In an age of increasing cyber threats, it’s crucial to stay informed and vigilant. A recent malware attack has been observed, targeting global WhatsApp users via malicious VBScript files, notably in Malaysia. Masks as business-related documents, this campaign showcases the recurring trend of exploiting trust through familiar communication channels. Let’s keep our cyber environment safe by staying updated and aware! Read more about this at [this link](https://qfeeds.com/mysterious-threat-actor-spreads-malicious-vbs-scripts-through-whatsapp-channels/)
OPNsense has released Patch 1, delivering important security and stability improvements to further strengthen the platform.
This update addresses a configuration line injection vulnerability affecting multiple GUI text fields (reported by lujiefsi) and resolves a missing `legacy_html_escape_form_data()` function related to certificate handling in administration settings. These fixes enhance system integrity and reinforce OPNsense’s ongoing commitment to secure, reliable network infrastructure.
With continued responsiveness to community-reported findings, OPNsense demonstrates its proactive approach to maintaining a robust and secure open-source firewall platform.
Read the full patch notes here:
https://forum.opnsense.org/index.php?topic=52149.msg269527#msg269527
Stay informed and vigilant! Unit 42 from Palo Alto Networks reveals a large-scale credential theft campaign named “FortiBleed”. This campaign targets Fortinet, MSSQL, and Sophos devices, using password lists curated from previous data breaches. Awareness and proactive cybersecurity measures can help combat such activities. Find more details here: https://qfeeds.com/understanding-the-landscape-strategies-to-combat-large-scale-credential-attacks/
OPNsense has released hotfix version **26.1.11_3**, continuing its commitment to stability and continuous improvement.
This update includes:
– A fix for privilege merging in `hasPrivilege()` (reported by iys8)
– Minor corrections to firewall menu registration for legacy pages
– Restored support for spaces in Monit start, stop, and condition fields
Each refinement reinforces OPNsense’s focus on reliability, usability, and responsive community-driven development.
Read the full update here:
https://forum.opnsense.org/index.php?topic=52257.msg269519#msg269519
Exciting news from Talos! They’ve introduced an innovative approach for enhancing automation in the analysis of Visual Basic 6 binaries. The method utilizes external scripting capabilities instead of embedding AI directly, resulting in more dynamic workflows. Stay up-to-date on this game-changing strategy. Read more: https://qfeeds.com/decoding-the-disassembler-harnessing-vbdecs-live-com-object-model-for-local-agentic-reverse-engineering/
OPNsense has released a new update addressing a series of security advisories, including recent FreeBSD-related reports published just yesterday.
The team highlights the growing number of security reports submitted for the core codebase — a positive sign of strong community engagement and responsible disclosure. They are actively working through these reports and continuously improving their internal processes to further strengthen platform security and responsiveness.
This update reflects OPNsense’s ongoing commitment to transparency, collaboration, and delivering a secure, reliable firewall platform for its users.
Read the full update here:
https://forum.opnsense.org/index.php?topic=52257.msg269443#msg269443
Recent research by Check Point has unveiled an innovative cryptocurrency clipboard hijacking campaign. Leveraging a multi-channel promotion strategy, these threat actors cleverly manipulate social media and legitimate news platforms to seem credible. Stay ahead by learning about these evolving tactics. Read more from the original Q-Feeds post here: https://qfeeds.com/from-celestial-ratings-to-digital-thumbs-up-the-role-of-fake-reputation-in-a-crypto-clipboard-hijacker/ #cybersecurity #cryptocurrency #Checkpoint
Stay ahead of cybersecurity trends with the latest developments. Ransomware-as-a-Service (RaaS) group, Gentlemen, has taken significant steps in optimizing their operations since their launch in late 2025. They are achieving this by utilizing comprehensive EDR killers tailored for affiliates. Learn more about this strategic advancement based on ESET’s research here: https://qfeeds.com/unveiling-the-shadows-inside-gentlemens-edr-killer-framework/ Let’s continue enhancing our defense strategies and stay one step ahead. #CyberSecurity #RaaS #EDR
The OPNsense team has announced a new partnership with Nordian to meet growing hardware demand while ensuring software development continues at its usual pace.
This collaboration marks an important inflection point, supporting both operational growth and long-term project goals. By strengthening its hardware capabilities, OPNsense reinforces its commitment to delivering reliable, high-quality open-source firewall solutions to its global community.
This strategic partnership positions OPNsense for continued innovation and sustainable growth.
Read the full announcement here: https://forum.opnsense.org/index.php?topic=52249.msg269384#msg269384
ESET’s recent research sheds light on the growing cybersecurity risks in manufacturing operation technology, further underlining the urgency for robust protective measures. The blend of information technology and operational technology is revealing new vulnerabilities, largely arising from reliance on aging systems over the years. Let’s secure the future by safeguarding legacy OT systems against evolving threats. For more insights, visit: https://qfeeds.com/securing-the-future-safeguarding-legacy-ot-systems-against-evolving-threats/
