Why Were Brazilian Government Websites Sending Visitors to Gambling Pages?

A Chinese-speaking threat cluster turned Brazilian government and university domains into trusted fronts for gambling scams, phishing and search manipulation.

A Chinese-speaking threat cluster turned Brazilian government and university domains into trusted fronts for gambling scams, phishing and search manipulation.

A ransomware operator used AI agents to execute more than 50 attack techniques in under ten hours, turning a complex intrusion into a machine-paced workflow.

On some Android phones, a person holding the locked device can answer a WhatsApp video call, open Meta AI's editor and browse the photo gallery without a PIN or biometric check.

A BGP hijack diverted Softaculous traffic, obtained a valid TLS certificate and delivered a malicious Virtualizor update to real servers.

Phishing victims installed a legitimate Faronics Deploy agent that enrolled their computers into attacker-controlled management consoles.

Plex gave every server owner and Desktop user a version target, but it has not disclosed the CVEs, severity or practical attack paths behind the warning.

A poisoned trackback can hide inside a WordPress backup until an administrator restores it, turning routine recovery into remote code execution.

BREEZE COMET stole the credentials and certificates behind trusted Brazilian payment workflows, then executed hundreds of fraudulent transactions within 24 to 48 hours.

Jack Henry says ShinyHunters used vishing to enter a non-production environment, exposing PII associated with fewer than ten clients.
Attackers are exploiting a Rails Active Storage flaw that can render server secrets as pixels and expose the keys needed for deeper compromise.