Over 1,000 exposed ComfyUI instances targeted by cryptomining botnet campaign

We have observed an active campaign targeting internet-exposed instances running ComfyUI, a popular and stable distribution platform, to participate in cryptocurrency mining and proxy botnets. “A dedicated Python scanner continuously sweeps across key cloud IP ranges looking for vulnerable targets and automatically installs malicious nodes via ComfyUI-Manager if exploitable nodes are not already present,” Censys […]
[Webinar] How to close the identity gap in 2026 before AI exploits enterprise risks

hacker newsApril 7, 2026SaaS Security / Enterprise Security The rapidly evolving threat landscape of 2026 has revealed a frustrating paradox for CISOs and security leaders. The bottom line is that even as identity programs mature, the risks are actually increasing. Hundreds of applications within a typical enterprise remain disconnected from central identity systems, according to […]
The hidden cost of repeated credential incidents

When we talk about credential security, the focus is usually on preventing breaches. This makes sense, as IBM’s 2025 Cost of Data Breach Report puts the average cost of a breach at $4.4 million. Avoiding even one major incident is enough to justify most security investments, but this headline number obscures a more persistent problem […]
New GPUBreach attack enables full CPU privilege escalation via GDDR6 bitflip

New academic research has identified multiple RowHammer attacks against high-performance graphics processing units (GPUs) that can be exploited to escalate privileges and, in some cases, take complete control of the host. The efforts are codenamed GPUBreach, GDDRHammer, and GeForge. GPUBreach goes a step further than GPUHammer by demonstrating for the first time that RowHammer bitflips […]
China-linked Storm-1175 exploits zero-day to rapidly deploy Medusa ransomware

Ravi LakshmananApril 7, 2026Vulnerability/Threat Intelligence China-based threat actors known for deploying Medusa ransomware are said to be involved in weaponizing a combination of zero-day and N-day vulnerabilities to orchestrate “high-velocity” attacks and compromise vulnerable internet-connected systems. The Microsoft Threat Intelligence team said, “Due to the attackers’ high operational tempo and proficiency in identifying exposed perimeter […]
Flowise AI Agent Builder under active CVSS 10.0 RCE exploitation. Over 12,000 instances exposed

Ravi LakshmananApril 7, 2026Artificial intelligence/vulnerabilities Threat actors are exploiting maximum-severity security flaws in Flowise, an open-source artificial intelligence (AI) platform, according to new findings from VulnCheck. The vulnerability in question is CVE-2025-59528 (CVSS score: 10.0), a code injection vulnerability that may allow remote code execution. In an advisory released in September 2025, Flowise states, “The […]
Iran-linked password dissemination campaign targets more than 300 Israeli Microsoft 365 organizations

As conflict continues in the Middle East, Iranian-linked attackers are suspected to be behind a password dissemination campaign targeting Microsoft 365 environments in Israel and the United Arab Emirates. According to Check Point, this activity is assessed as ongoing and carried out in three separate attack waves that occurred on March 3, 2026, March 13, […]
North Korea-linked hackers use GitHub as C2 in multi-stage attack targeting South Korea

Ravi LakshmananApril 6, 2026Malware/Threat Intelligence Threat actors believed to be affiliated with the Democratic People’s Republic of Korea (DPRK) have been observed using GitHub as a command and control (C2) infrastructure in multi-stage attacks targeting organizations in South Korea. According to Fortinet FortiGuard Labs, the attack chain includes an obfuscated Windows shortcut (LNK) file that […]
How SOCs solve critical risks in three steps

The attack surface no longer exists on a single operating system, nor are the campaigns targeting it. In enterprise environments, attackers move Windows endpoints, executive MacBooks, Linux infrastructure, and mobile devices, taking advantage of the fact that many SOC workflows are still fragmented by platform. For security leaders, this creates a costly operational gap. This […]
Axios Hack, Chrome 0-Day, Fortinet Exploits, Paragon Spyware and More

Ravie LakshmananApr 06, 2026Cybersecurity / Hacking This week had real hits. The key software got tampered with. Active bugs showed up in the tools people use every day. Some attacks didn’t even need much effort because the path was already there. One weak spot now spreads wider than before. What starts small can reach a lot of systems fast. New bugs, faster […]