Chinese Hacker Xu Zewei Extradited for US Cyberattacks
Xu Zewei, tied to Silk Typhoon, was extradited to the US on April 28, 2026, accused of cyberattacks on American universities. Details from the SecurityWeek report.
Xu Zewei, tied to Silk Typhoon, was extradited to the US on April 28, 2026, accused of cyberattacks on American universities. Details from the SecurityWeek report.
A deep dive into Dort, the alleged Canadian teen behind the Kimwolf botnet, their cybercrime ties, and the 2026 attacks on Krebs and a security researcher. Details on aliases, infrastructure, and criminal partnerships. Period.
At AIxCC in August 2025, AI systems found real bugs in code DARPA didn’t know existed—then Anthropic released Claude Mythos. The game has changed. .
China’s state-backed groups are using covert networks of compromised devices to execute attacks in a low-cost, low-risk, and deniable way, according to a report from Dark Reading. This tactic allows them to industrialize botnets, making it easier to launch attacks. The report highlights the growing concern of botnet attacks. China’s state-backed groups are industrializing botnets.
NIST warns quantum computers may crack current encryption within five years. Developers must act now to secure systems. The clock is ticking.
Itron confirmed a breach on April 13, 2026, exposing systems used by utilities worldwide. The incident raises urgent concerns for critical infrastructure security. Details here.
A new backdoor called FIRESTARTER compromised a federal Cisco Firepower device in September 2025, surviving patches and evading detection. Details from CISA and NCSC..
73 counterfeit VS Code extensions on Open VSX deliver GlassWorm v2 malware, targeting developers with stolen session tokens and credentials. Report published April 28, 2026.
UNC6692 deploys Snow malware via email bombing and social engineering. Attackers gain persistent access using Snowbelt, Snowglaze, and Snowbasin variants. Full analysis.
Fast16 malware hijacks legitimate Chrome extensions to steal credentials and bypass security. The attack abused trust mechanisms in the web ecosystem. A growing concern for developers and enterprises alike.