VECT 2.0 ransomware irreversibly destroys files larger than 131KB on Windows, Linux, and ESXi

Threat hunters warn that the cybercrime campaign known as VECT 2.0 acts more like a wiper than a ransomware, as the encryption implementation across Windows, Linux, and ESXi variants has critical flaws that make recovery impossible even for attackers. The fact that VECT’s locker permanently destroys large files rather than encrypting them means that even […]
Why secure data movement is the Zero Trust bottleneck that no one talks about

All security programs are based on the same premise: once the system is connected, the problem is resolved. Open a ticket, launch a gateway, and push data through. end. That assumption is wrong. This is also the main reason why Zero Trust programs stall. A new study my team just published shows the numbers. The […]
Unpatched critical flaw exposes Hugface LeRobot to uncertified RCE

Ravi LakshmananApril 28, 2026Vulnerability/Network Security Cybersecurity researchers have detailed a critical security flaw affecting LeRobot, Hugging Face’s open-source robotics platform, which has approximately 24,000 GitHub stars. This could be exploited to lead to remote code execution. The vulnerability in question is CVE-2026-25874 (CVSS score: 9.3), which is described as a case of untrusted data deserialization […]
A new handbook for the zero window era

When patching isn’t fast enough, NDR helps contain the next generation of threats. If you’ve been following advances in AI, you know that the exploit window, the short buffer that organizations relied on to patch and protect vulnerabilities after they were made public, is rapidly closing. Anthropic’s new model, Claude Mythos and his project Glasswing, […]
Chinese Silk Typhoon hacker extradited to US for coronavirus research cyber attack

Ravi LakshmananApril 28, 2026Cyber espionage/vulnerabilities A Chinese national accused of being a member of the Silk Typhoon hacking group has been extradited from Italy to the United States. Xu Zewei, 34, was arrested by Italian authorities in July 2025 on suspicion of ties to a Chinese state-backed threat group and for orchestrating cyberattacks against U.S. […]
Microsoft patches Entra ID role flaw that allowed service principal takeover

Ravi LakshmananApril 28, 2026Vulnerability/Identity Management Administrative roles for artificial intelligence (AI) agents within Microsoft Entra ID could potentially enable privilege escalation and identity takeover attacks, according to new findings from Silverfort. Agent Identity Administrator is a privileged built-in role introduced by Microsoft as part of the Agent Identity Platform to handle all aspects of identity […]
Microsoft confirms active exploitation of Windows Shell CVE-2026-32202

Ravi LakshmananApril 28, 2026Vulnerability/Threat Intelligence Microsoft on Monday revised its advisory for a currently patched high-severity security flaw affecting Windows Shell, acknowledging that the vulnerability is indeed being actively exploited. The vulnerability in question is CVE-2026-32202 (CVSS score: 4.3), a spoofing vulnerability that could allow attackers to access sensitive information. This issue was addressed as […]
Checkmarx confirms GitHub repository data posted to dark web after March 23rd attack

Ravi LakshmananApril 27, 2026 Checkmarx has revealed that an ongoing investigation related to a supply chain security incident has revealed that a cybercriminal group had published data related to the company on the dark web. “Based on current evidence, we believe this data comes from Checkmarx’s GitHub repository and that access to that repository was […]
Fast16 Malware, XChat Launch, Federal Backdoor, AI Employee Tracking & More

Ravie LakshmananApr 27, 2026Cybersecurity / Hacking Everything is dumb again. This week feels broken in a very familiar way. Old tricks are back. New tools are doing shady crap. Supply chains got hit. Fake help desks worked. Weird research showed how easy some attacks still are. Most of it feels like stuff we should have […]
Myths have changed the calculus of vulnerability discovery. Most teams are not ready on the repair side.

Anthropic’s Claude Mythos Preview has dominated security discussions since its April 7th announcement. Initial reports describe powerful AI systems focused on cybersecurity that can identify vulnerabilities at scale and raise serious questions about how quickly organizations can verify, prioritize, and remediate discovered vulnerabilities. Subsequent discussions have largely focused on the pertinent question of whether this […]