PhantomCore exploits TrueConf vulnerability to infiltrate Russian networks

A pro-Ukrainian hacktivist group called PhantomCore is said to have actively targeted servers running TrueConf video conferencing software in Russia since September 2025. This is according to a report published by Positive Technologies, which found that attackers were able to leverage an exploit chain of three vulnerabilities to remotely execute commands on susceptible servers. “Despite […]

Researchers discover 73 fake VS Code extensions delivering GlassWorm v2 malware

Ravi LakshmananApril 27, 2026Malware/Software Supply Chain Cybersecurity researchers have reported that dozens of Microsoft Visual Studio Code (VS Code) extensions on the Open VSX repository have been linked to a persistent information theft campaign called GlassWorm. A cluster of 73 extensions has been confirmed to be cloned versions of legitimate extensions. Six of these are […]

Fake CAPTCHA IRSF scam and 120 Keitaro campaign triggers global SMS, crypto fraud

Cybersecurity researchers have revealed details of a telecom fraud campaign that uses fake CAPTCHA verification tricks to trick unsuspecting users into sending international text messages, charging them to their cell phone bills and generating illegal revenue for attackers who lease phone numbers. The operation is believed to have been active since at least June 2020, […]

Researchers discover pre-Stuxnet ‘fast16’ malware targeting engineering software

Cybersecurity researchers have discovered new Lua-based malware that was created several years before the infamous Stuxnet worm, which was aimed at disrupting Iran’s nuclear program by sabotaging uranium enrichment centrifuges. A previously undocumented cyber sabotage framework dates back to 2005 and primarily targeted high-precision calculation software to falsify results, according to a new report published […]

CISA adds four exploited flaws to KEV, sets federal deadline for May 2026

Ravi LakshmananApril 25, 2026Network security/infrastructure security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added four vulnerabilities affecting SimpleHelp, Samsung MagicINFO 9 Server, and D-Link DIR-823X series routers to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The list of vulnerabilities is below – CVE-2024-57726 (CVSS Score: 9.9) – A […]

FIRESTARTER backdoor hits federal Cisco Firepower devices, survives security patch

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has disclosed that Cisco Firepower devices at an unnamed federal civilian agency running Adaptive Security Appliance (ASA) software were compromised by malware known as FIRESTARTER in September 2025. According to CISA and the UK National Cyber ​​Security Center (NCSC), FIRESTARTER has been assessed as a backdoor designed […]

NASA employees fall for Chinese phishing scam targeting US defense software

Ravi LakshmananApril 24, 2026Espionage/National Security; NASA’s Office of Inspector General (OIG) has revealed how Chinese nationals posed as U.S. researchers as part of a spear-phishing campaign to obtain sensitive information from space agencies, government agencies, universities, and private companies in violation of export control laws. “For years, NASA employees and research collaborators believed they were […]

Continuous observability as a decision engine

The AI ​​agent authority gap – from non-governance to delegation As we discussed in a previous article, AI agents are exposing structural gaps in enterprise security, but the problem is often viewed very narrowly. The problem is not simply that agents are new subjects. That means agents are delegated actors. They do not emerge with […]

26 FakeWallet apps targeting crypto seed phrases found in Apple App Store

Cybersecurity researchers have discovered a series of malicious apps in the Apple App Store that impersonate popular cryptocurrency wallets and attempt to steal recovery phrases and private keys since at least the fall of 2025. “When launched, these apps redirect users to a browser page that resembles the App Store and distribute Trojanized versions of […]

Tropic Trooper deploys AdaptixC2 using Trojanized SumatraPDF and GitHub

Ravi LakshmananApril 24, 2026Malware/Threat Intelligence Chinese-speaking individuals have been targeted in a new campaign that uses a trojanized version of the SumatraPDF reader to deploy the AdaptixC2 Beacon post-exploitation agent and ultimately facilitate the exploitation of Microsoft Visual Studio Code (VS Code) tunnels for remote access. Zscaler ThreatLabz, which discovered the campaign last month, says […]