New SparkCat variants of iOS, Android apps steal recovery phrase images from crypto wallets

Ravi LakshmananApril 3, 2026Mobile security/threat intelligence Cybersecurity researchers have discovered a new version of SparkCat malware on the Apple App Store and Google Play Store. It has been over a year since this Trojan was discovered targeting both mobile operating systems. The malware has been found hiding inside seemingly innocuous apps like enterprise messengers and […]

Drift loses $285 million in North Korea-related durable Nonce social engineering attack

Solana-based decentralized exchange Drift has admitted that attackers exfiltrated approximately $285 million from its platform during a security incident that occurred on April 1, 2026. “Earlier today, a malicious actor gained unauthorized access to the Drift protocol through a new attack involving a persistent nonce, resulting in a rapid takeover of Drift’s Security Council administrative […]

Hackers exploit CVE-2025-55182 to compromise 766 Next.js hosts and steal credentials

Ravi LakshmananApril 2, 2026Vulnerability/Threat Intelligence We have observed large-scale credential harvesting operations exploiting the React2Shell vulnerability as an initial infection vector to steal database credentials, SSH private keys, Amazon Web Services (AWS) secrets, shell command history, Stripe API keys, and GitHub tokens at scale. Cisco Talos attributes this operation to the threat cluster we track […]

Cisco Patch 9.8 CVSS IMC and SSM flaws allow remote systems to be compromised

Ravi LakshmananApril 2, 2026Network security/vulnerabilities Cisco has released an update that addresses a critical security flaw in the Integrated Management Controller (IMC). Successful exploitation of this flaw could allow an unauthenticated, remote attacker to bypass authentication and gain access to the system with elevated privileges. This vulnerability is tracked as CVE-2026-20093 and has a CVSS […]

Pre-Auth Chains, Android Rootkits, CloudTrail Evasion & 10 More Stories

Ravie LakshmananApr 02, 2026Cybersecurity / Hacking News The latest ThreatsDay Bulletin is basically a cheat sheet for everything breaking on the internet right now. No corporate fluff or boring lectures here, just a quick and honest look at the messy reality of keeping systems safe this week. Things are moving fast. The list includes researchers chaining small bugs together to […]

Researchers reveal mining operations using ISO lures to spread RATs and crypto miners

Ravi LakshmananApril 2, 2026Cryptomining/Malware A financially motivated operation codenamed REF1695 has been observed leveraging fake installers to deploy remote access trojans (RATs) and cryptocurrency miners since November 2023. “Beyond cryptomining, threat actors are monetizing infections through CPA (cost per action) fraud, directing victims to content locker pages under the guise of software registration,” Elastic Security […]

The State of Trusted Open Source Report

In December 2025, we shared the first-ever The State of Trusted Open Source report, featuring insights from our product data and customer base on open source consumption across our catalog of container image projects, versions, images, language libraries, and builds. These insights shed light on what teams pull, deploy, and maintain day to day, alongside the vulnerabilities and […]

Apple extends iOS 18.7.7 update to more devices to block DarkSword exploit

Ravi LakshmananApril 2, 2026Mobile security/vulnerabilities Apple on Wednesday expanded the availability of iOS 18.7.7 and iPadOS 18.7.7 to a wider range of devices to protect users from the risks posed by a recently released exploit kit known as DarkSword. “With iOS 18.7.7 available on more devices starting April 1, 2026, users who have automatic updates […]

CERT-UA impersonation campaign spreads AGEWHEEZE malware to 1 million emails

Ravi LakshmananApril 1, 2026Email security/artificial intelligence Ukraine’s Computer Emergency Response Team (CERT-UA) has revealed details of a new phishing campaign impersonating the cybersecurity agency itself to distribute a remote administration tool known as AGEWHEEZE. As part of the attack, the attacker, tracked as UAC-0255, sent emails impersonating CERT-UA on March 26 and 27, 2026, distributing […]