Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

4sysops
4sysops.com > archives > hijacked-hotel-wi-fi-pushes-fake-browser-updates-delivering-cornflake-rat

Hijacked hotel Wi-Fi pushes fake browser updates delivering CornFlake RAT – 4sysops

1+ mon, 1+ week ago   (24+ words) Attackers are using compromised hotel and conference-center Wi-Fi gateways to redirect guests to fake browser or operating-system updates. The campaign delivers...

4sysops
4sysops.com > archives > russian-hackers-use-owareaper-to-keep-microsoft-owa-access-after-resets

Russian hackers use OWAReaper to keep Microsoft OWA access after resets – 4sysops

1+ mon, 2+ week ago   (24+ words) A Microsoft Outlook Web Access flaw is allowing the Russian-aligned TA488 group to establish mailbox access that survives password changes, browser restarts, an...

4sysops
4sysops.com > archives > alex-stamos-former-chief-security-officer-at-facebook-warns-the-hugging-face-hack-shows-ai-is-ready-for-autonomous-cyber-attacks

Alex Stamos, former Chief Security Officer at Facebook, warns the Hugging Face hack shows AI is ready for autonomous cyber attacks – 4sysops

1+ mon, 3+ week ago   (26+ words) Alex Stamos says the OpenAI model escape and Hugging Face intrusion is a major cybersecurity warning because the model broke out of containment and carried out...

4sysops
4sysops.com > archives > critical-privilege-escalation-vulnerability-found-in-ubuntu-snap-confine

Critical privilege escalation vulnerability found in Ubuntu snap-confine – 4sysops

1+ mon, 3+ week ago   (25+ words) A high-severity local privilege escalation vulnerability, tracked as CVE-2026-8933, has been identified in the snap-confine component of Ubuntu’s snapd package....

4sysops
4sysops.com > archives > servicenow-cve-2026-6875-pre-auth-rce-now-exploited-in-the-wild

ServiceNow CVE-2026-6875 pre-auth RCE now exploited in the wild – 4sysops

1+ mon, 3+ week ago   (26+ words) CVE-2026-6875 is a critical pre-authentication code injection vulnerability in the ServiceNow AI Platform, a Platform-as-a-Service that organizations use to bui...

4sysops
4sysops.com > archives > hollowgraph-hides-espionage-c2-in-microsoft-365-calendars-set-for-2050

HollowGraph hides espionage C2 in Microsoft 365 calendars set for 2050 – 4sysops

1+ mon, 3+ week ago   (24+ words) Group-IB researchers identified HOLLOWGRAPH, a lean Windows.NET malware that hijacks a compromised Microsoft 365 account and abuses the Microsoft Graph API to...

4sysops
4sysops.com > archives > 7-zip-26-02-patches-rce-flaw-triggered-by-malicious-xz-archives

7-Zip 26.02 patches RCE flaw triggered by malicious XZ archives – 4sysops

1+ mon, 3+ week ago   (26+ words) 7-Zip version 26.02 addresses a remote code execution vulnerability tracked as CVE-2026-14266 that stems from a heap-based buffer overflow when processing speci...

4sysops
4sysops.com > archives > spirals-ransomware-exploits-iis-servers-to-encrypt-networks-in-under-24-hours

Spirals ransomware exploits IIS servers to encrypt networks in under 24 hours – 4sysops

1+ mon, 3+ week ago   (26+ words) The newly discovered Spirals ransomware, written in Rust, utilizes a rapid attack timeline to move from initial breach to full network encryption in less than a...

4sysops
4sysops.com > archives > cisa-mandates-urgent-patching-for-exploited-fortisandbox-command-injection-flaws

CISA mandates urgent patching for exploited FortiSandbox command injection flaws – 4sysops

1+ mon, 3+ week ago   (20+ words) CISA has added two critical vulnerabilities affecting FortiSandbox to its Known Exploited Vulnerabilities catalog following reports of active exploitation. The...

4sysops
4sysops.com > archives > phishing-campaigns-target-lastpass-and-bitwarden-users-with-fake-security-alerts

Phishing campaigns target LastPass and Bitwarden users with fake security alerts – 4sysops

1+ mon, 4+ week ago   (21+ words) A sophisticated phishing campaign is currently targeting users of LastPass and Bitwarden by sending fraudulent security notifications. These emails use spoofed...