The News.
Daily intel.
Daily breach reporting, CVE disclosures, malware analyses, and threat campaigns. Yesterday's incidents, this morning's coverage — written by practitioners for the analysts and defenders who need it first.
Google Raises Android Bug Bounties to $1.5M as Chrome Payouts Drop in AI Era
Google restructures its VRP: Android zero-click Pixel Titan M exploits now worth $1.5M while Chrome rewards fall as AI tools accelerate browser bug discovery.
Cyber-Enabled Cargo Theft Hit $725M in 2025 as FBI Warns Transportation Sector
FBI warns transportation and logistics firms of a 60% surge in cyber-enabled cargo theft, with losses reaching $725M in 2025 and average per-incident value up 36%.
30,000 Facebook Business Accounts Compromised via Google AppSheet Phishing Relay
Vietnamese-linked operation AccountDumpling abuses Google AppSheet to send phishing emails from a trusted Google domain, stealing Facebook Business credentials at scale.
SHADOW-EARTH-053: China-Aligned Hackers Target Asian Governments and NATO Member State
Trend Micro exposes SHADOW-EARTH-053, a China-linked APT exploiting ProxyLogon and deploying ShadowPad against government and defense targets across Asia and NATO.
Instructure Discloses Cybersecurity Incident Affecting Canvas Platform
Instructure, maker of the Canvas LMS used by millions globally, has disclosed a cybersecurity incident and shut down Canvas Data 2 while investigators probe the scope.
Cordial Spider and Snarky Spider: Vishing and SSO Abuse in Rapid SaaS Extortion Attacks
Cordial Spider and Snarky Spider use vishing calls and SSO-based AiTM phishing to extort retail and hospitality firms, demanding seven-figure ransoms.
Anthropic's Mythos Has Landed: Here's What Comes Next for Cyber
Anthropic Mythos Has Landed: In this latest installment of the Reporters' Notebook video series, we discuss how the new AI model threatens to completely u...
Another AI-Assisted Software Scan Yields 9-Year-Old Linux Bug
Another Assisted Software Scan: The proof-of-concept exploit code runs only 10 lines long, but luckily, a patch is already available.
Hugging Face and ClawHub Abused in Active Malware Distribution Campaign
Threat actors abuse Hugging Face and ClawHub with social engineering to deliver AMOS stealer and credential-theft malware targeting AI developers.