Self-propagating supply chain worm hijacks npm packages and steals developer tokens

Cybersecurity researchers have flagged a new set of packages that have been compromised by malicious parties to distribute a self-propagating worm that spreads through stolen developer npm tokens. The supply chain worm has been detected by both Socket and StepSecurity, and both companies are tracking the activity under the name CanisterSprawl because it used ICP […]

Harvester uses Microsoft Graph API to bring Linux GoGra backdoor to South Asia

Ravi LakshmananApril 22, 2026Cyber ​​espionage/malware The attacker, known as Harvester, is believed to have originated from a new Linux version of the GoGra backdoor, possibly introduced as part of an attack targeting organizations in South Asia. “This malware uses the legitimate Microsoft Graph API and Outlook mailboxes as covert command-and-control (C2) channels, allowing it to […]

Lotus Wiper Malware Destroys Venezuelan Energy Systems

Ravi LakshmananApril 22, 2026Malware/Critical Infrastructure Cybersecurity researchers have discovered a previously undocumented data wiper used in attacks targeting Venezuela between late last year and early 2026. According to Kaspersky Lab’s findings, this novel file wiper, called Lotus Wiper, was used in a destructive campaign targeting Venezuela’s energy and utilities sector. “The two batch scripts are […]

When cross-app permissions lead to risks

On January 31, 2026, researchers revealed that Moltbook, a social network built for AI agents, left its database widely available, exposing 35,000 email addresses and 1.5 million agent API tokens across 770,000 active agents. The more worrying part was in the private messages. Some of these conversations held clear-text third-party credentials, including OpenAI API keys, […]

Microsoft patches critical CVE-2026-40372 privilege escalation bug in ASP.NET Core

Ravi LakshmananApril 22, 2026Vulnerabilities/Encryption Microsoft has released an out-of-band update to address a security vulnerability in ASP.NET Core that could allow an attacker to escalate privileges. This vulnerability is tracked as CVE-2026-40372 and has a CVSS score of 9.1 out of 10.0. Severity is rated as Important. An anonymous researcher is credited with discovering and […]

New LOTUSLITE variant of Mustang Panda targets Indian banks and Korean policy world

Ravi LakshmananApril 22, 2026Cyber ​​espionage/malware Cybersecurity researchers have discovered a new variant of a known malware called LOTUSLITE distributed via themes related to the Indian banking sector. “The backdoor communicates with a dynamic DNS-based command and control server via HTTPS and supports remote shell access, file manipulation, and session management, indicating a continued set of […]

Cohere AI Terrarium sandbox flaw allows root code execution and container escape

Ravi LakshmananApril 22, 2026Vulnerabilities / Container Security A critical security vulnerability has been disclosed in a Python-based sandbox called Terrarium that could allow arbitrary code execution. This vulnerability is tracked as CVE-2026-5752 and is rated 9.3 on the CVSS scoring system. “A sandbox escape vulnerability in Terrarium could allow arbitrary code execution with root privileges […]

SystemBC C2 Server Reveals Over 1,570 Victims of Operation The Gentlemen Ransomware

Threat actors associated with The Gentlemen ransomware-as-a-service (RaaS) operations have been observed attempting to deploy a known proxy malware called SystemBC. A command and control (C2 or C&C) server linked to SystemBC uncovered a botnet with more than 1,570 victims, according to new research published by Check Point. “SystemBC establishes a SOCKS5 network tunnel within […]

22 BRIDGE:BREAK flaw exposes thousands of Lantronix and Silex serial IP converters

Ravi LakshmananApril 21, 2026Network security/vulnerabilities Cybersecurity researchers have identified 22 new vulnerabilities in popular models of serial-to-IP converters from Lantronix and Silex. These vulnerabilities could be exploited to hijack a susceptible device and alter data exchanged by the device. Forescout Research Vedere Labs has identified approximately 20,000 serial-to-Ethernet converters with the vulnerabilities, collectively codenamed BRIDGE:BREAK, […]

Ransomware negotiator pleads guilty to aiding and abetting 2023 BlackCat attack

Ravi LakshmananApril 21, 2026Insider Threat/Cybercrime A third person hired as a ransomware negotiator has pleaded guilty to conducting ransomware attacks against U.S. companies in 2023. Angelo Martino, 41, of Land O’Lakes, Florida, worked with the operators of BlackCat ransomware starting in April 2023 to help the electronic crime syndicate extract larger amounts of ransom money. […]