How to protect your SaaS from bot attacks using SafeLine WAF

Most SaaS teams remember the day their user traffic started to increase rapidly. Few people notice the day bots start targeting them. On paper, everything looks good: more signups, more sessions, more API calls. But in reality, something doesn’t feel right. Signups are increasing, but users aren’t activating. Server costs increase faster than revenue. Logs […]
APT28 is related to CVE-2026-21513 MSHTML 0-Day exploited before February 2026 Patch Tuesday

Ravi LakshmananMarch 2, 2026Vulnerability/Threat Intelligence New findings from Akamai reveal that a recently disclosed security flaw patched by Microsoft may have been exploited by a Russian-linked state-sponsored threat actor known as APT28. The vulnerability in question is CVE-2026-21513 (CVSS score: 8.8), a high-severity security feature bypass affecting the MSHTML framework. “A failure in the MSHTML […]
North Korean hackers publish 26 npm packages that hide cross-platform RAT Pastebin C2

Ravi LakshmananMarch 2, 2026Supply chain attacks/malware Cybersecurity researchers have revealed a new iteration of the ongoing Contagion Interview campaign. In this campaign, North Korean threat actors published a set of 26 malicious packages to the npm registry. Although these packages pose as developer tools, they contain the ability to use seemingly innocuous Pastebin content as […]
ClawJacked flaw allows malicious sites to hijack local OpenClaw AI agents via WebSockets

OpenClaw has fixed a high-severity security issue that, if successfully exploited, could allow a malicious website to connect to and take control of a locally running artificial intelligence (AI) agent. “Our vulnerability resides in the core system itself, with no plugins, marketplaces, or user-installed extensions, just a bare OpenClaw gateway that works as documented,” Oasis […]
Gemini Access exposes thousands of public Google Cloud API keys after API activation

New research reveals that Google Cloud API keys, typically designated as project identifiers for billing purposes, can be misused to authenticate sensitive Gemini endpoints and access private data. The findings come from Truffle Security, which discovered approximately 3,000 Google API keys (identified by the prefix “AIza”) embedded in client-side code to provide Google-related services such […]
Department of Defense designates human-induced supply chain risks surrounding AI military conflict

Ravi LakshmananFebruary 28, 2026National Security/Artificial Intelligence Anthropic Inc. fired back Friday after U.S. Secretary of Defense Pete Hegseth directed the Pentagon to designate artificial intelligence (AI) startups as a “supply chain risk.” “This action follows months of stalled negotiations over two exceptions we requested for the legal use of our AI model Claude: domestic mass […]
Department of Justice seizes $61 million in Tether linked to pig slaughtering crypto scam

Ravi LakshmananFebruary 27, 2026Financial crime/social engineering The US Department of Justice (DoJ) announced this week that it had seized $61 million worth of Tether allegedly linked to a fake cryptocurrency scheme known as Pig Butchering. The agency added that the seized funds were traced to a cryptocurrency address used to launder criminal proceeds stolen from […]
Ongoing web shell attack compromises over 900 Sangoma FreePBX instances

Ravi LakshmananFebruary 27, 2026Network security/vulnerabilities The Shadowserver Foundation revealed that more than 900 Sangoma FreePBX instances remain infected with web shells as part of an attack that exploits a command injection vulnerability starting in December 2025. Of these, 401 are in the United States, followed by 51 in Brazil, 43 in Canada, 40 in Germany, […]
Malicious Go crypto module steals passwords and deploys Rekoobe backdoor

Ravi LakshmananFebruary 27, 2026Malware / Linux Security Cybersecurity researchers have revealed details of a malicious Go module designed to harvest passwords, create persistent access via SSH, and distribute a Linux backdoor named Rekoobe. Go module, github[.]com/xinfeisoft/crypto impersonates the legitimate “golang.org/x/crypto” codebase, but injects malicious code into the remote endpoint that is responsible for leaking secrets […]
ScarCruft uses Zoho WorkDrive and USB malware to infiltrate air-gapped networks

Ravi LakshmananFebruary 27, 2026Malware/Surveillance The North Korean threat actor known as ScarCruft is said to be behind a new set of tools, including backdoors that use Zoho WorkDrive for command-and-control (C2) communications to retrieve more payloads, and implants that use removable media to relay commands and penetrate air-gapped networks. The campaign, codenamed “Ruby Jumper” by […]