Google fixes two active Chrome zero-days affecting Skia and V8

Ravi LakshmananMarch 13, 2026Browser security/vulnerabilities Google on Thursday released security updates for its Chrome web browser that address two high-severity vulnerabilities that have been reported to be exploited in the wild. Here is the list of vulnerabilities: CVE-2026-3909 (CVSS Score: 8.8) – An out-of-bounds write vulnerability in the Skia 2D graphics library allows remote attackers […]
9 CrackArmor flaws in Linux AppArmor allow route escalation and bypass container isolation

Ravi LakshmananMarch 13, 2026Linux / Vulnerabilities Cybersecurity researchers have uncovered multiple security vulnerabilities within the AppArmor module of the Linux kernel. These vulnerabilities can be exploited by unprivileged users to bypass kernel protections and escalate to root, compromising container isolation guarantees. The Qualys Threat Research Unit (TRU) has collectively codenamed these nine confusing sub-vulnerabilities CrackArmor. […]
Authorities disrupt SocksEscort proxy botnet exploiting 369,000 IPs in 163 countries

A court-sanctioned international law enforcement operation has dismantled a criminal agency service called SocksEscort that botnetized thousands of home routers around the world to commit large-scale fraud. “SocksEscort infected homes and small businesses’ internet routers with malware,” the U.S. Department of Justice (DoJ) said in a statement. “The malware allowed SocksEscort to direct internet traffic […]
Veeam patches 7 critical backup and replication flaws that could allow remote code execution

Ravi LakshmananMarch 13, 2026Vulnerabilities / Enterprise Security Veeam has released a security update that addresses multiple critical vulnerabilities in its backup and replication software that could allow remote code execution if successfully exploited. The vulnerabilities are: CVE-2026-21666 (CVSS score: 9.9) – Vulnerability that allows authenticated domain users to execute remote code on backup servers. CVE-2026-21667 […]
Rust-based VENON malware targets 33 Brazilian banks with credential-stealing overlay

Ravi LakshmananMarch 12, 2026Malware/Cybercrime Cybersecurity researchers have revealed details of a new banking malware written in Rust that targets users in Brazil. This is significantly different from other known Delphi-based malware families associated with the Latin American cybercrime ecosystem. The malware is designed to infect Windows systems and was first discovered last month, codenamed VENON […]
Hive0163 uses AI-assisted Slopoly malware for persistent access in ransomware attacks

Ravi LakshmananMarch 12, 2026Artificial intelligence/malware Cybersecurity researchers have revealed details of a suspected artificial intelligence (AI)-generated malware codenamed “Slopoly” used by a financially motivated attacker named Hive0163. “Although AI-generated malware like Slopoly is still relatively under the radar, it shows how easily threat actors can weaponize AI and develop new malware frameworks in a fraction […]
How to Scale Phishing Detection in Your SOC: 3 Steps for CISOs

Phishing has quietly turned into one of the hardest enterprise threats to expose early. Instead of crude lures and obvious payloads, modern campaigns rely on trusted infrastructure, legitimate-looking authentication flows, and encrypted traffic that conceals malicious behavior from traditional detection layers. For CISOs, the priority is now clear: scale phishing detection in a way that […]
OAuth Trap, EDR Killer, Signal Phishing, Zombie ZIP, AI Platform Hack & More

Ravie LakshmananMar 12, 2026Cybersecurity / Hacking News Another Thursday, another pile of weird security stuff that somehow happened in just seven days. Some of it is clever. Some of it is lazy. A few bits fall into that uncomfortable category of “yeah… this is probably going to show up in real incidents sooner than we’d […]
Attackers Don’t Just Send Phishing Emails. They Weaponize Your SOC’s Workload

The most dangerous phishing campaigns aren’t just designed to fool employees. Many are designed to exhaust the analysts investigating them. When a phishing investigation takes 12 hours instead of five minutes, the outcome can shift from a contained incident to a breach. For years, the cybersecurity industry has focused on the front door of phishing […]
Apple issues security update for older iOS devices targeted by Coruna WebKit exploit

Ravi LakshmananMarch 12, 2026Vulnerabilities/Malware Apple on Wednesday backported a fix to an older version of iOS, iPadOS, and macOS Sonoma after a security flaw was discovered to be used as part of the Coruna exploit kit. The vulnerability, tracked as CVE-2023-43010, is related to an unspecified vulnerability in WebKit that could lead to memory corruption […]