A phishing kit called Milk Dragon is luring online shoppers with fake brand discounts on Facebook and TikTok, then stealing their payment card details and one-time passwords, according to Group-IB.
The kit, also known as NaiLong, has been active since October 2025. Researchers linked it to 258 phishing pages and to victims in 66 countries.
FOMO instead of fear
Most phishing campaigns try to scare people into acting quickly. Common lures include fake fines, parcel delivery problems or alerts from a bank. Milk Dragon's operators take a different route. They place malicious links in social media marketplace listings and offer large, exclusive discounts on popular brands and consumer goods.
The University of Illinois Chicago (UIC) has confirmed a ransomware attack that cut off access to some systems at its College of Medicine. The attackers also took data from the college's servers.
A university spokesperson told Recorded Future News that an investigation is underway to establish whether "any personal, research or academic information was compromised." The university has not yet said what kind of data was taken or how many people may be affected.
Systems restored, patient care unaffected
According to UIC, the attack only hit part of the institution. "As a result of this ransomware event, some College of Medicine systems were temporarily unavailable," the spokesperson said. "However, all affected systems have since been restored. The university's main network was not affected, and there was no impact on patient care delivery at UI Health."
Citrix has shipped emergency fixes for CVE-2026-88779, a NetScaler vulnerability that attackers exploited as a zero-day before a patch existed. The company describes it as a denial-of-service bug. Researchers are now checking whether it can also be used to run code remotely.
The flaw is a memory buffer issue in NetScaler ADC and NetScaler Gateway appliances that use SAML authentication together with Gateway or AAA (authentication, authorization and auditing) functionality. Citrix rates it 8.7 on the CVSS scale. According to its advisory, it has been used in targeted attacks against unmitigated deployments.
"Citrix has observed targeted attacks on unmitigated NetScaler deployments which can lead to Denial of Service," the company said in a blog post. It added that repeated triggering can keep the service unavailable, and that its analysis found an impact on availability but not on the integrity of customer data.
Dell is urging customers to patch a critical vulnerability in the command-line interface (CLI) deployment tool of Dell System Update (DSU). The flaw could let a remote attacker run code with root privileges on unpatched systems.
The bug is tracked as CVE-2026-86360. Dell disclosed it in a security advisory published on Thursday, along with fixes for four other high-severity DSU flaws.
What DSU does and why it matters
DSU is an enterprise tool for IT administrators. They use it to push BIOS, firmware and software updates to Linux and Windows systems running on Dell's PowerEdge server infrastructure.
A newly identified Linux backdoor called ClingSTUN turns compromised systems into proxies and uses the Session Traversal Utilities for NAT (STUN) protocol to stay reachable, according to FortiGuard Labs. The malware also carries its own exploits, which let it spread to other devices.
STUN is a standard protocol that helps devices sitting behind network address translation (NAT) learn their public IP address and port mappings. ClingSTUN uses this capability to keep infected machines connected to its operators.
Two dozen flaws for initial access
FortiGuard Labs describes ClingSTUN as a back-connect proxy backdoor. To get onto systems, it targets two dozen vulnerabilities. Once installed, it sets up persistence so that it runs again during the boot sequence.
Guy Fawkes News is financed by advertising. You can choose how you want to use this website:
With advertising: we load an advertising script from a third-party ad network. The ad network may set cookies, use your IP address and device information, and may process data outside the EU. We also count your visits for our own visitor statistics (with a random ID stored in your browser).
Ad-free for €0.99 per month: no advertising and no advertising tracking. Cancel at any time.
You can change your decision at any time via "Cookie Settings" at the bottom of every page.