Research
-
Google Vertex AI SDK flaw let attackers hijack model uploads and run code
A flaw in Google’s Vertex AI SDK for Python let attackers hijack model uploads through a predictable bucket name and run code in Google’s serving environment. Google patched the issue, and researchers said they saw no exploitation in the wild.
-
New Rokarolla Android malware targets banking and crypto apps
A new Android banking trojan called Rokarolla targets 217 banking and cryptocurrency apps, uses 137 commands and can steal credentials, SMS codes and crypto payments, according to a technical analysis by Zimperium’s zLabs.
-
Researchers find Windows versions of SprySOCKS backdoor
Researchers found two Windows variants of the SprySOCKS backdoor and said they add stealth features, including kernel drivers and support for multiple network channels. The malware has been linked to China-associated espionage activity.
-
152 Chrome wallpaper extensions linked to ad tracking and traffic fraud
Researchers found 152 Chrome wallpaper extensions tied to a potentially unwanted program family, with 105,000 installs across 38 publisher accounts. The extensions were said to hide tracking and make extension-generated visits look like organic Google traffic.
-
SimpleHelp bug lets attackers create rogue technician accounts
A critical SimpleHelp flaw lets unauthenticated attackers create privileged technician accounts on OIDC-enabled servers. The bug affects version 5.5.15 and older, along with 6.0 pre-release builds, and was fixed on June 9.
-
North Korean hackers shift phishing campaign to GitHub repositories, researchers say
North Korean linked hackers used recruitment-themed phishing emails and malicious GitHub repositories to target nearly 100 organizations, researchers said. The campaign aimed to steal developer credentials and cryptocurrency wallet data across Windows, macOS and Linux.
-
Microsoft 365 Copilot flaw could expose emails and files with one click
Researchers said a single click on a Microsoft link could expose emails, calendar data and indexed files from Microsoft 365 Copilot Enterprise Search through a three-bug chain called SearchLeak.
-
Sniper Dz campaign used fake Facebook offers to target MENA users
Researchers said a fraud campaign targeted users in the Middle East and North Africa with fake Facebook offers, redirecting them through layered websites and browser tricks to push phishing, premium SMS, call scams and investment fraud.
-
The Gentlemen ransomware linked to 478 claimed victims, new analysis says
A new analysis says The Gentlemen ransomware has claimed 478 victims since March 2025 and shifted in July to an independent model after using resources from other ransomware services.








