The 3 Steps CISOs Must Follow

Every CISO knows the uncomfortable truth about their Security Operations Center: the people most responsible for catching threats in real time are the people with the least experience. Tier 1 analysts sit at the front line of detection, and yet they are also the most vulnerable to the cognitive and organizational pressures that quietly erode […]
Open Source CyberStrikeAI Deploys AI-Driven FortiGate Attacks in 55 Countries

Ravi LakshmananMarch 3, 2026Vulnerability / Artificial Intelligence The attackers behind the recently revealed artificial intelligence (AI)-assisted campaign targeting Fortinet’s FortiGate appliances leveraged an open-source AI-native security testing platform called CyberStrikeAI to carry out the attack. This new discovery is attributed to Team Cymru, whose use was detected after analyzing the IP address (‘212.11.64’).[.]250″) was used […]
AI Agents: The Next Wave of Identity Dark Matter

The rise of MCP in the enterprise Model Context Protocol (MCP) is rapidly becoming a practical way to move LLM from “chat” to real work. By providing structured access to applications, APIs, and data, MCP enables prompt-driven AI agents that can retrieve information, take actions, and automate end-to-end business workflows across the enterprise. This is […]
Starkiller phishing suite uses AitM reverse proxy to bypass multi-factor authentication

Cybersecurity researchers have revealed details of a new phishing suite called Starkiller that bypasses multi-factor authentication (MFA) protections by proxying legitimate login pages. It is promoted as a cybercrime platform by a threat group calling itself Jinkusu, and customers are given access to a dashboard where they can select brands to impersonate and enter the […]
Microsoft warns that OAuth redirect abuse can deliver malware to government targets

Ravi LakshmananMarch 3, 2026Phishing/Malware Microsoft on Monday warned of phishing campaigns that utilize phishing emails and OAuth URL redirection mechanisms to bypass traditional phishing defenses implemented in email and browsers. The company says the campaign targets government and public sector organizations, and the ultimate goal is to redirect victims to attacker-controlled infrastructure without stealing their […]
Google confirms CVE-2026-21385 in Qualcomm Android component has been exploited

Ravi LakshmananMarch 3, 2026Vulnerabilities / Mobile Security Google on Monday revealed that a high-severity security flaw affecting an open-source Qualcomm component used in Android devices was exploited. The vulnerability in question is CVE-2026-21385 (CVSS score: 7.8), which is a buffer overread in the graphics component. “Adding user-specified data without checking available buffer space will corrupt […]
SloppyLemming uses dual malware chain to target Pakistan and Bangladesh governments

Ravi LakshmananMarch 3, 2026Malware/phishing The threat activity cluster known as SloppyLemming is believed to be the result of new attacks targeting government agencies and critical infrastructure operators in Pakistan and Bangladesh. According to Arctic Wolf, this activity occurred between January 2025 and January 2026. This activity involves the use of two different attack chains delivering […]
New Chrome vulnerability allows malicious extension to escalate privileges via Gemini panel

Ravi LakshmananMarch 2, 2026Vulnerability / Artificial Intelligence Cybersecurity researchers have detailed a patched security flaw in Google Chrome that could allow an attacker to escalate privileges and access local files on the system. This vulnerability is tracked as CVE-2026-0628 (CVSS score: 8.8) and is described as a case of insufficient policy enforcement of the WebView […]
Google develops Merkle tree certificate to enable quantum-proof HTTPS in Chrome

Ravi LakshmananMarch 2, 2026Encryption/Browser Security Google has announced a new program in its Chrome browser that ensures HTTPS certificates are secure against future risks posed by quantum computers. “To ensure ecosystem scalability and efficiency, Chrome has no immediate plans to add traditional X.509 certificates, including post-quantum cryptography, to the Chrome root store,” the Chrome Secure […]
SD-WAN 0-Day, Critical CVEs, Telegram Probe, Smart TV Proxy SDK and More

Ravie LakshmananMar 02, 2026Cybersecurity / Hacking This week is not about one big event. It shows where things are moving. Network systems, cloud setups, AI tools, and common apps are all being pushed in different ways. Small gaps in access control, exposed keys, and normal features are being used as entry points. The pattern becomes […]