AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes
A phishing-as-a-service platform called AnonyMousKIT automates the theft of unlock codes for stolen iPhones by impersonating Apple support through email, SMS, WhatsApp, and AI-powered voice calls; researchers tracked the operation to 506 domains and 168 reseller storefronts, with a voice agent posing as an Apple representative convincing victims to read out their passcode so the device can be wiped, unlocked, and resold.
GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure
A critical code-injection flaw in GitLab Community and Enterprise Edition is already being exploited against honeypots just days after disclosure, allowing unauthenticated attackers to modify or delete public projects, forge merge records, and ban maintainers; researchers say AI-assisted attackers reproduced the bug within minutes of it becoming public, underscoring how quickly the window between patch release and exploitation is shrinking.
Malicious Firefox extensions steal your crypto wallet seed phrases and browser credentials
Researchers uncovered a network of 77 linked Firefox extensions, 40 of them actively malicious, built to harvest cryptocurrency wallet seed phrases and login credentials by posing as wallet tools or innocuous sports-score trackers before flipping to steal data; the campaign has run since at least March using a remote-controlled phishing setup, and Mozilla has since removed and blocklisted the offending add-ons.
Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490)
Citrix patched a critical authentication bypass in NetScaler ADC and Gateway that lets an attacker skirt login checks on appliances configured as a VPN gateway or AAA server under certain firmware and SAML conditions, alongside a lower-severity memory overflow bug tied to SIP ALG configurations; no in-the-wild exploitation had been confirmed at disclosure, but Citrix products are typically targeted quickly once bugs go public, so admins are being pushed to patch on an emergency basis.
Tricky ‘SynkLoader’ Multitool May Herald Ransomware
A newly discovered malware family called SynkLoader combines an in-memory PowerShell loader, a Python-based beacon, and a fake Windows lock-screen module that tricks victims into typing their password to “unlock” their machine, all delivered through phishing emails that impersonate an organization’s IT help desk via a self-registered Microsoft 365 tenant; researchers believe its network-profiling behavior suggests it’s being built by a ransomware group or access broker to stage larger attacks.