Six Android malware families target Pix payments, banking apps, and crypto wallets

Cybersecurity researchers have discovered six new Android malware families with the ability to steal data from compromised devices and commit financial fraud. Android malware ranges from traditional banking Trojans such as PixRevolution, TaxiSpy RAT, BeatBanker, Mirax, and Oblivion RAT to full-fledged remote administration tools such as SUXRAT. According to Zimperium, PixRevolution targets Brazil’s Pix instant […]

CISA reports active exploitation of n8n RCE bug as 24,700 instances remain exposed

Ravi LakshmananMarch 12, 2026Vulnerabilities / Enterprise Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical security flaw affecting n8n to its Known Exploited Vulnerabilities (KEV) catalog based on evidence of active exploitation. This vulnerability is tracked as CVE-2025-68613 (CVSS score: 9.9) and involves an expression injection case that could lead […]

Researchers trick Perplexity’s Comet AI browser into phishing scam in under 4 minutes

Ravi LakshmananMarch 11, 2026Artificial intelligence/browser security Agent web browsers that leverage artificial intelligence (AI) capabilities to autonomously perform actions across multiple websites on your behalf can be trained and tricked into falling prey to phishing and fraud traps. The core of the attack exploits the tendency of AI browsers to infer their behavior and use […]

Critical flaw in n8n could allow remote code execution and disclosure of stored credentials

Ravi LakshmananMarch 11, 2026 Vulnerabilities/Application Security Cybersecurity researchers have detailed two security flaws that have been patched in the n8n workflow automation platform. This includes two critical bugs that could lead to the execution of arbitrary commands. The vulnerabilities are listed below – CVE-2026-27577 (CVSS score: 9.4) – Expression sandbox escape leading to remote code […]

Meta disables 150,000 accounts linked to Southeast Asia fraud center in global crackdown

Ravi LakshmananMarch 11, 2026Cybercrime/Artificial Intelligence Meta announced on Wednesday that it has disabled more than 150,000 accounts associated with fraud centers in Southeast Asia as part of a coordinated effort with authorities in Thailand, the United States, the United Kingdom, Canada, South Korea, Japan, Singapore, the Philippines, Australia, New Zealand, and Indonesia. The company said […]

Dozens of vendors patch security flaws across enterprise software and network devices

Ravi LakshmananMarch 11, 2026Vulnerabilities / Enterprise Security SAP has released a security update that addresses two critical security flaws that can be exploited to execute arbitrary code on affected systems. The vulnerabilities in question are listed below – CVE-2019-17571 (CVSS score: 9.8) – Code injection vulnerability in SAP Quotation Management Insurance application (FS-QUO) CVE-2026-27685 (CVSS […]

What boards must demand in the age of automated AI abuse

“You knew and you could have acted, so why didn’t you act?” This is the question you don’t want to be asked. And in the aftermath of an incident, leaders are faced with an increasing number of questions to answer. For years, many executives and boards have treated large vulnerability backlogs as an unpleasant but […]

Microsoft patches 84 flaws (including 2 public zero-days) in March Patch Tuesday

Microsoft on Tuesday released patches for a set of 84 new security vulnerabilities affecting various software components, including two listed as publicly known. Of these, 8 are rated as “critical” and 76 are rated as “important.” Forty-six of the patched vulnerabilities are related to privilege escalation, followed by remote code execution (18), information disclosure (10), […]

UNC6426 Exploit nx npm supply chain attack to gain AWS administrator access within 72 hours

Ravi LakshmananMarch 11, 2026DevSecOps / AI Security The attacker, known as UNC6426, leveraged keys stolen after last year’s nx npm package supply chain breach to fully compromise victims’ cloud environments within 72 hours. The attack began with the theft of a developer’s GitHub token, which the threat actor used to gain unauthorized access to the […]

5 malicious Rust crates and AI bots exploit CI/CD pipelines to steal developer secrets

Cybersecurity researchers have discovered five malicious Rust crates that send .env file data to threat actors under the guise of time-related utilities. The Rust packages published on crates.io are: chrono_anchor dnp3times time_calibrator time_calibrators time-sync These crates impersonated timeapi.io on a per-socket basis and were published between late February and early March 2026. It has been […]