Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

Rescana
rescana.com > post > active-exploitation-alert-threat-actors-abuse-anthropic-claude-ai-to-extract-secrets-from-1-8m-android-apps-in-major-cre

Active Exploitation Alert: Threat Actors Abuse Anthropic Claude AI to Extract Secrets from 1.8M Android Apps in Major Credential Theft Campaign

5+ hour, 44+ min ago   (367+ words) Rescana Technical Analysis of Malware/TTPs The attack chain began with the automated mass-download of 1.8 million Android APKs from multiple app stores using a distributed pipeline orchestrated on ten AWS EC2 instances. The APKs were decompiled and scanned for hardcoded secrets…...

Rescana
rescana.com > post > large-scale-phishing-campaign-uses-invisible-unicode-and-activecampaign-to-evade-email-security-filters

Large-Scale Phishing Campaign Uses Invisible Unicode and ActiveCampaign to Evade Email Security Filters

1+ week, 23+ hour ago   (772+ words) rescana.com Large-Scale Phishing Campaign Uses Invisible Unicode and ActiveCampaign to Evade Email Security Filters A newly identified, large-scale phishing campaign is actively exploiting invisible Unicode characters to bypass traditional email security filters, sending millions of malicious emails globally. This…...

Rescana
rescana.com > post > jetbrains-cadence-breach-attackers-exploit-unpatched-teamcity-cve-2026-63077-to-exfiltrate-aws-credentials-and-source-co

JetBrains Cadence Breach: Attackers Exploit Unpatched TeamCity CVE-2026-63077 to Exfiltrate AWS Credentials and Source Code

1+ week, 1+ day ago   (299+ words) The breach demonstrates a pattern of targeting CI/CD platforms for supply chain compromise, credential theft, and lateral movement. The lack of timely patching, even by the vendor, highlights the importance of rapid vulnerability management in environments with access to…...

Rescana
rescana.com > post > active-exploitation-alert-north-korean-apts-deploy-ted-backdoor-in-compromised-haproxy-builds-to-hijack-web-traffic

Active Exploitation Alert: North Korean APTs Deploy Ted Backdoor in Compromised HAProxy Builds to Hijack Web Traffic

1+ week, 1+ day ago   (517+ words) Rescana Active Exploitation Alert: North Korean APTs Deploy Ted Backdoor in Compromised HAProxy Builds to Hijack Web Traffic Technical Analysis of Malware/TTPs The Ted backdoor is not a vulnerability in the official HAProxy codebase, but rather a malicious plugin…...

Rescana
rescana.com > post > cosmos-evm-vulnerability-exploited-critical-flaw-leads-to-multi-chain-blockchain-attacks-and-5-7m-losses

Cosmos EVM Vulnerability Exploited: Critical Flaw Leads to Multi-Chain Blockchain Attacks and $5.7M Losses

2+ week, 1+ day ago   (126+ words) Indicators of compromise include anomalous minting or burning of tokens, transactions involving vesting accounts with balances wrapping to 2^256, and the rapid creation and exploitation of vesting accounts. The exploit contracts were deployed to precomputed addresses and immediately used to trigger…...

Rescana
rescana.com > post > active-exploitation-of-mlflow-ssrf-vulnerability-cve-2026-64849-enables-cloud-credential-theft-and-account-compromise

Active Exploitation of MLflow SSRF Vulnerability (CVE-2026-64849) Enables Cloud Credential Theft and Account Compromise

3+ week, 3+ day ago   (698+ words) Rescana Active Exploitation of MLflow SSRF Vulnerability (CVE-2026-64849) Enables Cloud Credential Theft and Account Compromise A critical vulnerability has been identified and is being actively exploited in MLflow, a widely used open-source platform for managing the machine learning lifecycle. The…...

Rescana
rescana.com > post > massive-azure-entra-credential-theft-exposes-fortune-500-employee-directories-in-global-exfiltration-campaign

Massive Azure/Entra Credential Theft Exposes Fortune 500 Employee Directories in Global Exfiltration Campaign

3+ week, 6+ day ago   (392+ words) The exposure of service accounts and privileged users provides attackers with a roadmap for subsequent social engineering, spear-phishing, and privilege escalation attacks. The structured nature of the data enables highly targeted Business Email Compromise (BEC) and impersonation campaigns, as attackers…...

Rescana
rescana.com > post > critical-command-injection-vulnerability-in-snowflake-snowflake-connector-net-github-actions-exposes-jira-credentials

Critical Command Injection Vulnerability in Snowflake snowflake-connector-net GitHub Actions Exposes Jira Credentials

3+ week, 6+ day ago   (371+ words) This workflow was triggered on the issues: opened event, allowing any GitHub user to initiate it. The vulnerability originated from a change introduced in commit 094038e and merged via PR #1218 on June 18, 2026. The change replaced a previously safe pattern using environment…...