Microsoft warns that VBS malware distributed by WhatsApp can hijack Windows via UAC bypass

Ravi LakshmananApril 1, 2026Social engineering/malware Microsoft is warning of a new campaign that uses WhatsApp messages to distribute malicious Visual Basic Script (VBS) files. The campaign, which begins in late February 2026, utilizes these scripts to establish persistence and initiate a multi-step infection chain to enable remote access. At this time, it is unclear what […]

Casbaneiro Phishing targets Latin America and Europe using dynamic PDF lures

Ravi LakshmananApril 1, 2026Malware / Windows Security The multi-pronged phishing campaign targets Spanish-speaking users within organizations in Latin America and Europe, delivering Windows banking Trojans like Casbaneiro (also known as Metamorfo) via another piece of malware called Horabot. This activity is believed to be the work of Brazilian cybercrime threat actors tracked as Augmented Marauder […]

New Chrome zero-day CVE-2026-5281 in active exploitation – patch released

Ravi LakshmananApril 1, 2026Vulnerabilities / Browser security Google on Thursday released security updates for its Chrome web browser that address 21 vulnerabilities, including a zero-day flaw that the company says is being exploited in the wild. High severity vulnerability CVE-2026-5281 (CVSS score: N/A) involves a use-after-free bug in Dawn, an open source and cross-platform implementation […]

3 Reasons Why Attackers Will Use Trusted Tools Against You (And Why You Don’t See It Coming)

For years, cybersecurity has followed the familiar model of blocking malware and thwarting attacks. Now, attackers are moving on to their next attack. Threat actors now use malware less frequently in favor of what is already present in the environment. This includes abusing trusted tools, native binaries, and legitimate administrative utilities to move laterally, escalate […]

Google attributes Axios npm supply chain attack to North Korean group UNC1069

Ravi LakshmananApril 1, 2026Threat Intelligence/Software Security Google has officially attributed a supply chain breach of the popular Axios npm package to a cluster of financially motivated North Korean threat operations tracked as UNC1069. “We believe this attack was the work of a suspected North Korean threat actor, which we track as UNC1069,” John Hultquist, principal […]

Claude code source leaked via npm packaging error, confirmed by Anthropic

Ravi LakshmananApril 1, 2026Data Breach/Artificial Intelligence Anthropic on Tuesday admitted that the internal code of its popular artificial intelligence (AI) coding assistant, Claude Code, was accidentally released due to human error. “No sensitive customer data or credentials were involved or exposed,” an Anthropic spokesperson said in a statement shared with CNBC News. “This is a […]

Android developer verification rollout begins ahead of September enforcement

Ravi LakshmananMarch 31, 2026Mobile security/compliance Google announced Monday that it will officially roll out Android Developer Certification to all developers to address the problem of bad actors distributing harmful apps “hiding behind anonymity.” The development comes ahead of verification obligations due to come into force in Brazil, Indonesia, Singapore and Thailand next September, before being […]

TrueConf zero-day exploited to attack Southeast Asian government networks

Ravi LakshmananMarch 31, 2026Zero-day/vulnerabilities A high-severity security flaw in TrueConf client video conferencing software was exploited as a zero-day as part of a campaign targeting government agencies in Southeast Asia called TrueChaos. The vulnerability in question, CVE-2026-3502 (CVSS score: 7.8), is a lack of integrity checks when retrieving application update code, which could allow an […]

Vertex AI vulnerability exposes Google Cloud data and private artifacts

Ravi LakshmananMarch 31, 2026Cloud security / AI security Cybersecurity researchers have revealed security “blind spots” in Google Cloud’s Vertex AI platform that could allow artificial intelligence (AI) agents to be weaponized by attackers to gain unauthorized access to sensitive data and compromise an organization’s cloud environment. According to Palo Alto Networks Unit 42, this issue […]

Silver Fox uses AtlasCross RAT and fake domains to scale Asian cyber campaign

Chinese-speaking users are the target of an active campaign that uses typosquatted domains to impersonate trusted software brands to distribute a previously undocumented remote access Trojan named AtlasCross RAT. “The operation targeted VPN clients, encrypted messengers, video conferencing tools, cryptocurrency trackers, and e-commerce applications, with 11 identified distribution domains impersonating brands including Surfshark VPN, Signal, […]