Sponsor of the Day:
Jerkmate
https://bugs.gentoo.org/show_bug.cgi?id=CVE-2021-30184
780855 – (CVE-2021-30184) games-board/gnuchess-6.2.8-r1: code execution via malicious PGN file
code execution viacve 2021games board
https://thehackernews.com/2026/03/russian-ctrl-toolkit-delivered-via.html
Russian CTRL Toolkit Delivered via Malicious LNK Files Hijacks RDP via FRP Tunnels
Russian CTRL toolkit spread via malicious LNK files in February 2026, routing C2 through FRP-tunneled RDP to evade detection.
delivered viarussianctrltoolkitmalicious
https://bugs.gentoo.org/show_bug.cgi?id=CVE-2021-3624
839366 – (CVE-2021-3624) media-gfx/dcraw: integer overflow via malicious x3f
cve 2021 3624media gfxinteger overflowvia maliciousdcraw
https://thecybersecurity.news/general-cyber-security-news/sglang-cve-2026-5760-cvss-9-8-enables-rce-via-malicious-gguf-model-files-36483/
SGLang CVE-2026-5760 (CVSS 9.8) Enables RCE via Malicious GGUF Model Files | The Cyber Security News
A critical security vulnerability has been disclosed in SGLang that, if successfully exploited, could result in remote code execution on susceptible systems....
cvss 9 8cyber security newscve 2026rce viagguf model
https://www.securitymagazine.com/articles/101873-malicious-actors-spread-malware-via-metas-advertising-system
Malicious Actors Spread Malware Via Meta’s Advertising System | Security Magazine
Aug 28, 2025 - A Meta malvertising campaign has expanded to Android phones.
spread malwaresystem securitymaliciousactorsvia
https://blog.knowbe4.com/malicious-pdfs-carry-stealthy-backdoor
New Malicious PDFs Carry Stealthy Backdoor And Exfiltrate Data Via Email
Dec 26, 2025 - The Turla threat group, certainly Russian-speaking and widely attributed to Russian intelligence services, is back with a new phishing technique.
stealthy backdoordata vianewmaliciouspdfs
https://safedep.io/malicious-velora-dex-sdk-npm-compromised-rat/
Malicious @velora-dex/sdk Delivers Go RAT via npm - Real-time Open Source Software Supply Chain...
Version 9.4.1 of @velora-dex/sdk, a DeFi SDK with ~2,000 weekly downloads, was compromised to deliver a Go-based remote access trojan (minirat) targeting macOS...
real time opensource software supplydelivers govia npmmalicious