New Perseus Android banking malware monitors Notes app and extracts sensitive data

Ravi LakshmananMarch 19, 2026Malware/Mobile Security Cybersecurity researchers have uncovered a new Android malware family called Perseus that is actively distributed for device takeover (DTO) and financial fraud. Perseus builds on the foundations of Cerberus and Phoenix while evolving into a “more flexible and capable platform” for compromising Android devices through dropper apps distributed via phishing […]

How Ceros gives security teams visibility and control over their code

Security teams have spent years building identity and access controls for human users and service accounts. However, a new category of actors has quietly infiltrated most enterprise environments and operates completely outside of their control. Anthropic’s AI coding agent, Claude Code, is now running at scale across engineering organizations. It reads files, executes shell commands, […]

DarkSword iOS exploit kit uses 6 flaws, 3 zero-days to take over entire device

A new exploit kit for Apple iOS devices designed to steal sensitive data has been exploited by multiple attackers since at least November 2025, according to a report from Google Threat Intelligence Group (GTIG), iVerify, and Lookout. According to GTIG, multiple commercial surveillance vendors and suspected state-sponsored attackers utilized the full-chain exploit kit, codenamed DarkSword, […]

Warning of CISA, Zimbra, SharePoint flaw exploitation. Cisco’s zero-day hit in ransomware attacks

Ravi LakshmananMarch 19, 2026Network security/vulnerabilities The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has urged government agencies to patch two security flaws affecting Synacor Zimbra Collaboration Suite (ZCS) and Microsoft Office SharePoint, saying they are actively being exploited in the wild. The vulnerabilities in question are: CVE-2025-66376 (CVSS Score: 7.2) – A stored cross-site scripting […]

OFAC sanctions North Korean IT worker network for funding weapons of mass destruction program through fake remote jobs

The U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) has sanctioned six individuals and two entities for their involvement in the Democratic People’s Republic of Korea (DPRK) Information Technology (IT) Worker Program, which was designed to defraud U.S. companies and generate illicit proceeds to fund North Korea’s weapons of mass destruction (WMD) program. “The […]

Interlock ransomware exploits Cisco FMC Zero-Day CVE-2026-20131 to gain root access

Ravi LakshmananMarch 18, 2026Network security/ransomware Amazon Threat Intelligence is warning of an active Interlock ransomware campaign that exploits a recently revealed critical security flaw in Cisco Secure Firewall Management Center (FMC) software. The vulnerability in question, CVE-2026-20131 (CVSS score: 10.0), is a case of insecure deserialization of a user-supplied Java byte stream, which allows an […]

Get your threat model right

If the Magecart payload is hidden within the EXIF ​​data of a dynamically loaded third-party favicon, the malicious code never actually touches the repository and repository scanners cannot catch it. If your team employs Claude Code Security for static analysis, this is the exact technical boundary where AI code scanning stops and client-side runtime execution […]

9 critical IP KVM flaws allow unauthenticated root access across 4 vendors

Ravi LakshmananMarch 18, 2026Network security/vulnerabilities Cybersecurity researchers are warning of the risks posed by low-cost IP KVM (Keyboard, Video, Mouse Over Internet Protocol) devices. These devices can potentially give an attacker extensive control over a compromised host. The nine vulnerabilities discovered by Eclypsium span four different products: GL-iNet Comet RM-1, Angeet/Yeeso ES3 KVM, Sipeed NanoKVM, […]

How Mesh CSMA reveals and blocks attack vectors to Crown Jewel

Today’s security teams have no shortage of tools or data. They are overwhelmed by both. But amid terabytes of alerts, breaches, and misconfigurations, security teams still struggle to understand context. Q: What exposures, misconfigurations, and vulnerabilities chain together to create viable attack vectors for valuable attacks? Even the most mature security team has no easy […]

Bug in Ubuntu CVE-2026-3888 allows attackers to gain root by exploiting systemd cleanup timing

Ravi LakshmananMarch 18, 2026Linux / Endpoint security A high-severity security flaw affecting the default installation of Ubuntu Desktop versions 24.04 and later could be exploited to escalate privileges to the root level. This issue, tracked as CVE-2026-3888 (CVSS score: 7.8), could allow an attacker to gain control of a susceptible system. “This flaw (CVE-2026-3888) allows […]