Tough-torn hacking for hire campaign targets journalists in MENA region

The hacking-for-hire campaign, believed to be orchestrated by attackers with suspected ties to the Indian government, targeted journalists, activists, and government officials across the Middle East and North Africa (MENA), according to an investigation by Access Now, Lookout, and SMEX. Targets included prominent Egyptian journalists and government commentators Mostafa Al-Assal and Ahmed Eltantawi, who were […]
New Chaos variant targets misconfigured cloud deployments and adds SOCKS proxy

Ravi LakshmananApril 8, 2026Cryptomining/Network Security Cybersecurity researchers have warned of a new variant of malware called “Chaos” that can attack misconfigured cloud deployments, marking the expansion of infrastructure targeted by botnets. “Chaos malware is increasingly targeting misconfigured cloud deployments, expanding beyond its traditional focus on routers and edge devices,” Darktrace said in a new report. […]
Masjesu botnet launches as a rental DDoS service targeting IoT devices around the world

Ravi LakshmananApril 8, 2026IoT security/network security Cybersecurity researchers have lifted the curtain on a stealth botnet designed for distributed denial of service (DDoS) attacks. The botnet, called Masjesu, has been promoted as a rental DDoS service through Telegram since it first appeared in 2023. This botnet can target a wide range of IoT devices across […]
APT28 deploys PRISMEX malware in campaign targeting Ukraine and NATO allies

Ravi LakshmananApril 8, 2026Vulnerability / Cloud Security The Russian threat actor known as APT28 (also known as Forest Blizzard and Pawn Storm) is said to be involved in a new spear-phishing campaign targeting Ukraine and its allies, introducing a previously undocumented malware suite codenamed PRISMEX. “PRISMEX combines advanced steganography, Component Object Model (COM) hijacking, and […]
Reduce your IAM attack surface through the Identity Visibility and Intelligence Platform (IVIP)

The fragmented state of modern enterprise identity Enterprise IAM is nearing breaking point. As organizations grow, identities become increasingly fragmented across thousands of applications, distributed teams, machine identities, and autonomous systems. The result is identity dark matter. This is identity activity that is outside the visibility of centralized IAM and out of the reach of […]
Anthropic’s Claude Mythos discovers thousands of zero-day flaws across major systems

Ravi LakshmananApril 8, 2026Artificial intelligence/secure coding Artificial intelligence (AI) company Anthropic has announced a new cybersecurity initiative called Project Glasswing that uses a preview version of its new frontier model, Claude Mythos, to find and address security vulnerabilities. This model is used by Anthropic and smaller organizations such as Amazon Web Services, Apple, Broadcom, Cisco, […]
Korean hackers spread 1,700 malicious packages on npm, PyPI, Go, and Rust

A persistent North Korea-related campaign known as Contagious Interview has spread its tentacles by publishing malicious packages targeting the Go, Rust, and PHP ecosystems. “The threat actor’s package was designed to impersonate a legitimate developer tool.” […]”While silently acting as a malware loader, it extends Contagious Interview’s established strategy to coordinated supply chain operations across […]
Iran-linked hackers disrupt U.S. critical infrastructure by targeting PLCs exposed on the Internet

Iran-linked cyber attackers are targeting internet-connected operational technology (OT) devices across critical U.S. infrastructure, including programmable logic controllers (PLCs), cybersecurity and intelligence agencies warned Tuesday. “These attacks resulted in PLC degradation, display data manipulation, and in some cases business disruption and financial loss,” the Federal Bureau of Investigation (FBI) said in a post on X. […]
Russian state-affiliated APT28 exploits SOHO routers in global DNS hijacking campaign

The Russian-linked threat actor known as APT28 (also known as Forest Blizzard) is said to be involved in a new campaign to infiltrate and modify less secure MikroTik and TP-Link routers to take control of malicious infrastructure as part of a cyberespionage campaign since at least May 2025. This large-scale exploitation campaign, codenamed FrostArmada by […]
Docker CVE-2026-34040 allows attackers to bypass authentication and gain host access

Ravi LakshmananApril 7, 2026Vulnerabilities / DevSecOps A high-severity security vulnerability has been disclosed in Docker Engine that could allow an attacker to bypass the authentication plugin (AuthZ) under certain circumstances. This vulnerability, tracked as CVE-2026-34040 (CVSS score: 8.8), results from an incomplete remediation of CVE-2024-41110, the highest severity vulnerability in the same component that was […]