It looks like a normal resume, but the infection begins the moment it is opened.

It looks like a normal resume, but the infection begins the moment it is opened.

Malicious shortcut files disguised as resume files have recently been circulating, requiring corporate users to exercise caution. Threat actors name the files to resemble resume documents containing company names and job titles, and when executed, they display a legitimate decoy file alongside the malicious file to lower the user’s suspicion.

May 2026 Infostealer Trend Report

May 2026 Infostealer Trend Report

Content This report summarizes the distribution channels, number of infostealers, number of detections, target companies, and execution types of new infostealers collected during the month of May 2026. The collected samples were analyzed based on data from AhnLab SEcurity intelligence Center (ASEC)’s automated data collection system, Email Honeypot system, automated

Mozilla Product Security Update Advisory

Mozilla Product Security Update Advisory

Overview Security updates addressing vulnerabilities in Mozilla products have been released. The affected products are Firefox, Firefox ESR, Thunderbird, and Thunderbird ESR; users should update to the latest version. Affected Products and Versions Firefox versions prior to 152. Firefox ESR versions earlier than 140.12. Firefox ESR versions earlier than 115.37.

June 17, 2026

June 17, 2026 Hash 15b02f568845d66260b2e554742ba81a4 298f3c9c04787db3d82fe53321796de3d 3fc863ae2e9139afe7e55240ffed0a3f4 URL 1http[:]//xyl8[.]net/ 2http[:]//amumastudio[.]com/ 3http[:]//gameslasopa299[.]weebly[.]com/ IP 145[.]196[.]236[.]141 246[.]210[.]15[.]65 3101[.]126[.]89[.]57...

JCE Product Security Update Advisory (CVE-2026-48907)

JCE Product Security Update Advisory (CVE-2026-48907)

A security update has been released to address a remote code execution vulnerability (CVE-2026-48907) in JCE products. Affected products include JCE versions 2.7.x, 2.8.x, and 2.9.x. A Vulnerability Patch is provided in the latest update. Updating to JCE version 2.9.99.6 or later will patch the vulnerability. For JCE versions 2.7.x

What is the true nature of the shortcut file I thought was a privacy consent form?

What is the true nature of the shortcut file I thought was a privacy consent form?

Evidence has recently emerged that Malicious Files posing as “Consent Forms for the Collection and Use of Personal Information” have been circulating. Threat actors use file names that are easily mistaken for work documents to trick users into running them. These files are not actual documents but shortcut files; when