Axios supply chain attack pushes cross-platform RAT via compromised npm account

The popular HTTP client known as Axios came under supply chain attack after a malicious dependency was introduced in two newly published versions of npm packages. Axios versions 1.14.1 and 0.30.4 were found to inject “plain-crypto-js” version 4.2.1 as a bogus dependency. According to StepSecurity, these two versions were published using compromised npm credentials of […]

OpenAI fixes ChatGPT data extraction flaw and Codex GitHub token vulnerability

New research from Check Point reveals a previously unknown vulnerability in OpenAI ChatGPT that could allow sensitive conversation data to be exposed without the user’s knowledge or consent. “A single malicious prompt can turn a normal conversation into a secret exfiltration channel, exposing users’ messages, uploaded files, and other sensitive content,” the cybersecurity firm said […]

DeepLoad malware uses ClickFix and WMI persistence to steal browser credentials

Ravi LakshmananMarch 30, 2026Threat Intelligence/Browser Security The new campaign utilizes ClickFix social engineering tactics as a method to distribute a previously undocumented malware loader called DeepLoad. “While likely using AI-assisted obfuscation and process injection to evade static scans, credential theft begins quickly, capturing passwords and sessions even if the primary loader is blocked,” ReliaQuest researchers […]

Telecom Sleeper Cells, LLM Jailbreaks, Apple Forces U.K. Age Checks and More

Ravie LakshmananMar 30, 2026Cybersecurity / Hacking Some weeks are loud. This one was quieter but not in a good way. Long-running operations are finally hitting courtrooms, old attack methods are showing up in new places, and research that stopped being theoretical right around the time defenders stopped paying attention. There’s a bit of everything this […]

3 SOC Process Fixes to Unlock Tier 1 Productivity

Is it the threat itself or the processes surrounding the threat that are actually slowing down Tier 1? For many SOCs, the biggest delays are not caused by threats alone. These result from fragmented workflows, manual triage steps, and limited visibility early in the investigation. Correcting these process gaps will help Tier 1s move faster, […]

Secrecy Sprawl in 2026: 9 Points for CISOs

The proliferation of sensitive information continues, accelerating faster than most security teams expected in 2025. GitGuardian’s State of Secrets Sprawl 2026 report analyzed billions of commits across public GitHub and uncovered 29 million new hard-coded secrets in 2025 alone. This is a 34% increase over the previous year and the largest single-year increase ever. This […]

Russian CTRL toolkit delivered via malicious LNK file hijacks RDP via FRP tunnel

Ravi LakshmananMarch 30, 2026Malware/Network Security Cybersecurity researchers have discovered a Russian-originated remote access toolkit distributed via malicious Windows Shortcuts (LNK) files disguised as private key folders. According to Censys, the CTRL toolkit is custom-built using .NET and includes a variety of executables that facilitate credential phishing, keylogging, Remote Desktop Protocol (RDP) hijacking, and reverse tunneling […]

Three China-linked clusters target Southeast Asian governments in 2025 cyberattacks

Ravi LakshmananMarch 30, 2026Threat Intelligence/Network Intrusion Three China-aligned threat activity clusters targeted government agencies in Southeast Asia as part of a “complex and well-funded operation.” This campaign introduced various malware families including HIUPAN (aka USBFect, MISTCLOAK, or U2DiskWatch), PUBLOAD, EggStremeFuel (aka RawCookie), EggStremeLoader (aka Gorem RAT), MASOL RAT, PoshRAT, TrackBak Stealer, RawCookie, Hypnosis Loader, and […]