Don’t let myths run. But Claude is already in Salesforce

When Kevin Roos of the New York Times described Project Glasswing as a frontier AI model “more powerful than Anthropic has released to the public,” he wasn’t sensationalizing. That’s the correct reading. Anthropic built something so capable that they decided the responsible thing to do was to gate it behind a coalition of 50 organizations […]
Contextual AI hack-related Vercel breach exposes limited customer credentials

Ravi LakshmananApril 20, 2026Cloud security/data breach Web infrastructure provider Vercel has disclosed a security breach that allowed malicious parties to gain unauthorized access to “certain” Vercel internal systems. The incident stemmed from a breach of Context.ai, a third-party artificial intelligence (AI) tool used by the company’s employees. “The attacker used that access to take over […]
$13.74 million hack shuts down authorized Grinex exchange after tip-off

Ravi LakshmananApril 18, 2026Money laundering/regulatory compliance Kyrgyz-based crypto exchange Greenex, which was sanctioned by the UK and US last year, blamed Western intelligence agencies for a $13.74 million hack and announced it would cease operations. The exchange announced that it had suffered a large-scale cyber attack indicating the involvement of foreign intelligence agencies. The attack […]
Mirai Variant Nexcorium exploits CVE-2024-3721 to hijack TBK DVR and attack DDoS botnet

Ravi LakshmananApril 18, 2026IoT security/vulnerabilities According to research from Fortinet FortiGuard Labs and Palo Alto Networks Unit 42, threat actors are exploiting security flaws in TBK DVRs and End of Life (EoL) TP-Link Wi-Fi routers to deploy Mirai botnet variants on compromised devices. The attack targeting TBK DVR devices was found to exploit CVE-2024-3721 (CVSS […]
Three Microsoft Defender zero-days were actively exploited. 2 are not yet patched

Ravi LakshmananApril 17, 2026Vulnerabilities / Endpoint Security Huntress warns that attackers are exploiting three recently disclosed security flaws in Microsoft Defender to gain elevated privileges on compromised systems. This activity included exploitation of three vulnerabilities codenamed BlueHammer (GitHub sign-in required), RedSun, and UnDefend, all of which were released as zero-days by researchers known as Chaotic […]
Google to block 8.3 billion policy-violating ads in 2025, launches complete privacy review of Android 17

Google this week announced a series of new updates to its Play policies to strengthen user privacy and protect businesses from fraud, but also revealed that it will block or remove more than 8.3 billion ads and suspend 24.9 million accounts worldwide in 2025. The new policy update is related to Android contacts and location […]
NIST limits CVE enrichment after vulnerability submissions spike by 263%

Ravi LakshmananApril 17, 2026Vulnerability management The National Institute of Standards and Technology (NIST) announced changes to how it handles cybersecurity vulnerabilities and exposures (CVEs) listed in the National Vulnerability Database (NVD), saying that due to a sharp increase in CVE submissions, it will enrich only those that meet certain criteria. “CVEs that do not meet […]
Operation PowerOFF seizes 53 DDoS domains and exposes 3 million criminal accounts

Ravi LakshmananApril 17, 2026DDoS/Cybercrime An international law enforcement operation resulted in the closure of 53 domains and four arrests in connection with a commercial distributed denial of service (DDoS) operation used by more than 75,000 cybercriminals. An ongoing effort dubbed “Operation PowerOFF” has disrupted access to the DDoS rental service, taken down the technical infrastructure […]
Apache ActiveMQ CVE-2026-34197 added to CISA KEV amid active exploitation

Ravi LakshmananApril 17, 2026Vulnerabilities / Enterprise Security According to the US Cybersecurity and Infrastructure Security Agency (CISA), a recently disclosed high-severity security flaw in Apache ActiveMQ Classic is being exploited in the wild. To that end, the agency is adding this vulnerability, tracked as CVE-2026-34197 (CVSS score: 8.8), to its Known Exploited Vulnerabilities (KEV) catalog […]
Newly discovered PowMix botnet uses randomized C2 traffic to attack Czech workers

Ravi LakshmananApril 16, 2026Botnet/Cryptomining Cybersecurity researchers have warned that a previously undocumented botnet called PowMix has been active in a malicious campaign targeting workers in the Czech Republic since at least December 2025. “PowMix employs randomized command and control (C2) beacon intervals rather than persistent connections to C2 servers to evade detection of network signatures,” […]