER
OpenAI Apologizes for Australian Government Site Incidents
Sep 29 · INFO
Stay Updated
Get the latest cybersecurity news delivered to your inbox.