Qualcomm 0-Day, iOS Exploit Chains, AirSnitch Attack & Vibe-Coded Malware

Ravie LakshmananMar 09, 2026Cybersecurity / Hacking Another week in cybersecurity. Another week of “you’ve got to be kidding me.” Attackers were busy. Defenders were busy. And somewhere in the middle, a whole lot of people had a very bad Monday morning. That’s kind of just how it goes now. The good news? There were some […]

Can the security platform finally be delivered to the mid-market?

hacker newsMarch 9, 2026Endpoint security/security operations Mid-market organizations are constantly striving to achieve the same level of security as enterprise organizations. As awareness of supply chain attacks increases, customers and business partners are defining the security levels that must be met. What if you could easily prove that you meet these stringent security levels to […]

OpenClaw Security Crisis: Detecting AI Agent Risks

You’ve probably heard of OpenClaw. This open source AI agent quickly became one of the fastest growing repositories in GitHub’s history, gaining over 135,000 stars within a few weeks. However, this led to the first major AI agent security crisis of 2026. Reco helps you identify whether an AI agent is present in your environment. […]

Chrome extension turns malicious after ownership transfer, allowing code injection and data theft

Two Google Chrome extensions have become malicious after an apparent ownership transfer incident, providing attackers with the means to push malware downstream to customers, inject arbitrary code, and collect sensitive data. The extensions in question were both originally associated with a developer named “akshayanuonline@gmail.com” (BuildMelon) and are listed below. QuickLens – Google Lens search screen […]

CISO Executive Toolkit (Free Download)

What’s included? Get the five most widely used CISO resources in one place. Each asset is designed to solve real-world, recurring leadership challenges such as budgeting, team design, tool selection, best practice alignment, and board communication. Think of it as a ready-to-use toolkit that you can refer to all year long. CISO Budget Benchmarking SurveyUnderstand […]

Web server exploit and MimiKatz used in attacks targeting critical infrastructure in Asia

Ravi LakshmananMarch 9, 2026Threat Intelligence/Web Security High-value organizations in South Asia, Southeast Asia, and East Asia have been targeted by Chinese threat actors as part of a long-running campaign. This activity targets the aviation, energy, government, law enforcement, pharmaceutical, technology, and telecommunications sectors and has been attributed to a previously undocumented threat group known as […]

OpenAI Codex Security scans 1.2 million commits and finds 10,561 high-severity issues

Rabi LakshmananMarch 7, 2026DevSecOps / Artificial Intelligence OpenAI on Friday began deploying Codex Security, an artificial intelligence (AI)-powered security agent designed to discover, verify, and suggest fixes for vulnerabilities. This feature is available as a research preview to ChatGPT Pro, Enterprise, Business, and Edu customers via Codex Web and will be available for free next […]

Anthropic discovers 22 vulnerabilities in Firefox using Claude Opus 4.6 AI model

Rabi LakshmananMarch 7, 2026Browser security / artificial intelligence Anthropic announced Friday that it has discovered 22 new security vulnerabilities in its Firefox web browser as part of a security partnership with Mozilla. Of these, 14 were classified as severe, 7 were classified as moderate, and 1 was rated as low severity. This issue was resolved […]

Transparent Tribe uses AI to mass produce malware implants in campaign targeting India

Rabi LakshmananMarch 6, 2026Threat Intelligence/Cyber ​​Espionage Pakistan-aligned threat actors known as Transparent Tribe have become the latest hacking group to utilize artificial intelligence (AI)-powered coding tools to attack targets with various implants. According to new findings from Bitdefender, the campaign is designed to generate “a large number of mediocre implants” developed using lesser-known programming languages […]

Multi-stage VOID#GEIST malware that delivers XWorm, AsyncRAT, and Xeno RAT

Cybersecurity researchers have detailed a multi-stage malware campaign that uses batch scripts as a conduit to deliver various encrypted remote access Trojan (RAT) payloads for XWorm, AsyncRAT, and Xeno RAT. This stealth attack chain has been codenamed VOID#GEIST by Securonix Threat Research. At a high level, the obfuscated batch script is used to deploy a […]