5 places mature SOCs keep their MTTR fast and other SOCs are wasting their time

Security teams often present MTTR as an internal KPI. Management has a different view. Every hour that a threat exists in your environment can result in data breaches, service interruptions, regulatory exposure, and brand damage. The root cause of slow MTTR is rarely a “lack of analysts.” It’s almost always the same structural problem: threat […]

How attackers get in through your front door via identity-based attacks

The cybersecurity industry has spent the last few years tracking advanced threats such as zero-days, supply chain breaches, and AI-powered exploits. However, the most reliable entry point for attackers remains the same. That’s credential theft. Identity-based attacks remain the primary initial access vector for breaches today. Attackers obtain valid credentials through stuffing credentials from previously […]

NGate campaign targets Brazil, trojanizes HandyPay to steal NFC data and PINs

Ravi LakshmananApril 21, 2026Mobile security/artificial intelligence Cybersecurity researchers have discovered a new version of an Android malware family called NGate. This version was found to be exploiting a legitimate application called HandyPay instead of NFCGate. “The attackers obtained an app used to relay NFC data and patched it with malicious code that appears to be […]

Google patches flaw in Anti-Gravity IDE that allows prompt injection code execution

Ravi LakshmananApril 21, 2026Vulnerability / Artificial Intelligence Cybersecurity researchers have discovered a vulnerability in Google’s agent integrated development environment (IDE), Antigravity, that could be exploited to execute code. Since being patched, the flaw combines Antigravity’s authorized file creation functionality with insufficient input sanitization in Antigravity’s native file search tool find_by_name to bypass the program’s strict […]

CISA adds 8 exploited flaws to KEV, sets federal deadline for April-May 2026

Ravi LakshmananApril 21, 2026Network security/threat intelligence The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added eight new vulnerabilities to its Known and Exploited Vulnerabilities (KEV) catalog, including three flaws affecting Cisco Catalyst SD-WAN Manager, citing evidence of active exploitation. Here is the list of vulnerabilities: CVE-2023-27351 (CVSS Score: 8.2) – An improper authentication […]

SGLang CVE-2026-5760 (CVSS 9.8) enables RCE via a malicious GGUF model file

Ravi LakshmananApril 20, 2026Open source/server security A critical security vulnerability has been disclosed in SGLang that, if successfully exploited, could lead to remote code execution on a susceptible system. This vulnerability is tracked as CVE-2026-5760 and has a CVSS score of 9.8 out of 10.0. This is described as a case of command injection leading […]

Vercel Hack, Push Fraud, QEMU Abused, New Android RATs Emerge & More

Ravie LakshmananApr 20, 2026Cybersecurity / Hacking Monday’s recap shows the same pattern in different places. A third-party tool becomes a way in, then leads to internal access. A trusted download path is briefly swapped to deliver malware. Browser extensions act normally while pulling data and running code. Even update channels are used to push payloads. […]

Why most AI deployments stop after the demo

hacker newsApril 20, 2026Artificial intelligence / privacy The quickest way to fall in love with an AI tool is to watch a demo. Everything goes quickly. Encourage a clean landing. This system produces impressive output in seconds. It feels like the beginning of a new era for the team. But most AI efforts don’t fail […]

Vulnerability in Anthropic MCP design allows RCE and threatens AI supply chain

Ravi LakshmananApril 20, 2026Artificial intelligence/vulnerabilities Cybersecurity researchers have discovered a critical “design” weakness in the Model Context Protocol (MCP) architecture. This could pave the way for remote code execution and have cascading effects on the artificial intelligence (AI) supply chain. “This flaw allows arbitrary command execution (RCE) on systems running vulnerable MCP implementations, giving attackers […]

Researchers detect ZionSiphon malware targeting Israeli water and desalination OT systems

Cybersecurity researchers have flagged new malware called ZionSiphon that appears to be specifically designed to target water treatment and desalination systems in Israel. The malware, codenamed ZionSiphon by Darktrace, highlights its ability to set persistence, modify local configuration files, and scan for operational technology (OT)-related services on local subnets. According to details from VirusTotal, this […]