DAEMON Tools supply chain attack compromises official installer with malware

Ravi LakshmananMay 5, 2026Endpoint security/software security Kaspersky Lab findings reveal a new supply chain attack targeting the DAEMON Tools software, whose installer was compromised and delivered a malicious payload. “These installers are distributed from the official DAEMON Tools website and are signed with digital certificates owned by the DAEMON Tools developers,” said Kaspersky researchers Igor […]
China-linked UAT-8302 uses regionally shared APT malware to target governments

Ravi LakshmananMay 5, 2026Network security/endpoint security Attacks by advanced persistent threat (APT) groups aligned with China are believed to target government agencies in South America from at least late 2024 onwards, and in southeastern Europe by 2025. This activity is being tracked by Cisco Talos as UAT-8302, and post-exploitation activity includes the deployment of a […]
Backdoor attackers know, but most security teams haven’t shut them down yet

All the AI tools, workflow automation, and productivity apps that employees have connected to Google and Microsoft this year have left something behind. It’s a persistent OAuth token with no expiration date, no automatic cleanup, and, in most organizations, no one to monitor it. Boundary controls don’t know about it. MFA doesn’t stop that. And […]
MetInfo CMS CVE-2026-29014 can be exploited for remote code execution attacks

Ravi LakshmananMay 5, 2026Vulnerability/Network Security Threat actors are actively exploiting a critical security flaw affecting the open-source content management system (CMS) known as MetInfo, according to new findings from VulnCheck. The vulnerability in question is CVE-2026-29014 (CVSS score: 9.8), which is a code injection flaw that could lead to arbitrary code execution. The NIST National […]
We scanned 1 million publicly available AI services. How Bad Is Security Really?

The software industry has made real strides in delivering products securely over the past few decades, but the breakneck pace of AI adoption is putting that progress at risk. The promise of AI as a power multiplier and the pressure to deliver more value, faster, are driving companies to rapidly migrate to self-hosted LLM infrastructure. […]
ScarCruft hacks gaming platforms and deploys BirdCall malware on Android and Windows

Ravi LakshmananMay 5, 2026Cyber espionage/surveillance A North Korean-aligned state-sponsored hacker group known as ScarCruft compromised video gaming platforms with supply chain espionage attacks and trojanized their components with a backdoor called BirdCallto, likely targeting ethnic Koreans living in China. While previous versions of the backdoor primarily targeted only Windows users, the supply chain attack is […]
Weaver E-cology RCE flaw CVE-2026-22679 can be actively exploited via the debug API

Ravi LakshmananMay 5, 2026Vulnerability/Network Security A critical security vulnerability in Weaver (Fanwei) E-cology, an enterprise office automation (OA) and collaboration platform, has been exploited in the wild. This vulnerability (CVE-2026-22679, CVSS score: 9.8) is related to an unauthenticated remote code execution case that affects Weaver E-cology 10.0 versions prior to 20260312. The issue exists in […]
Microsoft details phishing campaign that targeted 35,000 users in 26 countries

Microsoft has revealed details of a large-scale credential theft campaign that combines decoy-themed code with legitimate email services to lure users to attacker-controlled domains and steal authentication tokens. This multi-stage campaign, observed from April 14th to 16th, 2026, targeted over 35,000 users in over 13,000 organizations across 26 countries, with 92% of targets located in […]
Phishing campaign using SimpleHelp and ScreenConnect RMM tools hits over 80 organizations

Ravi LakshmananMay 4, 2026Network security/endpoint security Since at least April 2025, we have observed active phishing campaigns targeting multiple vectors, using legitimate remote monitoring and management (RMM) software as a way to establish persistent remote access to compromised hosts. According to Securonix, the operation, codenamed VENOMOUS#HELPER, has affected more than 80 organizations, most of them […]
Progress on patching critical MOVEit automation bug to enable authentication bypass

Ravi LakshmananMay 4, 2026Vulnerabilities / Enterprise Software Progress Software has released an update that addresses two security flaws in MOVEit Automation, including a critical bug that could lead to authentication bypass. MOVEit Automation (formerly Central) is a secure, server-based managed file transfer (MFT) solution used to schedule and automate file movement workflows in enterprise environments […]