AI-Powered Phishing, Android Spying Tool, Linux Exploit, GitHub RCE & More

Ravie LakshmananMay 04, 2026Cybersecurity / Hacking This week, the shadows moved faster than the patches. While most teams were still triaging last month’s alerts, attackers had already turned control panels into kill switches, kernels into open doors, and open-source pipelines into silent delivery systems. The game has shifted from breach to occupation. They’re living inside […]
The year of AI-assisted attacks

On December 4, 2025, a 17-year-old boy was arrested in Osaka under Japan’s Unauthorized Access Prevention Act. The young man was running malicious code that extracted the personal data of more than 7 million users of Kaikatsu Club, Japan’s largest internet cafe chain. When asked, the young man explained his motivation for the hack. Because […]
Silver Fox deploys ABCDoor malware in India and Russia via tax-themed phishing

Ravi LakshmananMay 4, 2026Malware/Network Security A China-based cybercrime group known as Silver Fox is said to be involved in a new campaign targeting organizations in Russia and India using a new malware called ABCDoor. The campaign used a phishing email mimicking a communication from India’s Income Tax Department in December 2025, followed by a similar […]
Critical cPanel vulnerability exploited to target government and MSP networks

Ravi LakshmananMay 4, 2026Vulnerability/Network Security A previously unknown attacker was observed exploiting a recently disclosed cPanel vulnerability to target small clusters of managed service providers (MSPs) and hosting providers in the Philippines, Laos, Canada, South Africa, and the United States, as well as government and military organizations in Southeast Asia. This activity, detected by Ctrl-Alt-Intel […]
Zscaler ThreatLabz 2026 VPN Risk Report

Your VPN is helping attackers move as fast as AI of Zscaler ThreatLabz 2026 VPN Risk Report A dangerous disconnect is revealed. While attackers use AI to move at machine speed, legacy VPNs blind defenders and leave them exposed. Not being able to see what is happening greatly reduces response time and the likelihood of […]
Global crackdown arrests 276 people, shuts down 9 crypto fraud centers and seizes $701 million

A coordinated international operation involving U.S. and Chinese authorities has resulted in the arrest of at least 276 suspects and the closure of nine fraud centers used in a cryptocurrency investment fraud scheme targeting Americans, resulting in millions of dollars in losses. The crackdown was led by Dubai Police, part of the United Arab Emirates […]
A technical guide to secure Vibe coding: Prompts to production

Important pointsVibe Coding introduces a new shared responsibility modelAI platforms generate and host applications, but they do not secure them. Organizations remain responsible for authentication, data access, secrets, and application logic.Insecure defaults can spread risk across all applicationsIf security gaps exist in platform templates or generated code, they will be replicated to all apps built […]
CISA actively exploited Linux root access bug CVE-2026-31431 added to KEV

Ravi LakshmananMay 3, 2026Vulnerabilities / Container Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added recently revealed security flaws affecting various Linux distributions to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of them being exploited in the wild. This vulnerability is tracked as CVE-2026-31431 (CVSS score: 7.8) and is a case […]
Trellix confirms source code breach due to unauthorized repository access

Ravi LakshmananMay 2, 2026Data Breach/Enterprise Security Cybersecurity company Trellix has announced that it has suffered a breach that allowed unauthorized access to “portions” of its source code. The company said it had “recently identified” a breach of its source code repository and had begun working with “leading forensic experts” to immediately resolve the issue. He […]
Google AppSheet phishing campaign hacks 30,000 Facebook accounts

Ravi LakshmananMay 1, 2026Malware/Threat Intelligence A newly discovered Vietnam-related operation was observed using Google AppSheet as a “phishing relay” to distribute phishing emails aimed at compromising Facebook accounts. The operation was codenamed AccountDumpling by Guardio, and the plan was to sell stolen accounts back through illegal storefronts operated by threat actors. In total, it is […]