no alarms and no surprises please..
-
EU court adviser says banks must immediately refund phishing victims
EU court adviser says banks must immediately refund phishing victims Athanasios Rantos, the Advocate General of the Court of Justice of the EU (CJEU), has issued a formal opinion suggesting that banks must immediately refund account holders affected by unauthorized transactions, even when it’s their fault. […] Bill Toulas Go to bleepingcomputer
-
Hackers abuse .arpa DNS and ipv6 to evade phishing defenses
Hackers abuse .arpa DNS and ipv6 to evade phishing defenses Threat actors are abusing the special-use “.arpa” domain and IPv6 reverse DNS in phishing campaigns that more easily evade domain reputation checks and email security gateways. […] Lawrence Abrams Go to bleepingcomputer
-
Critical ExifTool Flaw Lets Malicious Images Trigger Code Execution on macOS
Critical ExifTool Flaw Lets Malicious Images Trigger Code Execution on macOS A newly discovered vulnerability is challenging the long-held belief that macOS systems are inherently immune to malware. Security researchers from Kaspersky’s Global Research and Analysis Team (GReAT) have identified a critical flaw that allows threat actors to execute malicious code on Macs simply by…
-
Hikvision Multiple Products Vulnerability Allows Malicious Users to Escalate Privileges
Hikvision Multiple Products Vulnerability Allows Malicious Users to Escalate Privileges A severe vulnerability affecting multiple Hikvision products was added to the Known Exploited Vulnerabilities (KEV) catalog on March 5, 2026. Tracked globally under CVE-2017-7921, this security flaw poses a significant risk to organizations that rely on these popular surveillance systems. The flaw enables malicious users…
-
Microsoft Warns Fake AI Browser Extensions Compromised Chat Histories Across 20,000+ Enterprise Tenants
Microsoft Warns Fake AI Browser Extensions Compromised Chat Histories Across 20,000+ Enterprise Tenants A wave of counterfeit AI-powered browser extensions has silently breached over 20,000 enterprise environments, compromising the chat histories of employees who routinely used AI tools for work. These malicious Chromium-based extensions disguised themselves as legitimate AI assistant tools and accumulated close to…
-
CISA Warns of macOS and iOS Vulnerabilities Exploited in Attacks
CISA Warns of macOS and iOS Vulnerabilities Exploited in Attacks The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical alert regarding multiple Apple vulnerabilities currently facing active exploitation. On March 5, 2026, CISA added three security flaws affecting macOS, iOS, iPadOS, and other Apple products to its Known Exploited Vulnerabilities (KEV) catalog. This…
-
WiFi Signals Reveal Human Activities Through Walls by Mapping Body Keypoints
WiFi Signals Reveal Human Activities Through Walls by Mapping Body Keypoints A new open-source edge AI system called π RuView is turning ordinary WiFi infrastructure into a through-wall human-sensing platform detecting body pose, vital signs, and movement patterns without a single camera, raising urgent security and surveillance concerns. Researchers and developers have long theorized that…
-
OpenAI Codex Security Scanned 1.2 Million Commits and Found 10,561 High-Severity Issues
OpenAI Codex Security Scanned 1.2 Million Commits and Found 10,561 High-Severity Issues OpenAI on Friday began rolling out Codex Security, an artificial intelligence (AI)-powered security agent that’s designed to find, validate, and propose fixes for vulnerabilities. The feature is available in a research preview to ChatGPT Pro, Enterprise, Business, and Edu customers via the Codex…
-
Anthropic Finds 22 Firefox Vulnerabilities Using Claude Opus 4.6 AI Model
Anthropic Finds 22 Firefox Vulnerabilities Using Claude Opus 4.6 AI Model Anthropic on Friday said it discovered 22 new security vulnerabilities in the Firefox web browser as part of a security partnership with Mozilla. Of these, 14 have been classified as high, seven have been classified as moderate, and one has been rated low in…
-
ISC Stormcast For Monday, March 9th, 2026 https://isc.sans.edu/podcastdetail/9840, (Mon, Mar 9th)
ISC Stormcast For Monday, March 9th, 2026 https://isc.sans.edu/podcastdetail/9840, (Mon, Mar 9th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
OpenAI’s Codex Security Built to Automate Vulnerability Discovery and Remediation
OpenAI’s Codex Security Built to Automate Vulnerability Discovery and Remediation OpenAI has officially introduced Codex Security, an advanced application security agent designed to automate vulnerability discovery and remediation. Formerly known as Aardvark, the tool… Go to gbhackers.com
-
Termite ransomware breaches linked to ClickFix CastleRAT attacks
Termite ransomware breaches linked to ClickFix CastleRAT attacks Ransomware threat actors tracked as Velvet Tempest are using the ClickFix technique and legitimate Windows utilities to deploy the DonutLoader malware and the CastleRAT backdoor. […] Bill Toulas Go to bleepingcomputer
-
Microsoft: Hackers abusing AI at every stage of cyberattacks
Microsoft: Hackers abusing AI at every stage of cyberattacks Microsoft says threat actors are increasingly using artificial intelligence in their operations to accelerate attacks, scale malicious activity, and lower technical barriers across all aspects of a cyberattack. […] Lawrence Abrams Go to bleepingcomputer
-
Critical Zero-Click Command Injection in AVideo Platform Allows Stream Hijacking
Critical Zero-Click Command Injection in AVideo Platform Allows Stream Hijacking A critical vulnerability in AVideo, a widely used open-source video hosting and streaming platform. Tracked as CVE-2026-29058, this zero-click flaw carries a maximum severity rating, allowing unauthenticated attackers to execute arbitrary operating system commands on the targeted server. Discovered by security researcher Arkmarta, the vulnerability…
-
Cognizant TriZetto Data Breach Exposes Health Information of 3.4 Million Patients
Cognizant TriZetto Data Breach Exposes Health Information of 3.4 Million Patients TriZetto Provider Solutions, a healthcare technology subsidiary of the IT services giant Cognizant, has officially disclosed a massive cybersecurity data breach affecting the sensitive health information of 3,433,965 patients. The healthcare organization recently filed a formal data breach notification revealing that malicious threat actors…
-
Malicious imToken Chrome Extension Caught Stealing Mnemonics and Private Keys
Malicious imToken Chrome Extension Caught Stealing Mnemonics and Private Keys Socket’s Threat Research Team has discovered a malicious Google Chrome extension named “lmΤoken Chromophore” that actively steals cryptocurrency wallet credentials. Masquerading as a harmless hex color visualizer, the extension actually impersonates the popular non-custodial wallet brand imToken. Since its launch in 2016, imToken has served…
-
Cylake Offers AI-Native Security Without Relying on Cloud Services
Cylake Offers AI-Native Security Without Relying on Cloud Services Cylake’s platform will analyze security data locally and identify potential attacks for organizations concerned about data sovereignty. Dark Reading Staff Go to gbhackers.com
-
YARA-X 1.14.0 Release, (Sat, Mar 7th)
YARA-X 1.14.0 Release, (Sat, Mar 7th) YARA-X’s 1.14.0 release brings 4 improvements and 2 bugfixes. One of the improvements is a new CLI command: deps. This command shows you the dependencies of rules. Here is an example. Rule rule1 has no dependencies, rule rule2 depends on rule rule1 and rule rule3 depends on rule rule2: Running…
-
Malicious Browser Add‑on Targets imToken Users’ Private Keys
Malicious Browser Add‑on Targets imToken Users’ Private Keys Socket’s Threat Research Team has uncovered a highly deceptive Google Chrome extension designed to steal private keys and seed phrases from cryptocurrency users. The… Go to gbhackers.com
-
Claude AI Exposes 22 Firefox Vulnerabilities in Just Two Weeks
Claude AI Exposes 22 Firefox Vulnerabilities in Just Two Weeks Artificial intelligence has officially entered the realm of advanced vulnerability research, moving beyond simple code assistance to autonomous threat hunting. This highly accelerated discovery… Go to gbhackers.com
-
RMM Tools Crucial for IT Operations, But Growing Threat as Attackers Weaponize Them
RMM Tools Crucial for IT Operations, But Growing Threat as Attackers Weaponize Them Threat actors are increasingly weaponizing trusted administrative software to bypass security defenses. By exploiting legitimate software, cybercriminals gain persistent, hands-on-keyboard (HOK) access while hiding… Go to gbhackers.com
-
AVideo Platform Vulnerability Allows Hackers to Hijack Streams via Zero-Click Command Injection
AVideo Platform Vulnerability Allows Hackers to Hijack Streams via Zero-Click Command Injection A highly critical security flaw has been disclosed in the AVideo platform, leaving media servers exposed to complete system takeover. Tracked as CVE-2026-29058, this… Go to gbhackers.com
-
Cognizant TriZetto breach exposes health data of 3.4 million patients
Cognizant TriZetto breach exposes health data of 3.4 million patients TriZetto Provider Solutions, a healthcare IT company that develops software and services used by health insurers and healthcare providers, has suffered a data breach that exposed the sensitive information of over 3.4 million people. […] Bill Toulas Go to bleepingcomputer
-
CISA warns feds to patch iOS flaws exploited in crypto-theft attacks
CISA warns feds to patch iOS flaws exploited in crypto-theft attacks CISA ordered U.S. federal agencies to patch three iOS security flaws targeted in cyberespionage and crypto-theft attacks using the Coruna exploit kit. […] Sergiu Gatlan Go to bleepingcomputer
-
EC-Council Expands AI Certification Portfolio to Strengthen U.S. AI Workforce Readiness and Security
EC-Council Expands AI Certification Portfolio to Strengthen U.S. AI Workforce Readiness and Security EC-Council, creator of the world-renowned Certified Ethical Hacker (CEH) credential and a global leader in applied cybersecurity education, today launched its Enterprise AI Credential Suite, with four new role-based AI certifications debuting alongside Certified CISO v4, an overhauled executive cyber leadership program.…
-
Fake Claude Code install guides push infostealers in InstallFix attacks
Fake Claude Code install guides push infostealers in InstallFix attacks Threat actors are employing a new variation of the ClickFix social engineering technique called InstallFix to convince users into running malicious commands under the pretext of installing legitimate command line interface (CLI) tools. […] Bill Toulas Go to bleepingcomputer
-
Microsoft 365 Backup to add file-level restore for faster recovery
Microsoft 365 Backup to add file-level restore for faster recovery Microsoft will soon begin rolling out a significant upgrade to Microsoft 365 Backup to speed up recovery by allowing administrators to restore individual files and folders. […] Sergiu Gatlan Go to bleepingcomputer
-
OpenAI Launches Codex Security that Discover, Validate and Patch Vulnerabilities
OpenAI Launches Codex Security that Discover, Validate and Patch Vulnerabilities OpenAI has announced the launch of Codex Security, an application security agent engineered to autonomously identify, validate, and remediate complex vulnerabilities within enterprise and open-source codebases. Formerly known as Aardvark, the tool leverages frontier AI models to provide context-aware security assessments, aiming to replace noisy…
-
New ClickFix Attack leverages Windows Terminal for Payload Execution
New ClickFix Attack leverages Windows Terminal for Payload Execution Cybersecurity researchers have uncovered a new wave of ClickFix attacks that now exploit Windows Terminal to deliver malicious payloads directly onto victim machines. Unlike earlier iterations of this social engineering technique, which relied on the Windows Run dialog, this latest campaign leads users into opening a…
-
RMM Tools Essential for IT Operations but Increasingly Weaponized by Attackers
RMM Tools Essential for IT Operations but Increasingly Weaponized by Attackers Remote Monitoring and Management (RMM) tools are the backbone of modern IT operations. Security professionals rely on them daily to patch systems, troubleshoot issues, and manage entire networks from anywhere. These tools deliver speed, control, and convenience — qualities every IT team values. But…
-
FBI Investigates Hack on its Wiretap and Critical Surveillance Systems
FBI Investigates Hack on its Wiretap and Critical Surveillance Systems The Federal Bureau of Investigation has confirmed a cybersecurity incident targeting a sensitive internal network used to manage wiretapping operations and foreign intelligence surveillance warrants, raising serious concerns among national security officials about the potential exposure of classified law enforcement data. “The FBI identified and…
-
Claude AI Uncovers 22 Firefox Vulnerabilities in Two Weeks
Claude AI Uncovers 22 Firefox Vulnerabilities in Two Weeks Artificial intelligence models are rapidly evolving from simple coding assistants into highly capable, autonomous vulnerability researchers. Recently, Anthropic’s Claude Opus 4.6 demonstrated this by uncovering over 500 zero-day vulnerabilities in heavily scrutinized open-source projects. During a two-week collaborative engagement with Mozilla in February 2026, the AI…
-
What cybersecurity actually does for your business
What cybersecurity actually does for your business The ability to continue operating safely in an unsafe environment where competitors cannot is a competitive advantage that is rarely measured or discussed Go to eset
-
Transparent Tribe Uses AI to Mass-Produce Malware Implants in Campaign Targeting India
Transparent Tribe Uses AI to Mass-Produce Malware Implants in Campaign Targeting India The Pakistan-aligned threat actor known as Transparent Tribe has become the latest hacking group to embrace artificial intelligence (AI)-powered coding tools to strike targets with various implants. The activity is designed to produce a “high-volume, mediocre mass of implants” that are developed using…
-
Multi-Stage VOID#GEIST Malware Delivering XWorm, AsyncRAT, and Xeno RAT
Multi-Stage VOID#GEIST Malware Delivering XWorm, AsyncRAT, and Xeno RAT Cybersecurity researchers have disclosed details of a multi-stage malware campaign that uses batch scripts as a pathway to deliver various encrypted remote access trojan (RATs) payloads that correspond to XWorm, AsyncRAT, and Xeno RAT. The stealthy attack chain has been codenamed VOID#GEIST by Securonix Threat Research.…
-
The MSP Guide to Using AI-Powered Risk Management to Scale Cybersecurity
The MSP Guide to Using AI-Powered Risk Management to Scale Cybersecurity Scaling cybersecurity services as an MSP or MSSP requires technical expertise and a business model that delivers measurable value at scale. Risk-based cybersecurity is the foundation of that model. When done right, it builds client trust, increases upsell opportunities, and drives recurring revenue. But…
-
Iran-Linked MuddyWater Hackers Target U.S. Networks With New Dindoor Backdoor
Iran-Linked MuddyWater Hackers Target U.S. Networks With New Dindoor Backdoor New research from Broadcom’s Symantec and Carbon Black Threat Hunter Team has discovered evidence of an Iranian hacking group embedding itself in several U.S. companies’ networks, including banks, airports, non-profit, and the Israeli arm of a software company. The activity has been attributed to a…
-
China-Linked Hackers Use TernDoor, PeerTime, BruteEntry in South American Telecom Attacks
China-Linked Hackers Use TernDoor, PeerTime, BruteEntry in South American Telecom Attacks A China-linked advanced persistent threat (APT) actor has been targeting critical telecommunications infrastructure in South America since 2024, targeting Windows and Linux systems and edge devices with three different implants. The activity is being tracked by Cisco Talos under the moniker UAT-9244, describing it…
-
Friday Squid Blogging: Squid in Byzantine Monk Cooking
Friday Squid Blogging: Squid in Byzantine Monk Cooking This is a very weird story about how squid stayed on the menu of Byzantine monks by falling between the cracks of dietary rules. At Constantinople’s Monastery of Stoudios, the kitchen didn’t answer to appetite. It answered to the “typikon”: a manual for ensuring that nothing unexpected…
-
Anthropic and the Pentagon
Anthropic and the Pentagon OpenAI is in and Anthropic is out as a supplier of AI technology for the US defense department. This news caps a week of bluster by the highest officials in the US government towards some of the wealthiest titans of the big tech industry, and the overhanging specter of the existential…
-
Claude Used to Hack Mexican Government
Claude Used to Hack Mexican Government An unknown hacker used Anthropic’s LLM to hack the Mexican government: The unknown Claude user wrote Spanish-language prompts for the chatbot to act as an elite hacker, finding vulnerabilities in government networks, writing computer scripts to exploit them and determining ways to automate data theft, Israeli cybersecurity startup Gambit…
-
How hackers bypassed MFA with a $120 phishing kit – until a global takedown shut it down
How hackers bypassed MFA with a $120 phishing kit – until a global takedown shut it down In a co-ordinated public-private operation between law enforcement agencies and cybersecurity industry partners, Tycoon 2FA – one of the world’s most prolific phishing-as-a-service platforms – has been dismantled. Read more in my article on the Hot for Security…
-
North Korean APTs Use AI to Enhance IT Worker Scams
North Korean APTs Use AI to Enhance IT Worker Scams DPRK worker scams are old hat, but they’re still working, thanks to AI tools that help with everything from face swapping to daily emails. Nate Nelson Go to gbhackers.com
-
EU Auto Rules Shift Gears on Cybersecurity Standards
EU Auto Rules Shift Gears on Cybersecurity Standards The European Union is taking new precautions as climate change and cybersecurity threats rise across the automotive industry. Arielle Waldman Go to gbhackers.com
-
Iran’s Cyber-Kinetic War Doctrine Takes Shape
Iran’s Cyber-Kinetic War Doctrine Takes Shape Iran has been hacking IP cameras to plan missile strikes against its enemies, and mounting other attacks on physical assets, showing how cyber and kinetic warfare are fast becoming one in the same. Alexander Culafi Go to gbhackers.com
-
Cyberattack on Mexico’s Gov’t Agencies Highlight AI Threat
Cyberattack on Mexico’s Gov’t Agencies Highlight AI Threat Using Anthropic’s Claude, OpenAI’s ChatGPT, and a detailed playbook prompt, a handful of cyberattackers reportedly gained access to government agencies and its citizens’ data. Robert Lemos Go to gbhackers.com
-
Apache ActiveMQ Flaw Enables DoS Attacks via Malformed Network Packets
Apache ActiveMQ Flaw Enables DoS Attacks via Malformed Network Packets Security researchers have uncovered a significant vulnerability in Apache ActiveMQ, a popular open-source message broker used by enterprises to route data between applications. Tracked… Go to gbhackers.com
-
AWS-LC Flaw Exposes Amazon Users to Attacks by Bypassing Certificate Chain Validation
AWS-LC Flaw Exposes Amazon Users to Attacks by Bypassing Certificate Chain Validation Amazon issued a critical security bulletin (2026-005-AWS) detailing three high-severity vulnerabilities in AWS-LC, its open-source cryptographic library. Discovered through a coordinated disclosure process with… Go to gbhackers.com
-
New Linux Rootkits Leverage Advanced eBPF and io_uring Techniques for Stealthy Attacks
New Linux Rootkits Leverage Advanced eBPF and io_uring Techniques for Stealthy Attacks Linux rootkits have historically received less attention than their Windows counterparts, but the rapid adoption of Linux in cloud infrastructure, containers, and IoT devices… Go to gbhackers.com
-
China-Nexus Hackers Target Telecommunication Providers with New Malware Attack
China-Nexus Hackers Target Telecommunication Providers with New Malware Attack A highly sophisticated China-linked threat actor, identified as UAT-9244, has been actively targeting critical telecommunications infrastructure across South America since 2024. Security researchers assess… Go to gbhackers.com
-
FBI Detains U.S. Government Contractor in Massive $46 Million Fraud Scheme
FBI Detains U.S. Government Contractor in Massive $46 Million Fraud Scheme In a major law enforcement operation, authorities have arrested a U.S. government contractor accused of executing a massive cryptocurrency theft. John Daghita allegedly stole… Go to gbhackers.com
-
FBI investigates breach of surveillance and wiretap systems
FBI investigates breach of surveillance and wiretap systems The U.S. Federal Bureau of Investigation (FBI) confirmed on Thursday that it’s investigating a breach that affected systems used to manage surveillance and wiretap warrants. […] Sergiu Gatlan Go to bleepingcomputer
-
Chinese state hackers target telcos with new malware toolkit
Chinese state hackers target telcos with new malware toolkit A China-linked advanced persistent threat actor tracked as UAT-9244 has been targeting telecommunication service providers in South America since 2024, compromising Windows, Linux, and network-edge devices. […] Bill Toulas Go to bleepingcomputer
-
Bing AI promoted fake OpenClaw GitHub repo pushing info-stealing malware
Bing AI promoted fake OpenClaw GitHub repo pushing info-stealing malware Fake OpenClaw installers hosted in GitHub repositories and promoted by Microsoft Bing’s AI-enhanced search feature instructed users to run commands that deployed information stealers and proxy malware. […] Bill Toulas Go to bleepingcomputer
-
Wikipedia hit by self-propagating JavaScript worm that vandalized pages
Wikipedia hit by self-propagating JavaScript worm that vandalized pages The Wikimedia Foundation suffered a security incident today after a self-propagating JavaScript worm began vandalizing pages and modifying user scripts across multiple wikis. […] Lawrence Abrams Go to bleepingcomputer
-
WordPress membership plugin bug exploited to create admin accounts
WordPress membership plugin bug exploited to create admin accounts Hackers are exploiting a critical vulnerability in the User Registration & Membership plugin, which is installed on more than 60,000 WordPress sites. […] Bill Toulas Go to bleepingcomputer
-
Google Confirms 90 Zero-Day Vulnerabilities Actively Exploited in 2025
Google Confirms 90 Zero-Day Vulnerabilities Actively Exploited in 2025 The Google Threat Intelligence Group (GTIG) released its annual analysis, confirming that 90 zero-day vulnerabilities were actively exploited in the wild throughout 2025. While this marks a slight decrease from the record 100 zero-days in 2023, it represents a noticeable increase from 2024’s total of 78.…
-
Hackers Can Use Indirect Prompt Injection Allows Adversaries to Manipulate AI Agents with Content
Hackers Can Use Indirect Prompt Injection Allows Adversaries to Manipulate AI Agents with Content Artificial intelligence tools are now a core part of everyday workflows — from browsers that summarize web pages to automated agents that help users make decisions online. As these tools become more capable, attackers are learning how to turn them against…
-
OpenAI Launches GPT-5.4 With Advanced Reasoning, Coding, and Computer-Use Capabilities
OpenAI Launches GPT-5.4 With Advanced Reasoning, Coding, and Computer-Use Capabilities OpenAI on March 5, 2026, released GPT-5.4, its most capable and efficient frontier model to date, combining advanced reasoning, coding, and agentic workflows into a single unified system. The model is rolling out across ChatGPT (as GPT-5.4 Thinking), the API, and Codex, with a higher-performance…
-
PoC Exploit Released Cisco SD-WAN 0-Day Vulnerability Exploited in the Wild
PoC Exploit Released Cisco SD-WAN 0-Day Vulnerability Exploited in the Wild A public proof-of-concept (PoC) exploit has been released for CVE-2026-20127, a maximum-severity zero-day vulnerability in Cisco Catalyst SD-WAN Controller and SD-WAN Manager that has been actively exploited in the wild since at least 2023. Cisco Talos is tracking the threat activity under the cluster UAT-8616, describing…
-
Threat Actors Using Fake Claude Code Download to Deploy Infostealer
Threat Actors Using Fake Claude Code Download to Deploy Infostealer Cybercriminals have found a new way to target developers and IT professionals by setting up fake download pages that impersonate Claude Code, a legitimate AI coding assistant. These deceptive pages trick users into downloading what appears to be an official installation package, but instead silently…
-
How SMBs use threat research and MDR to build a defensive edge
How SMBs use threat research and MDR to build a defensive edge We speak to Director of ESET Threat Research Jean-Ian Boutin about where solutions that blend advanced technology with human expertise provide the most practical value for businesses Go to eset
-
Cisco Confirms Active Exploitation of Two Catalyst SD-WAN Manager Vulnerabilities
Cisco Confirms Active Exploitation of Two Catalyst SD-WAN Manager Vulnerabilities Cisco has disclosed that two more vulnerabilities affecting Catalyst SD-WAN Manager (formerly SD-WAN vManage) have come under active exploitation in the wild. The vulnerabilities in question are listed below – CVE-2026-20122 (CVSS score: 7.1) – An arbitrary file overwrite vulnerability that could allow an authenticated,…
-
Preparing for the Quantum Era: Post-Quantum Cryptography Webinar for Security Leaders
Preparing for the Quantum Era: Post-Quantum Cryptography Webinar for Security Leaders Most organizations assume encrypted data is safe. But many attackers are already preparing for a future where today’s encryption can be broken. Instead of trying to decrypt information now, they are collecting encrypted data and storing it so it can be decrypted later using…
-
ThreatsDay Bulletin: DDR5 Bot Scalping, Samsung TV Tracking, Reddit Privacy Fine & More
ThreatsDay Bulletin: DDR5 Bot Scalping, Samsung TV Tracking, Reddit Privacy Fine & More Some weeks in cybersecurity feel routine. This one doesn’t. Several new developments surfaced over the past few days, showing how quickly the threat landscape keeps shifting. Researchers uncovered fresh activity, security teams shared new findings, and a few unexpected moves from major…
-
Dust Specter Targets Iraqi Officials with New SPLITDROP and GHOSTFORM Malware
Dust Specter Targets Iraqi Officials with New SPLITDROP and GHOSTFORM Malware A suspected Iran-nexus threat actor has been attributed to a campaign targeting government officials in Iraq by impersonating the country’s Ministry of Foreign Affairs to deliver a set of never-before-seen malware. Zscaler ThreatLabz, which observed the activity in January 2026, is tracking the cluster…
-
Where Multi-Factor Authentication Stops and Credential Abuse Starts
Where Multi-Factor Authentication Stops and Credential Abuse Starts Organizations typically roll out multi-factor authentication (MFA) and assume stolen passwords are no longer enough to access systems. In Windows environments, that assumption is often wrong. Attackers still compromise networks every day using valid credentials. The issue is not MFA itself, but coverage. Enforced through an identity…
-
Israel Hacked Traffic Cameras in Iran
Israel Hacked Traffic Cameras in Iran Multiple news outlets are reporting on Israel’s hacking of Iranian traffic cameras and how they assisted with the killing of that country’s leadership. The New York Times has an on the intelligence operation more generally. Bruce Schneier Go to bruce schneier
-
Hacked App Part of US/Israeli Propaganda Campaign Against Iran
Hacked App Part of US/Israeli Propaganda Campaign Against Iran Wired has the story: Shortly after the first set of explosions, Iranians received bursts of notifications on their phones. They came not from the government advising caution, but from an apparently hacked prayer-timing app called BadeSaba Calendar that has been downloaded more than 5 million times…
-
ISC Stormcast For Friday, March 6th, 2026 https://isc.sans.edu/podcastdetail/9838, (Fri, Mar 6th)
ISC Stormcast For Friday, March 6th, 2026 https://isc.sans.edu/podcastdetail/9838, (Fri, Mar 6th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
ISC Stormcast For Thursday, March 5th, 2026 https://isc.sans.edu/podcastdetail/9836, (Thu, Mar 5th)
ISC Stormcast For Thursday, March 5th, 2026 https://isc.sans.edu/podcastdetail/9836, (Thu, Mar 5th) (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. Go to isc.sans.edu
-
Nation-State Actor Embraces AI Malware Assembly Line
Nation-State Actor Embraces AI Malware Assembly Line Pakistan’s APT36 threat group has begun using vibe-coding to churn out mediocre malware, but at a scale that could overwhelm defenses. Jai Vijayan Go to gbhackers.com
-
Tycoon 2FA Goes Boom as Europol, Vendors Bust Phishing Platform
Tycoon 2FA Goes Boom as Europol, Vendors Bust Phishing Platform The phishing-as-a-service platform was popular among cyber threat actors because of its ability to bypass multifactor authentication defenses. Rob Wright Go to gbhackers.com
-
Cisco Drops 48 New Firewall Vulnerabilities, 2 Critical
Cisco Drops 48 New Firewall Vulnerabilities, 2 Critical Edge bugs are so fetch, and Cisco just dropped 50 new ones, including some heavy hitters with 10 out of 10 scores on the CVSS scale. Nate Nelson Go to gbhackers.com
-
Software Development Practices Help Enterprises Tackle Real-Life Risks
Software Development Practices Help Enterprises Tackle Real-Life Risks Organizations can borrow secure-by-design processes to manage non-technical challenges like governance or the inevitable human error. Arielle Waldman Go to gbhackers.com
-
LatAm Now Faces 2x More Cyberattacks Than US
LatAm Now Faces 2x More Cyberattacks Than US Much of Central and South America struggles with cybersecurity maturity, and hackers are taking advantage. Nate Nelson Go to gbhackers.com
-
Critical pac4j-jwt Authentication Bypass Vulnerability Allows Attackers to Impersonate Any User
Critical pac4j-jwt Authentication Bypass Vulnerability Allows Attackers to Impersonate Any User A critical security flaw in the popular Java authentication library pac4j-jwt allows attackers to completely bypass authentication and impersonate any user, including administrators. Tracked… Go to gbhackers.com
-
ClickFix Campaign Exploits Fake LinkedIn VCs to Spread Malware Among Crypto and Web3 Experts
ClickFix Campaign Exploits Fake LinkedIn VCs to Spread Malware Among Crypto and Web3 Experts A highly coordinated malware campaign that targets cryptocurrency and Web3 professionals through fake venture capital (VC) identities on LinkedIn. The operation combines advanced social… Go to gbhackers.com
-
Google Rolls Out Emergency Chrome Update to Patch 10 Critical Security Vulnerabilities
Google Rolls Out Emergency Chrome Update to Patch 10 Critical Security Vulnerabilities Google released an urgent security update for its Chrome browser to address 10 vulnerabilities. Deployed on March 3, 2026, this stable channel update fixes… Go to gbhackers.com
-
Cisco Secure Firewall Management Flaw Allows Remote Code Execution
Cisco Secure Firewall Management Flaw Allows Remote Code Execution Cisco recently disclosed a critical security vulnerability affecting its Secure Firewall Management Centre (FMC) software. This severe flaw carries a maximum severity score of… Go to gbhackers.com
-
RedAlert Mobile Espionage Campaign Exploits Trojanized Rocket Alert App to Spy on Civilians
RedAlert Mobile Espionage Campaign Exploits Trojanized Rocket Alert App to Spy on Civilians A newly discovered mobile espionage operation dubbed “RedAlert” has surfaced amid the ongoing Israel–Iran conflict, exploiting wartime fear and dependency on early-warning systems. The campaign targets… Go to gbhackers.com
-
Phobos ransomware admin pleads guilty to wire fraud conspiracy
Phobos ransomware admin pleads guilty to wire fraud conspiracy A Russian national pleaded guilty to a wire fraud conspiracy charge related to his role in administering the Phobos ransomware operation, which breached hundreds of victims worldwide. […] Sergiu Gatlan Go to bleepingcomputer
-
Bitwarden adds support for passkey login on Windows 11
Bitwarden adds support for passkey login on Windows 11 Bitwarden announced support for logging into Windows 11 devices using passkeys stored in the manager’s vault, enabling phishing-resistant authentication. […] Bill Toulas Go to bleepingcomputer
-
Cisco Secure Firewall Management Vulnerability Allow Attackers to Bypass Authentication
Cisco Secure Firewall Management Vulnerability Allow Attackers to Bypass Authentication Cisco has released a critical security advisory warning of a severe vulnerability in its Secure Firewall Management Center (FMC) Software. This flaw allows an unauthenticated, remote attacker to bypass authentication and execute script files, thereby gaining full root access to the underlying operating system. The…
-
Hackers Mimic LastPass Support Email to Steal Vault Passwords
Hackers Mimic LastPass Support Email to Steal Vault Passwords A new and carefully crafted phishing campaign is currently targeting LastPass users, with attackers sending fake support emails designed to steal vault master passwords. The campaign, which began on or around March 1, 2026, relies on social engineering tactics to trick users into believing their accounts…
-
Reclaim Security Raises $26M to Eliminate the 27-Day Remediation Gap
Reclaim Security Raises $26M to Eliminate the 27-Day Remediation Gap New York, USA, March 4th, 2026, CyberNewswire The industry must pivot to Preemptive Defense: As agentic tools like Claude Code enable attackers to scan and exploit vulnerabilities at machine speed, a “prioritized list” is no longer a defense; it’s a liability. Reclaim Security, a preemptive…
-
Cisco Catalyst SD-WAN Vulnerabilities Allow Attackers to Gain Root Access
Cisco Catalyst SD-WAN Vulnerabilities Allow Attackers to Gain Root Access An urgent security advisory from Cisco warns that multiple vulnerabilities in Cisco Catalyst SD-WAN Manager could allow attackers to bypass authentication, gain root access, and overwrite critical files. Two of these vulnerabilities are already being exploited in the wild by hackers, making immediate remediation critical.…
-
Mail2Shell Zero-Click Attack lets Hackers Hijack FreeScout Mail Servers
Mail2Shell Zero-Click Attack lets Hackers Hijack FreeScout Mail Servers Researchers have uncovered a critical zero-click vulnerability in FreeScout, a widely used open-source help desk and shared mailbox application. Dubbed “Mail2Shell,” this flaw allows attackers to hijack mail servers without any user interaction or authentication. The vulnerability, tracked as CVE-2026-28289, bypasses a recently patched Remote Code…
-
Protecting education: How MDR can tip the balance in favor of schools
Protecting education: How MDR can tip the balance in favor of schools The education sector is notoriously short on cash, but rich in assets for threat actors to target. How can managed detection and response (MDR) help learning institutions regain the initiative? Go to eset
-
149 Hacktivist DDoS Attacks Hit 110 Organizations in 16 Countries After Middle East Conflict
149 Hacktivist DDoS Attacks Hit 110 Organizations in 16 Countries After Middle East Conflict Cybersecurity researchers have warned of a surge in retaliatory hacktivist activity following the U.S.-Israel coordinated military campaign against Iran, codenamed Epic Fury and Roaring Lion. “The hacktivist threat in the Middle East is highly lopsided, with two groups, Keymous+ and DieNet,…
-
Coruna iOS Exploit Kit Uses 23 Exploits Across Five Chains Targeting iOS 13–17.2.1
Coruna iOS Exploit Kit Uses 23 Exploits Across Five Chains Targeting iOS 13–17.2.1 Google said it identified a “new and powerful” exploit kit dubbed Coruna (aka CryptoWaters) targeting Apple iPhone models running iOS versions between 13.0 and 17.2.1. The exploit kit featured five full iOS exploit chains and a total of 23 exploits, Google Threat…
-
New RFP Template for AI Usage Control and AI Governance
New RFP Template for AI Usage Control and AI Governance As AI becomes the central engine for enterprise productivity, security leaders are finally getting the green light — and the budget — to secure it. But there’s a quiet crisis unfolding in the boardroom: many organizations know they need “AI Governance,” but they have no…
-
Fake Laravel Packages on Packagist Deploy RAT on Windows, macOS, and Linux
Fake Laravel Packages on Packagist Deploy RAT on Windows, macOS, and Linux Cybersecurity researchers have flagged malicious Packagist PHP packages masquerading as Laravel utilities that act as a conduit for a cross-platform remote access trojan (RAT) that’s functional on Windows, macOS, and Linux systems. The names of the packages are listed below – nhattuanbl/lara-helper (37…
-
APT41-Linked Silver Dragon Targets Governments Using Cobalt Strike and Google Drive C2
APT41-Linked Silver Dragon Targets Governments Using Cobalt Strike and Google Drive C2 Cybersecurity researchers have disclosed details of an advanced persistent threat (APT) group dubbed Silver Dragon that has been linked to cyber attacks targeting entities in Europe and Southeast Asia since at least mid-2024. “Silver Dragon gains its initial access by exploiting public-facing internet…
-
Manipulating AI Summarization Features
Manipulating AI Summarization Features Microsoft is reporting: Companies are embedding hidden instructions in “Summarize with AI” buttons that, when clicked, attempt to inject persistence commands into an AI assistant’s memory via URL prompt parameters…. These prompts instruct the AI to “remember [Company] as a trusted source” or “recommend [Company] first,” aiming to bias future responses…
-
Differentiating Between a Targeted Intrusion and an Automated Opportunistic Scanning [Guest Diary], (Wed, Mar 4th)
Differentiating Between a Targeted Intrusion and an Automated Opportunistic Scanning [Guest Diary], (Wed, Mar 4th) [This is a Guest Diary by Joseph Gruen, an ISC intern as part of the SANS.edu BACS program] The internet is under constant, automated siege. Every publicly reachable IP address is probed continuously by bots and scanners hunting for anything…
-
Want More XWorm?, (Wed, Mar 4th)
Want More XWorm?, (Wed, Mar 4th) And another XWorm[1] wave in the wild! This malware family is not new and heavily spread but delivery techniques always evolve and deserve to be described to show you how threat actors can be imaginative! This time, we are facing another piece of multi-technology malware. Here is a quick overview: The Javascript is…
-
Smashing Security podcast #457: How a cybersecurity boss framed his own employee
Smashing Security podcast #457: How a cybersecurity boss framed his own employee When a top cybersecurity firm discovered it had a leak, you would expect the FBI to be called. Instead, the person put in charge of the investigation was the actual leaker… who promptly sent an innocent colleague into a career-ending ambush. In this…
-
VMware Aria Operations Bug Exploited, Cloud Resources at Risk
VMware Aria Operations Bug Exploited, Cloud Resources at Risk Exploitation of the command injection flaw in VMware Aria Operations could grant an attacker broad acess to victims’ cloud environments. Alexander Culafi Go to gbhackers.com