Npav Lab
-
Read moreHackers are using fake Claude AI installer pages and Google Ads to spread malware, steal credentials, and infect Windows and macOS systems.
-
Read moreHackers compromised official DAEMON Tools installers with malware in a major supply chain attack affecting users worldwide. Learn how to stay protected.
-
Read moreA critical PAN-OS vulnerability (CVE-2026-0300) in the User-ID Captive Portal allows unauthenticated remote code execution with root privileges. Limited exploitation has been linked to state-sponsored activity involving log tampering, Active Directory enumeration, and deployment of tunneling tools like EarthWorm and ReverseSocks5.
-
Read moreClaude Mythos AI is redefining cyber threats by discovering zero-day vulnerabilities and generating exploits faster than ever. Learn how businesses can stay protected.
-
Read moreA sophisticated phishing campaign uses fake compliance emails and AiTM attacks to steal authentication tokens and bypass MFA across thousands of organizations.
-
Read moreGoogle patches CVE-2026-0073, a critical Android zero-click flaw enabling remote shell access without user interaction. Update devices immediately.
-
Read moreA critical cPanel authentication bypass (CVE-2026-41940) was exploited in a cyber espionage campaign targeting government and military systems. Attackers gained root access, used SQL injection and custom malware tools, and exfiltrated over 4GB of sensitive data including defense and financial records.
-
Read moreResearchers reveal a phishing campaign using Google AppSheet emails to steal 30,000 Facebook accounts through fake Meta Support alerts and login pages
-
Read moreNew fake CAPTCHA scam tricks users into sending international SMS messages, causing hidden phone bill charges through SMS pumping fraud.
-
Read moreMicrosoft patches CVE-2026-32202, a Windows zero-click flaw exploited by APT28 hackers to bypass Defender SmartScreen and steal authentication hashes.