Flaw in Claude extension enabled zero-click XSS prompt injection via arbitrary websites

Ravi LakshmananMarch 26, 2026Browser security/vulnerabilities Cybersecurity researchers have revealed a vulnerability in Anthropic’s Claude Google Chrome extension that could be exploited to display a malicious prompt simply by visiting a web page. The flaw “allowed any website to silently insert a prompt into its assistant, as if the user had written the prompt,” Koi Security […]
How hackers and art forgers perfected the art of deception

Unmasking fraudsters is a challenge the art world has faced for decades, and Ermil de Holy’s work offers valuable lessons that can be applied to the world of defensive cybersecurity. In the 1960s, de Hory gained notoriety as a leading forger, passing masterpiece forgeries by Picasso, Matisse, and Renoir to unsuspecting collectors and prestigious museums. […]
PQC Push, AI Vuln Hunting, Pirated Traps, Phishing Kits & 20 More Stories

Ravie LakshmananMar 26, 2026Cybersecurity / Hacking News Some weeks in security feel loud. This one feels sneaky. Less big dramatic fireworks, more of that slow creeping sense that too many people are getting way too comfortable abusing things they probably shouldn’t even be touching. There’s a little bit of everything in this one, too. Weird […]
Coruna iOS Kit reuses 2023 Triangulation exploit code in new mass attack

Ravi LakshmananMarch 26, 2026Malware/Mobile Security New findings from Kaspersky Lab show that the recently discovered kernel exploits for two security vulnerabilities used in the Apple iOS exploit kit Coruna are updated versions of the same exploits used in the 2023 Operation Triangulation campaign. “When Coruna was first reported, the publicly available evidence was not enough […]
[Webinar] Stop guessing. Learn how to test your defenses against real attacks

hacker newsMarch 26, 2026Security testing/security automation Most teams have security tools in place. Alerts are firing, dashboards are looking clean, and threat information is flowing in. On the surface, everything feels like it’s under control. But there’s one question that usually doesn’t have an answer. The question is, can your defense actually stop an actual […]
WebRTC Skimmer bypasses CSP and steals payment data from e-commerce sites

Ravi LakshmananMarch 26, 2026Malware/Web Security Cybersecurity researchers have discovered a new payment skimmer that uses WebRTC data channels as a means to receive payloads and leak data, effectively bypassing security controls. “Instead of regular HTTP requests or image beacons, this malware uses WebRTC data channels to load its payload and exfiltrate stolen payment data,” Sansec […]
LeakBase administrator arrested in Russia over massively stolen credentials marketplace

Ravi LakshmananMarch 25, 2026Cybercrime/Dark Web The alleged administrator of the cybercrime forum Leakbase has been arrested by Russian law enforcement authorities, state media reported on Thursday. According to TASS news agency and MVD Media, a news website affiliated with Russia’s Ministry of Internal Affairs, the suspect is a resident of the city of Taganrog. The […]
GlassWorm malware uses Solana Dead Drops to deliver RAT and steal browser and encrypted data

Ravi LakshmananMarch 25, 2026Browser security/threat intelligence Cybersecurity researchers have warned of a new evolution in the GlassWorm campaign. The campaign provides a multi-stage framework capable of comprehensive data theft and installation of a remote access trojan (RAT) that deploys an information-stealing Google Chrome extension disguised as an offline version of Google Docs. “It logs keystrokes, […]
When AI agents are a threat, kill chains become obsolete

In September 2025, Anthropic revealed that state-sponsored threat actors used AI-coding agents to conduct autonomous cyber espionage against 30 targets around the world. The AI handled 80-90% of tactical operations on its own, performing reconnaissance, writing exploit code, and attempting lateral movement at machine speeds. While this incident is alarming, there are scenarios that should […]
Russian hacker sentenced to two years in prison for ransomware attack led by TA551 botnet

hacker newsMarch 25, 2026Cybercrime/Ransomware The US Department of Justice (DoJ) announced that a Russian national has been sentenced to two years in prison for managing a botnet used to launch ransomware attacks against US companies. Ilya Angelov, 40, of Tolyatchi, Russia, was also fined $100,000. Angelov, who operated under the online aliases Milano and Occult, […]