threat-intel GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address Threat actors linked to Dark Caracal have deployed a new Go-based malware framework, GoCaracal, utilizing an Ethereum smart contract to dynamically update its command-and-control (C2) address. This allows operators to change the malware's C2 server without requiring a new binary deployment, adding a layer of sophistica… The Hacker News · 3d ago Medium BRECCHethereumsmart contractc2
vulnerability Watchfire Controller Software A critical vulnerability (CVE-2026-5846) exists in Watchfire Controller Software, allowing a malicious user to deliver malicious firmware and gain full control of the device. Multiple versions of the software are affecte… CISA Advisories · Jul 30, 2026 Critical CVE-2026-5846UNDOCAcve-2026-5846industrial control systemsfirmware
threat-intel Bulgaria allowed surveillance tech firm to sell products to repressive regimes, report says A report by Human Rights Watch revealed that Bulgaria allowed a surveillance technology firm, Circles, to sell its products – including Pixcell, Landmark, and Voice Over Location Enabler software – to repressive regimes… The Record · Jun 18, 2026 High BUELUAsurveillancespywareexport control