04/28

Unprompted.au

http://Unprompted.au
Unprompted.au

Asia-26-Bai-Cast-Attack-Ghost-Bits-4.23.pdf

https://i.blackhat.com/Asia-26/Presentations/Asia-26-Bai-Cast-Attack-Ghost-Bits-4.23.pdf
Asia-26-Bai-Cast-Attack-Ghost-Bits-4.23.pdf

Unprompted.au

https://www.unprompted.au/
Unprompted.au

US reportedly charges Scattered Spider hacker arrested in Finland

https://www.bleepingcomputer.com/news/security/us-reportedly-charges-scattered-spider-hacker-arrested-in-finland/
US reportedly charges Scattered Spider hacker arrested in Finland

VECT: Ransomware by design, Wiper by accident - Check Point Research

https://research.checkpoint.com/2026/vect-ransomware-by-design-wiper-by-accident/
VECT: Ransomware by design, Wiper by accident - Check Point Research

BlueNoroff Uses ClickFix, Fileless PowerShell, and AI-Generated Fake Zoom Meetings to Target Web3 Sector - Arctic Wolf

https://arcticwolf.com/resources/blog/bluenoroff-uses-clickfix-fileless-powershell-and-ai-generated-zoom-meetings-to-target-web3-sector/
BlueNoroff Uses ClickFix, Fileless PowerShell, and AI-Generated Fake Zoom Meetings to Target Web3 Sector - Arctic Wolf

PyPI package with 1.1M monthly downloads hacked to push infostealer

https://www.bleepingcomputer.com/news/security/pypi-package-with-11m-monthly-downloads-hacked-to-push-infostealer/
PyPI package with 1.1M monthly downloads hacked to push infostealer

Microsoft Confirms Active Exploitation of Windows Shell CVE-2026-32202

https://thehackernews.com/2026/04/microsoft-confirms-active-exploitation.html
Microsoft Confirms Active Exploitation of Windows Shell CVE-2026-32202

Speakers - REcon 2026 Montreal

https://recon.cx/2026/en/speakers.html
Speakers - REcon 2026 Montreal

From DMV to Wallet: Understanding Verifiable Digital Credential Issuance | NIST

https://www.nist.gov/blogs/cybersecurity-insights/dmv-wallet-understanding-verifiable-digital-credential-issuance
From DMV to Wallet: Understanding Verifiable Digital Credential Issuance | NIST

OpenSSH Flaw Allowing Full Root Shell Access Lurked for 15 Years - SecurityWeek

https://www.securityweek.com/openssh-flaw-allowing-full-root-shell-access-lurked-for-15-years/
OpenSSH Flaw Allowing Full Root Shell Access Lurked for 15 Years - SecurityWeek

Microsoft Patches Entra ID Role Flaw That Enabled Service Principal Takeover

https://thehackernews.com/2026/04/microsoft-patches-entra-id-role-flaw.html
Microsoft Patches Entra ID Role Flaw That Enabled Service Principal Takeover

GitHub RCE Vulnerability: CVE-2026-3854 Breakdown | Wiz Blog

https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854
GitHub RCE Vulnerability: CVE-2026-3854 Breakdown | Wiz Blog